DATA PROCESSING ADDENDUM

This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement, Order Form, or other written agreement addressing the same subject matter (the "Agreement") between Customer and Akto Io, Inc. ("Processor"), pursuant to which Processor provides software and related services (the "Services") to Customer.

This DPA governs the Processing of Personal Data by Processor on behalf of Customer in connection with the Services.

For purposes of this DPA, Customer shall act as Controller (or Processor, where applicable), and Akto Io, Inc. shall act as Processor (or Sub-processor, where applicable), solely to the extent Personal Data is Processed in connection with the Services.

Customer and Processor are each referred to herein as a "Party" and collectively as the "Parties".

1. DEFINITIONS

For purposes of this DPA:

2. PURPOSE AND SCOPE

Processor shall Process Personal Data only as reasonably necessary to:

Processor shall not:

For clarity, nothing in this DPA shall restrict Processor’s rights under the Agreement to create, use, retain, and process Usage Data, Derived Data, AI Technology, provided that Processor does not disclose Personal Data in raw identifiable form except as permitted under the Agreement, this DPA, or applicable law.

3. CUSTOMER OBLIGATIONS

Customer represents and warrants that:

Customer shall promptly notify Processor of:

4. PROCESSOR OBLIGATIONS

Processor shall:

Where Customer’s requests for assistance are manifestly unfounded or excessive (in particular because of their repetitive character), Processor may charge a reasonable fee based on documented administrative costs, or may decline to act on such requests. Processor shall notify Customer in writing before imposing any such fee. This clause does not limit Processor’s obligation to assist with requests that are required as a result of Processor’s own breach of this DPA.

4A. DATA PROTECTION IMPACT ASSESSMENTS

Where Customer determines that a Data Protection Impact Assessment (DPIA) is required under applicable Data Protection Laws in connection with the Services, Processor shall, upon Customer's reasonable written request:

DPIA assistance requests shall be limited to one (1) per calendar year, except where legally required. Customer shall bear the costs of DPIA assistance, except where the DPIA is required primarily as a result of Processor's material breach of this DPA, in which case Processor shall bear its own costs. All DPIA assistance is subject to the confidentiality obligations in Section 5.

5. CONFIDENTIALITY

Processor shall ensure that personnel authorized to Process Personal Data:

Confidentiality obligations survive termination of this DPA for as long as Personal Data is retained.

6. SECURITY MEASURES

Processor shall maintain commercially reasonable administrative, technical, physical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, loss, or destruction.

Security measures include, where applicable:

Processor may update security measures from time to time, provided such updates do not materially diminish the overall security posture of the Services. Where Processor makes a material adverse change that materially diminishes such security posture, Processor shall provide commercially reasonable notice to Customer where required under the Agreement or applicable Data Protection Laws.

7. AUDIT RIGHTS

Processor shall provide its most recent SOC 2 Type II report (or ISO 27001 certification or equivalent third-party audit report) to Customer upon written request, subject to a mutual non-disclosure agreement. Provision of such report shall constitute primary satisfaction of Customer’s audit rights under this DPA absent a specific documented concern that such report does not address.

Upon reasonable written request not more than once annually (except where legally required following a confirmed security incident), Processor shall make available information reasonably necessary to demonstrate compliance with this DPA, including:

Processor shall provide standard, generally available documentary compliance information (including SOC 2 reports and security summaries) at no charge to Customer. Customer shall be responsible for reimbursing Processor's reasonable costs and expenses for extraordinary assistance, custom responses, repeated requests or onsite audit assistance as set out below.

Onsite audits shall only be permitted where legally required or where documentary information is reasonably insufficient. Any onsite audit shall:

8. INTERNATIONAL DATA TRANSFERS

Where Processing involves transfer of Personal Data outside a jurisdiction that restricts such transfer, the Parties shall rely on lawful transfer mechanisms, including where applicable:

Where the EU Standard Contractual Clauses (Commission Decision 2021/914), the UK International Data Transfer Addendum, or any equivalent lawful transfer mechanism applies to a transfer of Personal Data under this DPA, such clauses are hereby incorporated by reference into this DPA and deemed executed by the Parties as of the effective date of the Agreement. Annex I, Annex II, and Annex III of this DPA shall serve as the corresponding Annex I, Annex II, and Annex III to such clauses, as applicable. In the event of any conflict between this DPA and the incorporated transfer clauses, the transfer clauses shall prevail with respect to the transfer to which they apply.

Processor shall maintain supplementary safeguards reasonably designed to support lawful transfers, including encryption, access controls, onward transfer restrictions, and risk review of governmental access obligations.

Processor shall promptly notify Customer if Processor determines it can no longer meet applicable transfer obligations.

9. SUB-PROCESSORS

Customer grants Processor general authorization to engage Sub-processors.

Processor shall:

If Customer reasonably objects to a proposed Sub-processor on documented privacy or security grounds, the Parties shall work in good faith to resolve such objection. Processor may:

10. GOVERNMENT REQUESTS

If Processor receives a subpoena, regulatory request, or lawful governmental request for Personal Data, Processor shall, unless legally prohibited:

11. SECURITY INCIDENT

Processor shall maintain documented incident response procedures designed to identify, investigate, contain, mitigate, and remediate Security Incidents.

Processor shall notify Customer without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware of a confirmed Security Incident affecting Personal Data.

Where Processor reasonably suspects that a Security Incident may have occurred but has not confirmed the same, Processor may investigate and confirm before providing notice to the Customer. Processor shall provide follow-up updates as additional material information becomes reasonably available.

Notice shall include reasonably available information regarding:

Processor’s notification shall not be construed as admission of fault or liability. Processor shall provide commercially reasonable cooperation and information necessary for Customer to investigate, mitigate, and comply with legally required notification obligations arising from a confirmed Security Incident.

12. RETURN AND DELETION

Upon termination or expiration of Services, Processor shall make Personal Data available for export / retrieval for up to thirty (30) days following the effective date of termination or expiration, unless the Parties otherwise agree in writing or unless Processor is prevented from doing so by circumstances beyond its reasonable control (in which case Processor shall notify Customer promptly and use commercially reasonable efforts to make Personal Data available as soon as practicable).

Following such period, Processor shall delete or render inaccessible Personal Data  upon request from the Customer, except where retention is required or permitted for:

Any retained Personal Data remains subject to confidentiality and security obligations until securely deleted. Notwithstanding the foregoing, Processor shall not be required to delete data, records, outputs, insights, analytics, logs, security intelligence, aggregated data, anonymized data, de-identified data, or other information that Processor is permitted to retain under the Agreement, provided such retained information does not disclose Personal Data in raw identifiable form except as permitted under the Agreement, this DPA, or applicable law.

13. LIABILITY

All liability arising under this DPA shall be subject to the exclusions, disclaimers, and limitations of liability contained in the Agreement, including any aggregate liability cap, which are incorporated herein by reference.

Claims under this DPA, including privacy claims, security claims, Sub-processor claims, and transfer claims, shall count toward the aggregate liability cap under the Agreement unless expressly stated otherwise therein.

14. ORDER OF PRECEDENCE

In the event of conflict:

For clarity, this DPA shall not limit or override Processor’s ownership or product improvement rights under the Agreement, except to the extent this DPA or any mutually signed addendum expressly restricts the Processing of Personal Data in raw identifiable form.

15. REGULATORY INVESTIGATIONS

In the event of an investigation by any data protection authority, regulator, or supervisory authority  that relates to the Processing of Personal Data under this DPA, Processor shall:

The costs of such cooperation shall be borne by Customer, except where the investigation was initiated primarily as a result of Processor’s material breach of this DPA or willful misconduct, in which case such costs shall be borne by Processor. All liability arising from this Section remains subject to the limitations of liability in the Agreement.

16. MISCELLANEOUS

If any provision of this DPA is invalid or unenforceable, remaining provisions remain in effect.

Except where mandatory law provides otherwise, governing law and dispute resolution provisions in the Agreement apply to this DPA.

No third-party beneficiaries are created under this DPA except rights mandatorily granted to Data Subjects by law.

Clauses relating to confidentiality, retained data, security, liability, and dispute resolution survive termination.

Execution. This DPA is deemed executed by the Parties and becomes effective upon execution of the Agreement (including by written agreement, Order Form, click-through acceptance, or other legally binding acceptance referencing the Agreement), without requiring separate signature of this DPA unless expressly agreed otherwise in writing.

Amendments: This DPA may only be amended by a written instrument signed by authorized representatives of both Parties. No amendment shall be effective unless it expressly states that it amends this DPA.

17. WEBSITE VERSION; UPDATES

This DPA is made available by Akto Io, Inc. at www.akto.io/terms/dpa and may be incorporated by reference into the Agreement, Order Form, or other written agreement between Processor and Customer.

Last Updated: July 09, 2026
Version: 1.1

Unless otherwise agreed in writing, where no separate data processing addendum is executed by the Parties, the version of this DPA applicable to an Order Form shall be the version available at the above URL as of the Effective Date of such Order Form.

Processor may update this DPA from time to time. Any updated version shall apply prospectively and shall not amend the DPA applicable to an active Order Form unless permitted under the Agreement or otherwise agreed by the Parties in writing. Prior versions of this DPA may be requested by contacting legal@akto.io.

ANNEXURES

Annex I-A - LIST OF PARTIES & DESCRIPTION OF PROCESSING

Data Exporter: Customer, as identified in the Agreement.

Address: [Customer to complete: registered address]

Contact details: [Customer to complete: name, title, email of data protection contact]

Activities relevant to transfer: Receipt and use of Services; disclosure of Personal Data to Processor in connection with Services
Role: Controller (or Processor where applicable)

Data Importer: Akto Io, Inc.,
Address: 95 Third Street, 2nd Floor, San Francisco, California 94103.
Contact: Ankush Jain — ankush@akto.io.

Activities relevant to transfer: Processing Personal Data in connection with the provision, operation, support, security, maintenance, analytics, service improvement, and compliance purposes described in the Agreement and this DPA.
Role: Processor (or Sub-processor where applicable)

Categories of Data Subjects

These may include:

Categories of Personal Data

These may include:

Sensitive Data

Processor does not intentionally require Special Category Data for normal operation of Services. Customer shall avoid submitting such data unless expressly agreed in writing.

Nature of Processing

Collection, storage, organization, retrieval, analysis, transmission, support access, security monitoring, service optimization, and deletion or retention as permitted under the Agreement and this DPA..

Purpose

Provision, operation, maintenance, support, security, analytics, and service improvement and compliance purposes  as described in the Agreement and this DPA.

Duration

For the duration of the Agreement plus applicable deletion / backup retention cycles as set out in Section 12 of this DPA.

Annex I-B - DESCRIPTION OF TRANSFER

Frequency of Transfer

Continuous, for the duration of the Agreement, as triggered by Customer’s access to and use of the Services. Transfers occur on an ongoing basis each time the Services are accessed or Personal Data is submitted, processed, or retrieved by or on behalf of Customer.

Nature of Transfer

Transmission of Personal Data from Customer (Data Exporter) to Akto Io, Inc. (Data Importer) via encrypted network connection (TLS/HTTPS) for the purpose of providing the Services. Personal Data may be accessed remotely by Data Importer’s personnel for support, maintenance, and security purposes.

Purpose of Transfer

The transfer of Personal Data is necessary to enable Processor to provide the Services under the Agreement, including: security testing and monitoring; application telemetry analysis; authentication and access management; customer support; security incident response; service maintenance, analytics, service improvement, and other purposes permitted under the Agreement and this DPA.

Retention Period

Personal Data is retained for the duration of the Agreement and deleted upon request from the Customer subject to the exceptions set out in Section 12 of this DPA.

Transfers to Sub-processors

Where Personal Data is transferred onward to Sub-processors listed in Annex III, such transfers are made solely for the purposes described in Annex III (hosting, authentication, analytics, support, and communications). All Sub-processors are contractually bound by data protection obligations no less protective than those in this DPA. Sub-processor transfers are made under lawful transfer mechanisms as required by applicable Data Protection Laws.

Competent Supervisory Authority

The competent supervisory authority shall be determined in accordance with applicable Data Protection Laws and, where applicable, Clause 13 of the EU Standard Contractual Clauses, based on the Data Exporter’s place of establishment. For UK transfers, the competent authority is the UK Information Commissioner’s Office (ICO).

ANNEX II — TECHNICAL & ORGANIZATIONAL MEASURES

Processor maintains an information security program aligned to commercially reasonable industry practices,which may include, where applicable:

Security controls may evolve over time, provided the overall security posture of the Services is not materially diminished.

ANNEX III — SUB-PROCESSORS

Processor may use the following Sub-processors where applicable depending on the Services, configuration, support interactions, and features used by Customer. Processor may update the Sub-processor list in accordance with Section 9 of this DPA.

Sub-processor

Purpose

Region

Google Cloud Platform

Hosting / compute / storage

US

Google Workspace

Email / business communications

US

MongoDB, Inc.

Database Hosting

US

Mixpanel

Usage analytics

US

Intercom, Inc.

Customer support communications

US

Auth0, Inc. / Okta, Inc.

Authentication / SSO services

US

GitHub

Code Repository / CI Workflows

US