Data Processing Agreement

Latest Revision: September 10, 2026

The purpose of this policy is to establish a framework for sharing and processing data based on its sensitivity, value and criticality to the organization, so sensitive corporate and customer data can be secured appropriately.

This Data Processing Agreement ("DPA") is an amendment to the Straddle Payment Services Agreement ("Agreement") between Straddle Payments, Inc. and the customer identified in the Agreement ("Customer"), collectively (the "Parties") and governs Straddle's and its Affiliates' Processing of Personal Data. This DPA is effective as of the Effective Date of the Agreement.

1. Structure

You enter this DPA with Straddle Payments, Inc ("Straddle") a Delaware corporation with offices in Denver, CO.

2. Definitions

"CCPA" means the California Consumer Privacy Act of 2018, Cal. Civ. Code Sections 1798.100-1798.199, as amended by the California Privacy Rights Act of 2020.

"Data Controller" means the entity which, alone or jointly with others, determines the purposes and means of Processing Personal Data, which may include, as applicable, a "Business" as defined under the CCPA.

"Data Processor" means the entity that Processes Personal Data on behalf of the Data Controller, which may include, as applicable, a "Service Provider" as defined under the CCPA.

"Data Security Measures" means technical and organizational measures that are intended to secure Personal Data to a level of security appropriate for the risk of the Processing.

"Data Subject" means an identified or identifiable natural person to which Personal Data relates.

"DP Law" means all Law that applies to Personal Data Processing under your Straddle Services Agreement and this DPA, including international, federal, state, provincial and local Law relating to privacy, data protection or data security, including: (a) the California Consumer Privacy Act of 2018, as amended; (b) Virginia's Consumer Data Protection Act, Va. Code Ann. § 59.1-571 et seq.; (c) the Colorado Privacy Act, Colo. Rev. Stat. § 6-1-1301 et seq.; (d) Connecticut's Act Concerning Data Privacy and Online Monitoring, Pub. Act No. 22-15; (e) the Utah Consumer Privacy Act, Utah Code Ann. § 13-61-101 et seq.; (f) the Montana Consumer Data Privacy Act, Mont. Code Ann. § 30-14-2701 et seq.; (g) the Oregon Consumer Privacy Act, Or. Rev. Stat. § 646A.600 et seq.; (h) the Texas Data Privacy and Security Act, Tex. Bus. & Com. Code § 541.001 et seq.; (i) the Delaware Personal Data Privacy Act, Del. Code Ann. tit. 6, § 12D-101 et seq.; (j) the Iowa Consumer Data Protection Act, Iowa Code § 715D.1 et seq.; (k) the Tennessee Information Protection Act, Tenn. Code Ann. § 47-18-3201 et seq.; (l) any other applicable U.S. state consumer privacy or data protection law; (m) the Gramm-Leach-Bliley Act 15 U.S.C. §§ 6801-6809, §§ 6821-6827 and its implementing regulations; and (n) the current Nacha Operating Rules and Guidelines, as updated from time to time.

"GLBA" means the Gramm-Leach-Bliley Act 15 U.S.C. §§ 6801-6809, §§ 6821-6827 and its implementing regulations, including the Safeguards Rule (16 C.F.R. Part 314) and Privacy Rule (16 C.F.R. Part 313).

"Incident" means a data security incident involving the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Personal Data.

"Instructions" means the documented instructions provided by Customer to Straddle for the Processing of Personal Data, which include: (i) this DPA; (ii) the Agreement; and (iii) other written instructions expressly designated as "Data Processing Instructions" and mutually agreed to in writing by the Parties. Instructions do not include general use of the Services by Customer or its end users.

"Joint Controller" means a Data Controller that jointly determines the purposes and means of Processing Personal Data with one or more Data Controllers.

"Personal Data" means any information relating to an identified or identifiable natural person that is Processed in connection with the Services and includes "personal information" as defined under the CCPA and applicable U.S. state privacy laws.

"Process" or "Processing" means to perform any operation or set of operations on Personal Data or sets of Personal Data, such as collecting, recording, organizing, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing or destroying, as described under DP Law.

"Sub-processor" means an entity a Data Processor engages to Process Personal Data on that Data Processor's behalf in connection with the Services.

3. Straddle as Data Processor and Data Controller

3.1. Data Processing Roles.

Straddle Processes Personal Data in dual capacities depending on the nature of the Processing activity, as follows:

(a) Straddle as Data Processor: Straddle acts as a Data Processor (processing on Customer's behalf and according to Customer's Instructions) when:

  • Facilitating payment transactions that Customer initiates through the Straddle platform
  • Storing and transmitting transaction data as directed by Customer
  • Processing Customer's end user data solely to provide the requested Services

(b) Straddle as Data Controller: Straddle acts as a Data Controller (making independent decisions about Processing purposes and means) when:

  • Determining which payment methods, banks, and fraud prevention services to use
  • Conducting fraud monitoring, detection, and prevention activities
  • Performing anti-money laundering screening and know-your-customer verification
  • Complying with legal obligations, court orders, and regulatory requirements
  • Analyzing and developing Straddle's platform and services
  • Managing Straddle's own business operations and customer relationships

3.2. Data Processing Roles Matrix.

The following matrix clarifies Straddle's role for specific data types and processing activities:

Data TypeProcessing ActivityStraddle's Role
Customer end user contact informationStoring for transaction facilitationData Processor
Transaction details initiated by CustomerFacilitating payment processingData Processor
Payment account detailsTokenization and secure storageData Controller
Fraud signals and risk scoresFraud monitoring and preventionData Controller
Bank-sourced account and payment history for an end user's linked financial accountAccount verification, payment return-risk assessment and fraud preventionData Controller
Balance observations for an end user's linked financial account, including periodic refreshPayment return-risk assessment and fraud preventionData Controller
Sanctions, watchlist, politically-exposed-person and adverse-media screening resultsMeeting legal and regulatory obligationsData Controller
Identity verification dataKYC/AML complianceData Controller
Platform usage analyticsService improvement and developmentData Controller
Customer business informationManaging customer relationshipData Controller

3.3. Categories of Data Subjects and Personal Data.

(a) Data Subjects. Straddle may Process the Personal Data of Customer's end users, Customer's representatives, and any natural persons who access or use Customer's Straddle Account.

(b) Personal Data. Where applicable, Straddle may Process Payment Account Details, bank account details, billing and shipping addresses, names, dates/times/amounts of transactions, device identifiers, email addresses, IP addresses and location data, order identifiers, tax identification numbers and status, unique customer identifiers, and identity information including government-issued documents (e.g., national IDs, driver's licenses, and passports). Straddle may also Process the balance, account status and characteristics, and account and payment history it receives from a Data Source or financial institution for a linked financial account (including transaction dates, amounts and return history); risk scores, fraud signals and derived features produced from that information; phone, email and internet-connection attributes received from verification and fraud prevention providers; sanctions, watchlist, politically-exposed-person and adverse-media screening results; and, where applicable law permits and any required consent has been obtained, biometric templates generated to verify an identification document.

3.4. Data Processing Purposes.

(a) The purposes of Straddle's Processing of Personal Data when acting as a Data Processor include:

  • Servicing the Straddle platform as instructed by Customer
  • Facilitating payment transactions on behalf of Customer

(b) The purposes of Straddle's Processing of Personal Data when acting as a Data Controller include:

  • Determining the Processing methods when providing Straddle products and services, including selecting payment methods and third-party service providers (banks, fraud prevention, and validation providers)
  • Monitoring, preventing, and detecting fraudulent transactions and other fraudulent activity on the Straddle platform
  • Complying with Law, including applicable anti-money laundering screening and know-your-customer obligations
  • Analyzing and developing Straddle's services and platform
  • Managing Straddle's business operations and customer relationships

4. Straddle Obligations when Acting as a Data Processor

4.1. General Obligations.

To the extent that Straddle is acting as a Data Processor for Customer, Straddle will:

(a) Process Personal Data on behalf of and according to Customer's Instructions. Straddle will not sell, retain, use or disclose Personal Data for any purpose other than for the specific purposes of performing the Services and to comply with Law, unless otherwise permitted by the Agreement (including this DPA) or DP Law. If Straddle determines that any Instruction violates or infringes DP Law, Straddle will: (i) promptly inform Customer in writing; and (ii) have the right to refuse to follow such Instruction until Customer provides lawful alternative Instructions or withdraws the Instruction. Straddle will not be liable for any delays or failures to perform Services resulting from refusing to follow unlawful Instructions.

(b) Ensure that all persons Straddle authorizes to Process Personal Data in the context of the Services are granted access to Personal Data on a need-to-know basis and are committed to respecting the confidentiality of Personal Data through written confidentiality agreements.

(c) To the extent required by DP Law, inform Customer within five (5) business days of receiving requests from Data Subjects (including "verifiable consumer requests" as defined under the CCPA) exercising their applicable rights under DP Law to: (i) access (e.g., right to know under the CCPA) their Personal Data; (ii) have their Personal Data corrected or erased; (iii) restrict or object to Straddle's Processing; or (iv) data portability. Straddle will provide Customer with sufficient information to identify the Data Subject and the nature of the request. Straddle will not respond substantively to these requests unless Customer instructs Straddle in writing to do so and agrees to reimburse Straddle's reasonable costs for handling the request. Customer acknowledges that Customer is responsible for responding to Data Subject requests within the timeframes required by DP Law.

(d) To the extent required by DP Law, inform Customer within five (5) business days of receiving each law enforcement request or other legal process that requires Straddle to disclose Personal Data or participate in an investigation involving Personal Data, unless prohibited by law from doing so.

(e) To the extent required by DP Law, provide Customer with reasonable assistance through appropriate technical and organizational measures to assist Customer in complying with Customer's obligations under DP Law, including conducting data protection impact assessments and consulting with supervisory authorities. Such assistance will be provided at Customer's expense based on Straddle's then-current professional services rates, taking into account the nature of the Processing and the information available to Straddle.

(f) Implement and maintain a written information security program with the Data Security Measures stated in Exhibit 1 of this DPA. In addition, Straddle will implement a data security incident management program that addresses how Straddle will manage Incidents. If Straddle is required by DP Law to notify Customer of an Incident, or if Straddle reasonably determines that notification is appropriate, then Straddle will notify Customer within seventy-two (72) hours of Straddle's discovery of the Incident, or such shorter period as required by applicable DP Law. Straddle will partner with Customer to respond to the Incident, which may include identifying key partners, investigating the Incident, providing regular updates, and discussing notice obligations. Except as required by DP Law or with Customer's prior written consent, Straddle will not notify affected Data Subjects about an Incident.

(g) Engage Sub-processors as necessary to perform the Services on the basis of the general written authorization Customer grants to Straddle under Section 4.2 of this DPA.

(h) To the extent required by DP Law and upon Customer's written request, contribute to audits or inspections by making relevant audit reports available to Customer, which reports are Straddle's confidential information. Upon Customer's written request, and subject to the limitations in Section 4.1(i) below, Straddle will promptly provide documentation or complete a written data security questionnaire of reasonable scope regarding Straddle's and its Affiliates' Processing of Personal Data. All documentation provided, including any response to a security questionnaire, is Straddle's confidential information and subject to the confidentiality provisions of the Agreement.

(i) Audit Frequency and Exceptions. Customer may request audits or security questionnaires no more frequently than once annually, except that additional audits or questionnaires may be requested: (i) within thirty (30) days following an Incident affecting Customer's Personal Data; (ii) upon written request from a regulatory authority with jurisdiction over Customer; or (iii) upon reasonable suspicion of a material breach of this DPA, supported by specific factual basis provided in writing.

(j) At Customer's written election made within thirty (30) days following termination of the Agreement, and subject to Straddle's rights and obligations under the Agreement (including this DPA), either: (i) securely delete all Personal Data; or (ii) return Personal Data to Customer in a mutually agreed upon format. Following such deletion or return, Straddle will delete existing copies held by Straddle within ninety (90) days, except for Personal Data that Straddle is required or authorized by DP Law, Payments Association Rules, or other applicable law to retain. Straddle will provide Customer with written certification of deletion upon request.

4.2 Sub-processors

(a) Customer specifically authorizes Straddle to engage its Sub-processors and Affiliates from the list of Sub-processors and Affiliates detailed at https://trust.straddle.com ("Straddle Sub-processor List"). Customer acknowledges that Straddle's Sub-processors are essential to provide the Services and that if Customer objects to Straddle's use of a new Sub-processor as provided in Section 4.2(c), then notwithstanding anything to the contrary in the Agreement (including this DPA), Straddle will not be obligated to provide Customer the Services for which Straddle uses that Sub-processor, and Customer may terminate the affected Services without penalty.

(b) Straddle will enter into a written agreement with each Sub-processor that imposes on that Sub-processor data protection obligations comparable to those imposed on Straddle under this DPA, including implementing appropriate Data Security Measures. If a Sub-processor fails to fulfill its data protection obligations under that agreement, Straddle will remain liable to Customer for the acts and omissions of its Sub-processor to the same extent Straddle would be liable if performing the relevant Services directly under this DPA, subject to the limitations of liability set forth in the Agreement.

(c) New Sub-processors. Straddle will provide Customer with at least thirty (30) days' advance notice of any new Sub-processor by updating the Straddle Sub-processor List and sending notice to Customer's email address on file. Customer may object to a new Sub-processor on reasonable data protection grounds by providing written notice to Straddle within fifteen (15) days of notification. If Customer objects, the Parties will work together in good faith to resolve Customer's concerns. If the Parties cannot reach a resolution, Customer may terminate the affected Services without penalty by providing written notice within the initial thirty (30) day notice period.

4.3 CCPA and GLBA Compliance

(a) To the extent applicable to the Services, Straddle certifies that it understands and will comply with the requirements in this DPA relating to the CCPA, including the requirements applicable to "Service Providers" as defined under the CCPA.

(b) To the extent GLBA applies to the Services, Straddle represents that it maintains an information security program that complies with the GLBA Safeguards Rule (16 C.F.R. Part 314), including:

  • Designation of qualified personnel to oversee the information security program
  • Risk assessment processes appropriate to the size, complexity, and scope of Straddle's operations
  • Safeguards to control identified risks
  • Regular monitoring and testing of safeguards
  • Personnel training
  • Selection and oversight of service providers
  • Evaluation and adjustment of the information security program

4.4 Right to Refuse and Limitation of Liability.

(a) Notwithstanding anything to the contrary in the Agreement or this DPA, Straddle has the right to refuse to follow any Instruction that Straddle reasonably believes violates DP Law or other applicable law. Straddle will promptly notify Customer of any such refusal and the basis for it.

(b) Straddle and its Affiliates will not be liable for any claim made by a Data Subject or regulatory authority arising from or related to Straddle's or any of its Affiliates' acts or omissions, to the extent that: (i) Straddle was acting in accordance with Customer's Instructions; and (ii) such Instructions were unlawful or violated DP Law. In such cases, Customer will indemnify, defend, and hold harmless Straddle from any such claims, subject to Section 6 below.

(c) All liability limitations and exclusions set forth in the Agreement apply equally to this DPA, including any limitation on Straddle's total aggregate liability.

5. Your obligations when acting as a Data Controller

Customer must:

5.1 Provide only lawful Instructions to Straddle. Customer represents and warrants that its Instructions and its use of the Services comply with DP Law.

5.2 Comply with and perform its obligations under DP Law, including with regard to Data Subject rights, data security and confidentiality, and ensure it has an appropriate legal basis for the Processing of Personal Data as described in the Agreement, including this DPA.

5.3 Provide Data Subjects with all necessary information (including by means of a transparent and easily accessible public privacy notice) regarding Straddle's and Customer's Processing of Personal Data for the purposes described in the Agreement, including this DPA. Customer acknowledges that it is solely responsible for providing any required notices and obtaining any required consents for the collection and Processing of Personal Data prior to providing such Personal Data to Straddle.

5.4 Not transmit to Straddle any "sensitive personal information" as defined under DP Law (such as Social Security numbers, driver's license numbers, financial account credentials, precise geolocation data, or health information) except as expressly permitted by the Agreement or as necessary for Straddle to provide the Services. To the extent Customer transmits sensitive personal information to Straddle with authorization, Customer represents that it has obtained all necessary consents and authorizations under DP Law.

5.5 Respond to Data Subject requests within the timeframes required by DP Law and coordinate with Straddle as needed to fulfill such requests.

6. Mutual Indemnification

6.1 Customer will indemnify, defend, and hold harmless Straddle and its Affiliates, officers, directors, employees, and agents from and against any and all third-party claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising from or relating to: (a) Customer's breach of its obligations under Section 5 of this DPA; (b) Customer's violation of DP Law; or (c) any unlawful Instructions provided by Customer to Straddle.

6.2 Straddle will indemnify, defend, and hold harmless Customer and its Affiliates, officers, directors, employees, and agents from and against any and all third-party claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising from or relating to: (a) Straddle's breach of its obligations under Section 4 of this DPA when acting as a Data Processor; or (b) an Incident caused by Straddle's failure to implement the Data Security Measures set forth in Exhibit 1.

6.3 The indemnification obligations in this Section 6 are subject to the indemnification procedures and limitations set forth in the Agreement.

7. Term, Termination, and General Provisions

7.1 Term and Termination

This DPA will take effect on the Effective Date of the Agreement and will remain in effect for so long as Straddle Processes Personal Data under the Agreement, including during any wind-down period following termination of the Agreement.

7.2 Amendment

Straddle may amend this DPA from time to time to reflect changes in DP Law, regulatory requirements, or Straddle's data processing practices. Straddle will provide Customer with at least sixty (60) days' advance written notice of any material amendments by email to Customer's address on file and by posting the updated DPA at https://straddle.io/legal/dpa. Customer's continued use of the Services following the effective date of the amendment constitutes acceptance of the amended DPA. If Customer does not agree to a material amendment, Customer may terminate the Agreement without penalty by providing written notice to Straddle before the amendment's effective date.

7.3 Conflicts

In the event of any conflict between this DPA and the Agreement, this DPA will control with respect to data protection and privacy matters. In all other respects, the Agreement will control.

7.4 Dispute Resolution

Any disputes arising from or relating to this DPA will be resolved in accordance with the dispute resolution provisions set forth in the Agreement.

7.5 Severability

If any provision of this DPA is held to be invalid, illegal, or unenforceable, the remaining provisions will continue in full force and effect, and the invalid, illegal, or unenforceable provision will be reformed to the minimum extent necessary to make it valid and enforceable while preserving the Parties' intent.

7.6 Governing Law

This DPA will be governed by the same law that governs the Agreement.

EXHIBIT 1: STRADDLE DATA SECURITY MEASURES

1. Security Programs and Policies

1.1 Information Security Program.

Straddle maintains and enforces a comprehensive information security program that addresses how Straddle manages security, including the security controls Straddle employs. The security program includes:

(a) Documented policies that Straddle formally approves, externally publishes at https://trust.straddle.com and communicates to appropriate personnel, with annual reviews and updates.

(b) Documented, clear assignment of responsibility and authority for security program activities, including a designated Chief Information Security Officer or equivalent role.

(c) Policies covering, as applicable, acceptable computer use, data classification, cryptographic controls, access control, removable media, remote access, and incident response.

(d) Regular testing of key controls, systems, and procedures, including at least annual penetration testing and vulnerability assessments.

1.2 Privacy Program.

Straddle maintains and enforces a privacy program and related policies that address how Personal Data is collected, used, and shared in compliance with DP Law.

2. Risk and Asset Management

2.1 Risk Management.

Straddle performs regular risk assessments (at least annually) and implements and maintains controls for risk identification, analysis, monitoring, reporting, and corrective action.

2.2 Asset Management.

Straddle maintains and enforces an asset management program that appropriately classifies and controls hardware and software assets throughout their lifecycle, including secure disposal and sanitization of data-bearing media.

3. Personnel Education and Controls

3.1 Acknowledgment of Responsibilities.

All (a) Straddle employees; and (b) Straddle independent contractors who may have access to data, including those who Process Personal Data ((a) and (b), collectively "Personnel") acknowledge their data security and privacy responsibilities under Straddle's policies in writing.

3.2 Personnel Controls.

For Personnel, Straddle, either itself or through a third party:

(a) Implements pre-employment background checks and screening appropriate to the Personnel's role and level of access to Personal Data, in compliance with applicable law.

(b) Conducts security and privacy training at the time of onboarding and at least annually thereafter.

(c) Implements disciplinary processes for violations of data security or privacy requirements, up to and including termination.

(d) Upon termination or applicable role change, promptly (within 24 hours) removes or updates Personnel access rights and requires the Personnel to return or securely destroy any Personal Data in their possession.

3.3 Authentication.

Straddle authenticates each Personnel's identity through appropriate authentication credentials, including:

  • Multi-factor authentication (MFA) for all access to production systems containing Personal Data
  • Strong password requirements
  • Single sign-on (SSO) where technically feasible

4. Training and Awareness

4.1 Annual Security and Privacy Training.

Straddle's employees complete mandatory annual Security and Privacy awareness training on Straddle's data security and confidentiality policies and practices, with training completion tracked and verified.

4.2 Role-Based Training.

Personnel with elevated access to Personal Data receive additional role-specific training appropriate to their responsibilities.

5. Network and Operations Management

5.1 Policies and Procedures.

Straddle implements policies and procedures for network and operations management. These policies and procedures address system hardening, change control, segregation of duties, separation of development and production environments, technical architecture management, network security, malware protection, protection of data in transit and at rest, data integrity, encryption, audit logs, and network segregation.

5.2 Vulnerability Management.

Straddle performs vulnerability assessments and penetration testing on its systems and applications, including those that Process Personal Data, as follows:

  • Automated vulnerability scans at least weekly
  • Penetration testing by qualified third parties at least annually
  • Critical and high-severity vulnerabilities remediated according to Straddle's vulnerability management policy (critical within 15 days, high within 30 days)

5.3 Patch Management.

Straddle maintains a patch management program to ensure timely application of security patches to systems Processing Personal Data, with critical security patches applied within thirty (30) days of availability, or sooner if required by the severity of the vulnerability.

6. Technical Access Controls

6.1 Access Control.

Straddle implements measures to prevent data processing systems from being used by unauthorized persons, including the following measures:

(a) User identification and authentication procedures with unique user credentials.

(b) Password security procedures implementing strong passwords with special characters, minimum length of 12 characters, mandatory periodic password changes, and password history to prevent reuse, aligned with NIST 800-63B guidelines.

(c) Automatic account locking after a defined number of failed login attempts and session timeout after periods of inactivity.

(d) Monitoring and logging of failed authentication attempts with alerting for suspicious patterns.

(e) Multi-factor authentication for all access to systems containing Personal Data.

6.2 Data Access Control.

Straddle implements measures to ensure that persons entitled to use a data processing system gain access only to the Personal Data necessary for their authorized access rights, and that Personal Data cannot be read, copied, modified, or deleted without authorization, including:

(a) Internal policies and procedures for access management.

(b) Role-based access control (RBAC) systems with defined authorization schemes.

(c) Differentiated access rights based on profiles, roles, actions, and data objects following the principle of least privilege.

(d) Access monitoring and comprehensive logging of access to Personal Data.

(e) Regular access reviews (at least quarterly) to verify continued appropriateness of access rights.

(f) Documented access request, approval, provisioning, and deprovisioning procedures.

(g) Formal change control procedures for modifications to access rights.

(h) Secure deletion procedures for decommissioned accounts and data.

7. Physical Access Controls

7.1 Third-Party Data Center Security.

Straddle uses reputable third-party service providers to host its production infrastructure. Straddle relies on these third parties to manage the physical access controls to the data center facilities that they manage. Straddle requires these service providers to implement measures to prevent unauthorized persons from gaining physical access to the data processing systems and facilities where Personal Data is Processed, including:

(a) Physical access control systems and programs, including badge access systems.

(b) Security video surveillance and alarm systems with 24/7 monitoring.

(c) Defined access control roles and restricted area zones.

(d) Access control audit and logging measures.

(e) Electronic tracking and management programs for physical keys and access cards.

(f) Documented access authorization processes for employees and third parties.

(g) Trained uniformed security staff and/or advanced physical security controls.

7.2 Third-Party Verification.

Straddle reviews third-party audit reports at least annually to verify that Straddle's infrastructure service providers maintain appropriate physical access controls for the managed data centers. Straddle requires such providers to maintain at least one of the following certifications: SOC 2 Type II, ISO 27001, or comparable security certification. Straddle retains the right to request additional information or conduct audits of physical security controls if concerns arise.

8. Availability Controls

Straddle implements measures to ensure the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident, including:

8.1 Real-time database replication across multiple availability zones.

8.2 Automated backup procedures with encrypted backups taken at least daily and stored in geographically separate locations.

8.3 Hardware redundancy and failover capabilities for critical systems.

8.4 A documented disaster recovery plan that is tested at least annually, with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

8.5 Business continuity planning to ensure continued operations during disruptive events.

9. Disclosure Controls

Straddle implements measures to ensure that Personal Data: (a) cannot be read, copied, modified, or deleted without authorization during electronic transmission, transport, or storage on storage media (manual or electronic); and (b) can be verified and logged to determine to which companies or other legal entities Personal Data are disclosed.

These measures include:

  • Encryption of data in transit and at rest (as detailed in Section 12)
  • Transport security protocols (TLS 1.2 or higher)
  • Comprehensive logging and audit trails
  • Data loss prevention (DLP) tools and monitoring
  • Secure file transfer protocols

10. Entry Controls

Straddle implements measures to monitor whether data have been entered, changed, or removed (deleted), and by whom, from data processing systems, including:

10.1 Comprehensive logging and monitoring systems that capture user activities, system events, and data modifications.

10.2 Audit trails and documentation that record the who, what, when, and where of data access and modifications.

10.3 Log retention for at least one (1) year, with archives maintained for up to seven (7) years as required by applicable law.

10.4 Security Information and Event Management (SIEM) systems for real-time monitoring and alerting.

11. Separation Controls

Straddle implements measures to ensure that Personal Data collected for different purposes can be Processed separately, including:

11.1 "Least privilege" limitation of access to data by internal service and user role.

11.2 Segregation of functions between production and testing environments, with no production Personal Data used in testing without prior de-identification.

11.3 Documented procedures for storage, amendment, deletion, and transmission of data for different purposes.

11.4 Logical segmentation processes and technologies (including network segmentation, data tagging, and containerization) to manage the separation of Personal Data.

11.5 Multi-tenant architecture designed to maintain isolation between customer data.

12. Encryption

12.1 General Encryption Standards.

Straddle applies data encryption mechanisms at multiple points in Straddle's service to mitigate the risk of unauthorized access to data at rest and in transit. Straddle uses industry-standard encryption algorithms and key lengths, currently including AES-256 for data at rest and TLS 1.2 or higher for data in transit, and will update to stronger standards as they become available and industry-accepted. Access to Straddle cryptographic key materials is restricted to a limited number of authorized Straddle personnel with documented key management procedures.

12.2 Encryption in Transit.

To protect data in transit, Straddle requires all inbound and outbound data connections to be encrypted using TLS 1.2 or higher protocol, with a migration path to TLS 1.3 as browser and system support allows. For data traversing Straddle's internal production networks, Straddle uses mutual TLS (mTLS) to encrypt connections between production systems. Straddle disables insecure protocols (SSL, TLS 1.0, TLS 1.1) and weak cipher suites.

12.3 Encryption at Rest.

To protect data at rest, Straddle uses industry-standard encryption (AES-256 or equivalent) to encrypt all production data stored in server infrastructure, including databases, file systems, and backup media.

12.4 Payment and Banking Account Data Tokenization.

Payment card numbers and bank account numbers are separately encrypted using industry-standard encryption (AES-256 or equivalent) at the data field level and stored in a separate secured data vault with highly restricted access controls. Tokens are generated to support Straddle data processing while minimizing storage of sensitive payment credentials.

12.5 Key Management.

Straddle implements a formal key management program that includes:

  • Secure generation, distribution, storage, rotation, and destruction of cryptographic keys
  • Separation of key management duties
  • Regular key rotation (at least annually for data-at-rest keys)
  • Immediate key rotation in the event of suspected compromise

13. Change Management and System Configuration

13.1 Change Management.

Straddle implements formal change management processes for all changes to production systems and infrastructure, including:

  • Documented change requests and approvals
  • Risk assessment for proposed changes
  • Testing in non-production environments prior to production deployment
  • Rollback procedures for failed changes
  • Post-implementation reviews

13.2 System Configuration.

Straddle implements measures for ensuring secure system configuration, including:

  • Hardened default configuration baselines for all system types
  • Configuration management through infrastructure-as-code
  • Automated deployment tools that enforce configuration standards
  • Prohibition of manual configuration changes to production systems except in documented emergency situations

13.3 Configuration Management.

Straddle relies on deployment automation tools to deploy infrastructure and system configuration. These automation tools leverage infrastructure configurations that are managed through version-controlled code that flows through Straddle's change control processes. Straddle's change management processes require formal code reviews and two-party approvals prior to release to production.

13.4 Configuration Monitoring.

Straddle uses automated monitoring tools to monitor production infrastructure for deviations from known secure configuration baselines, with alerts generated for unauthorized changes.

14. Data Security Incident Management and Notification

14.1 Incident Response Program.

Straddle implements a comprehensive data security incident management program that addresses how Straddle identifies, responds to, contains, investigates, and remediates Incidents. The program includes:

  • Designated incident response team with defined roles and responsibilities
  • Incident classification and severity rating procedures
  • Documented incident response playbooks
  • Communication protocols for internal and external stakeholders
  • Post-incident review and lessons-learned processes

14.2 Incident Notification to Customers.

If Straddle becomes aware of an Incident affecting Customer's Personal Data, Straddle will notify Customer within seventy-two (72) hours of discovery, or such shorter period as required by applicable DP Law. Notification will include, to the extent known at the time:

  • Description of the Incident and the Personal Data affected
  • Likely consequences of the Incident
  • Measures taken or proposed to address the Incident and mitigate harm
  • Contact information for Straddle's incident response team

14.3 Incident Notification to Authorities and Data Subjects.

Straddle will notify impacted Data Subjects and Governmental Authorities (where applicable) of Incidents in a timely manner as required by DP Law. Where Customer is responsible for such notifications, Straddle will provide reasonable assistance to Customer to enable Customer to fulfill its notification obligations.

15. Reviews, Audit Reports, and Security Questionnaires

15.1 Security Questionnaires.

Upon written request, and subject to the limitations in Section 4.1(i) of the DPA, Straddle will complete a written data security questionnaire of reasonable scope and duration regarding Straddle's business practices and data technology environment in relation to the Processing of Personal Data. Straddle's responses to security questionnaires are Straddle's confidential information.

15.2 Audit Reports.

Straddle maintains industry-standard security certifications and undergoes regular third-party audits. Upon request and execution of appropriate non-disclosure agreements, Straddle will provide Customer with summaries of relevant audit reports, which may include SOC 2 Type II reports or equivalent certifications.

16. Data Retention and Deletion

16.1 Data Retention.

Straddle implements and maintains data retention policies and procedures related to Personal Data and reviews these policies and procedures at least annually. Personal Data is retained only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements.

16.2 Secure Deletion.

When Personal Data is deleted, Straddle uses secure deletion methods to render the data unrecoverable, including:

  • Cryptographic erasure (destroying encryption keys)
  • Overwriting data multiple times for magnetic media
  • Physical destruction of media where appropriate
  • Verification of deletion completion

16.3 Backup Retention.

Personal Data contained in backups is deleted in accordance with Straddle's standard backup retention schedules, which do not exceed one hundred eighty (180) days, except where longer retention is required by applicable law or regulation.

17. Sub-processor Security Requirements

17.1 Straddle requires all Sub-processors that Process Personal Data to implement and maintain data security measures that are substantially similar to those described in this Exhibit 1, appropriate to the nature and scope of the Sub-processor's Processing activities.

17.2 Straddle conducts due diligence on Sub-processors' security practices prior to engagement and periodically thereafter, including review of security certifications, audit reports, and security questionnaires.

18. Continuous Improvement

18.1 Straddle commits to continuously reviewing and improving its Data Security Measures to address evolving threats, incorporate industry best practices, and maintain compliance with DP Law.

18.2 Straddle will update the specific technical controls and standards referenced in this Exhibit 1 as necessary to maintain industry-standard security, provided that such updates do not materially reduce the overall level of security provided.

www.straddle.com

Denver, CO