Nooks Online Data Processing Addendum

Last Updated: October 6, 2026

This Data Processing Addendum (this “Addendum”) forms part of, and is incorporated into, the online terms of service, Master Services Agreement, Order Form, or other written or electronic agreement governing the provision of Services by Nooks Communications, Inc. to the customer identified in the applicable Order Form or Agreement (“Customer” or “Controller”) (the “Agreement”). “Customer” means the entity that enters into the applicable Order Form or Agreement with Nooks. This Addendum is entered into by and between Customer and Nooks Communications, Inc., a Delaware corporation with offices at 350 Bush Street, 8th Floor, San Francisco, CA 94104 (“Nooks” or “Processor”), without the need for a separate signature to this Addendum. Controller and Processor are each a “Party” and together the “Parties.”

This Addendum applies only to the extent that Processor Processes Customer Personal Data on behalf of Controller in connection with Customer’s access to and use of the Services under the Agreement.

‍

1. Definitions

1.1 “Adequacy Decision,” “Controller,” “Data Subject,” “Personal Data Breach,” “Process” or “Processing,” “Processor,” “Sub-Processor,” and “Supervisory Authority” have the meanings given to them under applicable Data Protection Laws.

1.2 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where “control” means ownership or control of more than fifty percent (50%) of the voting interests of the subject entity.

1.3 “Aggregated Data” has the meaning given to it in the Agreement.

1.4 “Agreement” has the meaning set forth in the preamble to this Addendum and includes the applicable online terms, Order Form, Master Services Agreement, or other written or electronic agreement between Customer and Nooks governing the Services.

1.5 “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.

1.6 “Customer Personal Data” means Personal Data Processed by Processor on behalf of Controller in connection with the Services, as further described in Annex 1.

1.7 “Data Protection Laws” means all applicable privacy, data protection, and data security laws, rules, and regulations applicable to the Processing of Customer Personal Data under the Agreement and this Addendum, as amended, replaced, or superseded from time to time, including, where applicable, the GDPR, UK GDPR, the Swiss Federal Act on Data Protection, the CCPA, and other applicable U.S. state privacy laws.

1.8 “Data Subject Request” means any request from a Data Subject to exercise rights under applicable Data Protection Laws, including rights of access, correction, deletion, restriction, objection, portability, or withdrawal of consent, as applicable.

1.9 “GDPR” means Regulation (EU) 2016/679.

1.10 “Sensitive Personal Data” means any Personal Data subject to heightened protection under applicable Data Protection Laws, including special categories of personal data under Article 9 of the GDPR and sensitive personal information under the CCPA.

1.11 “Services” means the services provided by Processor to Controller under the Agreement.

1.12 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, as may be amended, replaced, or superseded from time to time.

1.13 “UK Addendum” means the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses for international data transfers issued by the UK Information Commissioner’s Office, as may be amended, replaced, or superseded from time to time.

1.14 “UK GDPR” means the GDPR as retained in UK law by the European Union (Withdrawal) Act 2018, as amended.

‍

2. Roles of the Parties

2.1 Except as set out in Section 2.3, the Parties acknowledge and agree that, with respect to the Processing of Customer Personal Data, Controller is the Controller or Business, as applicable, and Nooks is the Processor or Service Provider, as applicable.

2.2 If Controller acts as a Processor on behalf of a third-party controller, Controller represents and warrants that its instructions to Processor, including its appointment of Processor as another processor, have been authorized by the relevant controller.

2.3 To the extent Processor’s creation and use of Aggregated Data, as permitted by the Agreement, constitutes Processing of Personal Data under applicable Data Protection Laws, Processor acts as an independent Controller with respect to that Processing, and not as a joint controller with Controller.

‍

3. Processing of Customer Personal Data

3.1 Processor shall Process Customer Personal Data only on documented instructions from Controller, including as set forth in the Agreement, this Addendum, and Controller’s use and configuration of the Services, unless otherwise required by applicable law. In such event, Processor shall inform Controller of that legal requirement before Processing, unless applicable law prohibits such notice on important grounds of public interest.

3.2 Processor shall Process Customer Personal Data only for the limited and specific purposes necessary to provide the Services, to perform its obligations and exercise its rights under the Agreement and this Addendum, and as otherwise permitted by applicable Data Protection Laws.

3.3 To the extent Processor Processes Personal Information subject to the CCPA, Processor agrees that it shall: (a) Process such Personal Information only for the business purposes and limited purposes described in the Agreement and this Addendum; (b) not sell or share such Personal Information (as defined under the CCPA); (c) not retain, use, or disclose such Personal Information for any purpose other than the business purposes and limited purposes described in the Agreement and this Addendum, except as otherwise permitted by the CCPA; (d) not retain, use, or disclose such Personal Information outside of the direct business relationship between Controller and Processor; and (e) not combine Personal Information received from or on behalf of Controller with Personal Information received from or on behalf of another person, or collected from Processor’s own interaction with a consumer, except as permitted by the CCPA.

3.4 To the extent permitted by the CCPA and other applicable Data Protection Laws, Processor may Process Personal Information solely for the limited and specific business purposes necessary to perform the Services, to carry out the rights and obligations expressly set out in the Agreement and this Addendum, and for such other purposes expressly permitted for a service provider or processor under applicable Data Protection Laws.

3.5 Processor certifies that it understands the restrictions in Section 3.3 and will comply with them.

3.6 Processor shall not use Customer Personal Data to train third-party generative artificial intelligence models. Processor is authorized to create and use Aggregated Data in accordance with the Agreement. Aggregated Data is not Customer Personal Data for purposes of this Addendum.

3.7 Controller shall not submit Sensitive Personal Data to the Services without Processor’s prior written consent.

3.8 If Processor receives a Data Subject Request relating to Customer Personal Data, Processor shall promptly notify Controller and shall not respond to the request except on Controller’s documented instructions or as required by applicable law.

3.9 If Processor believes that an instruction from Controller infringes applicable Data Protection Laws, Processor shall promptly inform Controller.

‍

4. Confidentiality and Personnel

4.1 Processor shall ensure that all personnel authorized to Process Customer Personal Data are subject to a contractual, professional, or statutory duty of confidentiality.

4.2 Processor shall ensure that access to Customer Personal Data is limited to personnel who require such access to perform the Agreement and this Addendum.

‍

5. Security Measures

5.1 Processor shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.

5.2 The technical and organizational measures implemented by Processor are described in Annex 2.

5.3 Processor shall regularly review and, where appropriate, update its technical and organizational measures.

‍

6. Personal Data Breach Notification

6.1 Processor shall notify Controller without undue delay, and in any event no later than seventy-two (72) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.

6.2 Such notification shall include, to the extent available: (a) a description of the nature of the Personal Data Breach; (b) the name and contact details of a contact point from which more information can be obtained; and (c) the measures taken or proposed to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

6.3 Processor shall promptly provide Controller with such further information and assistance as Controller may reasonably require in connection with a Personal Data Breach.

‍

7. Authorized Sub-Processors

7.1 Controller provides a general written authorization for Processor to engage Sub-Processors.

7.2 A current list of Sub-Processors engaged by Processor is maintained at www.nooks.ai/subprocessors or such successor website designated by Processor from time to time (the “Sub-Processor List”).

7.3 Processor shall notify Controller of any addition or replacement of Sub-Processors by: (a) posting such changes to the Sub-Processor List; and (b) sending an email notification to those individuals who have opted in to receive such updates through Processor’s designated notification form located at www.nooks.ai/privacy-notifications or such successor website designated by Processor from time to time.

7.4 Controller may object to a change on documented, reasonable grounds relating to a Sub-Processor’s inability to comply with applicable Data Protection Laws or the data protection obligations in this Addendum. Such objection must be made in writing within fourteen (14) days after the update is posted or, if the relevant individual has subscribed, the notification is sent.

7.5 If Controller objects on such grounds, the Parties shall work in good faith for a period of thirty (30) days to find an appropriate workaround or to provide additional evidence of the Sub-Processor’s compliance.

7.6 If no resolution is reached, Processor may, at its option, either: (a) refrain from using the Sub-Processor for Controller’s Customer Personal Data; or (b) permit Controller to terminate the affected Service as its sole and exclusive remedy.

‍

8. Sub-Processor Obligations

8.1 Processor will enter into a written agreement with each Sub-Processor containing data protection obligations that are no less protective than those in this Addendum.

8.2 Such obligations shall include implementing appropriate technical and organizational security measures to ensure a level of security appropriate to the risk.

8.3 Processor will remain fully liable to Controller for the performance of the Sub-Processor’s data protection obligations to the extent required by applicable Data Protection Laws.

‍

9. Assistance with Data Subject Rights, DPIAs, and Legal Requests

9.1 Taking into account the nature of the Processing, Processor shall provide reasonable assistance to Controller, through appropriate technical and organizational measures, insofar as possible, for the fulfilment of Controller’s obligation to respond to Data Subject Requests under applicable Data Protection Laws.

9.2 Taking into account the nature of the Processing and the information available to Processor, Processor shall provide reasonable assistance to Controller with Data Protection Impact Assessments (“DPIAs”), prior consultations with Supervisory Authorities, and similar regulatory assessments where required by applicable Data Protection Laws.

9.3 Unless prohibited by applicable law, Processor shall promptly notify Controller if Processor receives a legally binding request from a government authority or law enforcement agency for disclosure of Customer Personal Data before making any such disclosure.

‍

10. Audit and Demonstration of Compliance

10.1 Processor shall make available to Controller, upon reasonable written request, all information reasonably necessary to demonstrate Processor’s compliance with this Addendum.

10.2 Subject to reasonable confidentiality obligations and appropriate safeguards, and only to the extent that Processor’s then-current audit documentation (including ISO 27001:2022 certification and SOC 2 Type II reports) does not reasonably satisfy Controller’s audit requirements, Processor shall allow for and contribute to reasonable audits and inspections by Controller or an independent auditor mandated by Controller, provided that: (a) Controller provides at least thirty (30) days’ prior written notice; (b) audits occur no more than once per calendar year, unless required by a competent authority or following a confirmed Personal Data Breach; (c) audits are conducted during normal business hours, in a manner that minimizes disruption to Processor’s business; and (d) Controller bears its own audit costs and reimburses Processor for reasonable costs incurred in connection with the audit, except where the audit reveals a material breach of this Addendum by Processor.

‍

11. Return and Deletion of Customer Personal Data

11.1 Upon termination or expiration of the Agreement or this Addendum, Controller may request the return of Customer Personal Data by written notice to Processor within thirty (30) days after the effective date of termination or expiration, and Processor shall return such Customer Personal Data in accordance with the Agreement. Following such period (or, if later, completion of a timely requested return), Processor shall delete Customer Personal Data in accordance with its data retention practices, unless applicable law requires Processor to retain some or all of the Customer Personal Data or such Customer Personal Data is retained in archival or backup copies generated in the ordinary course of Processor’s business. Processor shall delete any Customer Personal Data retained in archival or backup copies in accordance with Processor’s standard backup retention and deletion practices and shall continue to protect such Customer Personal Data in accordance with this Addendum until deleted. For the avoidance of doubt, the obligations in this Section 11 do not apply to Aggregated Data, which Processor may continue to retain and use in accordance with the Agreement.

11.2 Where Processor is required by applicable law to retain Customer Personal Data, Processor shall continue to protect such Customer Personal Data in accordance with this Addendum and shall not Process such Customer Personal Data for any purpose other than compliance with the applicable legal obligation.

‍

12. International Data Transfers

12.1 Processor is certified under the EU-U.S. Data Privacy Framework ("EU-U.S. DPF") as administered by the U.S. Department of Commerce. To the extent that Processor Processes Customer Personal Data from the EEA, the United Kingdom, or Switzerland in reliance on its DPF certification, Processor commits to handle such data in accordance with the applicable DPF Principles. To the extent that Processor Processes Customer Personal Data originating from the EEA, Switzerland, or the United Kingdom in a country that has not been recognized by the European Commission as providing an adequate level of protection for Personal Data, and that the EU-U.S. DPF does not apply, Processor shall implement alternative transfer mechanisms as set out in Section 12 of this Addendum.

12.2 For transfers of Personal Data subject to the GDPR from the EEA to a country outside the EEA that is not subject to an Adequacy Decision, the European Commission Standard Contractual Clauses (“SCCs”) are hereby incorporated by reference and shall apply as follows: (a) Module Two (Controller to Processor) shall apply; (b) the optional docking clause in Clause 7 shall apply; (c) in Clause 9, Option 2 shall apply, and the time period for prior notice of Sub-Processor changes shall be fourteen (14) days; (d) in Clause 11, the optional language shall not apply; (e) in Clause 17, Option 1 shall apply and the SCCs shall be governed by the laws of Ireland; (f) in Clause 18(b), disputes shall be resolved before the courts of Ireland; (g) Annex I to the SCCs shall be deemed completed with the information set out in Annex 1 to this Addendum; and (h) Annex II to the SCCs shall be deemed completed with the information set out in Annex 2 to this Addendum.

12.3 For transfers of Personal Data subject to the UK GDPR from the UK to a country outside the UK that is not subject to an adequacy regulation under the UK GDPR, the SCCs as modified by the UK Addendum are hereby incorporated by reference. The relevant tables and appendices of the UK Addendum shall be deemed completed using the information set out in Annex 1 and Annex 2 to this Addendum.

12.4 For transfers of Personal Data subject to the Swiss Federal Act on Data Protection from Switzerland to a country outside Switzerland that is not subject to an Adequacy Decision, the SCCs shall apply with the following modifications: (a) references to “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss Federal Act on Data Protection; (b) references to “EU,” “Union,” and “Member State” shall be interpreted to include Switzerland; (c) the competent Supervisory Authority shall be the Swiss Federal Data Protection and Information Commissioner; and (d) references to the courts and governing law shall be interpreted to permit data subjects in Switzerland to enforce their rights in Switzerland as required by Swiss law.

‍

13. Term and Termination

13.1 This Addendum shall remain in effect for so long as Processor Processes Customer Personal Data on behalf of Controller under the Agreement.

13.2 Any obligations under this Addendum that by their nature are intended to survive termination or expiration shall survive, including obligations relating to confidentiality, return or deletion of Customer Personal Data, liability, international transfers, and audit rights.

‍

14. Liability and Indemnification

14.1 Each Party shall be liable for damages caused by its breach of this Addendum to the extent provided by applicable law and the Agreement.

14.2 Any claims, liabilities, damages, losses, costs, expenses, or indemnification obligations arising under or in connection with this Addendum shall be subject to the limitations and exclusions of liability set forth in the Agreement, except to the extent prohibited by applicable Data Protection Laws or the Standard Contractual Clauses.

‍

15. General Provisions

15.1 In the event of any conflict between this Addendum and the Agreement with respect to the subject matter of this Addendum, this Addendum shall prevail.

15.2 If any provision of this Addendum is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid or unenforceable provision shall be replaced with a valid provision that most closely reflects the Parties’ original intent.

15.3 Nooks may update this Addendum from time to time by posting an updated version on its website or trust center; provided that no update will materially reduce the level of protection for Customer Personal Data during the then-current subscription term unless required to comply with applicable Data Protection Laws. The version of this Addendum in effect as of the effective date of the applicable Order Form or Agreement will apply to that Order Form or Agreement, unless the Parties agree otherwise or the updated version is required by applicable Data Protection Laws. Updates to the Sub-Processor List may be made in accordance with Section 7.

15.4 This Addendum is effective without a separate signature when incorporated into the Agreement. If this Addendum is separately executed, it may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one instrument.

15.5 This Addendum shall be governed by the governing law and jurisdiction provisions set forth in the Agreement, except to the extent otherwise required by the SCCs or UK Addendum with respect to international data transfers.

This Addendum is effective as of the effective date of the Agreement or the date Customer first accesses or uses the Services, whichever is earlier.

‍

ANNEX 1: DESCRIPTION OF PROCESSING
A. List of Parties

Data Exporter: The Customer identified in the Agreement.

Role: Controller, or Processor where applicable.

Activities relevant to the transfer: Receipt and use of the Services as described in the Agreement.

Data Importer: Nooks Communications, Inc., 350 Bush Street, 8th Floor, San Francisco, CA 94104

Role: Processor

Activities relevant to the transfer: Provision of the Services as described in the Agreement.

B. Description of Processing

Categories of Data Subjects: Customer’s authorized users; Customer’s employees, contractors, and agents; Customer’s prospects, leads, business contacts, and communication recipients.

Categories of Personal Data: Contact and identification data, including name, email address, phone number, job title, and company; authentication and account data, including user email address, and login information; CRM and sales engagement data, including contact, account, sequence, task, and engagement information; communication data, including call recordings, call transcripts, email content, email metadata, and attachments; product usage data; and technical data such as IP address, browser information and session data.

Sensitive Personal Data: No Sensitive Personal Data is intended to be transferred unless expressly authorized in writing by Processor.

Frequency of the Processing: Continuous.

Nature and Purpose of the Processing: To provide the Services as described in the Agreement.

Retention Period: For the term of the Agreement and thereafter in accordance with Section 11 of this Addendum.

For transfers to Sub-Processors, the subject matter, nature, and duration of the Processing are as necessary for the Sub-Processor to perform the applicable outsourced services on behalf of Processor in connection with the Services.

C. Competent Supervisory Authority

For GDPR transfers, the competent Supervisory Authority shall be determined in accordance with Clause 13 of the SCCs. Where Customer is established in an EU Member State, the Supervisory Authority of that Member State shall act as the competent Supervisory Authority. Where Customer is not established in the EU but falls within Article 3(2) of the GDPR and has appointed an EU representative under Article 27, the Supervisory Authority of the Member State in which such representative is established shall act as the competent Supervisory Authority. For UK transfers, the UK Information Commissioner’s Office shall be the competent Supervisory Authority. For Swiss transfers, the Swiss Federal Data Protection and Information Commissioner shall be the competent Supervisory Authority.

‍

ANNEX 2: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

This Annex describes the technical and organizational security measures maintained by Nooks Communications, Inc. (“Nooks”) in connection with its Processing of Customer Personal Data under the Data Processing Addendum (the “Addendum”). Capitalized terms not defined in this Annex have the meanings given in the Addendum or the Agreement.

Nooks shall maintain technical and organizational measures materially consistent with those described in this Annex. These measures address the confidentiality, integrity, and availability of the systems and services used to Process Customer Personal Data.

The measures apply to the relevant systems, personnel, and Processing activities within Nooks’ responsibility. Safeguards for infrastructure and services operated by Sub-Processors are addressed through the applicable provider’s security controls and Nooks’ assessment and contractual oversight of that provider, as described below and in the Addendum.

‍

1. Security Program

1.1 Information security management. Nooks maintains a documented information security program comprising policies, procedures, assigned responsibilities, and technical controls appropriate to the nature of the Services and the risks associated with Processing Customer Personal Data.

1.2 Policies and procedures. The program addresses access control, personnel security, asset management, acceptable use, encryption, endpoint security, secure development, vulnerability management, incident response, business continuity, and vendor management. Security policies and procedures are made available to relevant personnel and reviewed at least annually. Material changes to Nooks’ operations, technology, or identified risks are considered when updating the program.

1.3 Responsibilities and oversight. Nooks assigns responsibility for administering its information security program and coordinating security activities across relevant functions. Management reviews the program and material security risks through its established governance processes.

1.4 Risk management. Nooks evaluates information security risks affecting the Services and Customer Personal Data and identifies appropriate treatment measures. Findings from risk assessments, security testing, incidents, and independent assessments inform corrective actions and security improvements. Exceptions to internal security policies are subject to documented approval and review.

‍

2. Personnel Security

2.1 Background screening. Nooks maintains personnel-screening procedures that include background checks for employees, as appropriate and permitted by applicable law. Screening requirements for temporary personnel and third parties are determined based on the relevant role, anticipated access, and business requirements. The nature and scope of screening are proportionate to the individual’s responsibilities and applicable legal requirements.

2.2 Confidentiality. Personnel authorized to Process Customer Personal Data are subject to contractual, professional, or statutory confidentiality obligations. Nooks’ onboarding procedures require applicable confidentiality commitments to be in place before personnel are granted access to Customer Personal Data or other confidential information.

2.3 Security awareness. Security awareness training is required as part of Nooks’ onboarding process and periodically thereafter, including at least annually. Training addresses personnel responsibilities for protecting information, recognizing security threats, and reporting suspected incidents. Relevant personnel receive additional guidance appropriate to their security, technical, or operational responsibilities. Nooks retains records of training completion.

2.4 Policy compliance. Personnel are required to review and, where applicable, acknowledge Nooks’ information security policies and comply with applicable acceptable-use and information-handling requirements. Suspected policy violations are reviewed and addressed through applicable management, security, legal, or personnel processes, as appropriate.

2.5 Changes in responsibilities. Nooks maintains procedures designed to appropriately modify or revoke system and information access when personnel responsibilities change or when employment or another engagement ends. Continuing confidentiality obligations remain subject to applicable employment, engagement, or confidentiality terms.

‍

3. Asset Management and Information Classification

3.1 Asset identification. Nooks maintains inventories and ownership information for relevant information systems, cloud resources, devices, and data repositories used to support its operations. Inventoried assets include employee endpoints and network infrastructure. These records support access administration, security assessment, and identification of systems involved in Processing Customer Personal Data. Asset inventories are reviewed on a recurring basis to ensure accuracy.

3.2 Information classification. Nooks maintains an information-classification framework that assigns handling requirements according to the sensitivity of information and the potential consequences of unauthorized disclosure, modification, or loss. Customer Personal Data is subject to restricted handling requirements, including authorized access, approved storage locations, and applicable encryption and retention controls.

3.3 Approved systems and handling. Personnel are required to Process Customer Personal Data using approved systems and in accordance with the applicable business purpose, access permissions, and information-handling requirements. Nooks maintains a list of approved tools and systems, and access to repositories containing Customer Personal Data is restricted to authorized personnel and service functions.

3.4 Asset lifecycle. Nooks’ asset-management and device-management procedures address provisioning, changes in assignment, deprovisioning, and disposal. Where third-party vendors are engaged for physical asset return, sanitization, or disposal, Nooks retains records confirming secure data erasure prior to reallocation or retirement. Security requirements continue to apply while an asset remains capable of storing or providing access to Customer Personal Data.

‍

4. Access Control

4.1 Authorization and least privilege. Nooks grants workforce access to Customer Personal Data and production systems according to business need and job responsibilities, consistent with the principle of least privilege. Access requests and changes are subject to authorization by the applicable system owner, data owner, or other authorized personnel.

4.2 Individual accountability. Personnel use individually assigned accounts for routine system access. Privileged, service, and emergency accounts are administered through the applicable access-management procedures. Access to shared credentials, where required for an authorized operational purpose, is restricted.

4.3 Access reviews. Nooks reviews access rights to relevant systems, including privileged access, to determine whether permissions remain appropriate no less than annually. Access rights are adjusted when responsibilities change and promptly removed when no longer required or when employment or an engagement ends.

4.4 Privileged and remote access. Human administrative access to Nooks’ primary cloud infrastructure requires multi-factor authentication and is subject to managed network access and device-trust controls. Remote administrative connections are encrypted. Designated infrastructure permissions are granted through privileged-access-management workflows with applicable entitlement and duration restrictions when technically feasible.

4.5 Service identities and credentials. Service accounts and other non-human identities are subject to authentication and authorization controls appropriate to their functions. Access to associated credentials and tokens is restricted to authorized personnel and systems. Credential administration and incident-response procedures address the revocation or replacement of credentials when required.

4.6 Personnel access to Customer Personal Data. Workforce access is limited to personnel who require it to provide, support, maintain, or secure the Services or carry out other Processing authorized under the Addendum. Such access remains subject to the confidentiality, authorization, and security requirements described in this Annex.

‍

5. Endpoint Security

5.1 Device management. Nooks centrally manages company-issued workforce devices, including employee endpoints, through its device-management processes. Device provisioning and administration are subject to applicable security configuration and access requirements.

5.2 Required protections. Nooks enforces full-disk encryption, endpoint detection and response (EDR) or alternative protection, and automatic screen locking on all company-issued devices used to access production systems. Device authentication and security settings are administered through Mobile Device Management (MDM) systems. Third-party contractor devices accessing Nooks’ systems are required to meet Nooks’ authentication requirements as a condition of access.

5.3 Maintenance. Nooks’ device-management requirements address operating-system and security updates and the maintenance of endpoint protection. Personnel are required to protect assigned devices against unauthorized use and to report loss, theft, or suspected compromise. Compliance with device-management policies is monitored through MDM tooling on a continuous basis.

5.4 Deprovisioning and incident handling. Nooks uses available device-management capabilities, including remote locking or wiping where appropriate, to address lost, compromised, returned, or retired company-issued devices. Where third-party vendors are engaged for physical device return or disposal, Nooks retains records confirming secure data erasure prior to reallocation or retirement. Device handling remains subject to applicable investigation, preservation, and secure-disposal requirements.

‍

6. Physical and Environmental Security

6.1 Production hosting. Nooks’ primary production environment is hosted on cloud service providers in the United States. Physical security and environmental protection of the underlying production data centers are provided by the hosting provider. Sub-Processors may Process Customer Personal Data in the locations identified in the Sub-Processor List.

6.2 Data-center safeguards. Nooks relies on its hosting provider’s controls for restricting and monitoring physical access to production facilities and equipment, protecting against environmental hazards, maintaining supporting power and environmental systems, and managing the retirement of physical storage media. Nooks evaluates relevant provider security documentation and independent assurance through its supplier-management processes.

6.3 Corporate facilities. Nooks maintains documented physical access controls governing entry to its offices and other Nooks-controlled facilities. These controls include badge-controlled access at designated building or suite entry points. Access to locked equipment-storage and telecommunications rooms is restricted to authorized personnel, and visitor access is subject to appropriate authorization and oversight. Visitors entering badge-restricted areas are escorted by a Nooks employee. Personnel are required to protect devices and confidential information against unauthorized physical access when working on-site or remotely.

‍

7. Cloud Infrastructure and Network Security

7.1 Network protection. Nooks uses cloud network controls, including firewall rules and access restrictions, to limit exposure of relevant production resources. Network and application access rules are configured according to the function and access requirements of the relevant resource or service.

7.2 Application protection. Nooks uses web application firewall (WAF) or equivalent application-protection controls for relevant public-facing service endpoints. These controls operate with cloud security monitoring and application controls to identify and respond to suspicious or unauthorized activity.

7.3 Administrative interfaces. Access to infrastructure administration interfaces is restricted through the authentication, authorization, managed network access, and device-trust measures described in Section 4 of this Annex. Permissions to modify security-relevant infrastructure settings are limited to authorized personnel and service identities.

7.4 Configuration management. Security-relevant infrastructure configurations and changes are managed through applicable access-control and change-management procedures.

‍

8. Encryption

8.1 Encryption in transit. Nooks uses TLS 1.2 or higher to protect Customer Personal Data transmitted through the Services’ HTTPS interfaces. Encrypted remote administrative connections are used for access to production infrastructure.

8.2 Encryption at rest. Customer Personal Data stored in Nooks’ primary cloud production data stores is encrypted at rest using AES-256 encryption or an equivalent industry-standard alternative. Company-issued endpoints used to access production systems are subject to the full-disk encryption requirements in Section 5 of this Annex. Backup data is protected as described in Section 12 of this Annex.

8.3 Key management. Encryption at rest in the primary cloud production environment uses provider-managed encryption keys. The hosting provider administers the lifecycle of those keys through its managed encryption capabilities. Nooks restricts administrative access to relevant storage and encryption configurations through cloud identity and access controls.

‍

9. Security Logging and Monitoring

9.1 Security events. Nooks collects relevant security and administrative events from its cloud environment and connected systems. Depending on the source system, records include information such as the event time, user or service identity, action performed, affected resource, and outcome.

9.2 Centralized monitoring. Nooks uses centralized Security Information and Event Management (SIEM) capabilities to aggregate relevant logs, apply detection rules, and support security investigations. Alerts are evaluated and escalated according to the nature and severity of the activity.

9.3 Log protection and retention. Access to security logs and monitoring systems is restricted to authorized personnel. Logs collected in Nooks’ centralized SIEM system are retained for at least twelve (12) months. Retention of other logs and investigation records is governed by the applicable documented schedules, subject to the Addendum and applicable law.

9.4 Review and improvement. Nooks reviews and updates relevant logging sources, detection rules, and alerting arrangements as appropriate following changes to systems, identification of new threats, or lessons from security investigations. Monitoring activities support the identification of unauthorized access and the investigation of suspected misuse.

‍

10. Secure Development and Change Management

10.1 Development controls. Nooks maintains software development and change management processes incorporating version control, code review, automated static security analysis, and controlled deployment procedures. Security findings are evaluated through the applicable development and vulnerability-management processes.

10.2 Repository and deployment access. Access to source-code repositories, build systems, and deployment capabilities is restricted to authorized personnel and service identities according to their responsibilities. Changes are recorded through the relevant version-control and deployment workflows.

10.3 Infrastructure changes. Changes to cloud resources managed through infrastructure as code are maintained in version control and subject to approval before automated application when applicable. Permissions to administer or apply infrastructure changes are managed through the applicable access-control procedures.

10.4 Security fixes. Security patches and corrective changes are assessed and deployed according to their urgency, potential impact, and applicable change-management requirements. Testing and validation are performed as appropriate to the affected system and the nature of the change.

‍

11. Vulnerability and Patch Management

11.1 Vulnerability identification. Nooks maintains a vulnerability-management program that uses automated scanning, security assessments, and relevant threat and vulnerability information to identify weaknesses affecting applications and cloud infrastructure. Vulnerability assessments include ongoing automated vulnerability scanning.

11.2 Independent penetration testing. Nooks engages an independent provider to conduct penetration testing of the Services at least annually. Testing scope is selected to address relevant service components, architecture, and material security risks. Findings are reviewed by the responsible security and engineering personnel.

11.3 Risk assessment and remediation. Identified vulnerabilities are evaluated according to severity, exploitability, exposure, and potential impact on Customer Personal Data and the Services. Nooks tracks remediation or mitigation according to its documented risk-based procedures and timelines.

11.4 Exceptions and dependencies. Where immediate remediation is not practicable, Nooks evaluates available mitigation measures and manages any exception through its risk-management procedures. Findings involving infrastructure or services operated by a Sub-Processor are addressed with the responsible provider through the applicable supplier and support processes.

11.5 Patch management. Security patches and updates for systems within Nooks’ responsibility are evaluated and applied according to risk and the relevant operational requirements. Maintenance of underlying infrastructure operated by a cloud provider is addressed through that provider’s maintenance processes and Nooks’ applicable service configuration and oversight.

‍

12. Business Continuity, Backup, and Disaster Recovery

12.1 Continuity planning. Nooks maintains documented business-continuity and disaster-recovery procedures addressing disruptions to the Services and the availability of Customer Personal Data. These procedures identify relevant responsibilities, dependencies, escalation arrangements, and recovery activities.

12.2 Backup arrangements. Nooks uses scheduled database backups and available point-in-time recovery capabilities for relevant production data stores. Backup arrangements are selected according to the requirements and recovery capabilities of the applicable system.

12.3 Backup protection. Backup data is protected through encryption and access restrictions. Access to backup administration and recovery functions is limited to authorized personnel and systems. Backup retention and expiration are governed by the applicable retention schedules and the Addendum.

12.4 Recovery procedures. Nooks maintains procedures for restoring affected systems or data using available recovery mechanisms and for coordinating with relevant infrastructure providers. Recovery activities include assessing service functionality and addressing issues identified during the recovery process.

12.5 Exercises and review. Nooks conducts periodic business-continuity and disaster-recovery tabletop exercises to evaluate response responsibilities, coordination, recovery procedures, and communications. Identified improvements are documented and considered in updates to the relevant plans and procedures.

12.6 Contractual recovery commitments. Any customer-specific service-availability commitments, recovery time objectives, or recovery point objectives are governed by the Agreement or an expressly agreed service-level schedule.

‍

13. Security Incident Management

13.1 Response procedures. Nooks maintains a documented incident-response process addressing the identification, assessment, escalation, investigation, containment, remediation, and recovery of security incidents.

13.2 Coordination and investigation. Response activities are coordinated among relevant security, engineering, management, legal, and customer-facing personnel according to the incident’s nature and severity. Nooks uses available logs and other relevant information to assess the affected systems, potential impact, and appropriate response.

13.3 Corrective action. Nooks takes appropriate measures to contain identified incidents, address their causes, and mitigate adverse effects. Material incidents are reviewed, and relevant findings and corrective actions are documented through the incident-review process.

13.4 Customer notification and assistance. Notification of Personal Data Breaches, investigation updates, and related assistance to Customer are governed by the Addendum. Nooks coordinates with relevant Sub-Processors where their participation is necessary to investigate or address an incident.

‍

14. Data Handling, Retention, and Disposal

14.1 Purpose limitation and minimization. Nooks Processes Customer Personal Data for the purposes authorized under the Addendum and applies information-handling controls appropriate to the relevant Processing. Personnel access and use are limited according to business need and the applicable authorization.

14.2 Scope of protection. Customer Personal Data contained in recordings, transcripts, prompts, AI outputs, support records, logs, and exports remains subject to the applicable protections of the Addendum. Its location in a different system or form does not, by itself, remove those protections.

14.3 Retention and deletion. Nooks maintains procedures addressing the retention, return, and deletion of Customer Personal Data. Applicable retention periods, Customer instructions, backup expiration, and legally required preservation are governed by the Addendum and the agreed requirements for the Services.

14.4 Return, correction, and privacy assistance. Nooks provides assistance with authorized requests to locate, access, export, correct, restrict, or delete Customer Personal Data through available service functionality and operational procedures, taking into account the nature of the Processing. Relevant actions involving Sub-Processors are coordinated with those providers as required by the Addendum.

14.5 Device and media disposal. Nooks’ device-management and disposal procedures address the removal of confidential information from company-controlled devices and media when they are deprovisioned or retired. Physical disposal of storage media used by cloud hosting providers is managed through those providers’ security and media-management procedures.

14.6 AI Processing. Customer Personal Data supplied to AI features or included in their outputs is subject to the applicable access, confidentiality, security, and data-handling requirements in this Annex. AI providers engaged to Process Customer Personal Data are subject to the applicable Sub-Processor requirements.

‍

15. Sub-Processor Management

15.1 Assessment. Before permitting a relevant Sub-Processor to Process Customer Personal Data, Nooks evaluates the provider’s security and privacy practices in light of the proposed Processing, the sensitivity of the information involved, access requirements, and available independent assurance.

15.2 Contractual safeguards. Nooks enters into written agreements with Sub-Processors addressing the applicable confidentiality, security, incident-management, assistance, and return or deletion obligations required by the Addendum.

15.3 Allocation of responsibilities. Where a provider operates underlying infrastructure or a managed service, Nooks identifies the relevant division of security responsibilities and administers the configurations, permissions, and other controls within Nooks’ responsibility. Provider-operated safeguards are evaluated through relevant documentation, assurance reports, and supplier-management activities.

15.4 Changes and ongoing coordination. Sub-Processor additions, replacements, objections, and international transfers are governed by the Addendum. Nooks coordinates relevant security findings, incidents, and data-handling requests with the responsible provider through its supplier-management processes.

‍

16. Compliance, Assurance, and Maintenance of Measures

16.1 Independent assurance. Nooks maintains an independent assurance program that includes SOC 2 Type II examinations and ISO/IEC 27001:2022 certification for the applicable audited or certified scope.

16.2 Assessment and corrective action. Nooks evaluates the effectiveness of its security measures through its risk-management activities, security testing, monitoring, internal reviews, and independent assessments. Relevant findings are assessed and addressed through the applicable corrective-action processes.

16.3 Security documentation. Relevant reports, certifications, and security documentation are made available through Nooks’ Trust Center or upon reasonable request, subject to appropriate confidentiality and security requirements. Customer audit and verification rights are governed by the Addendum.

16.4 Updates. Nooks may update its security measures as technology, operations, and security risks evolve, in accordance with the Addendum. Such updates shall not materially diminish the overall protection of Customer Personal Data.

16.5 Contractual coordination. This Annex supplements the Addendum’s security obligations. Processing instructions, Personal Data Breach notifications, retention and deletion obligations, Sub-Processor authorization, audit rights, international transfers, and liability remain governed by the applicable provisions of the Addendum and Agreement

‍

ANNEX 3: SUB-PROCESSOR LIST

A current list of Sub-Processors engaged by Processor in connection with the Services is maintained at:

www.nooks.ai/subprocessors or such successor website designated by Processor from time to time.

For each Sub-Processor, the Sub-Processor List shall identify, as applicable:

  • the Sub-Processor’s name;
  • the location where Customer Personal Data is stored or processed;
  • a description of the outsourced services;
  • the categories of Customer Personal Data involved; and
  • the categories of Data Subjects affected.

Last reviewed May 1, 2026.

Consent Preferences