Skip to content
Legal

Customer Agreement

Effective Date: March 14, 2024

Vaultera Customer Agreement

Effective Date: March 14, 2024

TERMS OF SERVICE

This Customer Agreement ("Agreement") is entered into as of the Effective Date between Vaultera ehf, a company registered in Iceland (kennitala: 5902240140) ("Vaultera" or "we") and the entity executing this Agreement ("Customer" or "you").

Introduction

This Agreement governs your use of Vaultera's services, including but not limited to Vaultera Vault (PCI DSS Level 1 card tokenization and secure storage) and Vaultera Switch (payment orchestration with smart routing to multiple Payment Service Providers). By accessing or using these services, you agree to be bound by all terms and conditions contained herein. If you do not agree to these terms, you may not use our services. Please note that modifications to this Agreement are detailed in Section 26 (Changes to this Agreement).


1. DEFINITIONS AND INTERPRETATIONS

1.1 "Vaultera Services" means the software-as-a-service offerings provided by Vaultera, including Vaultera Vault, Vaultera Switch, and any related services, documentation, and support.

1.2 "Customer Data" means any data, content, or information that Customer submits to, stores in, or processes through the Vaultera Services, including transaction data, tokenized payment card data, and customer information.

1.3 "Confidential Information" means any non-public information disclosed by one party to the other, marked as confidential or reasonably understood to be confidential, excluding information that is publicly available through no breach of this Agreement.

1.4 "Applicable Law" means the laws of Iceland, including data protection laws and regulations, without regard to conflict of law principles.

1.5 "Payment Card Industry Data Security Standard" or "PCI DSS" means the current version of the industry-standard security specification maintained by the PCI Security Standards Council.


2. SERVICES DESCRIPTION

2.1 Service Offerings Vaultera provides payment infrastructure services designed for use by merchants and service providers in the hospitality, e-commerce, and related industries. The Vaultera Services include:

a) Vaultera Vault: PCI DSS Level 1 compliant payment card tokenization and secure storage services that allow secure handling of payment card data without storing sensitive card data on Customer's systems.

b) Vaultera Switch: Payment orchestration and intelligent routing services enabling customers to route transactions through multiple Payment Service Providers (PSPs), optimizing transaction success rates and costs.

2.2 Service Levels Service availability, features, uptime requirements, support levels, and pricing are subject to the specific service agreement, service level agreement (SLA), and pricing schedule provided to Customer. All documentation is incorporated by reference into this Agreement.

2.3 Changes to Services Vaultera reserves the right to modify, suspend, or discontinue the Vaultera Services (or any component thereof) at any time, with at least thirty (30) days prior written notice to Customer, except in cases of emergency maintenance or security issues, which may be implemented with reasonable notice.


3. ELIGIBILITY AND ACCOUNT REGISTRATION

3.1 Eligibility By using the Vaultera Services, you represent and warrant that:

a) You are of legal age and have the authority to enter into this Agreement on behalf of your organization;

b) Your organization is not located in, nor organized under the laws of, any jurisdiction subject to comprehensive economic sanctions or embargoes;

c) You are not identified on any government restricted party list or sanctions list maintained by any government authority;

d) You will use the Vaultera Services only in compliance with all applicable laws and regulations.

3.2 Account Responsibilities You agree to:

a) Maintain the confidentiality of your API keys, authentication credentials, and any access tokens provided by Vaultera;

b) Assume full responsibility for all activities that occur under your account;

c) Notify Vaultera immediately of any unauthorized access to your account or any security breach of which you become aware;

d) Implement reasonable security measures to protect your credentials from unauthorized disclosure.

3.3 Account Information You are responsible for ensuring that all information you provide to Vaultera in connection with your account is accurate, complete, and current. You agree to update your information as necessary to maintain accuracy.


4. FEES AND PAYMENT TERMS

4.1 Fees and Pricing Fees for the Vaultera Services are determined by your service agreement, including your selected plan tier, transaction volume, and any add-on features. A pricing schedule will be provided separately.

4.2 Billing a) Usage-based charges are billed monthly in arrears based on actual usage of the Vaultera Services during the preceding calendar month.

b) All fees are stated in US Dollars (USD) unless otherwise specified in your service agreement.

c) Invoices will be provided electronically, unless otherwise arranged.

4.3 Payment Customer agrees to pay invoices within thirty (30) days of invoice date. Payment should be made according to the payment instructions provided on the invoice or in your service agreement.

4.4 Late Payment If payment is not received within thirty (30) days of invoice date, Vaultera may:

a) Charge interest on the outstanding balance at the rate of 1.5% per month or the maximum rate permitted by applicable law, whichever is lower;

b) Suspend access to the Vaultera Services until payment is made;

c) Terminate this Agreement if the account remains delinquent for more than sixty (60) days.

4.5 Taxes Unless Customer provides a valid tax exemption certificate, all fees are exclusive of applicable sales tax, value-added tax (VAT), or other similar taxes, which will be added to invoices and must be paid by Customer.

4.6 No Refunds Except as required by applicable law, all fees paid are non-refundable.


5. ACCEPTABLE USE POLICY

5.1 General Restrictions You agree not to use the Vaultera Services in any manner that:

a) Violates any applicable law, regulation, or the rights of any third party;

b) Is intended for any unlawful purpose or in furtherance of illegal activity;

c) Infringes upon any intellectual property rights of Vaultera or third parties;

d) Harasses, threatens, defames, or abuses any person or entity.

5.2 Technical Restrictions You agree not to:

a) Attempt to gain unauthorized access to the Vaultera Services, systems, or networks;

b) Interfere with or disrupt the normal operation of the Vaultera Services or any networks connected to the services;

c) Transmit any viruses, malware, worms, or other harmful or malicious code;

d) Use automated systems, robots, scrapers, or similar tools to access, monitor, or copy content from the Vaultera Services except as expressly authorized by Vaultera;

e) Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of the Vaultera Services;

f) Resell, distribute, license, or otherwise make available the Vaultera Services to any third party without express written permission from Vaultera.

5.3 Content Restrictions You agree not to submit to the Vaultera Services:

a) Any content that is unlawful, defamatory, or harmful;

b) Any content that violates the rights of third parties.

5.4 Enforcement Vaultera reserves the right to suspend or terminate access to the Vaultera Services immediately, without notice, if you violate this Acceptable Use Policy. Vaultera also reserves the right to report violations to law enforcement authorities as required or permitted by law.


6. INTELLECTUAL PROPERTY RIGHTS

6.1 Vaultera Ownership Vaultera retains all right, title, and interest in and to the Vaultera Services, including all software, documentation, technology, processes, and know-how. Customer is granted a limited, non-exclusive, non-transferable license to use the Vaultera Services solely in accordance with this Agreement.

6.2 Customer Content Customer retains all right, title, and interest in Customer Data. By submitting Customer Data to the Vaultera Services, Customer grants Vaultera a limited license to process, store, and transmit Customer Data as necessary to provide the Vaultera Services.

6.3 Feedback If you provide feedback, suggestions, or improvements regarding the Vaultera Services, Vaultera may use such feedback without restriction and without obligation to you.

6.4 Trademarks All Vaultera names, logos, and marks are trademarks or registered trademarks of Vaultera ehf. You may not use any Vaultera trademarks without prior written permission.


7. DATA PROCESSING AND SECURITY

7.1 Data Processing Standards The Vaultera Services are designed to process payment card data in a PCI DSS Level 1 compliant manner. Vaultera maintains PCI DSS Level 1 certification and provides an Attestation of Compliance (AOC) upon request.

7.2 Card Data Tokenization

7.2.1 Vaultera's Tokenization Service Vaultera's Hosted Services are specifically designed to process payment card data in a secure, PCI DSS-compliant manner. When Customer submits payment card data to Vaultera's tokenization service, Vaultera encrypts, securely stores, and manages that card data according to PCI DSS standards. In return, Vaultera provides a unique token that represents the card data. This token can be used for subsequent transactions without exposing the actual card data.

7.2.2 Data Types Accepted Payment card data submitted for tokenization typically includes:

  • Card holder name
  • Card number (primary account number)
  • Expiration date
  • Card verification value (CVV)
  • Billing address
  • Other data necessary for payment processing

7.2.3 Data Types Not Accepted Customer agrees not to submit the following types of data to the Vaultera Services:

  • Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA), except as directly necessary for payment processing at healthcare merchants
  • Biometric data unrelated to payment transactions (fingerprints, facial recognition data, etc.)
  • Government-issued identification numbers (passport numbers, driver's license numbers, social security numbers) except where such numbers are embedded in or directly required for payment card processing
  • Any data that Customer is prohibited from sharing by applicable law or regulation

7.2.4 Customer Responsibility Customer is responsible for ensuring that it has the legal right to submit any personal data to the Vaultera Services, including but not limited to:

  • Obtaining necessary consent from data subjects (cardholders and other individuals whose data is submitted)
  • Complying with all applicable data protection laws, including GDPR, the Icelandic Data Protection Act, and any other applicable regulations
  • Maintaining appropriate data processing agreements with Vaultera where required by law

7.3 Security Measures Vaultera implements industry-standard security measures to protect Customer Data, including:

a) Encryption of data in transit using TLS/SSL or equivalent protocols;

b) Encryption of sensitive data at rest;

c) Multi-factor authentication and access controls;

d) Regular security assessments and penetration testing;

e) Secure key management practices;

f) Employee access restrictions and training;

g) Incident detection and response procedures.

7.4 Data Retention and Deletion

a) Vaultera will retain Customer Data only for as long as necessary to provide the Vaultera Services and comply with applicable legal obligations.

b) Upon termination of this Agreement, Customer Data will be securely deleted within ninety (90) days, unless Customer is in breach of this Agreement or Vaultera is required to retain the data by applicable law.

c) Tokenized payment card data will be cryptographically destroyed in accordance with PCI DSS requirements.

7.5 Backups Vaultera maintains backups of Customer Data for disaster recovery purposes. Backups are encrypted and securely stored. Backup retention follows the same deletion schedule as primary data.

7.6 Audit Rights

a) Customer has the right to audit Vaultera's compliance with security obligations under this Agreement, upon reasonable notice and no more than once per calendar year, unless there is reasonable suspicion of a security violation.

b) Such audits must be conducted by the Customer or a qualified third-party auditor under confidentiality obligations.

c) Vaultera may require the auditor to sign a non-disclosure agreement prior to conducting the audit.

7.7 Regulatory Compliance

7.7.1 PCI DSS Compliance Vaultera maintains PCI DSS Level 1 certification and complies with all requirements of the PCI Data Security Standard. Vaultera provides an annual Attestation of Compliance (AOC) to customers upon request.

7.7.2 Data Protection Compliance Vaultera complies with applicable data protection laws, including:

  • The Icelandic Data Protection Act (lög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018)
  • The EU General Data Protection Regulation (GDPR, Regulation 2016/679)
  • Other applicable data protection and privacy laws in jurisdictions where Vaultera operates

7.7.3 Incident Notification In the event of a security incident or data breach involving Customer Data, Vaultera will:

a) Notify Customer without undue delay and, where required by law, no later than 72 hours after becoming aware of the breach;

b) Provide reasonable assistance to Customer in meeting any regulatory notification requirements;

c) Cooperate with Customer in investigating the incident.


8. CONFIDENTIALITY

8.1 Definition "Confidential Information" means non-public information disclosed by one party to the other, marked as confidential or reasonably understood to be confidential by the receiving party, excluding information that:

a) Is or becomes publicly available through no breach of this Agreement;

b) Is independently developed without reference to the disclosing party's Confidential Information;

c) Is rightfully received from a third party without confidentiality obligations;

d) Is approved for release by written consent of the disclosing party.

8.2 Obligations The receiving party agrees to:

a) Protect Confidential Information using the same degree of care it uses to protect its own confidential information, but in no case less than reasonable care;

b) Limit access to Confidential Information to employees, contractors, and advisors who have a legitimate need to know;

c) Not disclose Confidential Information to third parties without prior written consent.

8.3 Exceptions to Confidentiality Notwithstanding the above, a party may disclose Confidential Information:

a) As required by law, regulation, or court order, provided the disclosing party gives the other party prompt notice to allow the other party to seek protection of the information;

b) To comply with legal or regulatory requirements, including requests from law enforcement or regulatory authorities.

8.4 Return or Destruction Upon termination of this Agreement, each party will, at the request of the other party, return or destroy all Confidential Information in its possession.


9. REPRESENTATIONS AND WARRANTIES

9.1 Mutual Warranties Each party represents and warrants that:

a) It has the right and authority to enter into this Agreement;

b) Its execution and performance of this Agreement is authorized by its governing documents and does not violate any law or agreement to which it is bound;

c) It will comply with all applicable laws and regulations in performing its obligations under this Agreement.

9.2 Vaultera Warranties Vaultera warrants that:

a) The Vaultera Services will be provided in a professional manner consistent with industry standards;

b) The Vaultera Services will comply with all applicable laws and regulations, including PCI DSS and data protection laws;

c) Vaultera has the right to provide the Vaultera Services and that the services do not infringe upon third-party intellectual property rights;

d) Vaultera maintains appropriate insurance for its operations and obligations under this Agreement.

9.3 Customer Warranties Customer warrants that:

a) It has the legal right to submit all Customer Data to the Vaultera Services;

b) Its submission of Customer Data does not violate any law or third-party rights;

c) All information provided to Vaultera in connection with this Agreement is accurate and complete;

d) It has obtained all necessary consents from cardholders and other individuals whose data will be processed through the Vaultera Services.

9.4 DISCLAIMER EXCEPT AS EXPRESSLY PROVIDED IN THIS SECTION 9, VAULTERA MAKES NO OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. THE VAULTERA SERVICES ARE PROVIDED "AS IS."


10. INDEMNIFICATION

10.1 Indemnification by Vaultera Vaultera will defend, indemnify, and hold harmless Customer from and against any third-party claims, losses, damages, liabilities, and expenses (including reasonable attorneys' fees) arising from:

a) Any breach by Vaultera of its representations, warranties, or obligations under this Agreement;

b) Any claim that the Vaultera Services infringe upon a third party's intellectual property rights;

c) Any violation by Vaultera of applicable law or regulation in providing the Vaultera Services.

10.2 Indemnification by Customer Customer will defend, indemnify, and hold harmless Vaultera from and against any third-party claims, losses, damages, liabilities, and expenses (including reasonable attorneys' fees) arising from:

a) Customer's breach of this Agreement;

b) Customer's violation of applicable law or regulation in using the Vaultera Services;

c) Customer Data, including any claim that Customer Data infringes upon third-party rights;

d) Customer's use of the Vaultera Services in violation of the Acceptable Use Policy.

10.3 Indemnification Procedures The indemnified party must:

a) Provide prompt written notice of the claim;

b) Grant the indemnifying party sole control of the defense and settlement;

c) Provide reasonable cooperation in the defense.


11. LIMITATION OF LIABILITY

11.1 Limitation TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL VAULTERA BE LIABLE FOR:

a) Any indirect, incidental, special, consequential, or punitive damages, including lost profits, lost revenue, lost data, or business interruption, even if Vaultera has been advised of the possibility of such damages;

b) Any damages arising from your use of or inability to use the Vaultera Services or any content transmitted through the services;

c) Any unauthorized access to or alteration of your data unless such access results directly from Vaultera's gross negligence or willful misconduct.

11.2 Cap on Liability Except for breaches of confidentiality obligations, indemnification obligations, or intellectual property infringement claims, Vaultera's total cumulative liability to Customer under or in connection with this Agreement shall not exceed the total fees paid by Customer to Vaultera in the twelve (12) months immediately preceding the event giving rise to liability. If no fees have been paid during such period, Vaultera's liability shall not exceed five hundred US Dollars (USD $500).

11.3 Essential Term Customer acknowledges that Vaultera's willingness to provide the Vaultera Services is conditioned upon the limitations of liability set forth in this Section 11, and that these limitations are an essential element of this Agreement.


12. TERM AND TERMINATION

12.1 Term This Agreement commences on the Effective Date and continues for the initial term specified in your service agreement. Unless otherwise specified, the initial term is one (1) year.

12.2 Renewal Unless either party provides written notice of non-renewal at least thirty (30) days prior to the end of the then-current term, this Agreement will automatically renew for successive one (1) year terms on the same terms and conditions.

12.3 Termination for Convenience Either party may terminate this Agreement for any reason upon thirty (30) days written notice to the other party, provided all outstanding fees have been paid.

12.4 Termination for Cause Either party may terminate this Agreement immediately upon written notice if:

a) The other party materially breaches this Agreement and fails to cure such breach within fifteen (15) days of written notice;

b) The other party becomes insolvent, bankrupt, or subject to receivership or similar proceedings;

c) The other party violates the Acceptable Use Policy.

12.5 Effect of Termination Upon termination or expiration of this Agreement:

a) All rights and licenses granted to Customer are immediately revoked;

b) Customer's access to the Vaultera Services will be immediately revoked;

c) Customer Data will be securely deleted within ninety (90) days, unless Customer is in material breach or Vaultera is required to retain the data by applicable law;

d) Customer must pay all outstanding fees and expenses;

e) Sections 6, 8, 9.4, 10, 11, 12.5, 15, 16, 17, 18, 19, 21, and 28 shall survive termination.

12.6 Survival The provisions of this Agreement that by their nature should survive termination, including those relating to intellectual property, confidentiality, indemnification, limitation of liability, and governing law, shall survive termination or expiration.


13. WARRANTIES AND DISCLAIMERS

13.1 Service Availability While Vaultera strives to maintain high availability of the Vaultera Services, Vaultera does not guarantee uninterrupted service or that the services will be error-free.

13.2 No Warranty of Results Vaultera does not warrant any particular results from your use of the Vaultera Services. Customer assumes all responsibility and risk for your use of the services.

13.3 Third-Party Services The Vaultera Services may integrate with or depend upon third-party services, including Payment Service Providers, infrastructure providers, and other partners. Vaultera is not responsible for the availability, performance, or security of these third-party services except to the extent required by applicable law.

13.4 Data Integrity While Vaultera implements security measures to protect Customer Data, Vaultera cannot guarantee that unauthorized access or data loss will never occur. Customer is responsible for maintaining backups of any critical data and testing recovery procedures.


14. FORCE MAJEURE

14.1 Events of Force Majeure Neither party shall be held liable for any failure or delay in performance under this Agreement arising from events beyond the reasonable control of that party, including:

a) Acts of God (earthquakes, volcanic eruptions, tsunamis, etc.);

b) War, terrorism, or armed conflict;

c) Pandemic or epidemic;

d) Strikes, labor disputes, or labor stoppages not attributable to the party's own actions;

e) Government actions or sanctions;

f) Network infrastructure failures beyond the party's reasonable control.

14.2 Mitigation The party affected by a force majeure event shall use reasonable efforts to mitigate the impact and resume performance under this Agreement.

14.3 Notice The party invoking force majeure shall provide prompt written notice to the other party describing the force majeure event and its anticipated duration.


15. BUSINESS CONTINUITY AND DISASTER RECOVERY

15.1 Business Continuity Plan Vaultera maintains a comprehensive business continuity and disaster recovery plan designed to:

a) Minimize service interruptions in the event of a disaster;

b) Recover critical systems and data within the recovery time objective (RTO) and recovery point objective (RPO) specified in the applicable SLA;

c) Ensure continuous operation from a geographically diverse location if primary systems become unavailable.

15.2 Recovery Time Objectives Specific RTO and RPO commitments are detailed in the applicable Service Level Agreement (SLA).

15.3 Testing Vaultera tests its disaster recovery procedures at least annually and maintains documentation of test results.


16. SUPPORT AND MAINTENANCE

16.1 Support Levels Vaultera provides technical support according to the support level specified in your service agreement. Support levels may include:

a) Standard support: business hours support with 24-hour response time;

b) Premium support: 24/7 support with expedited response times;

c) Enterprise support: dedicated support contact with specified service levels.

16.2 Maintenance Windows Vaultera may perform scheduled maintenance on the Vaultera Services with advance notice when reasonably possible. Maintenance will be scheduled to minimize customer impact and, when possible, outside of business hours.

16.3 Emergency Maintenance Vaultera may perform emergency maintenance without notice if necessary to:

a) Protect the security or integrity of the Vaultera Services;

b) Respond to a security incident or attack;

c) Restore service following an outage.


17. SURVIVAL

The following provisions of this Agreement shall survive any termination or expiration:

Sections 7.7.3 (Incident Notification), 10 (Indemnification), 11 (Limitation of Liability), 12.5 (Effect of Termination), 12.6 (Survival), 13.2 (No Warranty of Results), 15 (Business Continuity), 16.3 (Emergency Maintenance), 17 (Survival), 18.2 (Dispute Resolution), 19 (Governing Law), 21 (Entire Agreement), 24 (Limitation on Injunctive Relief and Rights), 25 (Export Restrictions), and 28 (GDPR Data Protection Addendum).


18. DISPUTE RESOLUTION

18.1 Informal Resolution Before pursuing formal dispute resolution, the parties agree to attempt to resolve any dispute through good faith negotiation between senior representatives of each party.

18.2 Arbitration If informal resolution fails, any dispute arising out of or relating to this Agreement shall be resolved through binding arbitration rather than in court, except that:

a) Either party may seek injunctive or other equitable relief in court to prevent irreparable harm;

b) Either party may pursue claims in small claims court if the claim is within the jurisdiction and dollar limitations of such court.

Arbitration shall be conducted:

a) Under the Rules of Arbitration of the International Chamber of Commerce (ICC);

b) In the English language;

c) By a single arbitrator with experience in software and payment systems;

d) In Reykjavik (Iceland) or London (UK), as mutually agreed between the parties.

18.3 Arbitration Costs Each party shall bear its own attorneys' fees and costs. The arbitrator's fees and costs shall be split equally between the parties, unless the arbitrator awards fees to the prevailing party.

18.4 Confidentiality Arbitration proceedings shall be confidential. Neither party shall disclose the existence of the arbitration, the claims, or the outcome without the other party's consent, except as required by law.


19. GOVERNING LAW

19.1 Applicable Law This Agreement shall be governed by and construed in accordance with the laws of Iceland, without regard to its conflict of law principles. The parties expressly exclude the application of the UN Convention on Contracts for the International Sale of Goods.

19.2 Legal Venue Any action or proceeding arising out of or relating to this Agreement shall be brought exclusively in the courts of Reykjavik, Iceland, to which both parties consent and submit.


20. COMPLIANCE WITH LAWS

20.1 Legal Compliance Each party agrees to comply with all applicable laws and regulations in performing its obligations under this Agreement, including:

a) Data protection and privacy laws;

b) Consumer protection laws;

c) Anti-corruption laws, including the UK Bribery Act and Iceland's anti-corruption laws;

d) Import/export and sanctions laws;

e) Anti-money laundering (AML) and Know Your Customer (KYC) regulations.

20.2 Regulatory Changes If changes in applicable law make performance of this Agreement impossible or impractical, the parties agree to negotiate in good faith to amend this Agreement as necessary to comply with such changes.


21. ENTIRE AGREEMENT

21.1 Integration This Agreement, including all exhibits, appendices, schedules, service level agreements, privacy policies, and any other documents incorporated by reference, constitutes the entire agreement between the parties concerning the subject matter and supersedes all prior negotiations, understandings, and agreements, whether written or oral.

21.2 Modification No modification, amendment, or waiver of this Agreement shall be valid unless made in writing and signed by authorized representatives of both parties.

21.3 Severability If any provision of this Agreement is found to be invalid or unenforceable, that provision shall be modified to the minimum extent necessary to make it valid, or if such modification is not possible, the provision shall be severed. The remainder of this Agreement shall remain in full force and effect.


22. ASSIGNMENT

22.1 Restrictions on Assignment Neither party may assign, transfer, or delegate its rights or obligations under this Agreement without the prior written consent of the other party, except that Vaultera may assign this Agreement to an affiliate or successor in connection with a merger, acquisition, or sale of substantially all of its assets. Any unauthorized assignment shall be void.

22.2 Effect of Assignment Any permitted assignment does not relieve the assigning party of its obligations under this Agreement.

22.3 Binding Effect This Agreement binds and inures to the benefit of the parties and their permitted successors and assigns.


23. NOTICES

23.1 Method of Notice All notices, requests, and other communications required under this Agreement shall be in writing and shall be delivered by:

a) Personal delivery;

b) Overnight courier service (FedEx, DHL, etc.);

c) Certified mail, postage prepaid, return receipt requested;

d) Email to the email address designated by the recipient for notices.

23.2 Notice Addresses Notices to Vaultera shall be sent to:

Vaultera ehf Nóatún 17 105 Reykjavik, Iceland legal@vaultera.co

Notices to Customer shall be sent to the contact information provided in your service agreement.

23.3 Effective Date of Notice A notice shall be effective:

a) Upon personal delivery;

b) One (1) business day after sending by overnight courier;

c) Three (3) business days after mailing by certified mail;

d) Upon delivery when sent by email.


24. LIMITATIONS ON INJUNCTIVE RELIEF AND ADDITIONAL RIGHTS

24.1 No Injunctive Relief Except as provided in Section 18.2, neither party shall be entitled to seek injunctive or other equitable relief in any court of law for breach of this Agreement. The party's sole remedy for breach shall be to pursue damages through arbitration as described in Section 18.

24.2 Limitation on Class Actions You agree that any arbitration or court action shall be conducted on an individual basis and not as a class action, collective action, or representative action. You expressly waive any right to participate in a class action against Vaultera.

24.3 30-Day Right to Opt Out You have the right to opt out of binding arbitration by sending written notice to Vaultera at legal@vaultera.co within thirty (30) days of first accepting this Agreement. Your notice must state your name, email address, and clearly express your intent to opt out of the binding arbitration provision. If you opt out, all other terms of this Agreement will continue to apply, but the dispute resolution provisions will be governed by Section 18.2.


25. EXPORT RESTRICTIONS

25.1 Export Controls Customer acknowledges that the Vaultera Services may be subject to Iceland, European Union, and United States export control laws and regulations, including without limitation the EU Regulation (EC) 833/2014 and any successor legislation.

25.2 Compliance with Export Laws Customer agrees to comply with all applicable export and re-export restrictions and to not:

a) Permit the Vaultera Services to be accessed by, or provide services to, any person or entity located in, organized under the laws of, or residing in any country subject to EU, Icelandic, or US comprehensive economic sanctions or embargoes;

b) Permit access to the Vaultera Services by any person or entity identified on any EU consolidated list of persons, groups, and entities subject to restrictive measures, the Icelandic list of designated persons, or US government restricted party lists (SDN list, Entity List, etc.);

c) Use the Vaultera Services in connection with the design, development, or production of nuclear, chemical, or biological weapons or missile technology.

25.3 Screening Obligations Customer is responsible for screening its end users and customers against applicable restricted party lists before permitting them to use any services that incorporate the Vaultera Services.

25.4 Changes in Sanctions Vaultera may immediately suspend the services or terminate this Agreement if sanctions or export restrictions change in a manner that makes continued provision of services unlawful or impractical.


26. CHANGES TO THIS AGREEMENT

26.1 Right to Modify Vaultera may modify this Agreement at any time by posting the modified version to the Vaultera website or by sending written notice to Customer. Non-material changes become effective immediately. Material changes shall become effective upon the earlier of:

a) Thirty (30) days after written notice;

b) Customer's continued use of the Vaultera Services following notice of the change.

26.2 Material Changes Material changes include, but are not limited to:

a) Changes to pricing or fees;

b) Changes to data processing or retention practices;

c) Expansion of Vaultera's permitted uses of Customer Data;

d) Changes to service availability commitments.

26.3 Right to Terminate If Customer objects to a material change to this Agreement, Customer may terminate this Agreement without penalty within thirty (30) days of notice of the change. If Customer continues to use the Vaultera Services after the thirty-day period, Customer's objection is waived and the changed terms shall be binding.


27. GENERAL PROVISIONS

27.1 Entire Agreement This Agreement, together with any exhibits, schedules, and referenced documents, constitutes the complete agreement between the parties concerning the Vaultera Services.

27.2 Order of Precedence In the event of conflicting provisions, the following order shall apply:

  1. Service-specific agreements or exhibits signed after this master agreement
  2. This Customer Agreement
  3. Referenced policies and schedules
  4. Privacy Policy
  5. Acceptable Use Policy

27.3 Counterparts This Agreement may be executed in one or more counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument. Counterparts may be signed electronically or in facsimile and shall have the same effect as original signatures.

27.4 Waiver The failure of either party to enforce any right or provision of this Agreement shall not constitute a waiver of such right or provision. Any waiver must be in writing and signed by the waiving party.

27.5 Relationship of the Parties The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, or employment relationship between the parties.

27.6 Third-Party Beneficiaries This Agreement is intended solely for the benefit of the parties and their successors and assigns. No third party has any rights under this Agreement.

27.7 Equitable Relief Notwithstanding any other provision of this Agreement, either party may seek equitable relief (including injunction) in court to prevent irreparable harm from unauthorized use of intellectual property or breach of confidentiality obligations.

27.8 Contact Information For all inquiries, requests, and legal notices concerning this Agreement, please contact:

Vaultera ehf Nóatún 17 105 Reykjavik, Iceland Email: legal@vaultera.co

28. GDPR DATA PROTECTION ADDENDUM

28.1 Definitions

a) "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

b) "Personal Data" means any information relating to an identified or identifiable natural person, including payment card data containing personal information, cardholder names, billing addresses, and any other data that identifies or could identify a person.

c) "Processing" means any operation performed on Personal Data, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, or deletion.

d) "Data Protection Laws" means all applicable data protection and privacy laws and regulations, including but not limited to: - The Icelandic Data Protection Act (lög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018) - Regulation (EU) 2016/679 (the General Data Protection Regulation or "GDPR") - Any additional national data protection laws in jurisdictions where the parties operate

e) "Controller" means the natural or legal person that determines the purposes and means of Processing Personal Data.

f) "Processor" means the natural or legal person that processes Personal Data on behalf of a Controller.

28.2 Roles and Responsibilities

a) Customer as Controller: Customer acts as the Data Controller for Personal Data submitted to the Vaultera Services. Customer determines the purposes for which Personal Data is processed (payment processing, fraud detection, etc.) and the means by which such processing occurs.

b) Vaultera as Processor: Vaultera acts as a Data Processor on behalf of Customer. Vaultera processes Personal Data only upon documented instructions from Customer and only for the purposes of providing the Vaultera Services.

c) Subprocessors: Vaultera may engage subprocessors to assist in providing the Vaultera Services, including Payment Service Providers, cloud infrastructure providers, and security service providers. Vaultera maintains a current list of authorized subprocessors on its website. Vaultera shall inform Customer of any changes to subprocessors with at least 30 days' notice, allowing Customer to object to new subprocessors.

28.3 Processing Instructions

a) Vaultera shall process Personal Data only in accordance with documented instructions from Customer, including with regard to transfers of Personal Data outside the European Economic Area (EEA).

b) If Vaultera receives a direct request from a Data Subject (such as a cardholder) to access, modify, or delete their Personal Data, Vaultera shall promptly notify Customer to allow Customer to respond to the request in accordance with Data Protection Laws.

c) Vaultera shall not process Personal Data for its own purposes or commercial advantage, except as strictly necessary to provide the Vaultera Services or as required by law.

28.4 International Data Transfers

a) Transfer Mechanisms: Vaultera may transfer Personal Data outside the EEA only pursuant to appropriate safeguards, including: - Standard Contractual Clauses (SCCs) as adopted by the European Commission - Binding Corporate Rules (BCRs) - Adequacy decisions issued by the European Commission - Such other mechanisms as may be permitted under GDPR Article 46

b) Current Mechanisms: Vaultera's standard mechanism for international transfers is the use of Standard Contractual Clauses (SCCs). Where required, Vaultera shall implement transfer impact assessments in accordance with GDPR and EDPB guidance.

c) Suspension of Transfers: If a legal challenge or regulatory decision affects the lawfulness of a transfer mechanism, Vaultera shall inform Customer and work with Customer to identify an alternative lawful transfer mechanism. If no lawful transfer mechanism is available, Vaultera may suspend the services until a lawful mechanism is established.

28.5 Security and Confidentiality

a) Vaultera shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, including as described in Section 7.3 of this Agreement.

b) Vaultera shall ensure that any persons authorized to process Personal Data on behalf of Vaultera are committed to confidentiality or under an appropriate legal obligation of confidentiality.

c) Vaultera shall assist Customer in fulfilling Data Subject rights and shall assist Customer in demonstrating compliance with Data Protection Laws.

28.6 Data Subject Rights

a) Access Requests: Data Subjects have the right to request access to their Personal Data. Vaultera shall, upon request from Customer, provide reasonable assistance in responding to such requests within the legally required timeframe (typically 30 days under GDPR).

b) Rectification: Data Subjects have the right to request correction of inaccurate Personal Data. Customer shall ensure that Customer's systems provide the ability to update cardholder information, and Vaultera shall assist by updating tokenized records where applicable.

c) Erasure: Data Subjects have the right to request deletion of their Personal Data ("right to be forgotten"), subject to legitimate retention obligations. Vaultera shall delete Personal Data upon verified request from Customer, except where retention is required by law or for ongoing dispute resolution.

d) Portability: Data Subjects have the right to receive their Personal Data in a structured, commonly used, and machine-readable format. Vaultera shall assist Customer in providing this information to Data Subjects.

e) Objection: Data Subjects may object to certain processing activities. Vaultera shall respect such objections in accordance with Customer's instructions.

28.7 Data Breach and Incident Notification

a) Notification Timeline: In the event of a security incident or data breach involving Personal Data, Vaultera shall notify Customer without undue delay and, where required by law, within 72 hours of becoming aware of the incident.

b) Information Provided: Vaultera's notification shall include, to the extent known: - A description of the incident and the Personal Data affected - The likely consequences of the incident - Any measures taken to mitigate the impact - The name and contact information of Vaultera's data protection contact

c) Cooperation: Vaultera shall cooperate fully with Customer in investigating the incident, responding to regulatory inquiries, and implementing remedial measures.

d) Authority Reporting: Where required by law, Customer is responsible for reporting the breach to relevant supervisory authorities. Vaultera shall provide reasonable assistance to Customer in fulfilling these obligations.

e) Data Subject Notification: Vaultera shall, if directed by Customer and where legally required, assist Customer in notifying affected Data Subjects of the breach.

28.8 Audit and Inspection

a) Audit Rights: Vaultera shall make available to Customer all information necessary to demonstrate compliance with this Section 28 and shall allow for and contribute to audits and inspections, including those conducted by independent auditors, subject to reasonable notice and confidentiality obligations.

b) Audit Frequency: Customer may conduct audits no more than once per calendar year under normal circumstances. More frequent audits may be permitted if there is reasonable suspicion of non-compliance or following a data breach.

c) Certification: Vaultera maintains certifications relevant to data protection and security, including PCI DSS Level 1 certification and SOC 2 attestations (where applicable). Copies of these certifications are available upon request.

d) Audit Costs: Customer shall bear its own costs for audits. If audits conducted by third parties are requested, Customer shall ensure that the auditor is bound by confidentiality obligations.

28.9 Data Protection Impact Assessments

a) Customer Responsibility: Customer is responsible for determining whether a Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 for its use of the Vaultera Services.

b) Vaultera Cooperation: Vaultera shall provide reasonable assistance to Customer in conducting a DPIA, including providing information about Vaultera's processing activities, security measures, and data flows.

c) High-Risk Processing: If Customer determines that the processing involves high risk, Vaultera shall cooperate with Customer and any relevant supervisory authority in implementing mitigation measures.

28.10 Data Retention and Deletion

a) Retention Period: Vaultera shall retain Personal Data only for so long as necessary to provide the Vaultera Services and comply with applicable legal obligations.

b) Deletion on Termination: Upon expiration or termination of this Agreement, Vaultera shall, at Customer's election: - Securely delete all Personal Data; or - Return all Personal Data to Customer in a commonly used format

c) Legal Retention: Notwithstanding the above, Vaultera may retain Personal Data to the extent required by applicable law, including regulatory and tax obligations. Any legally required retention shall be limited to the minimum necessary for compliance.

c) Cryptographic Destruction: All tokenized payment card data and associated Personal Data shall be cryptographically destroyed in accordance with PCI DSS standards, not merely deleted or overwritten.

28.11 Data Protection Officer

a) Contact Information: Vaultera has designated a Data Protection Officer (DPO) to oversee compliance with Data Protection Laws. Data Subjects and regulatory authorities may contact the DPO at:

  Data Protection Officer
  Vaultera ehf
  Nóatún 17
  105 Reykjavik, Iceland
  Email: dpo@vaultera.co

b) Accessibility: The DPO is accessible to Data Subjects and regulatory authorities and shall respond to inquiries regarding data protection practices within 30 days.


PRIVACY POLICY

Effective Date: March 14, 2024

Introduction

Vaultera ehf ("Vaultera," "we," "us," or "our") is committed to full compliance with the Icelandic Data Protection Act (lög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018), the EU General Data Protection Regulation ("GDPR"), and all other applicable data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services.


1. INFORMATION WE COLLECT

1.1 Information You Provide

Account Registration Information

  • Name, email address, phone number
  • Company name and website
  • Billing address
  • Payment information (processed securely through third-party payment processors)
  • Tax ID or VAT number
  • Any other information you voluntarily provide

Communication Information

  • Messages sent to our support team
  • Email correspondence
  • Chat or phone support interactions
  • Feedback and survey responses

Payment Card Data

  • Full card numbers, expiration dates, and verification codes (only for customers using our tokenization services)
  • Cardholder names and billing addresses
  • Such data is processed in accordance with PCI DSS Level 1 standards and is encrypted and securely stored

1.2 Information Collected Automatically

Website Visitors

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Referring website (if applicable)
  • Operating system
  • Device information
  • Approximate geographic location

Service Users

  • API usage patterns and frequency
  • Feature usage and preferences
  • Error logs and debugging information
  • Security events and access logs
  • Transaction metadata (excluding sensitive card data)

Cookies and Similar Technologies

  • Vaultera uses cookies and similar tracking technologies to recognize repeat visitors, facilitate login, and understand how you use our services
  • Most web browsers allow you to control cookies through browser settings; you may disable cookies, but this may limit functionality
  • Session cookies expire when you close your browser; persistent cookies remain until manually deleted or they expire
  • We use both first-party and third-party cookies for analytics and functionality

1.3 Information from Third Parties

  • Payment processors and financial institutions (transaction information)
  • Marketing partners (campaign performance data)
  • Analytics providers (aggregated usage data)
  • Public records and business databases (company information)

2. LEGAL BASIS FOR PROCESSING

We process personal data only where we have a lawful basis under GDPR and other applicable data protection laws:

2.1 Lawful Bases

a) Contractual Necessity: Processing necessary to provide you with the Vaultera Services you have requested

b) Legal Obligation: Processing required to comply with law (regulatory requirements, tax obligations, law enforcement requests)

c) Legitimate Interests: Processing in our legitimate business interests, including: - Improving our services and website - Detecting and preventing fraud - Ensuring network and system security - Marketing our services (with opt-in consent where required) - Understanding how our services are used

d) Consent: Processing based on your explicit consent, which you may withdraw at any time

e) Vital Interests: Processing necessary to protect vital interests (safety, health, life)

For each category of processing, we conduct regular impact assessments to ensure the balance of interests favors processing.


3. HOW WE USE YOUR INFORMATION

3.1 Service Provision

  • To provide, maintain, and improve the Vaultera Services
  • To process payment card tokenization and storage
  • To handle your transactions and billing
  • To provide technical support and respond to inquiries
  • To authenticate your identity and prevent unauthorized access

3.2 Communication

  • To send you service announcements and updates
  • To respond to your inquiries and provide customer support
  • To send account-related notifications
  • To request feedback or participation in surveys

3.3 Analytics and Improvement

  • To understand how you use the Vaultera Services
  • To identify usage trends and service improvements
  • To optimize website and service performance
  • To conduct research and analytics

3.4 Security and Fraud Prevention

  • To detect and prevent fraud and security threats
  • To monitor for unauthorized access attempts
  • To investigate suspicious activity
  • To comply with security standards (PCI DSS)

3.5 Marketing (with consent where required)

  • To send promotional emails and updates about new services
  • To inform you about special offers and promotions
  • To conduct targeted marketing campaigns
  • You may opt out of marketing communications at any time

3.6 Legal and Compliance

  • To comply with legal obligations and regulatory requirements
  • To enforce our agreements and policies
  • To protect our legal rights and interests
  • To respond to subpoenas and legal process

4. DISCLOSURE OF YOUR INFORMATION

4.1 Service Providers

We may share your information with third-party service providers who assist us in operating our website and providing the Vaultera Services, including:

  • Payment processors
  • Cloud hosting providers
  • Customer support platforms
  • Analytics providers
  • Email service providers
  • Security and monitoring services

All service providers are contractually obligated to use your information only as necessary to provide services to us and must maintain appropriate confidentiality and security safeguards.

4.2 Subprocessors

As described in the GDPR Addendum (Section 28.2), Vaultera may engage subprocessors to assist in providing the Vaultera Services. A current list of subprocessors is maintained at www.vaultera.co/subprocessors. We notify customers of changes to subprocessors with at least 30 days' notice.

4.3 Payment Service Providers

When you submit payment card data for tokenization, your information is shared with secure Payment Service Providers (PSPs) as necessary to facilitate transactions. These PSPs process data in accordance with PCI DSS standards.

4.4 Legal Requirements

We may disclose your information if required to do so by law or if we believe in good faith that such disclosure is necessary to:

  • Comply with legal obligations, court orders, or regulatory requests
  • Enforce our Terms of Service and other agreements
  • Protect the security or integrity of our services
  • Protect the rights, privacy, safety, or property of Vaultera, users, or the public
  • Detect and prevent fraud or security issues

4.5 Business Transfers

If Vaultera is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

4.6 Aggregated and De-identified Information

We may share aggregated or de-identified information that cannot reasonably identify you with third parties for research, marketing, analytics, and other purposes.


5. DATA RETENTION

5.1 Retention Periods

We retain personal data only for as long as necessary to:

  • Provide the Vaultera Services
  • Comply with legal and regulatory obligations
  • Resolve disputes and enforce agreements
  • Comply with PCI DSS and other security standards

5.2 Specific Retention Practices

a) Account Information: Retained while your account is active and for three (3) years after account termination, unless longer retention is required by law

b) Transaction Data: Retained for seven (7) years to comply with tax and financial regulations

c) Payment Card Data: Tokenized card data is retained only while your account is active or as required by payment network rules. Upon account termination, card data is cryptographically destroyed within 90 days

d) Website Logs: Log files are retained for 90 days unless investigation of a security incident requires longer retention

e) Marketing Communications: Email addresses are retained until you unsubscribe from marketing communications

5.3 Deletion

When we delete personal data, we use secure methods to ensure data cannot be recovered (secure deletion, cryptographic destruction, or physical destruction of media).


6. YOUR DATA SUBJECT RIGHTS

Under applicable data protection laws, you have the following rights regarding your personal data:

6.1 Right of Access

You have the right to request access to the personal data we hold about you. We will provide this information in a clear, accessible format within 30 days of a verified request.

6.2 Right of Rectification

You have the right to request correction of inaccurate or incomplete personal data. You can often update your information directly in your account settings; otherwise, submit a request to our Data Protection Officer.

6.3 Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data, subject to:

  • Legal retention obligations
  • Our need to maintain records for legal defense
  • Contractual obligations
  • Tax and financial reporting requirements

Upon termination of your account, personal data will be deleted within 90 days, except where retention is required by law.

6.4 Right to Restrict Processing

You have the right to request that we limit how we process your personal data, for example, if you dispute its accuracy or the lawfulness of processing.

6.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as CSV) and to transmit that data to another organization. We will provide this information within 30 days of a verified request.

6.6 Right to Object

You have the right to object to:

  • Marketing communications (you can unsubscribe at any time)
  • Processing for direct marketing purposes
  • Processing based on legitimate interests
  • Automated decision-making affecting you

6.7 Right Against Automated Decision-Making

You have the right not to be subject to automated decision-making that produces legal or similarly significant effects concerning you. However, automated security screening and fraud detection are exempt from this right as they are necessary for our legitimate security interests.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights. In Iceland, complaints may be filed with the Icelandic Data Protection Authority (Persónuvernd). In the EU, complaints may be filed with your national data protection authority.

6.9 Exercising Your Rights

To exercise any of these rights, please contact:

Data Protection Officer Vaultera ehf Nóatún 17 105 Reykjavik, Iceland Email: dpo@vaultera.co

We will respond to your request without undue delay and, where required by law, within 30 days. We may request verification of your identity to protect the security of your personal data. For requests concerning cardholder data related to tokenization, we may direct you to contact the merchant/organization where you provided your card information initially.


7. SECURITY OF YOUR INFORMATION

7.1 Security Measures

We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

a) Encryption: - Data in transit is encrypted using TLS 1.2 or higher - Sensitive data at rest is encrypted using AES-256 or equivalent - Payment card data is encrypted in accordance with PCI DSS requirements

b) Access Controls: - Multi-factor authentication (MFA) required for staff access - Role-based access control (RBAC) limiting access to necessary data - Regular access reviews and audit logs - Background checks for staff with access to sensitive data

c) Network Security: - Firewalls and intrusion detection systems - Regular security scans and vulnerability assessments - Penetration testing conducted annually - DDoS protection and mitigation

d) Monitoring: - Continuous security monitoring and logging - Automated alerts for suspicious activities - Incident response team on standby - Security incident investigations

e) PCI DSS Compliance: - PCI DSS Level 1 certification maintained annually - Attestation of Compliance (AOC) available upon request - Regular security audits by qualified assessors - Annual recertification

f) Backups: - Regular encrypted backups of data - Tested backup recovery procedures - Geographically diverse backup storage - Backup retention in accordance with legal requirements

g) Third-Party Security: - Vendor security assessments and audits - Data processing agreements with all vendors - Contractual security and confidentiality obligations

7.2 Limitations

While we use extensive security measures, no system is 100% secure. We cannot guarantee absolute protection against unauthorized access or data loss. You are responsible for:

  • Maintaining the confidentiality of your passwords and credentials
  • Protecting your devices from malware and unauthorized access
  • Monitoring your account for suspicious activity
  • Reporting unauthorized access immediately

8. ACCESSING AND UPDATING YOUR INFORMATION

8.1 Account Updates

You may access, review, update, and correct your account information at any time by logging into your Vaultera account and navigating to account settings.

8.2 Information Available for Update

You can generally update:

  • Your name and contact information
  • Billing address
  • Company information
  • Password and security settings
  • API key management
  • Notification preferences

8.3 Contact Us

For assistance updating your information or if you need to request changes that are not available in your account settings, please contact:

Support Team Vaultera ehf Email: support@vaultera.co Website: www.vaultera.co/support

8.4 Data Access Requests

For detailed requests to access all information we hold about you, please contact the Data Protection Officer using the contact information in Section 6.9.


9. THIRD-PARTY LINKS AND SERVICES

Our website may contain links to third-party websites and services that are not operated by Vaultera. This Privacy Policy applies only to the information we collect through our website and services. We are not responsible for:

  • The privacy practices of third-party websites
  • Information collected by third-party services
  • Security of data transmitted to third parties

We recommend reviewing the privacy policies of any third-party services before providing your information.


10. COOKIES AND SIMILAR TECHNOLOGIES

10.1 Types of Cookies We Use

a) Essential Cookies: Required for core website functionality, security, and authentication (these cannot be disabled)

b) Functional Cookies: Enable you to stay logged in and remember preferences

c) Analytics Cookies: Help us understand how you use the website and services

d) Marketing Cookies: Track your interactions for targeted advertising and marketing optimization

e) Third-Party Cookies: Set by third-party analytics and marketing partners with our consent

10.2 Cookie Management

Most web browsers allow you to control cookies through browser settings. You may:

  • Disable cookies (though this may affect website functionality)
  • Delete existing cookies
  • Receive notifications when cookies are set
  • Accept cookies only from trusted sites

Instructions for controlling cookies in popular browsers are available on browser developers' websites.

10.3 Analytics

Vaultera uses analytics services (which may include Google Analytics and similar providers) to understand website usage. These services may place cookies on your device and may be subject to their own privacy policies. For information about how Google Analytics handles data, visit https://policies.google.com/privacy.

We may change our analytics providers from time to time. Current analytics providers are listed on our website at www.vaultera.co/privacy.

10.4 Opt-Out Options

For behavioral advertising opt-out options, visit:

  • Digital Advertising Alliance (DAA): www.aboutads.info/choices
  • Network Advertising Initiative (NAI): www.networkadvertising.org/choices
  • Your browser's "Do Not Track" settings

11. CHILDREN'S PRIVACY

11.1 Age Restrictions

The Vaultera Services are not intended for children under 16 years of age (or such higher minimum age as may be required by applicable law in a specific jurisdiction). We do not knowingly collect personal data from children under 16.

11.2 Parental Consent

If a parent or guardian believes their child has provided information to Vaultera, they should contact us immediately at dpo@vaultera.co. We will take appropriate steps to delete such information.

11.3 Age Verification

In certain jurisdictions, we may require age verification to ensure compliance with applicable children's privacy laws. If you are under 16, please do not use our services.


12. INTERNATIONAL DATA TRANSFERS

12.1 Transfers Outside Iceland and the EU

If you are located in the European Economic Area (EEA) and we transfer your personal data outside the EEA (for example, to the United States or other non-EEA countries), we do so only:

a) To countries approved by the European Commission as having an adequate level of data protection;

b) Pursuant to Standard Contractual Clauses (SCCs) adopted by the European Commission;

c) With your explicit consent;

d) As necessary for contract performance.

12.2 Transfer Impact Assessment

Vaultera conducts transfer impact assessments in accordance with GDPR and European Data Protection Board (EDPB) guidance to assess the legal status of transfers and implement additional safeguards where necessary.

12.3 United States Processing

If your data is transferred to the United States, it will be processed in accordance with the EU-US Data Privacy Framework or other lawful transfer mechanisms. By using the Vaultera Services, you acknowledge that your data may be transferred to and processed in the United States and other countries.


13. CALIFORNIA PRIVACY RIGHTS (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

13.1 Rights Under CCPA

  • Right to know what personal information is collected
  • Right to know whether your personal information is shared or sold
  • Right to delete personal information collected from you
  • Right to opt-out of the sale or sharing of your personal information
  • Right to non-discrimination for exercising your privacy rights

13.2 Submitting a Request

To submit a CCPA request, email dpo@vaultera.co with the subject line "California Privacy Request." Include enough information to allow us to verify your identity.

We will respond to verified requests within 45 days. You have the right to appeal our decision if we deny your request.

13.3 Shine the Light

California residents also have the right under California Civil Code Section 1798.83 (Shine the Light Law) to request information about the disclosure of personal information to third parties for their direct marketing purposes. To make such a request, contact dpo@vaultera.co with "Shine the Light" in the subject line.


14. DATA PROTECTION OFFICER

Vaultera has appointed a Data Protection Officer (DPO) to oversee compliance with data protection laws and to be the point of contact for data subjects and regulatory authorities.

Contact Information:

Data Protection Officer Vaultera ehf Nóatún 17 105 Reykjavik, Iceland Email: dpo@vaultera.co The DPO is available to respond to inquiries from data subjects and supervisory authorities and can be contacted regarding:

  • Data subject rights requests
  • Concerns about our data processing practices
  • Breach notifications
  • Privacy policy questions

15. REGULATORY AUTHORITIES

If you have concerns about our data protection practices or believe we have violated your data protection rights, you have the right to lodge a complaint with a supervisory authority:

Iceland: Icelandic Data Protection Authority (Persónuvernd) Rauðarárstig 10 105 Reykjavik, Iceland www.personu vernd.is

European Union: Your national data protection authority (for more information, visit https://edpb.ec.europa.eu/about-edpb/board/members_en)

United States (for California residents): California Attorney General, Office of Privacy Protection www.oag.ca.gov/privacy


16. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on our website and update the "Effective Date" at the top of this policy.

If we make material changes that adversely affect your privacy rights, we will notify you by email or by posting a prominent notice on our website prior to implementing the change. Your continued use of the Vaultera Services following notice of changes constitutes your acceptance of the updated Privacy Policy.


17. CONTACT US

For questions or concerns about this Privacy Policy, our data protection practices, or to exercise your data subject rights, please contact:

Data Protection Officer Vaultera ehf Nóatún 17 105 Reykjavik, Iceland Email: dpo@vaultera.co Legal/General Inquiries Vaultera ehf Nóatún 17 105 Reykjavik, Iceland Email: legal@vaultera.co

Customer Support Email: support@vaultera.co Website: www.vaultera.co/support


ACCEPTABLE USE POLICY

Effective Date: March 14, 2024

1. PURPOSE

This Acceptable Use Policy ("Policy") establishes standards for acceptable and unacceptable uses of the Vaultera Services. This Policy applies to all customers, users, and any other parties accessing or using the Vaultera Services.


2. PROHIBITED ACTIVITIES

You agree that you will not use the Vaultera Services for any of the following prohibited purposes or in any manner that:

2.1 Unlawful Activities

  • Any activity that violates applicable federal, state, local, or international law or regulation
  • Activity that constitutes fraud, forgery, or misrepresentation
  • Money laundering or terrorist financing activities
  • Selling, distributing, or possessing illegal drugs or controlled substances
  • Human trafficking or forced labor activities
  • Sale of counterfeit goods
  • Activity in violation of any judicial or regulatory order

2.2 Intellectual Property Violations

  • Infringement of patents, copyrights, trademarks, or other intellectual property rights
  • Unauthorized use of another person's or entity's intellectual property
  • Disclosure of trade secrets
  • Violation of licensing agreements

2.3 Security Threats and Technical Abuse

  • Attempting to gain unauthorized access to the Vaultera Services or any related systems
  • Reverse engineering, decompiling, or disassembling any part of the Vaultera Services
  • Introducing viruses, malware, worms, or other harmful code
  • Executing denial of service (DoS) or distributed denial of service (DDoS) attacks
  • Port scanning or network mapping
  • Sniffing network traffic or attempting to intercept communications
  • Using automated tools to scrape, crawl, or extract data from the services without authorization
  • Exploiting security vulnerabilities or zero-day exploits
  • Creating or operating botnets

2.4 Fraud and Deception

  • Credit card fraud, including use of stolen or unauthorized credit card numbers
  • Identity theft or impersonation
  • Phishing or social engineering attacks
  • Creating false or misleading representations
  • Misrepresenting affiliation with Vaultera or other entities
  • Engaging in chargebacks or payment disputes without legitimate grounds
  • Operating Ponzi schemes or pyramid schemes

2.5 Harassment and Abuse

  • Threats, intimidation, or harassment of individuals or entities
  • Defamation, libel, or slander
  • Cyberbullying or cyberstalking
  • Sending unsolicited bulk communications (spam)
  • Sending threatening or abusive messages
  • Persistent harassment after being asked to stop

2.6 Content Restrictions

  • Transmitting obscene, sexually explicit, or pornographic material
  • Transmitting child sexual abuse material (CSAM) in any form
  • Transmitting material that glorifies or encourages violence or harm
  • Transmitting material that promotes discrimination, hatred, or violence based on protected characteristics (race, ethnicity, religion, gender, sexual orientation, disability, etc.)
  • Transmitting material that promotes or encourages suicide or self-harm

2.7 Data Misuse

  • Selling or transferring personal data without proper authorization or consent
  • Using payment card data for purposes other than authorized transactions
  • Storing sensitive data in non-encrypted formats
  • Sharing API keys or authentication credentials with unauthorized parties
  • Using the Vaultera Services to process data in violation of data protection laws
  • Operating a personal data broker service using cardholder data
  • Attempting to decode, decrypt, or reverse-engineer tokenized payment data

2.8 Resale and Unauthorized Use

  • Reselling or distributing the Vaultera Services without authorization
  • Using the Vaultera Services on behalf of third parties without proper agreements
  • Integrating the Vaultera Services into products or services without explicit permission
  • Using the Vaultera Services to provide competing payment services
  • Sharing a single account among multiple organizations or unrelated entities

2.9 Compromised Accounts

  • Using account credentials that have been compromised or stolen
  • Using accounts of other individuals without authorization
  • Failing to notify Vaultera of unauthorized account access
  • Continuing to use an account known to be compromised

2.10 Sanctions and Restricted Parties

  • Using the Vaultera Services in any jurisdiction subject to comprehensive economic sanctions
  • Processing transactions for individuals or entities on government restricted party lists (SDN list, Entity List, consolidated EU list, etc.)
  • Facilitating transactions with terrorists, terrorist organizations, or terrorist supporters
  • Circumventing sanctions through shell companies or intermediaries

3. CONSEQUENCES OF VIOLATIONS

Vaultera reserves the right to take action in response to violations of this Policy, including:

3.1 Suspension of Access

Vaultera may suspend your access to the Vaultera Services immediately, without notice, if:

  • Your account is used for fraud or illegal activity
  • You attempt unauthorized access to Vaultera systems
  • You compromise the security or integrity of the services
  • You violate the Acceptable Use Policy

3.2 Termination of Service

Vaultera may terminate your account and this Agreement if:

  • Violations continue after notice and opportunity to cure
  • The violation involves illegal activity
  • The violation poses a security or legal risk to Vaultera or other users

3.3 Reporting to Authorities

Vaultera may report violations to law enforcement, regulatory authorities, or other appropriate entities if:

  • The violation involves illegal activity
  • The violation poses a threat to public safety
  • Vaultera is required to do so by law

3.4 Civil Remedies

Vaultera may pursue civil remedies, including:

  • Injunctive relief to prevent continued violations
  • Damages for losses caused by violations
  • Recovery of costs and attorneys' fees

3.5 No Refunds

If your account is suspended or terminated for violations, you forfeit all remaining fees and credits. No refunds will be provided.


4. MONITORING AND ENFORCEMENT

4.1 Monitoring

Vaultera uses automated systems and human review to monitor for violations of this Policy, including:

  • Anomaly detection algorithms
  • Pattern matching for known fraud signatures
  • Transaction monitoring and analysis
  • Network security monitoring
  • Compliance checks against restricted party lists

4.2 Due Process

Before suspending or terminating your account for violations:

  • Vaultera will provide written notice of the alleged violation (unless doing so would compromise security)
  • You will have an opportunity to respond and provide context
  • Vaultera will conduct a fair investigation
  • Emergency suspensions may occur without prior notice if necessary for security

4.3 Appeals

If your account is suspended or terminated, you may appeal the decision by contacting legal@vaultera.co within thirty (30) days. Appeals will be reviewed by a different team member than the original decision maker.


5. COOPERATION WITH LAW ENFORCEMENT

5.1 Legal Process

Vaultera will comply with subpoenas, warrants, and other lawful legal process from authorized law enforcement agencies. We may disclose account information, transaction records, and other data as required by law.

5.2 Preservation

If Vaultera receives notice of potential criminal activity or legal proceedings, we may preserve evidence and transaction records as required by law.

5.3 Voluntary Reporting

Vaultera may voluntarily report suspected fraud, money laundering, or other illegal activity to the appropriate authorities, including INTERPOL, national law enforcement agencies, financial intelligence units, and regulatory authorities.


6. THIRD-PARTY MARKETPLACE AND RESELLERS

If you resell, integrate, or facilitate access to the Vaultera Services through a marketplace or reseller arrangement, you are responsible for:

  • Ensuring your end users comply with this Policy
  • Monitoring for violations by your end users
  • Reporting violations to Vaultera
  • Maintaining appropriate data processing agreements
  • Implementing necessary security and compliance measures

7. CHANGES TO THIS POLICY

Vaultera may modify this Acceptable Use Policy at any time. Material changes will be communicated via email or notice on our website. Your continued use of the Vaultera Services constitutes acceptance of the updated Policy.


8. CONTACT US

To report violations of this Policy or to request clarification, contact:

Compliance Team Vaultera ehf Email: compliance@vaultera.co Legal: legal@vaultera.co


SECURITY POLICY

Effective Date: March 14, 2024

1. OVERVIEW

This Security Policy outlines Vaultera ehf's comprehensive approach to information security and describes the technical, administrative, and physical controls implemented to protect customer data and ensure the integrity and availability of the Vaultera Services.


2. SECURITY PRINCIPLES

Vaultera's security approach is founded on the following principles:

2.1 Risk-Based Security

Security investments and controls are prioritized based on the likelihood and potential impact of identified risks. We conduct regular risk assessments to identify threats and vulnerabilities affecting our services.

2.2 Defense in Depth

We implement multiple layers of security controls to prevent, detect, and respond to threats. No single control is relied upon exclusively.

2.3 Confidentiality, Integrity, and Availability

All security controls are designed to protect the confidentiality (unauthorized access), integrity (unauthorized modification), and availability (unauthorized disruption) of customer data and services.

2.4 Compliance with Standards

Vaultera maintains compliance with industry-recognized security standards, including:

  • PCI DSS Level 1 (payment card industry standard)
  • GDPR and Icelandic data protection requirements
  • ISO/IEC 27001 principles (where applicable)
  • NIST Cybersecurity Framework

2.5 Continuous Improvement

Security is an ongoing process. Vaultera regularly reviews and updates security policies, procedures, and controls based on threat intelligence, vulnerability assessments, and lessons learned from incidents.


3. ORGANIZATIONAL SECURITY

3.1 Security Governance

Vaultera's leadership is responsible for establishing security policies, allocating resources, and ensuring compliance. A dedicated Chief Information Security Officer (CISO) or equivalent role oversees security strategy and implementation.

3.2 Security Roles and Responsibilities

  • CEO/Leadership: Ultimate responsibility for security and compliance
  • CISO/Security Lead: Overall security strategy and implementation
  • System Administrators: Maintaining secure systems and infrastructure
  • Developers: Secure coding practices and application security
  • IT Staff: Access control, patch management, and user management
  • All Employees: Security awareness and compliance with policies

3.3 Employee Training and Awareness

  • All employees receive security training upon hire
  • Annual security awareness training for all staff
  • Specific training for roles with access to sensitive data
  • Phishing and social engineering awareness programs
  • Regular security communications and updates
  • Documentation of training completion

3.4 Incident Response Plan

Vaultera maintains a documented incident response plan that includes:

  • Procedures for detecting and reporting security incidents
  • Incident classification and severity levels
  • Communication protocols and escalation procedures
  • Evidence preservation and forensic investigation procedures
  • Customer notification requirements and timelines
  • Regulatory reporting obligations
  • Post-incident review and lessons learned

3.5 Background Checks

All Vaultera employees and contractors with access to customer data or sensitive systems undergo background checks, including:

  • Criminal history verification
  • Identity verification
  • Reference checks
  • In some cases, credit history checks for financial-sensitive roles

4. ACCESS CONTROL

4.1 Authentication

  • Multi-factor authentication (MFA) required for all staff access to systems
  • Strong password requirements (minimum 12 characters, complexity)
  • Password managers for secure credential storage
  • MFA enforcement for customer API access
  • Session management with automatic timeouts
  • Prohibition on password sharing or reuse across services

4.2 Authorization and Least Privilege

  • Role-based access control (RBAC) for system and data access
  • Principle of least privilege: users receive minimum necessary access
  • Separation of duties to prevent any single person from having excessive permissions
  • Regular access reviews (at least annually)
  • Prompt removal of access when roles change or employees depart
  • Approval workflows for privileged access requests

4.3 User Account Management

  • Documented account provisioning and deprovisioning procedures
  • User account review for inactive accounts (disabled after 90 days of inactivity)
  • Segregation of user and system accounts
  • Monitoring of privileged account usage
  • Documented access control lists (ACLs) for sensitive resources
  • Changes to access controls are logged and audited

4.4 Third-Party and Vendor Access

  • Vendor access is provisioned only when necessary
  • Contractual data protection and confidentiality agreements required
  • Vendor access is monitored and reviewed regularly
  • Access is revoked immediately when relationships end
  • VPN or secure channels required for remote vendor access

4.5 API Key Management

  • API keys are randomly generated using cryptographically secure methods
  • Keys are never displayed in full after creation
  • Keys are rotated regularly (at least annually)
  • Keys can be revoked immediately by account holders
  • Compromised keys are disabled and reset immediately
  • Key usage is logged and monitored for anomalies

5. CRYPTOGRAPHY AND ENCRYPTION

5.1 Encryption in Transit

  • All data transmitted to/from Vaultera Services is encrypted using TLS 1.2 or higher
  • Perfect Forward Secrecy (PFS) is supported for all TLS connections
  • Weak ciphers and older protocols (SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1) are disabled
  • Certificate validity is monitored, and certificates are renewed before expiration
  • HSTS (HTTP Strict Transport Security) is implemented on all web endpoints

5.2 Encryption at Rest

  • Sensitive data at rest is encrypted using AES-256 or equivalent strong encryption
  • Payment card data is encrypted in accordance with PCI DSS requirements
  • Encryption keys are managed separately from encrypted data
  • Database encryption is enabled for all databases containing sensitive data
  • Backups are encrypted using the same encryption standards

5.3 Key Management

  • Encryption keys are generated using cryptographically secure random generators
  • Keys are stored in secure key management systems (e.g., AWS KMS, Azure Key Vault, or hardware security modules)
  • Keys are protected from unauthorized access and theft
  • Key rotation is performed regularly (at least annually)
  • Compromised keys are rotated immediately
  • Key access is restricted and logged
  • Archived keys are retained for decryption of historical data but not used for new encryption

5.4 Hashing and Password Protection

  • Customer passwords are hashed using strong algorithms (bcrypt, scrypt, or PBKDF2)
  • Password hashes are salted with unique, random values
  • Rainbow tables and brute force attacks are mitigated through strong hashing
  • Customer passwords are never stored in plain text

6. NETWORK SECURITY

6.1 Firewalls and Network Segmentation

  • Firewalls protect all external network boundaries
  • Internal network is segmented by function and security requirements
  • Payment card data is isolated in PCI DSS-compliant network segments (cardholder data environment or CDE)
  • Access between network segments is controlled via firewalls
  • Firewall rules are regularly reviewed and updated
  • Default-deny ingress rule: all traffic is blocked unless explicitly permitted

6.2 Intrusion Detection and Prevention

  • Network-based intrusion detection systems (IDS) monitor for suspicious activity
  • Host-based intrusion prevention systems (IPS) protect individual servers
  • Alerting is enabled for suspicious network patterns
  • Logs from IDS/IPS are reviewed for indicators of compromise
  • Signatures and rules are updated regularly

6.3 Network Access Control (NAC)

  • Unauthorized devices are prevented from connecting to network
  • Devices must meet security requirements (antivirus, patch level, encryption) to connect
  • Compliance with security policies is verified before network access

6.4 Wireless Security

  • Wireless networks are encrypted with WPA2 or higher standards
  • Default administrative credentials are changed
  • Wireless networks are regularly scanned for rogue access points
  • Guest wireless networks are isolated from critical systems

6.5 DDoS Protection

  • DDoS mitigation services are implemented for external-facing services
  • Rate limiting is implemented on APIs
  • Traffic analysis identifies and blocks DDoS patterns
  • Incident response procedures for DDoS attacks

6.6 DNS and Proxy Security

  • DNS queries are monitored for malicious domains
  • Proxy servers filter and log web traffic
  • SSL/TLS inspection is performed where applicable (with notification to users)
  • DNS poisoning and cache poisoning attacks are mitigated

7. APPLICATION SECURITY

7.1 Secure Development Practices

  • Secure coding guidelines and training for all developers
  • Code reviews are conducted for all code changes
  • Developers follow OWASP Top 10 protection measures
  • Security is addressed in the design phase (threat modeling)
  • Input validation and output encoding prevent injection attacks
  • Authentication and authorization checks are integrated throughout
  • Error messages do not reveal sensitive information

7.2 Testing and Quality Assurance

  • Static application security testing (SAST) is performed on source code
  • Dynamic application security testing (DAST) tests running applications
  • Penetration testing is conducted at least annually
  • Security scanning is integrated into continuous integration/continuous deployment (CI/CD)
  • Bug bounty programs may be used to identify vulnerabilities

7.3 Vulnerability Management

  • Security vulnerabilities are tracked and prioritized
  • Critical vulnerabilities are addressed within 24-48 hours
  • High vulnerabilities are addressed within 7 days
  • Medium and low vulnerabilities are addressed within 30 days
  • Patches are tested before deployment to production
  • Vulnerability disclosures are coordinated with affected parties

7.4 Dependency Management

  • Third-party libraries and dependencies are regularly scanned for vulnerabilities
  • Software Bill of Materials (SBOM) is maintained
  • Out-of-date libraries are updated promptly
  • Unnecessary dependencies are removed
  • License compliance is verified for all dependencies

7.5 Logging and Monitoring

  • All security-relevant events are logged (authentication, authorization, data access, changes, errors)
  • Logs include timestamp, user, action, and result
  • Logs are stored in tamper-proof systems
  • Log retention meets legal and regulatory requirements
  • Logs are reviewed for indicators of compromise
  • Automated alerting for critical security events

8. DATA SECURITY AND PCI DSS COMPLIANCE

8.1 Cardholder Data Environment (CDE)

  • Payment card data is processed and stored only in a PCI DSS-compliant environment
  • Access to the CDE is restricted to authorized personnel
  • The CDE is isolated from other networks
  • Tokenization is used to remove payment card data from customer systems

8.2 Data Classification

  • Vaultera classifies data based on sensitivity (public, internal, confidential, restricted)
  • Handling requirements vary based on classification
  • Restricted data (payment card information, personal information) receives highest protection

8.3 Data Handling

  • Data is accessed only for authorized business purposes
  • Sharing of sensitive data is logged and monitored
  • Data is not copied to unauthorized locations
  • Unnecessary data is securely deleted
  • Data minimization: only necessary data is collected and retained

8.4 Backup and Recovery

  • Regular automated backups are performed daily
  • Backups are encrypted and stored securely
  • Backups are stored in geographically diverse locations
  • Recovery procedures are tested regularly (at least quarterly)
  • Recovery Time Objective (RTO) and Recovery Point Objective (RPO) are defined and tested
  • Backup deletion follows data retention schedules

8.5 Secure Deletion

  • Data deletion uses secure methods to prevent recovery (secure overwrite, cryptographic destruction, or physical destruction)
  • Data on decommissioned storage devices is destroyed securely
  • Certificates of destruction are maintained for evidence
  • Deleted data cannot be recovered through normal forensic methods

9. PHYSICAL SECURITY

9.1 Data Center Security

  • Data centers are controlled by trusted third parties with security certifications
  • Physical access is restricted with multiple layers (guards, badge readers, biometric access)
  • Visitor access is logged and monitored
  • Surveillance cameras monitor sensitive areas
  • Environmental controls (temperature, humidity) protect equipment

9.2 Office Security

  • Office access is controlled with badge readers and locks
  • Visitor management procedures are in place
  • Sensitive information is secured in locked cabinets
  • Screens and keyboards are positioned to prevent unauthorized viewing (clean desk policy)
  • No sensitive data is stored on paper without proper safeguards

9.3 Equipment and Media

  • IT equipment is tracked and inventoried
  • Equipment is secured against theft
  • Hard drives and other media containing data are encrypted
  • Decommissioned equipment is securely wiped or destroyed
  • Remote work equipment is protected with encryption and full-disk encryption

9.4 Environmental Controls

  • Fire suppression systems protect data centers and server rooms
  • Smoke detection alerts for early warning
  • Water detection systems prevent damage from leaks
  • Temperature and humidity are monitored and controlled
  • Backup power systems (UPS, generators) ensure continuous operation

10. AUDIT AND COMPLIANCE

10.1 Internal Audits

  • Internal security audits are conducted annually or more frequently
  • Audits assess compliance with security policies and standards
  • Audit findings are documented and remediated
  • Audit reports are provided to senior management and board

10.2 Third-Party Audits

  • Annual PCI DSS audits conducted by qualified security assessors
  • SOC 2 Type II audits (if applicable) verify security controls
  • Annual penetration testing by independent security firms
  • Attestation of Compliance (AOC) is provided to customers upon request
  • Audit reports demonstrate compliance with security standards

10.3 Compliance Certifications

  • PCI DSS Level 1 certification is maintained annually
  • Compliance with GDPR is verified through DPA audits
  • Compliance with Icelandic data protection law is ensured
  • ISO/IEC 27001 certification may be pursued (timeline to be determined)

10.4 Compliance Monitoring

  • Security controls are monitored on an ongoing basis
  • Deviations from policies are investigated and corrected
  • Change control processes ensure security impact is assessed before changes
  • Compliance status is reported to management regularly

11. INCIDENT RESPONSE

11.1 Detection

  • 24/7 monitoring for security incidents using automated tools
  • Employees and customers can report suspected incidents
  • Threat intelligence feeds inform detection of emerging threats
  • Anomaly detection algorithms identify unusual activity

11.2 Incident Response Team

  • Dedicated incident response team is on standby
  • Team includes security, operations, legal, and communication representatives
  • Team members receive incident response training
  • Roles and responsibilities are clearly defined

11.3 Containment and Eradication

  • Upon detection, incidents are immediately contained to prevent spread
  • Affected systems may be isolated or taken offline
  • Forensic investigation is conducted to understand the incident
  • Root cause is identified and remediated
  • Evidence is preserved for potential law enforcement involvement

11.4 Notification

  • Customers affected by a data breach are notified without undue delay (within 72 hours where required by GDPR)
  • Notification includes details of the incident, affected data, and remediation steps
  • Supervisory authorities are notified as required by law
  • Law enforcement is contacted if the incident involves criminal activity
  • Public disclosure is made if required by law and magnitude of impact

11.5 Recovery and Post-Incident

  • Systems are restored from backups once the threat is eliminated
  • Patches and security updates are applied to prevent recurrence
  • Post-incident review is conducted to identify improvements
  • Lessons learned are documented and shared with the team
  • Security controls are enhanced based on incident analysis

12. BUSINESS CONTINUITY AND DISASTER RECOVERY

12.1 Business Continuity Plan

  • Documented procedures for maintaining critical services during disruptions
  • Redundancy for critical systems and infrastructure
  • Regular testing of recovery procedures (at least annually)
  • Regular communication with customers about recovery capabilities

12.2 Recovery Time and Data Loss Objectives

  • Recovery Time Objective (RTO): 4 hours (service restored to operational status)
  • Recovery Point Objective (RPO): 1 hour (data loss limited to 1 hour of transactions)
  • Objectives vary by service component and are detailed in the Service Level Agreement

12.3 Disaster Recovery Testing

  • Disaster recovery procedures are tested at least quarterly
  • Testing includes failover to backup systems and data restoration
  • Test results are documented and any issues are corrected
  • Alternate sites are available in case of data center failures

12.4 Communication During Incidents

  • Customers are notified of incidents and status updates
  • Regular communications continue during recovery
  • Status page provides real-time incident information
  • Post-incident report is provided after resolution

13. THIRD-PARTY SECURITY

13.1 Vendor Assessment

  • Security assessments are conducted on all vendors before engagement
  • Assessments evaluate data protection practices, security certifications, and compliance
  • Vendors must meet minimum security requirements
  • Assessments are repeated annually or when vendors undergo significant changes

13.2 Vendor Contracts

  • Data processing agreements are required for all vendors handling customer data
  • Contracts include security and confidentiality requirements
  • Contracts specify sub-processor usage and approval requirements
  • Contracts allow for security audits and compliance verification
  • Termination procedures include secure data deletion

13.3 Vendor Monitoring

  • Vendor compliance is monitored on an ongoing basis
  • Vendors are regularly assessed for security incidents or breaches
  • Changes to vendor security posture are evaluated
  • Immediate action is taken if vendors fail to meet security requirements
  • Vendor relationships may be terminated for security violations

14. SECURITY UPDATES AND PATCH MANAGEMENT

14.1 Patch Management

  • Security patches are applied promptly to all systems
  • Critical security patches are applied within 24-48 hours
  • Non-critical patches are applied within 30 days
  • Patches are tested before production deployment
  • Patch status is tracked and reported

14.2 Software Updates

  • Operating systems are updated regularly with latest versions
  • Applications and libraries are kept current
  • Outdated software with known vulnerabilities is replaced
  • Updates are coordinated to minimize service disruption

14.3 System Hardening

  • Systems are hardened according to security baselines
  • Unnecessary services and ports are disabled
  • Default configurations are changed to secure values
  • Security configuration standards are maintained

15. SECURITY POLICY COMPLIANCE

15.1 Policy Review

  • Security policies are reviewed annually and updated as needed
  • Changes to policy are communicated to all relevant personnel
  • Training is provided on new or updated policies
  • Compliance with policies is monitored

15.2 Enforcement

  • Non-compliance with security policies is investigated
  • Corrective actions are taken for violations
  • Disciplinary actions may include training, suspension, or termination
  • Documented evidence of corrective actions is maintained

15.3 Exceptions

  • Exceptions to security policies require formal approval
  • Exceptions are documented with business justification and risk assessment
  • Exceptions are reviewed regularly and must be renewed annually
  • Exceptions do not exempt from compliance with fundamental security principles

16. CONTACT AND ESCALATION

16.1 Security Incidents

To report a security incident or suspected vulnerability:

Email: security@vaultera.co Secure Reporting: https://www.vaultera.co/security-report

16.2 Security Policy Questions

For questions about this Security Policy:

Email: security@vaultera.co Data Protection Officer: dpo@vaultera.co

16.3 Vulnerability Disclosure

Responsible disclosure of security vulnerabilities is welcomed. Please contact security@vaultera.co with details of any discovered vulnerabilities. Vaultera commits to:

  • Acknowledging receipt of vulnerability reports within 24 hours
  • Providing regular updates on remediation progress
  • Avoiding public disclosure until a patch is available
  • Crediting the researcher appropriately (if desired)

17. APPROVAL AND REVIEW

This Security Policy is approved by Vaultera's leadership and will be reviewed annually. The next scheduled review is March 2025. Any significant security incidents or regulatory changes may trigger an earlier review.

Document Approval:

Approved by: Steinar Atli Skarphedinsson, CEO Date: March 14, 2024 Next Review Date: March 14, 2025


END OF DOCUMENT

This comprehensive Vaultera Customer Agreement, including all component policies, replaces any previous versions and takes effect on the date specified above.