Version 1.0 · In force from 4 August 2026

SCHEDULE H

ENTERPRISE TECHNICAL & ORGANIZATIONAL SECURITY MEASURES

(Technical & Organizational Measures pursuant to Article 28 and Article 32 GDPR)

Version 1.0 · Effective Date: 4 August 2026

This Enterprise Technical & Organizational Security Measures Schedule (the "TOMs") forms an integral part of the Terms of Service (the "Agreement") accepted electronically by the Customer (including by clickwrap acceptance during account registration or online checkout). This document is published at a permanent URL on ONLYAI’s website and is incorporated into the Agreement by reference. It applies between DOSTART VENTURES LIMITED, registration number HE 487770, registered under the laws of Cyprus ("Company", "Dostart Ventures", "Processor", "Provider", "we", "our" or "us") and the Customer identified in the applicable electronic Order Form ("Customer" or "Controller").

Capitalized terms not otherwise defined herein shall have the meanings assigned to them in the Agreement or the DPA.

1. PURPOSE

1.1 Objective

This Schedule describes the administrative, organizational, technical and physical safeguards implemented and maintained by the Company for the protection of Customer Data Processed on behalf of Customers in connection with the provision of the ONLYAI Platform.

The measures described herein have been designed to ensure that Customer Data is Processed in a manner that ensures an appropriate level of security having regard to:

  • the state of the art;
  • the costs of implementation;
  • the nature, scope, context and purposes of Processing;
  • the likelihood and severity of risks to the rights and freedoms of natural persons;
  • the Company's contractual obligations;
  • evolving cybersecurity threats;
  • developments in artificial intelligence technologies.

The Company acknowledges that information security constitutes a continuous governance function and, accordingly, undertakes to review and enhance its security measures periodically to reflect technological developments, regulatory requirements and emerging risks.

1.2 Regulatory Framework

Without representing formal certification unless expressly stated elsewhere, the Company's information security governance programme has been developed having regard to principles reflected in:

  • Regulation (EU) 2016/679 ("GDPR"), including Articles 5, 24, 25, 28 and 32;
  • Regulation (EU) 2024/1689 (EU Artificial Intelligence Act), where applicable;
  • ISO/IEC 27001;
  • ISO/IEC 27002;
  • ISO/IEC 27017;
  • ISO/IEC 27018;
  • ISO/IEC 27701;
  • ISO/IEC 42001;
  • NIST Cybersecurity Framework 2.0;
  • NIST SP 800-53;
  • CIS Critical Security Controls;
  • OWASP Application Security Verification Standard (ASVS);
  • OWASP Software Assurance Maturity Model (SAMM).

References to any standard, framework or guidance shall not be construed as a representation that the Company has obtained formal certification or independent attestation unless expressly stated.

2. SECURITY GOVERNANCE PRINCIPLES

The Company has established an enterprise-wide Information Security Management Framework ("ISMF") intended to ensure that information security considerations are embedded throughout the lifecycle of its products, infrastructure, business operations and artificial intelligence systems.

The Company's security governance programme is founded upon the following strategic principles:

  • confidentiality;
  • integrity;
  • availability;
  • authenticity;
  • accountability;
  • resilience;
  • least privilege;
  • need-to-know;
  • security by design;
  • privacy by design and by default;
  • defence in depth;
  • continuous improvement.

Security controls are selected and implemented using a risk-based methodology proportionate to the sensitivity of the information Processed and the risks associated with the relevant Processing activities.

3. ORGANIZATIONAL SECURITY MEASURES

3.1 Information Security Governance

The Company maintains documented information security governance arrangements designed to ensure the consistent implementation, oversight and continuous improvement of information security controls throughout the organization.

Such governance arrangements include, where appropriate:

  • documented security policies and standards;
  • allocation of information security responsibilities;
  • executive oversight of cybersecurity risks;
  • periodic review of security controls;
  • documented incident response procedures;
  • vendor security governance;
  • security awareness initiatives;
  • periodic internal compliance reviews.

3.2 Security Policies

The Company maintains and periodically reviews internal policies governing, among other matters:

  • information security;
  • acceptable use;
  • access governance;
  • secure software development;
  • cryptographic controls;
  • vulnerability management;
  • incident response;
  • business continuity;
  • artificial intelligence governance;
  • privacy governance.

Such policies are subject to periodic review and may be updated in response to technological developments, evolving threats or changes in Applicable Law.

3.3 Security Responsibilities

Information security responsibilities are allocated across relevant organizational functions.

The Company designates appropriately qualified personnel to oversee information security governance, cybersecurity operations and compliance activities.

Security responsibilities are incorporated into relevant operational processes and communicated to personnel whose duties involve access to Company Information Assets or Customer Data.

4. PERSONNEL SECURITY

4.1 Confidentiality Obligations

Individuals granted access to Customer Data are subject to legally enforceable confidentiality obligations appropriate to the nature of the information to which access is provided.

Such obligations survive termination of employment or engagement to the extent permitted by Applicable Law.

4.2 Personnel Screening

Where appropriate, lawful and proportionate having regard to the relevant role and jurisdiction, the Company may conduct reasonable pre-engagement screening procedures designed to verify the suitability of personnel who may obtain access to confidential information or Customer Data.

4.3 Security Awareness

The Company maintains an ongoing information security awareness programme intended to promote secure working practices throughout the organization.

Training programmes may address:

  • phishing;
  • social engineering;
  • credential security;
  • secure handling of Personal Data;
  • artificial intelligence security;
  • prompt injection risks;
  • secure development practices;
  • incident reporting obligations.

Training content is periodically reviewed and updated to reflect emerging threats and evolving regulatory requirements.

4.4 Access Revocation

Upon termination of employment, engagement or authorized access, the Company implements procedures designed to ensure the timely revocation of logical access rights, recovery of Company assets and protection of confidential information.

5. IDENTITY AND ACCESS GOVERNANCE

The Company maintains identity and access management controls designed to ensure that access to Customer Data is restricted to authorized individuals with a legitimate business need.

Such controls may include:

  • centralized identity management;
  • Role-Based Access Control (RBAC);
  • least privilege administration;
  • segregation of duties;
  • privileged access management;
  • periodic entitlement reviews;
  • approval workflows;
  • session management;
  • automated access revocation;
  • administrative activity monitoring.

Administrative privileges are granted only where operationally necessary and are subject to enhanced monitoring and periodic review.

6. AUTHENTICATION AND CREDENTIAL MANAGEMENT

The Company employs authentication mechanisms designed to reduce the risk of unauthorized access to Customer Data and Company systems.

Controls may include:

  • Multi-Factor Authentication for privileged users;
  • secure password policies;
  • password complexity requirements;
  • password hashing using industry-recognized algorithms;
  • secure credential storage;
  • token-based authentication;
  • authentication rate limiting;
  • account lockout mechanisms;
  • secure session management.

Authentication mechanisms are periodically reviewed to ensure continued effectiveness against evolving attack vectors.

7. CRYPTOGRAPHIC SAFEGUARDS

7.1 Cryptographic Governance

The Company maintains a comprehensive cryptographic governance framework designed to preserve the confidentiality, integrity and authenticity of Customer Data throughout its collection, transmission, storage, processing and disposal.

Cryptographic controls are selected, implemented and periodically reviewed having regard to the sensitivity of the information processed, the state of technological development, recognized industry practices, applicable regulatory requirements and the Company's evolving risk profile.

The Company shall periodically evaluate the continued appropriateness of cryptographic mechanisms and may replace or enhance such mechanisms where reasonably necessary to maintain an appropriate level of protection.

7.2 Data Encryption

The Company employs industry-recognized cryptographic measures designed to protect Customer Data against unauthorized access, disclosure or alteration.

Without limitation, such safeguards may include:

  • encryption of Customer Data during electronic transmission using contemporary transport security protocols;
  • encryption of Customer Data at rest where appropriate having regard to the nature of the information processed;
  • encryption of backup media where reasonably appropriate;
  • secure certificate lifecycle management;
  • cryptographic integrity verification mechanisms;
  • secure cryptographic key generation, storage, rotation and retirement procedures.

The Company reserves the right to modify specific cryptographic technologies over time, provided that any replacement affords a level of protection that is not materially less protective than the technology replaced.

7.3 Cryptographic Key Management

The Company maintains documented procedures governing the lifecycle management of cryptographic keys.

Such procedures may address, where appropriate:

  • key generation;
  • key distribution;
  • secure storage;
  • key rotation;
  • key revocation;
  • key destruction;
  • access restrictions;
  • separation of cryptographic duties.

Access to cryptographic material shall be restricted to appropriately authorized personnel whose responsibilities reasonably require such access.

8. INFRASTRUCTURE SECURITY

8.1 Secure Cloud Infrastructure

The ONLYAI Platform is designed to operate upon professionally managed cloud infrastructure incorporating multiple layers of administrative, logical and technical safeguards intended to promote operational resilience and information security.

The Company seeks to architect its production environment in accordance with recognized cloud security principles, including:

  • logical segregation of environments;
  • infrastructure hardening;
  • redundancy of critical services;
  • controlled administrative access;
  • secure configuration management;
  • infrastructure monitoring;
  • resilience against common cybersecurity threats.

8.2 Environment Segregation

Where operationally appropriate, the Company maintains logical separation between environments used for:

  • software development;
  • testing;
  • quality assurance;
  • staging;
  • production.

Customer Data shall not be used within non-production environments except where appropriate technical and organizational safeguards have been implemented and such Processing is reasonably necessary for legitimate operational purposes.

8.3 Configuration Management

The Company maintains configuration management processes intended to reduce the likelihood of unauthorized, insecure or unintended changes to production infrastructure.

Configuration changes shall, where appropriate:

  • be documented;
  • undergo appropriate review;
  • be subject to testing prior to deployment;
  • be capable of rollback where reasonably practicable.

9. NETWORK SECURITY

9.1 Network Protection

The Company maintains network security controls designed to protect systems supporting the Services against unauthorized access, malicious activity and disruption.

Network security measures may include:

  • network segmentation;
  • traffic filtering;
  • firewall technologies;
  • distributed denial-of-service protection;
  • secure routing;
  • intrusion detection mechanisms;
  • intrusion prevention mechanisms;
  • virtual private networking;
  • secure administrative channels.

9.2 Communications Security

Electronic communications between systems are protected through appropriate security mechanisms intended to preserve confidentiality and integrity.

The Company periodically reviews network architecture to identify opportunities for improving operational resilience and reducing cybersecurity exposure.

10. SECURE SOFTWARE DEVELOPMENT

10.1 Secure Software Development Lifecycle

The Company maintains a Secure Software Development Lifecycle ("SSDLC") intended to integrate security considerations throughout the lifecycle of software products, infrastructure and artificial intelligence systems.

Security considerations are incorporated into, among other phases:

  • requirements definition;
  • architecture design;
  • software development;
  • code review;
  • testing;
  • deployment;
  • maintenance;
  • retirement.

10.2 Secure Development Principles

Software developed by or on behalf of the Company shall, where reasonably appropriate, be developed in accordance with secure engineering principles, including:

  • secure coding practices;
  • peer review;
  • dependency management;
  • change management;
  • secrets management;
  • input validation;
  • output validation;
  • authentication controls;
  • authorization controls;
  • secure error handling.

10.3 Security Testing

The Company may implement one or more security testing methodologies, including:

  • static application security testing (SAST);
  • dynamic application security testing (DAST);
  • dependency scanning;
  • vulnerability scanning;
  • manual security review;
  • penetration testing;
  • secure code review.

The nature, frequency and scope of such testing shall be proportionate to the Company's risk assessment and operational requirements.

10.4 Change Management

Changes affecting production systems shall be managed through documented change management procedures designed to reduce operational and security risks.

Material production changes shall, where appropriate:

  • undergo technical review;
  • be tested prior to deployment;
  • be approved by appropriately authorized personnel;
  • be documented;
  • be capable of rollback where reasonably practicable.

11. ARTIFICIAL INTELLIGENCE SECURITY CONTROLS

11.1 AI Security Governance

Recognizing the unique security considerations associated with artificial intelligence systems, the Company has established governance measures intended to reduce risks arising from the operation of AI-enabled functionality within the ONLYAI Platform.

Such governance measures are intended to complement, and not replace, the Company's broader Information Security Management Framework.

11.2 AI-Specific Security Measures

Without limitation, the Company may implement controls designed to mitigate risks associated with:

  • prompt injection;
  • prompt leakage;
  • unauthorized prompt disclosure;
  • adversarial inputs;
  • model manipulation;
  • unauthorized automation;
  • excessive model permissions;
  • hallucination-related operational risks;
  • prohibited content generation;
  • unauthorized disclosure of Customer Data through AI outputs.

11.3 Human Oversight

Consistent with the Company's AI Governance Framework, the ONLYAI Platform is designed to facilitate meaningful human oversight of AI-assisted communications.

The Company provides Customers with functionality intended to support human supervision, review and intervention where appropriate.

The implementation and operational use of such functionality remain the responsibility of the Customer.

11.4 AI Output Governance

The Company employs technical and procedural safeguards designed to reduce the likelihood of inappropriate AI-generated outputs.

Such safeguards may include:

  • configurable moderation rules;
  • escalation workflows;
  • confidence thresholds;
  • prohibited content detection;
  • conversation termination mechanisms;
  • customer-defined operational parameters.

The Company acknowledges that probabilistic AI systems cannot guarantee the absence of erroneous or inappropriate outputs and Customers remain responsible for exercising appropriate human oversight.

12. DATA LIFECYCLE SECURITY

12.1 Information Lifecycle Management

The Company applies security controls throughout the lifecycle of Customer Data, including:

  • collection;
  • transmission;
  • storage;
  • use;
  • archival;
  • deletion;
  • destruction.

Security controls are selected having regard to the sensitivity of the information processed and the purposes of Processing.

12.2 Data Minimization

The Company seeks to limit the Processing of Customer Data to that reasonably necessary for the provision, maintenance, security and improvement of the Services in accordance with documented Customer instructions and Applicable Law.

12.3 Secure Deletion

Where Customer Data is deleted pursuant to Customer instructions, contractual obligations or applicable retention policies, the Company shall implement procedures designed to render such information inaccessible or irrecoverable within a commercially reasonable period, subject to technical limitations, legal retention obligations and disaster recovery processes.

13. LOGGING, MONITORING AND AUDITABILITY

13.1 Security Logging

The Company maintains logging mechanisms intended to facilitate the detection, investigation and remediation of security events affecting the Services.

Depending upon the relevant systems, logs may include information relating to:

  • authentication events;
  • administrative activities;
  • system errors;
  • security alerts;
  • infrastructure events;
  • API activity;
  • access attempts.

13.2 Monitoring

The Company maintains monitoring capabilities designed to identify operational anomalies, cybersecurity events and service degradation affecting the ONLYAI Platform.

Monitoring activities are conducted for legitimate operational, security and compliance purposes and in accordance with Applicable Law.

13.3 Auditability

The Company seeks to maintain sufficient records to support the investigation of security incidents, compliance verification and operational troubleshooting, subject to applicable retention policies and legal requirements.

14. VULNERABILITY MANAGEMENT

14.1 Vulnerability Management Framework

The Company maintains a documented vulnerability management programme designed to identify, evaluate, prioritize and remediate security vulnerabilities affecting the ONLYAI Platform, supporting infrastructure and related services.

The programme is intended to reduce the likelihood that identified vulnerabilities may adversely affect the confidentiality, integrity, availability or resilience of Customer Data.

Vulnerability management activities are performed on a risk-informed basis, taking into consideration the severity of the identified vulnerability, the likelihood of exploitation, the potential business impact, the availability of mitigating controls and the operational characteristics of the affected systems.

14.2 Identification of Vulnerabilities

The Company may employ one or more mechanisms designed to identify actual or potential security vulnerabilities, including, where appropriate:

  • automated vulnerability scanning;
  • dependency analysis;
  • software composition analysis;
  • security monitoring;
  • threat intelligence;
  • penetration testing;
  • secure code review;
  • responsible disclosure programmes;
  • vendor security notifications.

The Company reserves the right to determine the frequency, scope and methodology of such activities in accordance with its internal risk management procedures.

14.3 Remediation

Where vulnerabilities are identified, the Company shall implement remediation measures within commercially reasonable timeframes appropriate to the assessed risk.

Remediation activities may include:

  • software updates;
  • configuration changes;
  • compensating controls;
  • infrastructure modifications;
  • temporary mitigations;
  • risk acceptance, where appropriate and documented.

Nothing contained in this Schedule shall require the immediate remediation of every identified vulnerability where the Company has reasonably determined that alternative safeguards adequately reduce the associated risk.

15. BUSINESS CONTINUITY AND OPERATIONAL RESILIENCE

15.1 Operational Resilience

The Company recognizes that operational resilience and service availability constitute important components of the provision of the ONLYAI Platform.

Accordingly, the Company maintains commercially reasonable governance arrangements intended to support the continuity and restoration of critical business operations during disruptive events, having regard to the nature, scale and complexity of the Services and the technical infrastructure reasonably within the Company’s control.

Customer acknowledges that the availability and resilience of the ONLYAI Platform may depend upon third-party cloud infrastructure providers, external API providers, Supported Platform integration services, managed database providers, object storage providers, artificial intelligence routing and inference providers, queueing and caching infrastructure, content delivery networks, telecommunications providers and other external technology dependencies.

The Company does not warrant uninterrupted operation of such third-party infrastructure and shall not be responsible under this Schedule for outages, degradation or failures occurring within systems not owned and directly controlled by the Company, without prejudice to the Company’s obligations under the DPA and its commercially reasonable third-party risk management procedures.

15.2 Business Continuity Planning

The Company maintains documented business continuity and disaster recovery procedures appropriate to the nature, scale and complexity of its operations.

Such procedures are designed to support the timely restoration of material services following events that may adversely affect the availability of the ONLYAI Platform.

Business continuity arrangements may include, where appropriate:

  • redundancy of critical infrastructure;
  • geographically distributed cloud services;
  • backup and recovery capabilities;
  • failover procedures;
  • disaster recovery testing;
  • crisis management procedures;
  • incident communication protocols.

15.3 Testing

The Company may periodically review and test aspects of its business continuity arrangements to evaluate their continued effectiveness and identify opportunities for improvement.

Testing methodologies shall be determined by the Company having regard to operational requirements and evolving risks.

16. INFORMATION SECURITY INCIDENT MANAGEMENT

16.1 Incident Response Framework

The Company maintains a documented Information Security Incident Response Framework designed to facilitate the timely identification, containment, investigation, remediation and recovery of information security incidents affecting Customer Data or the Services.

The Company's incident management programme forms part of its broader governance framework and supports compliance with applicable contractual and regulatory obligations.

16.2 Incident Lifecycle

The Company's incident response procedures may include activities relating to:

  • identification;
  • triage;
  • classification;
  • containment;
  • forensic preservation;
  • investigation;
  • eradication;
  • recovery;
  • post-incident review;
  • implementation of corrective actions.

16.3 Notification

Where required under the Agreement, the DPA or Applicable Law, the Company shall notify the Customer of a confirmed Personal Data Breach without undue delay after becoming aware of the breach.

Such notification shall be provided in accordance with the procedures set forth in the Data Processing Agreement.

16.4 Lessons Learned

Following material security incidents, the Company may conduct post-incident reviews intended to evaluate root causes, identify opportunities for improvement and enhance the effectiveness of existing security controls.

17. PHYSICAL SECURITY

To the extent that Customer Data is processed within facilities operated directly by the Company or by its cloud infrastructure providers, reasonable physical security measures shall be implemented to protect systems against unauthorized physical access, damage or interference.

Depending upon the relevant facility, such measures may include:

  • controlled physical access;
  • visitor management;
  • environmental monitoring;
  • surveillance;
  • redundant power supplies;
  • fire detection and suppression;
  • physical asset protection.

Where the Company utilizes third-party cloud infrastructure providers, responsibility for physical security shall primarily rest with such providers pursuant to applicable contractual arrangements.

18. THIRD-PARTY RISK MANAGEMENT

18.1 Supplier Governance

The Company recognizes that third-party service providers may materially influence the security of the Services.

Accordingly, the Company maintains governance procedures intended to evaluate security risks associated with third-party providers prior to their engagement.

18.2 Due Diligence

Prior to engaging a Subprocessor or other material service provider that may Process Customer Data, the Company shall conduct commercially reasonable, risk-based due diligence appropriate to the nature, criticality and risk profile of the services provided, particularly where the relevant provider materially facilitates access to Customer Personal Data, Supported Platform Data or AI-assisted Processing.

Such assessment may consider:

  • information security posture;
  • technical capabilities;
  • regulatory compliance;
  • contractual safeguards;
  • operational resilience;
  • data protection commitments;
  • incident response capabilities.

18.3 Contractual Safeguards

Where Customer Data is Processed by a Subprocessor, the Company shall ensure that the relevant provider is contractually bound by obligations providing a level of protection substantially equivalent to those imposed upon the Company under the Data Processing Agreement.

19. CONTINUOUS IMPROVEMENT

The Company recognizes that information security constitutes an ongoing process rather than a static set of controls.

Accordingly, the Company shall periodically evaluate the effectiveness of its Information Security Management Framework and may implement improvements having regard to:

  • technological developments;
  • changes in Applicable Law;
  • evolving cybersecurity threats;
  • security incidents;
  • penetration testing results;
  • customer feedback;
  • industry best practices;
  • emerging artificial intelligence risks.

Nothing contained herein shall prevent the Company from adopting additional safeguards that exceed the measures described within this Schedule.

20. SECURITY MODIFICATIONS

The Company may modify, replace or enhance the technical and organizational measures described in this Schedule from time to time in order to:

  • improve the security of the Services;
  • address emerging threats;
  • respond to technological developments;
  • comply with Applicable Law;
  • improve operational resilience.

Provided that such modifications do not materially diminish the overall level of protection afforded to Customer Data, the implementation of updated security measures shall not constitute an amendment to the Agreement requiring Customer consent.

21. INTERPRETATION

The Parties acknowledge and agree that:

(a) the measures described in this Schedule reflect the Company's security governance programme as of the Effective Date;

(b) information security requires continuous adaptation to evolving threats and technologies;

(c) the Company retains discretion to determine the specific technical means by which equivalent or enhanced security outcomes are achieved;

(d) references to particular technologies or standards are illustrative of the Company's security objectives and shall not require the continued use of any specific technology where an equivalent or superior alternative has been implemented;

(e) this Schedule shall be interpreted consistently with Article 28 and Article 32 GDPR and the Parties' shared objective of ensuring an appropriate level of security for Customer Data.

22. ORDER OF PRECEDENCE

In the event of any inconsistency between this Schedule and the Information Security Policy adopted by the Company, this Schedule shall govern solely for the purposes of defining the Company's contractual obligations to the Customer under the Agreement.

The Information Security Policy shall remain an internal governance instrument and may be amended by the Company from time to time without constituting an amendment to the Agreement.