This addendum is prepared in advance so Korium can be offered to financial-institution customers. It applies only where the Customer is a “financial institution” under the Gramm-Leach-Bliley Act (GLBA) and this addendum has been executed as part of the Agreement; it is otherwise inactive. It has not yet been reviewed by qualified counsel, and the internal program items it commits to (a designated Qualified Individual, a written risk assessment, a formal penetration-test / vulnerability-scan cadence, and an annual security report) should be stood up before it is offered to a live financial-institution customer.
This GLBA Safeguards Addendum (“Addendum”) supplements the Subscription Terms of Service and the Data Processing Addendum (“DPA”) between Kyroco, LLC (“Kyroco,” “Service Provider”) and a Customer that is a Financial Institution (“Customer”). It sets out Kyroco’s commitments as a service provider under the FTC Safeguards Rule (16 CFR Part 314) with respect to Customer Information that Kyroco processes on Customer’s behalf through Korium.
Kyroco is not itself a financial institution. This Addendum applies where Customer is a Financial Institution and Korium receives or maintains Nonpublic Personal Information (NPI) / Customer Information on Customer’s behalf. It complements - and does not replace - the security measures and processing terms in the DPA, which continue to apply.
“GLBA” means the Gramm-Leach-Bliley Act and its implementing regulations, including the FTC Standards for Safeguarding Customer Information (16 CFR Part 314, the “Safeguards Rule”). “Financial Institution” has the meaning in the Safeguards Rule. “Nonpublic Personal Information” (“NPI”) and “Customer Information” have the meanings in the Safeguards Rule, and refer to the records containing NPI that Kyroco handles or maintains on Customer’s behalf. Terms not defined here have the meaning in the DPA or Agreement.
Kyroco maintains a written information security program with administrative, technical, and physical safeguards appropriate to its size and complexity, the nature and scope of its activities, and the sensitivity of the Customer Information at issue, designed to protect the security, confidentiality, and integrity of that information consistent with the Safeguards Rule. The program is overseen by a designated Qualified Individual (Robert Sfeir), is based on a written risk assessment of foreseeable internal and external risks, and is reported on to Kyroco’s leadership at least annually.
Kyroco’s program includes the safeguards described in Annex II of the DPA, which are designed to align with the Safeguards Rule, including:
Kyroco will use and disclose NPI / Customer Information solely to provide and support the Service on Customer’s instructions and as permitted under the Agreement, the DPA, and applicable law. Kyroco will not use, sell, or disclose NPI for its own purposes, and will not redisclose NPI except as permitted by GLBA’s reuse-and-redisclosure limits. Kyroco does not use Customer Content (including any NPI it contains) to train, fine-tune, or improve general-purpose or foundation AI models.
Kyroco will cooperate with Customer’s obligation to oversee its service providers, including by (a) making available information reasonably necessary for Customer to assess Kyroco’s safeguards (such as summaries, certifications, or reports like SOC 2, where available), and (b) supporting Customer’s periodic reassessment of Kyroco’s program. Kyroco imposes comparable obligations on its own subprocessors and remains responsible for them, as described in the Subprocessors list and the DPA.
Kyroco will notify Customer without undue delay after becoming aware of a security event affecting Customer Information, and will provide information reasonably available to it to enable Customer to meet its own obligations - including any obligation to notify the FTC of a “notification event” (a security breach involving the unauthorized acquisition of unencrypted Customer Information of 500 or more consumers) within the timeframe required by the Safeguards Rule. This complements the breach-notification terms in the DPA.
On termination, and at Customer’s choice, Kyroco will return or securely dispose of Customer Information as described in the DPA, including derived artifacts and routine backups on Kyroco’s standard cycle. Audit and information-access rights are as set out in the DPA.
This Addendum supplements the Agreement and the DPA; if a conflict arises with respect to the safeguarding of Customer Information, this Addendum controls to the extent required by the Safeguards Rule. All other terms of the Agreement and DPA, including limitations of liability, remain in effect. This Addendum applies only while Customer is a Financial Institution and Kyroco processes Customer Information on its behalf.
Draft prepared 2026-07-21 for legal review; precautionary. The internal program elements (the written risk assessment, formal test cadence, and annual report) must be operational before this Addendum is offered to a live financial-institution customer.