Additional Confidentiality Agreement

for Customers subject to a statutory or professional duty of confidentiality

Supplement to the ReviewBird Licence and Usage Terms and to the Data Processing Agreement

Version 1.0.0, dated July 27, 2026.

Non-binding English translation. The German version prevails.

Contracting Parties

Provider: Schild Roth SEO Agentur GmbH, Bismarckstr. 1–3, 50672 Cologne, Germany, represented by its Managing Director Timothy Scherman – hereinafter the “Provider” –

and

Customer: the professional bound by secrecy under the SaaS agreement; the details of name/company, address and representation are taken from the registration data – hereinafter the “Customer” –

Preamble

The Customer uses the Software-as-a-Service platform “ReviewBird”. It is subject to a statutory or professional duty of confidentiality – for example as a member of the healthcare professions, of the legal or tax advisory professions or of another profession named in Section 203 of the German Criminal Code (StGB) – and processes, in the course of its activity, in particular professional secrets and, where applicable, special categories of personal data. The Provider may act as another cooperating person within the meaning of Section 203 StGB in connection with setup, operation, maintenance, security or support.

In normal operation, the personal data processed in ReviewBird is to be protected against access by the Provider through technical and organizational measures. In exceptional cases, access may become necessary in particular to remedy disruptions or in the context of support. The Parties therefore additionally agree as follows:

Section 1 Subject matter, scope and order of precedence

(1) This agreement specifies the Provider’s obligations to protect the professional and private secrets entrusted to the Customer or otherwise made known to it. It applies to all services in connection with ReviewBird in which the Provider or persons engaged by it have the opportunity to obtain knowledge of protected information.

(2) This agreement applies in addition to the SaaS agreement including the Licence and Usage Terms, and to the Data Processing Agreement and the technical and organizational measures described therein.

(3) In the event of contradictions, the Data Processing Agreement takes precedence for data protection matters. For the protection of statutory or professional secrets, this agreement takes precedence over the Licence and Usage Terms. Otherwise, the provisions of the SaaS agreement remain unaffected.

(4) This agreement does not establish any independent right of the Provider to access Customer, End Customer or other protected data.

Section 2 Protected information

(1) “Professional secrets” means all facts that are attributable to the personal or material private sphere of a person, are known only to a limited group of persons, in whose confidentiality the person concerned has a legitimate interest, and which have been entrusted to or otherwise become known to the Customer in its professional capacity.

(2) This includes in particular the identity of patients, clients or other persons in a relationship of trust, the existence of a treatment, advisory or other relationship of trust, contact details, appointments and appointment categories, treatment, advisory or health information (where applicable), communication content, feedback, reviews and all information derivable therefrom.

(3) “Confidential information” further means all non-obvious commercial, organizational, technical or security-related information of the Customer, in particular access credentials, configurations, interface information, security measures and trade secrets.

(4) Not covered is information that the Provider demonstrably already lawfully knew, that becomes generally known without breach of this agreement, that is lawfully communicated by a third party entitled to do so, or that the Provider has independently developed. Mandatory statutory or professional confidentiality obligations remain unaffected.

Section 3 Confidentiality obligations of the Provider

(1) The Provider shall treat professional secrets and confidential information as strictly confidential. It shall use them exclusively to the extent required to perform the SaaS agreement, to comply with a documented instruction of the Customer or to fulfill a mandatory statutory obligation.

(2) The Provider may neither use protected information for its own purposes nor disclose it to third parties. This applies in particular to advertising, profiling, analysis and training purposes as well as to use as a reference or case study.

(3) The Provider shall restrict access according to the necessity and need-to-know principle. Protected information may be made accessible only to persons whose involvement is necessary for the respective contractual purpose and who have been bound in advance pursuant to Section 6.

(4) Reproductions, extracts, screenshots, local downloads and transfers of protected information are permitted only insofar as they are strictly necessary for the specific contractual purpose and are appropriately protected.

(5) The contractual use of non-personal technical operating and system data that allows no conclusions to be drawn about content, End Customers or individual users is governed by the Licence and Usage Terms.

Section 4 Cooperation under Section 203 StGB

(1) Insofar as this is necessary for the provision of the contractually owed services, the Provider is involved in the Customer’s professional activity as another cooperating person. The authority to obtain knowledge extends no further than the specific cooperation requires.

(2) The Provider is hereby expressly bound to secrecy. It has been informed that the unauthorized disclosure of another person’s secret may be a criminal offence, in particular under Section 203(4) StGB, and that the unauthorized exploitation of another person’s secrets may also have criminal consequences.

(3) If the Provider engages further persons who, in the course of their activity, have the opportunity to obtain knowledge of professional secrets, it shall ensure before their deployment that they are bound to secrecy to at least an equivalent standard and instructed about the possible criminal consequences of unauthorized disclosure.

(4) The Provider shall document the obligations under paragraph 3 and demonstrate their existence to the Customer in a suitable form upon justified request. The rights of the employees concerned and the Provider’s trade secrets shall be safeguarded in doing so.

Section 5 Support, administration and emergency access

(1) Routine inspection by the Provider of personal Customer or End Customer data is not envisaged. Support and administration access takes place only insofar as it is necessary to handle a specific support case, to remedy a disruption, for security purposes or to implement a documented instruction.

(2) Access to protected information generally requires a documented support request or instruction from the Customer. If immediate access is required to avert a present security risk or imminent significant data loss and is covered by the documented instructions, the Provider may take the necessary measures and shall inform the Customer without undue delay.

(3) Access is limited to the necessary scope and period. The Provider logs at least the person accessing, the time, the reason and the essential access actions. These logs are retained for three years from the end of the year in which the access took place.

(4) Upon completion of the support case, special authorizations granted are withdrawn without undue delay. Temporarily created support copies, extracts or screenshots are deleted as soon as they are no longer required, and at the latest 30 calendar days after completion of the support case.

(5) The Provider does not request the Customer’s personal passwords; they are technically neither known to nor readable by it. Where access is required, time-limited support access or other technically controlled access procedures are used.

Section 6 Employees and other cooperating persons

(1) The Provider engages only carefully selected employees or other cooperating persons who have been appropriately instructed and bound to confidentiality. Access is limited on a role basis to those persons whose activity requires it.

(2) The obligation of the persons engaged continues to apply after the end of their activity or of their employment or contractual relationship.

(3) Sub-processors are engaged in accordance with the Data Processing Agreement. Insofar as they may obtain knowledge of professional secrets, the Provider shall bind them to at least equivalent secrecy before the start of their activity and shall require them to bind further persons engaged accordingly.

(4) The Provider’s responsibility for the persons engaged by it to perform the contract is governed by the SaaS agreement and by statutory provisions.

Section 7 Technical and organizational safeguards

(1) The Provider protects protected information by appropriate technical and organizational measures in accordance with the state of the art. Details are set out in the Data Processing Agreement and the technical and organizational measures documented therein.

(2) These include in particular appropriate encryption, role-based authorizations, multi-factor authentication for privileged access, logging, secure administration channels and procedures for regularly reviewing the effectiveness of the protective measures, insofar as required by the nature and risk of the processing.

(3) Protected information may not be processed via private or non-approved accounts, devices, data carriers or communication channels. Transmission in support tickets or unencrypted messages is to be limited to what is strictly necessary; identifying details are to be pseudonymized where possible.

(4) Changes to the technical and organizational measures may not fall below the agreed level of protection. Material changes are documented in accordance with the Data Processing Agreement.

Section 8 Disclosure obligations, requests and incidents

(1) If the Provider is obliged to disclose protected information on the basis of a statutory, judicial or official order, it shall limit the disclosure to what is strictly necessary. Insofar as legally permissible, it shall inform the Customer in advance and give it the opportunity to seek legal protection.

(2) The Provider shall forward requests from patients, clients, authorities or other third parties concerning protected information to the Customer without undue delay. It shall not answer them itself unless legally obliged to do so or instructed by the Customer in documented form.

(3) The Provider shall inform the Customer without undue delay of any established or reasonably suspected unauthorized acquisition of knowledge, disclosure, alteration, loss or other impairment of protected information, via the contact address stored in the user account. The notification shall contain the information available according to the respective state of knowledge regarding the nature, scope, data affected, possible consequences and countermeasures taken.

(4) The Provider shall take appropriate measures without undue delay to contain and investigate the incident, secure the necessary evidence and support the Customer in fulfilling its statutory and professional obligations. External communications are made only on the documented instruction of the Customer, unless the Provider is subject to a mandatory obligation of its own.

Section 9 Return, erasure and retention

(1) The return, export, blocking and erasure of Customer and End Customer data are governed by the SaaS agreement, the Data Processing Agreement and the agreed deletion concept.

(2) Local support copies, extracts and other protected information temporarily stored outside the production system are securely deleted once the purpose has ceased to apply. Data in backup copies is deleted or overwritten within the agreed backup deletion cycle of 30 calendar days and blocked against productive use until then.

(3) Insofar as statutory retention obligations preclude erasure, the information concerned is blocked for other purposes and continues to be protected in accordance with this agreement. The Customer’s statutory documentation and retention obligations remain unaffected.

Section 10 Commencement, duration and survival

(1) This agreement enters into force upon its acceptance by the Customer, and at the latest when the Provider first has the opportunity to obtain knowledge of protected information.

(2) It applies for the term of the SaaS agreement. The confidentiality obligations continue to apply without time limit after its termination, for as long as the information concerned is secret or protected under statutory or professional provisions.

(3) Termination of the SaaS agreement does not affect erasure, cooperation, documentation and information obligations that have already arisen.

Section 11 Formation of contract and final provisions

(1) This agreement provided by the Provider constitutes a binding offer to conclude an additional confidentiality agreement. The Customer accepts it during the registration or onboarding process by ticking the correspondingly designated checkbox. Before acceptance, the Customer is given the opportunity to retrieve and save the agreement.

(2) The Provider logs the acceptance with the applicable version, date, time and user account and completes the Customer details from the registration data. The accepted version is made permanently available to the Customer as a PDF in its user account.

(3) Amendments and supplements to this agreement require text form unless a stricter form is required by law. Individual agreements remain unaffected.

(4) Liability, applicable law, place of jurisdiction and the assignment of rights are governed by the provisions of the SaaS agreement. Mandatory statutory provisions remain unaffected.

(5) Should individual provisions of this agreement be or become invalid in whole or in part, the validity of the remaining provisions remains unaffected. The statutory provisions take the place of the invalid provision.

Declaration of the Provider

The Provider confirms the above obligations and makes this agreement available to the Customer as a supplementary contractual document for acceptance. This agreement is issued by the Provider for the benefit of the Customer; a handwritten signature by the Customer is not required.

Record of acceptance by the Customer (automatically populated): accepted on [date] at [time] by user account [identifier]; Customer [business name]; version used [version].