Security Addendum
Effective Date: August 28, 2026 · Version 1.0
Global B2B SaaS Security Addendum.
1. Purpose and Scope
This Security Addendum (“Addendum”) describes the baseline technical and organisational security measures Wowmotive aims to apply in connection with the Services. The measures described are risk-based and aspirational targets, not absolute guarantees, and are subject to change as Wowmotive’s program evolves.
2. Information Security Program
Wowmotive will use commercially reasonable efforts to maintain a risk-based information-security program appropriate to the nature, scope, context and risks of the Services and Personal Data processed.
3. Security Framework Alignment
Wowmotive may use ISO/IEC 27001-aligned controls as a reference framework. Nothing in this Addendum represents that Wowmotive is certified to ISO/IEC 27001 or holds a SOC 2 report unless expressly and currently identified in writing.
4. UAE Regulatory Security Standard
Where the UAE PDPL applies, Wowmotive will use reasonable efforts to implement technical and organisational measures proportionate to the risks of Personal Data processing.
5. Access Control
Wowmotive aims to apply role-based access control, least-privilege access, unique credentials, and multi-factor authentication for privileged administrative access where technically supported and commercially practicable.
6. Encryption and Data Protection
Wowmotive aims to use encryption in transit for Customer Data transmitted over public networks and encryption at rest where appropriate to risk and architecture.
7. Logging, Monitoring and Detection
Wowmotive aims to maintain security-relevant logging and monitoring appropriate to critical systems.
8. Vulnerability and Security Testing
Wowmotive aims to maintain risk-based vulnerability identification and remediation processes and periodic security testing appropriate to systems and risk.
9. Secure Development and Change Management
Wowmotive aims to integrate security considerations into its development and change-management processes.
10. Backup, Business Continuity and Recovery
Wowmotive aims to maintain backup and recovery processes appropriate to the Services and risk, without guaranteeing any specific recovery point or recovery time.
10A. Production Access by Remote Personnel and Contractors
Where authorised Wowmotive personnel, or the independent third-party contracted development team based in Pakistan (engaged as a Subprocessor and not Wowmotive personnel), require access to production systems or Customer Data, Wowmotive aims to apply role-based access, least privilege, and logging appropriate to the risk. The Pakistan-based contractor is engaged under Wowmotive’s standard vendor confidentiality and security terms and is subject to security obligations designed to align with this Addendum, on a best-efforts basis. Customer Data will not knowingly be copied into development or test environments except under approved controls.
11. Incident Response and Personal Data Breaches
Wowmotive aims to maintain procedures for detection, triage, containment, and recovery from security incidents. Where a security incident constitutes a Personal Data Breach affecting Customer Data, Wowmotive’s notification and cooperation obligations are governed by the DPA. Where Wowmotive acts as Controller for Personal Data it independently controls, Wowmotive will notify the UAE Data Office within the timeframe required by Applicable Law, consistent with the DPA’s Controller-notification provisions.
12. Personnel Security
Personnel and contractors with access to Customer Data will be subject to confidentiality obligations appropriate to their role.
13. Subprocessor Security
Wowmotive will use reasonable efforts to require appropriate security and confidentiality measures from Subprocessors, subject to the DPA.
14. Physical and Infrastructure Security
Wowmotive relies on appropriately secured third-party cloud and infrastructure providers for services outside Wowmotive’s direct physical control and disclaims responsibility for their independent security failures beyond Wowmotive’s own contractual and legal obligations.
15. Data Retention and Secure Disposal
When Customer Data is no longer required, Wowmotive will use reasonable efforts to delete, anonymise, or otherwise dispose of it, subject to legal retention and backup requirements.
16. Security Evidence and Customer Assurance
Wowmotive will not represent that a SOC 2 report or ISO/IEC 27001 certificate exists unless it is current and expressly identified. Where commercially appropriate and no more than once per twelve-month period, Wowmotive may provide eligible customers with security summaries, subject to confidentiality restrictions and, for material additional requests, a reasonable fee.
17. Security Commitments Are Risk-Based and Best-Efforts
Wowmotive may update non-contractual security documentation, operational procedures, control descriptions, or security-assurance materials without prior notice where reasonably necessary as its security program evolves. Such updates do not by themselves amend, waive, or reduce any binding contractual security commitment unless amended in accordance with the MSA. The measures in this Addendum are aspirational, proportionate to Wowmotive’s resources as a growth-stage company, and do not create a warranty of any specific security outcome. Customer-specific security requirements exceeding this Addendum must be expressly agreed in a signed Order Form or amendment, including any associated fees.
18. Third-Party GPS and Connectivity
Wowmotive does not control and has no liability for the security, availability, or physical operation of independent third-party infrastructure, cellular coverage, or GPS signal availability.
19. Customer Security Responsibilities
Customer is solely responsible for managing its own user accounts and permissions, protecting its credentials, and implementing required driver and employee notices.
20. Compliance and Legal Precedence
This Addendum does not replace or limit obligations Applicable Law actually imposes. The DPA controls over this Addendum for Personal Data processing matters. The MSA controls for general legal terms, liability, and contractual remedies.
21. No Automatic Certification Commitment
ISO/IEC 27001 and SOC 2 are not, by this Addendum alone, a promise that Wowmotive currently holds either certification or report.
22. Incorporation
This Security Addendum becomes binding when incorporated into an executed Order Form or other written agreement.