NORTHWIND ANALYTICS PTY LTD INFORMATION SECURITY POLICY Version 2.1 — Approved by the Board, March 2026 1. PURPOSE AND SCOPE This policy sets out how Northwind Analytics protects the information it holds on behalf of its customers and its own staff. It applies to all employees and contractors, and to all systems that store or process customer data, including our production cloud environment and the laptops issued to staff. 2. ROLES The Chief Technology Officer is accountable for information security. Day to day responsibility sits with the platform engineering team. All staff are responsible for following this policy and for reporting anything that looks wrong. 3. ACCESS CONTROL Access to production systems is granted on a least privilege basis and approved by the CTO before it is provisioned. Every person has their own named account; shared logins are not permitted. Access is reviewed at the start of each quarter and any account no longer needed is removed. Staff who leave have their access revoked on their final day. Multi-factor authentication is required for the cloud console, the source code repository and the password manager. 4. DATA PROTECTION Customer data is encrypted in transit using TLS 1.2 or above. Production databases sit on encrypted volumes. Backups are taken nightly and retained for thirty days. We do not copy customer data into development or test environments. Where test data is needed it is generated synthetically. 5. CHANGE MANAGEMENT All changes to production go through pull request review by a second engineer. Deployments are automated and every deployment is recorded. Emergency changes may be made without prior review but must be documented within one business day. 6. SUPPLIER MANAGEMENT We maintain a list of the third parties that process customer data on our behalf. Before a new supplier is engaged, the CTO reviews their security documentation. Contracts with suppliers include confidentiality obligations. 7. INCIDENT RESPONSE Suspected security incidents are reported to security@northwind.example immediately. The CTO decides whether an incident has occurred and coordinates the response. Customers affected by a confirmed breach of their data are notified without undue delay. 8. BUSINESS CONTINUITY Our production environment runs across two availability zones. Database backups are tested by restore at least once a year. 9. ACCEPTABLE USE Company laptops are for company work. Staff must not install unapproved software, must lock their screen when away from the desk, and must not connect company equipment to untrusted networks without using the company VPN. 10. TRAINING New starters complete a security induction in their first week. All staff repeat security awareness training annually. 11. POLICY REVIEW This policy is reviewed annually by the CTO and approved by the Board.