SUNDRITO PRIVACY POLICY Release v1.3 — EN 1. WHO WE ARE SUNDRITO is the product/service brand operated by Sundry Kitchens LLC (“Sundry Kitchens LLC,” “Provider,” “we,” “us”). SUNDRITO is not represented here as a separate legal entity or registered assumed name. Public application: https://app.sundrito.com. Privacy contact: privacy@sundrito.com. Business/notice address: 2211 Southwest Blvd Apt 7Z, Tulsa, OK 74107. 2. SCOPE This Policy describes how SUNDRITO handles personal information in connection with its operational systems platform, related implementation/support activities, commercial interactions and authorized users. It does not replace a customer’s own obligations to its employees, contractors, guests, vendors or other individuals. 3. INFORMATION WE MAY PROCESS Depending on the activated service, we may process: business identity and location information; names, work email addresses and account identifiers; membership, role and location assignments; assessment responses and evidence notes; operational findings and recommendations; implementation, SOP, training, competency and execution records; operational metrics; support communications; commercial contact/order records; and security, authentication, access and audit metadata. 4. DATA WE DO NOT REQUEST BY DEFAULT SUNDRITO is designed around data minimization. Unless a separately approved feature and legal basis require it, users should not enter Social Security numbers, government identifiers, payment-card numbers, personal banking credentials, medical information, immigration information, full payroll files, passwords for unrelated systems, or other sensitive personal information unnecessary for the Service. 5. PURPOSES We use information to: provide and administer the Service; authenticate and authorize users; configure customer workspaces; conduct the governed assessment-to-improvement workflow; create and maintain customer operational content; provide training/execution/measurement functions; support users; communicate service and transactional messages; protect the Service and tenants; maintain audit/history; administer subscriptions; and comply with legal obligations. 6. CUSTOMER-CONTROLLED WORKFORCE DATA For workforce-related personal information entered by a Customer, the Customer generally determines why the information is collected and used for its business operations, and SUNDRITO generally processes it to provide the contracted Service. Customer remains responsible for employment-law notices, lawful instructions and decisions. SUNDRITO does not use platform records as independent authority to hire, fire, discipline, set compensation or make other high-impact employment decisions. 7. AI-ASSISTED PROCESSING Some features may use automated or AI-assisted analysis to organize evidence, suggest operational findings, draft content or recommend next actions. Such outputs require appropriate human review and are not automatically verified facts. Details and limits appear in the AI-Assisted Operational Intelligence Notice. If a third-party AI provider is later used to process Customer Data in Production, the applicable provider and data-use terms must be disclosed before that use is treated as part of the released privacy baseline. 8. SERVICE PROVIDERS / SUBPROCESSORS We use service providers to operate the Service. The current verified Production infrastructure includes Render for application hosting/runtime, Supabase for database/authentication/backend infrastructure, and Resend for transactional email. Current details and processing locations are maintained in the SUNDRITO Subprocessor List. We do not treat development tools as subprocessors merely because they are used in software development; a vendor is listed when it processes covered Customer Data for the Service. 9. SELLING / TARGETED ADVERTISING SUNDRITO’s current Product baseline does not authorize sale of Customer personal information or use of Customer personal information for unrelated targeted advertising. Resend open and click tracking are currently disabled for the verified SUNDRITO sending domain. Any future materially different advertising/tracking use requires separate Product, privacy and legal review. 10. DISCLOSURE We may disclose information to service providers acting on our behalf; to a successor in a corporate transaction subject to appropriate protections; to comply with law or valid legal process; to protect rights, safety, security or integrity; and as directed or authorized by the applicable Customer. We do not authorize cross-customer disclosure of Customer Data except where legally required or explicitly authorized. 11. DATA LOCATION AND INTERNATIONAL USE Current verified core Production providers operate in U.S. regions. Customers outside the United States or future international operations may create additional transfer/legal requirements. SUNDRITO will not claim international data-transfer compliance until the applicable transfer mechanism, provider terms and jurisdictional requirements are reviewed. 12. RETENTION, EXPORT AND DELETION We retain information while needed to provide the Service and for justified security, audit, contractual, accounting or legal purposes. Retention/deletion timing is governed by the released Retention, Export & Offboarding Policy, applicable Product/provider capabilities, contractual terms, and law. Customer operational assets are intended to be portable through governed export/representation capabilities where supported. Deactivation may preserve historical truth where deletion would undermine required audit records, subject to applicable law. 13. SECURITY SUNDRITO uses technical and organizational controls designed to reduce unauthorized access and cross-tenant disclosure. The current Security & Data Protection Exhibit describes verified controls and known release conditions. No system is absolutely secure, and SUNDRITO does not claim certifications or guarantees not separately verified. 14. PRIVACY RIGHTS Depending on where an individual resides and which law applies, an individual may have rights to request access, correction, deletion, portability, information about processing, or other rights. SUNDRITO will evaluate requests under applicable law and the relevant Customer relationship. Where SUNDRITO processes information only on a Customer’s instructions, we may direct the requester to the Customer or assist the Customer as required. This applicability-based language is intentional because U.S. state privacy obligations differ by jurisdiction and scope. 15. CHILDREN The Service is intended for business use and is not directed to children. Customers must not knowingly create accounts for children or submit children’s personal information unless a separately approved lawful use case and required protections exist. 16. SECURITY / PRIVACY INCIDENTS We maintain an operational incident process for suspected unauthorized access or exposure. Notification obligations depend on the facts, affected data, contractual commitments and applicable law. This Policy does not promise a universal notification deadline beyond obligations that actually apply. 17. CHANGES We may update this Policy as the Service and legal requirements evolve. Material changes affecting Customer Data should be versioned and communicated through a governed notice/acceptance process where required. 18. CONTACT Privacy questions and requests: privacy@sundrito.com Postal/legal notice address: 2211 Southwest Blvd Apt 7Z, Tulsa, OK 74107