RoofHyve Security Addendum

Owner / Publisher

RoofHyve Inc.

Product

RoofHyve

Effective Date

June 12, 2026

Last Updated

June 29, 2026

Audience

Roofing company customers/subscribers and RoofHyve

Applies To

Security of Customer Data processed through the RoofHyve platform

1. Purpose and Scope

This Security Addendum supplements the Terms of Service, Data Processing Addendum, and Service Level Agreement and describes the administrative, technical, and organizational measures RoofHyve uses to protect Customer Data. Capitalized terms not defined here have the meaning given in the Terms or DPA.

2. Security Program

RoofHyve maintains a written information security program containing administrative, technical, and physical safeguards appropriate to the nature of the data processed and the size and complexity of RoofHyve’s operations. The program is reviewed periodically and updated as threats, technologies, and operations evolve.

3. Access Controls

RoofHyve applies role-based access controls and the principle of least privilege. Access to Customer Data is limited to personnel with a business need, uses unique credentials, and is supported by multi-factor authentication where available. Access rights are reviewed periodically and promptly revoked when no longer needed.

4. Authentication and Credentials

RoofHyve maintains password and session controls, protects stored credentials and secrets, and uses commercially reasonable measures to prevent unauthorized authentication.

5. Encryption

RoofHyve encrypts Customer Data in transit using industry-standard protocols such as TLS and uses encryption at rest where supported by the applicable database, storage, or infrastructure layer. Encryption keys are managed with appropriate safeguards.

6. Network and Infrastructure Security

The Services are hosted on cloud infrastructure, including Microsoft Azure. RoofHyve uses network segmentation, firewalls, secure configuration, and monitoring to protect production systems.

7. Vulnerability and Patch Management

RoofHyve performs risk-based vulnerability management, applies security patches in a timely manner based on severity, follows secure development practices, and manages material production changes through a controlled process.

8. Logging and Monitoring

RoofHyve maintains activity and audit logs, monitors for security events, and retains logs in accordance with its policies, operational needs, and applicable law.

9. Personnel Security

RoofHyve personnel are bound by confidentiality obligations, receive security awareness training, and are subject to appropriate screening where permitted by law and relevant to their role.

10. Subprocessors

RoofHyve engages subprocessors in accordance with the DPA and imposes appropriate contractual safeguards. A current subprocessor list is available on request at dpa@roofhyve.com.

11. Incident Response

RoofHyve maintains an incident response process and will notify Customer of confirmed Security Incidents involving Customer Data without undue delay, as described in the DPA and subject to applicable law.

12. Backups and Resilience

RoofHyve maintains backup and recovery capabilities aligned with the Service Level Agreement. No backup or recovery process guarantees recovery of all data.

13. Customer Responsibilities

Customer is responsible for account security, user permissions, credential management, secure configuration of the Services, lawful use of the platform, and prompt reporting of suspected security issues.

13A. Account Deletion and Access Revocation

When an individual user account deletion or access removal request is verified and approved for processing, RoofHyve may disable or revoke the user login access, terminate active sessions, remove the user from active access where applicable, and apply deletion, anonymization, or restriction measures to personal account profile information where possible.

Security logs, audit logs, backup records, access history, incident records, and other security-related records may be retained in accordance with RoofHyve policies, operational needs, legal obligations, and the Agreement, even if an individual user account is deleted, anonymized, restricted, or closed.

14. Audits and Assessments

Subject to confidentiality, security, and operational limits, RoofHyve will provide information reasonably necessary to demonstrate compliance with this Security Addendum, as described in the DPA.

15. Changes

RoofHyve may update this Security Addendum to reflect evolving threats, technologies, and standards. Material changes will be communicated where required by applicable agreements or law.

Contact Information

RoofHyve Inc.

Legal Mailing Address: 2146 Pine St, Redding, CA 96001

Legal Notices: legal@roofhyve.com

DPA / Subprocessor Requests: dpa@roofhyve.com

Security: security@roofhyve.com

Support: support@roofhyve.com