Personal Data Processing and Protection Rules

(hereinafter the “Rules”)

I. General Provisions

1. These Rules are part of contractual regulations binding the Parties for all agreements concluded and performed, ongoing cooperation, and offer/inquiry exchanges with Grupa Hossa S.A. and Hossa.biz. Sp. z o.o., both registered in Gdańsk (“Companies”).

2. Each Party is a Controller of Personal Data within the meaning of Article 4(7) GDPR, including the personal data of its employees, associates, members of the Companies’ and Communities’ bodies, attorneys, subcontractors and service providers, as well as its customers’ personal data (“Personal Data Administered by the Party”).

3. Personal Data Administered by the Party were disclosed or obtained by the Personal Data Controller in compliance with applicable laws, in particular, they were disclosed by the individuals to whom the Personal Data relate in connection with preparing, concluding and performing agreements entered into by the Party with those individuals.

4. In the course of their business, the Parties enter into agreements (“Agreements”) under which they provide mutual services, including, in particular, each Party may provide such services on behalf of and/or at the request of the other Party, also directly to that other Party’s customers as the final recipients of such services.

5. In connection with Agreements concluded and performed, one Party may disclose Personal Data Administered by the Party to the other Party.

6. Disclosure by the Parties of Personal Data Administered by the Party takes place in accordance with the GDPR. Where processing Personal Data requires the consent of the data subject, the Personal Data Controller has obtained such consent for disclosure.

7. IIndividuals whose Personal Data are concerned have received the legally required information that the Party is the Controller of their Personal Data, including information on the purposes, scope and methods of processing, the possibility of entrusting or otherwise transferring their Personal Data to another entity, the rules of such processing, and their rights to control how their Personal Data are processed.

8. Disclosure of Personal Data Administered by the Party may take the form of:

1) entrusting the other Party with processing Personal Data on behalf of and/or at the request of the entrusting Party; in such case, the Party receiving the Personal Data becomes a Processor within the meaning of Article 4(8) GDPR (“Entrusted Processing of Personal Data”);

2) transferring Personal Data so that the Party receiving them becomes their Controller within the meaning of Article 4(7) GDPR, determining further purposes and methods of processing (“Transfer of Personal Data”).

9. Personal Data entrusted to a Party for processing or transferred by the other Party shall not be transferred to third countries, in particular outside the EEA, or to international organisations.

II. Entrusted Processing of Personal Data

1. The Party entrusted with Processing Personal Data, pursuant to Section I.7.1), shall, as Processor, process Personal Data in accordance with these Rules, the GDPR and other applicable laws.

2. The Party entrusted with Processing Personal Data shall, as Processor, process Personal Data only for the purpose and within the scope for which they were disclosed, i.e. to perform the Agreements and in connection with their performance, with particular regard to the type of Personal Data received, the categories of data subjects, the basis for transferring the Personal Data, and the nature and purpose of processing. Personal Data entrusted to a Party by the other Party may also be processed by that other Party to fulfil its legal obligations and for its legitimate interests.

3. Personal Data entrusted to a Party by the other Party shall not be further entrusted to any third party without the prior consent of the Personal Data Controller. In such case, the Processor must ensure appropriate control over further processing by the third party, including concluding an appropriate data processing agreement imposing on the third party obligations regarding Personal Data processing and protection substantially consistent with these Rules. The Processor shall be liable to the Personal Data Controller for the third party’s actions as for its own actions.

4. Each Party, as Processor, subject to statutory obligations under applicable law, once the basis and purpose for which Personal Data were entrusted to it cease to exist (including, in particular, after termination of the Agreement in connection with which the Personal Data were entrusted, taking into account the period for pursuing and limitation of claims under that Agreement), and upon the Personal Data Controller’s request, shall return or delete all Personal Data without retaining copies and provide the Controller with confirmation of deletion.

5. Each Party, as Personal Data Controller, has the right to audit how the other Party, as Processor, processes the Personal Data entrusted to it.

6. The Controller’s audit right referred to in Section 5 shall be exercised by submitting relevant questions and requests for explanations to the Processor. The Processor shall respond without delay, no later than within 14 days.

7. Each Party, as Processor, shall promptly notify the Party acting as Controller of:

1) any legally authorised request for disclosure of Personal Data addressed to the Processor by a competent state authority, unless applicable law prohibits such notification, in particular to ensure the confidentiality of an investigation or inquiry or due to an important public interest;

2) any unauthorised access, or attempted access, to Personal Data, specifying the circumstances, effects and measures taken to prevent the breach and its effects;

3) any request received from a data subject whose Personal Data were entrusted by the Controller to the Processor, concerning the fact, purpose or scope of processing or operations performed on that person’s Personal Data, while refraining from responding until receiving the Controller’s position; the Controller shall provide that position promptly and in any event within 7 days.

III. Transfer of Personal Data

1. Each Party to which the other Party, as Controller, has transferred Personal Data under Section I.7.2), undertakes, as Controller of that data, to process it in accordance with these Rules, the GDPR and other applicable laws.

2. Each Party to which the other Party has transferred Personal Data and which has become the Controller shall process that Personal Data as Controller only for the purpose and within the scope for which it was transferred, with particular regard to the type of Personal Data received, the categories of data subjects, the basis for transfer, and the nature and purpose of processing.

3. Each Party to which the other Party has transferred Personal Data and which has become the Controller thereof, to the extent transferred, undertakes to fulfil all information obligations under the GDPR towards the data subjects concerned.

IV. Personal Data Protection

1. Each Party shall implement technical and organisational measures to ensure processing and security of Personal Data in compliance with applicable law, including the GDPR, and this Agreement.

2. Personal Data shall be processed only by authorised employees and associates of the Party who have been appropriately trained in processing and protecting Personal Data and are contractually or legally bound to confidentiality. The Party shall supervise, verify and enforce compliance with adopted procedures, rules and instructions by its employees and associates.

3. Personal Data shall be processed by the Parties only at locations comprising the Party’s registered office and places of business.

4. Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of data subjects, the Parties shall apply technical and organisational measures appropriate to ensure a level of security for processing and protection of Personal Data proportionate to that risk:

1) preventing unauthorised persons from accessing Personal Data processing systems, including preventing them from reading, copying, modifying or deleting Personal Data;

2) ensuring the security of Personal Data during electronic transmission and during transport or storage on data carriers, protecting it against reading, copying, modification or deletion;

3) ensuring the ability to verify and determine whether, and by whom, Personal Data was entered into, modified or deleted from data processing systems;

4) ensuring protection against accidental destruction or loss of Personal Data;

5) ensuring the possibility of separately processing Personal Data collected for different purposes;

6)PD processing systems: C/I/A/resilience

7) ensuring the ability to promptly restore the availability of Personal Data in the event of physical or technical incidents;

8)Ensure effective test/measure/eval. of technical/organisational measures for Personal Data security.

V. Parties' cooperation re PD processing

1. The Parties shall cooperate and collaborate to ensure their compliance, in connection with the processing of Personal Data, with the applicable GDPR provisions and other relevant data protection and privacy laws.

2. The Parties shall cooperate and collaborate in fulfilling their statutory obligations towards data subjects, including information obligations and obligations related to exercising their rights to control the processing of Personal Data, such as rectification, erasure, restriction of processing, access and data portability.

3. The Parties shall exchange all information necessary to demonstrate compliance of their procedures for processing and protecting Personal Data, and their implementation, with applicable law, in particular Article 3 of the GDPR, and shall permit and participate in audits, including inspections, conducted by the Other Party or an auditor authorised by it.

4. If, for any reason, even temporarily, a Party is unable, hindered or restricted in performing any provision of these Rules, it shall promptly notify the Other Party, informing it of measures taken or planned to remedy the situation.

5. Each Party shall indemnify and hold the Other Party harmless from all liability arising from or related to its breach of these Rules, including liability for damages, compensation or other obligations towards data subjects, and any penalties or fines imposed by competent courts or administrative authorities.

6. Each Party shall bear its own costs related to implementing these Rules.