Access Control Policy

Exactflow Prosta Spółka Akcyjna • KRS 0001218490 • NIP 5342706763 • REGON 543770217

ul. Stanisława Bodycha 87, 05-816 Reguły, Poland

Effective Date: 15 July 2026

Version 1.0

1. Overview

The ExactFlow Platform and the ExactFlow Marketplace are multi-tenant systems in which multiple customers, sellers, and buyers share common infrastructure while their respective data remains subject to strict logical separation. The integrity of that separation depends upon the discipline with which the Company controls access to its systems, including access granted to Payment Partners and Delivery Partners whose systems interoperate with those of the Company.

2. Purpose

The purpose of this Policy is to ensure that access to the Company's systems and Information Assets is granted on a least-privilege and need-to-know basis, is authorised before being granted, is reviewed periodically, and is withdrawn promptly once no longer required, in fulfilment of the security-of-processing obligation established by Article 32 of the GDPR.

3. Scope

This Policy shall apply to every system, application, database, and data store supporting the Platform and the Marketplace; to human users and non-human identities, including Service Accounts, automation credentials, and application programming interface keys; and to access granted to a Third Party, including a Payment Partner or a Delivery Partner, where that Third Party's systems interoperate with the Company's systems.

4.1 Guiding Principles

Access to Information Assets shall be governed by the principles of least privilege, need-to-know, and default-deny. These principles shall apply equally to human users and to Service Accounts and other non-human identities.

4.2 Authentication

Access shall be authenticated through a centralised identity provider using single sign-on wherever the underlying system supports it.

Multi-Factor Authentication shall be mandatory for all administrative and privileged access to production infrastructure and cloud provider consoles, for all remote access to corporate or production networks, for all access to systems holding personal data, and, wherever the Platform or the Marketplace supports it, for seller- and buyer-facing accounts.

An application-based authentication factor or a hardware security key shall be preferred over an authentication factor transmitted by SMS.

Every account shall be protected by a strong, unique credential, generated and stored through the Company's approved password manager.

Administrative sessions shall be subject to inactivity timeouts, and session tokens shall be rotated upon privilege escalation and invalidated upon logout or credential change.

4.3 Authorisation

Access shall be granted through role-based access control, whereby permissions are attached to a defined role corresponding to a job function, and an individual shall be assigned to a role rather than accumulating permissions individually over time.

Privileged Access shall be restricted to a named, minimal group of individuals, logged in enhanced detail, and, where the underlying system permits it, granted only for the period required.

Where practicable, no single individual shall hold unchecked, end-to-end control over a sensitive action; where such segregation is not achievable, a compensating control shall be applied and the residual risk recorded in the Risk Register.

Access controls shall enforce strict logical separation between tenants of the Platform, and between individual sellers and buyers on the Marketplace, such that no user, process, or administrative action may access another party's data other than through a documented and audited support process.

4.4 Provisioning and De-provisioning

Access shall be requested and approved before being granted, identifying the requester, the system and level of access sought, and the business justification. Access provisioned without such a request and approval shall constitute a control failure irrespective of the requester's seniority.

An individual commencing employment or engagement shall be granted access aligned with the standard profile for their role, and shall complete Multi-Factor Authentication enrolment before first access.

On a change of role, access associated with the previous role shall be withdrawn and access appropriate to the new role granted, and access shall not be permitted to accumulate.

On termination of employment or engagement, access shall be withdrawn within two hours of notification to the IT function by the Human Resources function, across every system to which the individual had access, and any shared credential to which the individual had access shall be rotated.

User and Privileged Access shall be reviewed at least quarterly to confirm continued necessity and appropriate level, and a reconciliation of active accounts against the current staff list shall be performed at least weekly.

4.5 Service Accounts and Third-Party Access

A Service Account or application programming interface key shall be scoped to the minimum permissions required for its specific purpose and shall not be embedded in source code or configuration files.

Access granted to a Payment Partner or a Delivery Partner shall be limited strictly to the data required to perform the function for which the access is granted.

An inventory of Service Accounts, application programming interface keys, and Third-Party access credentials shall be maintained and reviewed alongside the review conducted under Section 4.4.

4.6 Remote Administrative Access

Remote administrative access to production systems shall be permitted only through authenticated, Multi-Factor Authentication-protected channels.

Direct exposure of an administrative interface to the public internet shall not be permitted under any circumstances.

5. Policy Compliance

Compliance with this Policy shall be mandatory. The Security function shall be responsible for periodic access reviews and for monitoring the use of Privileged Access; the IT function shall be responsible for provisioning and withdrawing access in accordance with approved requests.

6. Exceptions

An exception to this Policy shall be documented and approved in advance by the Chief Information Security Officer, with the reason and, where applicable, a time limit recorded.

7. Related Standards, Policies, and Processes

This Policy shall be read together with the Information Security Policy, the Cryptography & Key Management Policy, the Third-Party & Partner Risk Management Policy, and the HR Security & Confidentiality Policy.

8. Definitions and Terms

"Access Control" means the means by which the right to use, view, or otherwise interact with an Information Asset is granted, limited, or withdrawn.

"Least Privilege" means the principle that access shall be limited to the minimum necessary for a role to be performed.

"Privileged Access" means access rights that exceed those of a standard user, including administrative access to infrastructure, databases, or security tooling.

"Multi-Factor Authentication" means authentication requiring two or more independent factors of proof of identity.

"Service Account" means a non-human identity used by a system or automated process to access another system.

9. Revision History

Version 1.0 — July 2026

ExactFlow Access Control Policy | ExactFlow