Data Classification Policy

Exactflow Prosta Spółka Akcyjna • KRS 0001218490 • NIP 5342706763 • REGON 543770217

ul. Stanisława Bodycha 87, 05-816 Reguły, Poland

Effective Date: 15 July 2026

Version 1.0

1. Overview

Information held by the Company varies materially in its sensitivity. Information already published on the Marketplace requires materially less protection than a seller's financial details, and a seller's financial details require materially less protection than the Company's authentication credentials and cryptographic key material. This Policy establishes the scheme by which such information is distinguished, and the same scheme is described in operational detail within the Company's wider Asset Management & Data Classification Policy; this document constitutes the standalone statement of that scheme.

2. Purpose

The purpose of this Policy is to define how the Company classifies information according to its sensitivity, and the storage, transmission, and disposal requirements attaching to each classification level, such that protection is applied in a manner proportionate to sensitivity rather than uniformly.

3. Scope

This Policy shall apply to all information created, received, stored, processed, or transmitted by the Company in connection with the Platform or the Marketplace, in any form, including information shared with, or received from, a Hosting Provider, a Payment Partner, a Delivery Partner, or a Marketplace Channel.

4.1 Classification Levels

Information shall be classified as Public, Internal, Confidential, or Restricted.

Public information is information that has been explicitly approved for release outside the Company and carries no expectation of confidentiality, including published marketing content, the public Privacy Policy and Terms of Service, and Marketplace product listings.

Internal information is information not intended for public release, the disclosure of which would not cause serious harm, and which is broadly accessible within the Company, including routine internal documentation.

Confidential information is information the unauthorized disclosure of which would cause meaningful harm to the Company, a customer, or an individual, including seller and buyer account data, commercial contract terms, source code, and the findings of Third-Party due diligence.

Restricted information is the Company's most sensitive category, comprising information the unauthorised disclosure of which would cause severe harm, including authentication credentials and cryptographic key material, payment tokens and transaction records, seller verification and anti-money-laundering records, and delivery recipient data during an active security investigation.

4.2 Assignment of Classification

The Asset Owner shall assign the classification of an Information Asset at the point of its creation or receipt. Where no more specific classification is warranted, an Information Asset shall default to Internal.

Classification shall be reviewed whenever the context of an Information Asset changes materially.

Every Information Asset shall be recorded in the Company's asset inventory together with the name of its Asset Owner, and an Information Asset identified without a named owner or an assigned classification shall be treated as requiring immediate remediation.

4.3 Handling Requirements

Public information shall be subject to no special requirement as to storage, transmission, or disposal.

Internal information shall be stored and transmitted only through Company-approved systems and channels, and disposed of through standard deletion.

Confidential information shall be encrypted at rest and in transit, access to it shall be controlled on a least-privilege basis, it shall not be entered into an artificial intelligence or large-language-model tool that has not been specifically approved, and it shall be disposed of in accordance with the Data Retention & Deletion Policy.

Restricted information shall be encrypted at rest using the strongest available cipher, access to it shall be limited to a named, minimal group of individuals with every access logged, transmission shall be limited to the minimum necessary recipients, and disposal shall be by secure deletion with verification, with cryptographic erasure of the encryption key preferred for encrypted stores.

4.4 Application to Third-Party and Channel Data Flows

Information shared with a Payment Partner in connection with a transaction shall be classified as Confidential or Restricted depending on whether it includes a payment token or transaction identifier.

Information shared with a Delivery Partner for the purpose of order fulfilment shall be scoped and classified such that only the minimum necessary recipient information is transmitted at each stage, consistent with the data-minimisation approach described in the Third-Party & Partner Risk Management Policy.

Classification shall be applied to a data flow with a Marketplace Channel before the corresponding integration is enabled, and not retrospectively once that integration is operational.

5. Policy Compliance

Compliance with this Policy shall be mandatory. Asset Owners shall be responsible for assigning and periodically reviewing the classification of the information they own, and the Security function shall maintain the classification scheme and audit its accurate application across the asset inventory.

An Information Asset identified without the handling controls appropriate to its classification shall be treated as a security finding requiring prompt remediation.

6. Exceptions

An exception to this Policy shall be documented and approved in advance by the Chief Information Security Officer.

7. Related Standards, Policies, and Processes

This Policy shall be read together with the Asset Management & Data Classification Policy, the Cryptography & Key Management Policy, the Access Control Policy, the Data Retention & Deletion Policy, and the Third-Party & Partner Risk Management Policy.

8. Definitions and Terms

"Asset Owner" means the individual accountable for the protection of a specific Information Asset.

"Classification Level" means one of the four sensitivity tiers — Public, Internal, Confidential, or Restricted — that determines the handling requirements applicable to a given item of information.

"Data Minimisation" means the principle of limiting personal data collected or shared to what is directly relevant and necessary for the specified purpose.

9. Revision History

Version 1.0 — July 2026

ExactFlow Data Classification Policy | ExactFlow