Exactflow Prosta Spółka Akcyjna • KRS 0001218490 • NIP 5342706763 • REGON 543770217
ul. Stanisława Bodycha 87, 05-816 Reguły, Poland
Effective Date: 15 July 2026
Version 1.0
The Company relies upon external parties, including Hosting Providers, Payment Partners, and Delivery Partners, to operate the Platform and the Marketplace. Consequently, a material proportion of the incidents the Company must address will not originate within its own systems. This Policy, and the RB-01 Incident Response Runbook that accompanies it, are drafted with that circumstance in view.
The purpose of this Policy is to set out how the Company detects, responds to, and recovers from security incidents and Personal Data Breaches, and how it discharges its obligations to notify the competent supervisory authority and affected individuals. The RB-01 Incident Response Runbook is a concise operational document intended for use by on-call personnel during an active incident; its brevity shall not be construed as diminishing any obligation set out in this Policy.
This Policy shall apply to every security incident and Personal Data Breach affecting the Platform, the Marketplace, or the Company's corporate systems, including an incident originating at, or first reported by, a Hosting Provider, a Payment Partner, or a Delivery Partner.
Any employee, contractor, or automated monitoring system that identifies a suspected Security Incident shall report it immediately through the channel described in the RB-01 Runbook. The Incident Lead shall assess severity and scope without awaiting full confirmation.
A Security Incident confirmed as unauthorized access to production data, active ransomware, or an outage affecting a significant portion of the system shall be classified as Critical, and the Chief Information Security Officer and the Incident Lead shall be engaged within thirty minutes.
A suspected breach of personal or customer data, the compromise of a single system, or an incident reported by a Third Party affecting Company data, shall be classified as High and addressed within two hours.
A contained Security Incident with little or no evidence of data exposure shall be classified as Medium and addressed within one business day.
A policy violation with no indication of compromise shall be classified as Low and addressed within five business days.
Upon detection of a Security Incident, the Company shall contain the affected system while preserving the evidence required for investigation and, where applicable, regulatory notification.
Following containment, the Company shall eradicate the cause of the Security Incident and shall recover the affected service from a verified, restore-tested backup, confirming normal operation before the Security Incident is considered resolved.
Every Security Incident classified as Medium or above shall be subject to a post-incident review, the findings of which shall be recorded in the Risk Register.
Where a Security Incident constitutes a Personal Data Breach, the Company shall notify the Polish Data Protection Authority without undue delay and, where feasible, within seventy-two hours of Awareness, in accordance with Article 33 of the GDPR, and, where the Personal Data Breach is likely to result in a high risk to the rights and freedoms of the individuals concerned, shall notify those individuals without undue delay, in accordance with Article 34 of the GDPR.
Where the NIS2 Directive applies to the Company, an early warning shall be issued within twenty-four hours of Awareness, a fuller notification within seventy-two hours, and a final report within one month.
Where a product with digital elements operated by the Company falls within the scope of the Cyber Resilience Act, an early warning shall be issued within twenty-four hours, a full notification within seventy-two hours, and a final report within fourteen days for an actively exploited vulnerability, submitted through the applicable EU reporting platform.
Where a Security Incident originates at, or affects, a Payment Partner, a Delivery Partner, or a Hosting Provider, the Company's obligation to notify under Section 4.3 shall apply independently and shall not be discharged by the Third Party's notification to the Company or to its own regulator.
A Delivery Partner acting as an independent Controller in respect of recipient data shall be treated as such for these purposes, and its compliance with its own notification obligations shall not discharge the Company's separate obligation in respect of any processing of the Company's own affected by the same event.
Every Security Incident shall be recorded in the Company's incident register irrespective of its severity.
The Company shall exercise this Policy and the RB-01 Runbook through a tabletop exercise at least annually.
Compliance with this Policy shall be mandatory. The Chief Information Security Officer shall own this Policy and the incident response process, leading or overseeing the response to Critical and High-severity incidents and determining whether regulatory notification is required.
A delay in reporting a suspected Security Incident shall be treated as a distinct violation of this Policy, independent of the severity of the underlying incident.
There shall be no exception to the obligation to report a suspected Security Incident.
Any deviation from the notification periods in Section 4.3 shall be escalated immediately to the Chief Information Security Officer and to Legal, and shall be documented together with the reason for the deviation.
"Security Incident" means any event that has compromised, or plausibly could compromise, the confidentiality, integrity, or availability of an Information Asset.
"Personal Data Breach" means a personal data breach within the meaning of Article 4(12) of the GDPR.
"Awareness" means the point at which the Company has a reasonable degree of certainty that a Security Incident has occurred and may have compromised personal data, being the point from which the notification periods in Section 4.3 shall run.
"Incident Lead" means the individual coordinating the response to a specific Security Incident.
Version 1.0 — July 2026