Exactflow Prosta Spółka Akcyjna • KRS 0001218490 • NIP 5342706763 • REGON 543770217
ul. Stanisława Bodycha 87, 05-816 Reguły, Poland
Effective Date: 15 July 2026
Version 1.0
Exactflow Prosta Spółka Akcyjna (the "Company") operates the ExactFlow Platform, a software-as-a-service system providing order management, customer relationship management, and warehouse management functions to business customers, and the ExactFlow Marketplace (Exact Solution), on which business and consumer sellers offer goods for sale to buyers. In the course of operating these systems, the Company processes information belonging to its employees, its customers, and the sellers and buyers who transact on the Marketplace, and relies upon external parties, including Hosting Providers, Payment Partners, Delivery Partners, and Marketplace Channels, in doing so.
This Policy constitutes the apex instrument of the Company's Information Security Management System and shall govern the interpretation and application of every subordinate policy adopted by the Company in the field of information security.
The purpose of this Policy is to establish the Company's commitment to protecting the confidentiality, integrity, and availability of the information it processes, and to give effect to the Company's obligations under the General Data Protection Regulation, applicable Polish implementing legislation, and the contractual obligations owed to the Company's commercial partners. This Policy shall further serve as the foundation for the Company's pursuit of certification to ISO/IEC 27001:2022.
This Policy shall apply to all employees, contractors, and temporary staff of the Company, irrespective of their place of work; to all Information Assets created, received, stored, or otherwise processed by the Company; to every environment in which the Company's systems operate, including production, staging, development, and corporate environments; and to every Third Party engaged by the Company in connection with the Platform or the Marketplace, including Hosting Providers, Payment Partners, Delivery Partners, and Marketplace Channels. The specific requirements applicable to each category of Third Party are set out in the Third-Party & Partner Risk Management Policy.
The Company shall establish, resource, and review measurable information security objectives at least annually, and upon any material change to the business, its technology, or the regulatory environment in which it operates. The Company's information security objectives shall include, without limitation:
Protection of the personal data of sellers, buyers, and employees in a manner proportionate to its sensitivity, consistent with Article 5 and Article 32 of the GDPR.
Maintenance of the availability of customer-facing services consistent with the recovery objectives established under the Business Continuity & Disaster Recovery Plan.
Detection of, response to, and, where required, notification of security incidents and personal data breaches within the periods prescribed by the Incident Response & Breach Notification Policy, including the seventy-two-hour period prescribed by Article 33 of the GDPR.
Continued development of an Information Security Management System aligned with ISO/IEC 27001:2022, with certification as the intended outcome.
The Company shall act as Controller in respect of the personal data of its employees and of sellers and buyers with whom it deals directly on the Marketplace, and shall act as Processor in respect of personal data processed on the documented instructions of a Platform customer. The Company's lead supervisory authority for the purposes of the GDPR shall be the Polish Data Protection Authority (Urząd Ochrony Danych Osobowych), the Company's main establishment in the European Union being located in Poland.
The Company shall, to the extent applicable, comply with the risk-management and incident-reporting requirements of Directive (EU) 2022/2555 (the NIS2 Directive) and with the obligations imposed by Regulation (EU) 2024/2847 (the Cyber Resilience Act) in respect of products with digital elements. Where the Company deploys an artificial intelligence system, including a system that interacts directly with a natural person, the Company shall comply with the applicable transparency and risk-management obligations of Regulation (EU) 2024/1689 (the Artificial Intelligence Act).
A transfer of personal data to a recipient established outside the European Economic Area shall be subject to an appropriate safeguard under Chapter V of the GDPR, and no such transfer shall take place until that safeguard has been confirmed. The Company shall maintain a Legal & Regulatory Requirements Register recording the obligations applicable to it and the function accountable for demonstrating compliance.
Access to Information Assets shall be granted on the basis of least privilege and need-to-know, and shall be withdrawn once no longer required.
Security controls shall be applied in layers, such that the failure of a single control shall not result in the complete loss of protection of an Information Asset.
Privacy and security requirements shall be incorporated into the design of a new system or feature from inception, consistent with Article 25 of the GDPR.
Every Information Asset, identified risk, and control shall have a named, accountable owner.
Where the Company operates production infrastructure across more than one hosting environment, equivalent controls shall apply to each without exception, and a control implemented on one such environment only shall not be treated as implemented.
Top Management shall be accountable for the Information Security Management System and shall demonstrate that accountability by approving this Policy and ensuring it is adequately resourced.
The Chief Information Security Officer shall be responsible for the day-to-day operation of the Information Security Management System, including the maintenance of this Policy and its subordinate policies, the operation of the risk management process, the leadership of the response to significant incidents, and reporting to Top Management on the Company's security posture.
Pending the appointment of a Data Protection Officer under Article 37 of the GDPR, the Chief Information Security Officer shall act as the Company's interim point of contact for data protection matters.
Top Management, together with the Chief Information Security Officer, shall conduct a formal review of the Information Security Management System at least annually, and following any incident classified as Critical.
This Policy shall be implemented through the following subordinate policies: the Acceptable Use Policy, the Access Control Policy, the Cryptography & Key Management Policy, the Risk Management Policy, the Network Security & Firewall Policy, the Antivirus & Endpoint Protection Policy, the Incident Response & Breach Notification Policy, the Business Continuity & Disaster Recovery Plan, the Backup Policy, the Data Retention & Deletion Policy, the Data Classification Policy, the Personal Data Protection Policy, the Third-Party & Partner Risk Management Policy, the Secure Development Policy, the Vulnerability Management & Disclosure Policy, the Change Management Policy, the Logging & Monitoring Policy, the Physical & Environmental Security Policy, the HR Security & Confidentiality Policy, and the Security Awareness & Training Policy.
Compliance with this Policy shall be mandatory for every person and party within its scope. A breach of this Policy by an employee or contractor may result in disciplinary action up to and including termination of employment or engagement, and, where the breach involves unlawful conduct, referral to the competent authorities.
A breach of this Policy by a Third Party may result in the suspension or termination of the commercial relationship, without prejudice to any other remedy available to the Company.
The Chief Information Security Officer shall measure compliance with this Policy through internal audit, the annual management review, and the metrics reported under each subordinate policy.
Any exception to a specific requirement of this Policy shall be documented, time-limited, and approved in advance by the Chief Information Security Officer. A person proceeding without such approval shall be treated as non-compliant with this Policy irrespective of the underlying justification.
"Company" means Exact Flow Prosta Spółka Akcyjna.
"Platform" means the ExactFlow software-as-a-service system, comprising order management, customer relationship management, and warehouse management functions provided to business customers.
"Marketplace" means the ExactFlow Marketplace, on which business and consumer sellers offer goods for sale to buyers.
"Information Asset" means any data, system, application, device, or document that has value to the Company and accordingly requires protection.
"Information Security Management System" means the system of policy, risk assessment, control, and continual improvement by which the Company manages information security risk, established with reference to ISO/IEC 27001:2022.
"Controller" means a controller within the meaning of Article 4(7) of the GDPR.
"Processor" means a processor within the meaning of Article 4(8) of the GDPR.
"Third Party" means any natural or legal person, other than an employee, contractor, or temporary staff member of the Company, that accesses, stores, or processes Company or customer information in connection with the Platform or the Marketplace.
"Hosting Provider" means a Third Party that provides cloud infrastructure on which the Company operates production systems.
"Payment Partner" means a Third Party that processes payment transactions on behalf of the Company.
"Delivery Partner" means a Third Party that provides delivery or logistics services in connection with the fulfilment of orders placed through the Platform or the Marketplace.
"Marketplace Channel" means an external sales or marketplace channel with which the Marketplace is integrated.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"Top Management" means the person or body that directs and controls the Company at the highest level.
Version 1.0 — July 2026