Exactflow Prosta Spółka Akcyjna • KRS 0001218490 • NIP 5342706763 • REGON 543770217
ul. Stanisława Bodycha 87, 05-816 Reguły, Poland
Effective Date: 15 July 2026
Version 1.0
The Company processes personal data belonging to its employees, the customers who use the Platform and their own end users, and the sellers and buyers who trade on the Marketplace. The Company does so in two distinct capacities recognised under the GDPR: as Controller, where it determines for itself why and how personal data is processed, and as Processor, where it carries out instructions given by a Platform customer that is itself the Controller.
The purpose of this Policy is to set out the Company's commitment to protecting personal data in accordance with the GDPR and applicable Polish implementing legislation, and to describe the principles, individual rights, and accountability measures applicable to every processing activity undertaken by the Company.
This Policy shall apply to all personal data processed by the Company in connection with the Platform and the Marketplace, including data relating to employees and job applicants, Platform customers and their own end users, Marketplace sellers and buyers, and any individual whose data is received from, or shared with, a Third Party.
Personal data shall be processed lawfully, fairly, and transparently. Personal data shall be collected only for specified, explicit, and legitimate purposes, and collection shall be limited to what is adequate, relevant, and necessary for those purposes.
Personal data shall be kept accurate and, where necessary, up to date, and shall not be retained for longer than necessary, in accordance with the Data Retention & Deletion Policy.
Personal data shall be processed with security appropriate to its sensitivity, in accordance with the Information Security Policy and its subordinate policies.
The Company shall be able to demonstrate compliance with the principles set out in this Section, in accordance with Article 5(2) of the GDPR.
Every processing activity undertaken by the Company shall have an identified lawful basis under Article 6 of the GDPR, recorded in the Company's Record of Processing Activities.
Order and payment processing on the Marketplace shall rely on the performance of a contract with the buyer or seller. Compliance with tax, accounting, and anti-money-laundering obligations shall rely on legal obligation. Fraud prevention, transaction monitoring, and security logging shall rely on the Company's legitimate interest, balanced against the interests and rights of the individuals concerned. Marketing communications shall rely on consent, capable of withdrawal at any time.
The Company shall not intentionally collect Special Category Data in the ordinary course of operating the Platform or the Marketplace, and Special Category Data received unintentionally shall be deleted without undue delay absent a specific, documented basis for retention.
A Data Subject in respect of whom the Company acts as Controller may exercise the rights set out in Chapter III of the GDPR, comprising the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object, and rights relating to automated decision-making.
A request shall be logged, the requester's identity verified, and any applicable ground for refusal or restriction assessed, and the Company shall act on the request within one month of receipt, extendable by a further two months for a complex request, with notice provided to the Data Subject.
An erasure request granted under this Section shall be actioned across primary systems and backups in accordance with the Data Retention & Deletion Policy.
Where the Company processes data as Processor on behalf of a Platform customer, a request received directly by the Company shall be redirected to that customer, and the Company shall provide reasonable assistance to that customer in responding.
The Company shall act as Controller in respect of its employees' personal data, Marketplace seller and buyer data collected directly through the Marketplace, and corporate marketing and website-analytics data, and shall act as Processor where it operates the Platform's order-management, customer relationship management, and warehouse management functions on behalf of a customer that itself determines the purposes and means of that processing.
The Company's Record of Processing Activities shall distinguish these roles for every processing activity, in accordance with Article 30(1) and Article 30(2) of the GDPR respectively, and shall be reviewed at least annually.
Privacy and security requirements shall be incorporated into the design of a new feature or system from inception, in accordance with Article 25 of the GDPR, as further provided in the Secure Development Policy.
Personal data shall be protected by the technical and organisational measures required under Article 32 of the GDPR, implemented through the Information Security Policy, the Access Control Policy, the Cryptography & Key Management Policy, and the Logging & Monitoring Policy.
A transfer of personal data to a recipient outside the European Economic Area shall be subject to an appropriate safeguard under Chapter V of the GDPR, confirmed before the transfer takes place.
Where the recipient is established in the United States and is certified thereunder, the Company may rely on the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses.
The due-diligence and transfer-mechanism confirmation applicable to a given Third Party shall be as set out in the Third-Party & Partner Risk Management Policy.
A Personal Data Breach shall be assessed and, where required, notified in accordance with the Incident Response & Breach Notification Policy and Articles 33 and 34 of the GDPR.
Where a new or changed processing activity is likely to result in a high risk to individuals, a Data Protection Impact Assessment shall be conducted before that processing begins, applying the risk-assessment methodology set out in the Risk Management Policy, in accordance with Article 35 of the GDPR.
No Data Protection Officer has been appointed as of the Effective Date of this Policy. Pending that appointment, the Chief Information Security Officer shall hold interim accountability for data protection compliance, including oversight of Data Protection Impact Assessments, breach-notification determinations, and the handling of Data Subject requests.
The Company shall review at least annually whether its processing activities warrant the appointment of a Data Protection Officer under Article 37 of the GDPR.
The Company's Record of Processing Activities, Legal & Regulatory Requirements Register, and Risk Register shall constitute its core accountability documentation under Article 5(2) of the GDPR.
Neither the Platform nor the Marketplace is directed at children, and neither is knowingly used by children. The Company shall not knowingly collect personal data from an individual below the age of digital consent under applicable Polish and EU law, and shall delete any such data without undue delay upon becoming aware of its collection.
Compliance with this Policy shall be mandatory. Every employee and contractor shall be responsible for handling personal data in accordance with this Policy and the Acceptable Use Policy, and a new processing activity, Third-Party relationship, or product feature involving personal data shall be assessed against this Policy before implementation.
An exception to this Policy shall be documented and approved in advance by the Chief Information Security Officer, in consultation with Legal where the exception concerns a matter of legal interpretation.
"Data Subject" means an identified or identifiable natural person whose personal data is processed.
"Special Category Data" means the special categories of personal data referred to in Article 9 of the GDPR.
"Data Protection Impact Assessment" means the assessment required under Article 35 of the GDPR for processing likely to result in a high risk to the rights and freedoms of natural persons.
"Data Protection Officer" means the officer to be appointed by the Company under Article 37 of the GDPR.
Version 1.0 — July 2026