Personal Data Protection Policy

I. CONTROLLER'S CONTACT DETAILS

1.1. S.C. COMSALES GRUP S.R.L. (hereinafter the Company), registered in the State Register of Legal Entities on 06.04.2006, state identification number 1006600016756, registered office: MD-2037, Chişinău, 5A Meșterul Manole str., office 105.

II. PRINCIPLES OF PERSONAL DATA PROCESSING

2.1. Personal data processed within the Company are handled in accordance with the applicable legislation and international standards governing the protection of personal data.

2.2. The processing of personal data within the Company is based on the following principles:

2.2.1. lawfulness, fairness and transparency — personal data are processed in good faith and in accordance with the applicable legal provisions, in a fair and transparent manner in relation to the data subject;

2.2.2. purpose limitation — personal data are collected for specified, explicit and legitimate purposes and are not further processed in a manner incompatible with those purposes;

2.2.3. data minimisation — personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;

2.2.4. accuracy — personal data are accurate and, where necessary, kept up to date; every reasonable step is taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;

2.2.5. storage limitation — personal data are kept only for as long as is necessary for the purposes for which they are processed; data may be stored for longer periods for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes, subject to the implementation of appropriate technical and organisational measures to safeguard the rights and freedoms of the data subject;

2.2.6. integrity and confidentiality — personal data are processed in a manner that ensures appropriate security, including appropriate technical or organisational measures ensuring adequate protection of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

III. LEGAL BASES FOR THE PROCESSING OF PERSONAL DATA

3.1. The legal bases for the processing of personal data within the Company are:

3.1.1. the legal obligations incumbent on the Company under the legislation on limited liability companies and the applicable legal framework;

3.1.2. performance of a contract to which the data subject is party, or steps taken at the data subject's request prior to entering into a contract;

3.1.3. the Company's legitimate interest, provided that such interest does not prejudice the interests or the fundamental rights and freedoms of the data subject;

3.1.4. the consent of the data subject (where applicable).

IV. HOW PERSONAL DATA ARE COLLECTED AND PROCESSED

4.1. The Company processes data provided directly by data subjects, as well as data subsequently generated on the basis thereof.

4.2. The Company processes personal data made public by the data subjects themselves, within the limits of the applicable legislation.

4.3. Personal data are processed manually, by automated means, or both.

V. PURPOSES OF PERSONAL DATA PROCESSING

5.1. Personal data are processed within the Company for the following purposes, as applicable:

5.1.1. concluding, performing and terminating contractual relationships with customers for the purpose of the Company providing services and products, as well as taking steps at Customers' request prior to entering into a contract;

5.1.2. concluding, carrying out and terminating contractual relationships with the Company for the purpose of the Company acquiring goods, services and works;

5.1.3. concluding, carrying out and terminating employment relationships with the Company, undertaking internships, providing recruitment assistance, career advancement, ensuring employee safety, monitoring the volume and quality of work duties performed;

5.1.4. participation in training sessions and webinars organised by the Company;

5.1.5. providing the Company's products/services, including online, to the Company's customers and other individuals who occasionally benefit from the services provided;

5.1.6. fulfilling legal obligations to provide information, including personal data, at the request of authorised public authorities, private-law entities, individuals, their representatives, and other applicants who, under the applicable legislation, are entitled to request the Company to provide information;

5.1.7. debt recovery, enforced collection of amounts owed to the Company, and administration of garnishments and seizures;

5.1.8. providing information/responses and handling requests/complaints/claims of any nature addressed to the Company by various persons, through any channel, including online chats;

5.1.9. monitoring, security and protection of persons, premises and property by means of video cameras installed at the Company's premises;

5.1.10. recording of communications through digital/analogue channels and of telephone calls and conversations, for the purpose of improving the efficiency and quality of the services provided to the customer, and for the proper conclusion and performance of contracts with customers;

5.1.11. carrying out direct marketing, using communication channels (e-mail, sms, instant messaging applications, chatbots), as well as by sending newsletters or other commercial communications, for the purpose of promoting the Company's products/services, contests and promotions organised by the Company and its partners, based on the data subject's consent, as well as other communications in the Company's legitimate interest;

5.1.12. verifying customer satisfaction and the quality of the services and products purchased, based on the Company's legitimate interest in continuously improving the products and services it provides;

5.1.13. other purposes related to the Company's business.

5.2. Personal data are processed within the Company only for the purposes stated and notified in accordance with the applicable legislation, without seeking to obtain information for purposes other than those listed.

5.3. The Company has implemented an automated customer support system on its website, as well as on the instant messaging applications Telegram and Viber, based on the use of an artificial intelligence solution that provides instant responses to customers' various questions. This system does not issue automated decisions concerning customers.

VI. DATA SUBJECTS

6.1. The processing of personal data within the Company concerns the following categories of persons:

6.1.1. the Company's employees and founders;

6.1.2. individuals who occasionally benefit from the services/products provided by the Company;

6.1.3. individual customers and prospective customers of the Company;

6.1.4. contact persons, legal or contractual representatives, employees or individuals designated by a customer of the Company, co-debtors, guarantors, ultimate beneficial owners, as well as their family members;

6.1.5. contact persons, legal or contractual representatives, employees or individuals designated by a contractual partner of the Company;

6.1.6. persons applying for a job with the Company, undertaking internships with the Company, or participating in training sessions;

6.1.7. persons visiting the Company's premises, production area or construction sites, where video surveillance cameras are installed, without the purpose of identifying the individual;

6.1.8. visitors to the Company's official web pages, including the Company's official social media pages and chatbots;

6.2. Data subjects are informed of the purpose and conditions of the processing of their personal data through appropriate notices in the forms presented to them within the scope of the services provided by the Company (applications/contracts/questionnaires/declarations), through the Company's website, and through other means of communication established by the Company.

VII. CATEGORIES OF PERSONAL DATA PROCESSED

7.1. Depending on the purpose of processing personal data and/or the nature of the contractual relationship with the Company (employee, customer, partner), and taking into account the specifics of the Company's activities, the following categories of personal data may be processed:

7.1.1. general identification data: surname, first name, patronymic and pseudonym (where applicable), date and place of birth, citizenship;

7.1.2. contact details: domicile and residence (where applicable), phone/fax number, e-mail address, including social media accounts within support/chatbot services, and in the case of participation in contests organised by the Company on social media;

7.1.3. data assigned by public authorities: personal identification number, series and number of the identity document;

7.1.4. professional data: profession, occupation, employer's name or nature of own activity;

7.1.5. data concerning family status: marital status, dependants;

7.1.6. electronic signature, handwritten signature;

7.1.7. image: photo (from the identity document provided) and video (recorded by video surveillance cameras installed at the Company's premises);

7.1.8. voice: recorded during telephone conversations with the Company's representatives;

7.1.9. health-related data in specific cases provided for by law;

7.1.10. technical data when using services provided online or when visiting the Company's website: IP address (Internet Protocol), browser type and version, operating system and platform, device type and mobile device brand, and other information contained in cookie files;

7.1.11. other data necessary for business purposes.

7.2. The Company avoids processing special categories of personal data (racial or ethnic origin, political or religious beliefs, health-related data or data concerning intimate life, as well as data concerning criminal convictions), except where:

7.2.1. processing is necessary for the fulfilment of obligations and the exercise of specific rights of the Company, to the extent authorised by the applicable legislation;

7.2.2. the processing concerns personal data which have been made public;

7.2.3. processing is necessary for the establishment or exercise of a right before a court;

7.2.4. processing is necessary for granting benefits to the Company's customers/employees.

7.3. Prior to the conclusion of a contract (with an employee, customer, business partner, etc.), during the pre-contractual stage, personal data may be processed in order to prepare offers or purchase orders, or to fulfil other requirements necessary for entering into the contract.

7.4. A data subject's refusal to provide the Company with the personal data necessary to carry out the proposed/requested activity may result in the Company being unable to provide its services and/or achieve its other processing purposes.

VIII. PERSONAL DATA RETENTION PERIOD

8.1. Personal data are processed within the Company for such periods as allow the identification of data subjects for no longer than is necessary to achieve the purposes for which they were collected and subsequently processed.

8.2. In addition, the Company is legally required to keep all documents and information necessary for compliance with due-diligence measures concerning customers and beneficial owners for a period of 5 years from the termination of the business relationship, including so that such documents and information may be provided, upon request, to the authorised bodies and/or used as evidence in court. As an exception, and only at the request of the Company's supervisory authorities, the retention period for certain types of information may be extended for a further period not exceeding 5 years.

8.3. Video footage obtained through video surveillance is stored for a period of 60 days. As an exception, the retention period may be extended where required/permitted by the applicable legislation. The Company may retain video recordings for an extended period on the basis of its legitimate interest, namely: defending the rights and interests of the company/data subject in court, interacting with public authorities, or initiating internal investigations.

8.4. Audio recordings (telephone conversations) may be retained for up to 3 years. The retention period for recordings is as required/permitted by the applicable legislation.

8.5. Upon expiry of the processing period, personal data are destroyed/deleted depending on the medium on which they were stored, with records of this fact being kept in accordance with internal regulations. Where expressly required by law, such data may be retained as archival documents in accordance with the rules of the State Archive Service.

IX. TRANSFER OF PERSONAL DATA

9.1. Information containing personal data is treated by the Company as confidential. Such information is not disclosed to third parties, except where the Company is legally required to provide such information to public authorities, supervisory or tax authorities and/or courts, or to other bodies authorised by law, in accordance with the applicable regulations.

9.2. The transfer of personal data to third parties is documented and subject to a prior thorough assessment of the purpose and legal basis for the intended disclosure of a given volume of personal data. Data may be transferred to third parties in the following cases:

9.2.1. to the Company's contractual partners authorised by the Company, to the extent and within the limits necessary to achieve the purposes for which the relevant data are processed;

9.2.2. to supervisory or tax authorities and/or courts, or to other bodies authorised by law, where the Company is required to provide such information in accordance with the applicable legislation. 9.3. The Company transfers personal data to delivery service providers where the customer has requested home delivery of a product.

9.4. The Company is entitled to transfer personal data to debt-collection companies, to companies to which the Company has outsourced certain services, and to other persons acting as the Company's authorised representatives, in accordance with instructions received from the Company.

9.5. When personal data are transferred to third parties, the recipient is notified of the requirement to process such data solely for specified purposes, through the corresponding notice included at the end of any document created and classified by the Company as Confidential; in the case of the Company's suppliers and business partners, instructions on how to process the data are provided and guarantees regarding the security of the transferred data are requested (contractual clauses, confidentiality agreements, industry certifications, etc.).

X. RIGHTS OF DATA SUBJECTS

10.1. Data subjects whose personal data are processed by the Company under the applicable legislation are entitled to the following rights:

10.1.1. to obtain, free of charge, information regarding their personal data processed by the Company, the purpose of processing, the categories of data concerned, and the recipients or categories of recipients to whom such data are disclosed, etc.;

10.1.2. to have free access to their personal data, including the right to obtain copies of such data, except in cases provided for by the applicable legislation;

10.1.3. the right to intervene regarding their personal data, comprising the right to rectify, update, block or erase personal data whose processing infringes the law, in particular due to the incomplete or inaccurate nature of the data;

10.1.4. the right to object at any time, free of charge, on grounds relating to their particular situation, to the processing of personal data concerning them, except where the law provides otherwise;

10.1.5. to lodge a complaint with the supervisory authority for personal data processing in the event of a breach of the applicable legislation on the protection of personal data;

10.1.6. the right to withdraw, at any time, consent previously given for the processing of personal data, without affecting the lawfulness of processing carried out before such withdrawal;

10.1.7. the right not to be subject to an individual decision, meaning the right to request the annulment, in whole or in part, of any individual decision producing legal effects on their rights and freedoms and based solely on automated processing of personal data intended to evaluate certain aspects of their personality;

10.1.8. the right to apply to a court for compensation for material/moral damage suffered as a result of unlawful processing of personal data;

10.1.9. other rights provided for by the legislation of the Republic of Moldova, as well as by applicable international regulations.

10.2. In order to exercise one or more rights regarding the processing of personal data, the data subject may submit a written and signed request/complaint at the Company's registered office in Chişinău, 5A Meșterul Manole str., office 105, or by e-mail to: protectia.datelor.csg@gmail.com. Any request submitted to the Company will be processed accordingly, in line with the procedure established within the Company.

XI. PERSONAL DATA PROTECTION MEASURES

11.1. The Company has implemented a comprehensive system of personal data security measures and continues to develop technical and organisational measures to ensure an adequate level of data protection.

11.2. Where a type of processing, in particular one based on the use of new technologies, is likely to result in a high risk to the rights and freedoms of data subjects, the Company carries out an assessment of the impact of the processing operations on the protection of personal data.

11.3. Before implementing automated solutions, new products and services involving the use of new technologies, including automated data processing, the Company's subdivisions carry out an assessment of the impact of the intended processing operations on the protection of personal data and seek the opinion of the person responsible for personal data protection.

11.4. The Company uses advanced security methods and technologies, together with strict policies applicable to employees and work procedures (including antivirus solutions, firewalls, and information encryption systems). All operational and data-processing systems run in secure environments, so that information is protected against unauthorised access. Access to the Company's information/systems is granted only to authorised persons and for clearly defined purposes, in strict accordance with internal security policies. Employees are trained on the importance of maintaining the confidentiality of information upon hiring, as well as subsequently through thematic training sessions.

11.5. Before being granted access to the personal data record-keeping system, the Company's employees are informed that the use of the system is monitored and that unauthorised processing of data is sanctioned in accordance with the applicable legislation.

11.6. Upon hiring, employees take part in initial training organised by the company. As part of this process, employees are informed about how personal data are processed within the Company, in accordance with the legal requirements in the field of personal data protection.

11.7. Identification and authentication of users accessing information in the personal data record-keeping system is carried out, along with the generation of security audit logs within the system, in accordance with the Company's internal regulations.

11.8. The administration of user access accounts to the personal data record-keeping systems is ensured through automated support tools, in accordance with the Company's internal regulations.

11.9. Where an employee's employment relationship with the Company has ended, been suspended or changed, and as a result the new duties no longer require access to personal data, as well as in the event of a change in the employee's access rights, or the employee's prolonged absence from the workplace (more than 2 months), the user's access to the system is revoked or suspended.

11.10. In order to detect and prevent cases of unauthorised access rights being granted, the persons responsible for the personal data record-keeping systems ensure a regular review, at least once a year and after any change in a user's status or an employee's position, of users' access rights to the relevant systems.

11.11. The premises where personal data are processed (where the components of the personal data record-keeping systems are located) are equipped with technical security measures ensuring the security of data media, restriction of access by unauthorised persons, and visual monitoring of persons having access to those premises. Access is restricted, being permitted only to persons holding the necessary authorisation and only during working hours.

11.12. Identification, recording and elimination of deficiencies in software used to process information within the personal data record-keeping systems is ensured, including the installation of patches and updates, and protection against malicious software (viruses).

11.13. Technologies and means for detecting unlawful access/intrusions are used, enabling the monitoring of events and the detection of attacks, including the detection of attempts at unauthorised use of information from the personal data record-keeping system.

11.14. Backup copies of personal data from the components related to the personal data record-keeping systems are created in accordance with internal regulations.