Privacy
Policy

This Privacy Policy is issued by the companies of the Enolya group (Enolya Investments Sp. z o.o., Enolya Investments spółka z ograniczoną odpowiedzialnością Enolya 1 Alternatywna Spółka Inwestycyjna sp. k.a.) and is addressed to all users of our website https://www.enolya.pl/ (hereinafter: the “Website”), as well as clients, business partners, suppliers, service providers and their contact persons (collectively: the “Contractors”).

Definitions used in this Policy are explained in Section XIII below.

The purpose of this Policy is to provide information on how the personal data of Contractors who are natural persons — including sole proprietors — and contact persons obtained from any Contractors are processed by the Controller, including where such data is provided to the Controller in connection with cooperation or with the performance of agreements concluded between the Controller and its Contractors.

The Controller of your personal data, within the scope set out in Section II below, is:

Enolya Investments sp. z o.o., headquartered in Warsaw, Aleja Jana Pawła II 27, 00-867 Warsaw, entered into the register of entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw, under KRS no.: 0000898751, NIP: 9512519158, REGON: 388923505.

The Controller’s contact details are provided in Section XII below.

The Controller has determined that each company within the Controller’s group will process Personal Data only to the extent necessary and defined in Section II. All obligations related to joint controllership — including responding to data subjects’ requests, managing personal data breaches and notifying supervisory authorities or the affected individuals, as well as maintaining processing activity records — shall be performed by Enolya Investments. The Controller’s contact point is indicated in Section XII.

Notwithstanding the above arrangements, you may exercise your GDPR rights against any of the Controller’s companies.

This Policy may be amended or updated to reflect changes in the Controller’s personal data processing practices or changes in applicable law. We encourage you to read this Policy carefully and regularly review this page to stay informed about any updates.

II. Legal Bases and Purposes of Processing Contractors’ Personal Data

Collection of Personal Data

Personal data is collected directly from you or may be obtained from other entities — e.g., our Contractors who have provided your data in connection with the performance of agreements with the Controller, such as your employer, principal, or any entity you represent in dealings with the Controller. We may also obtain your Personal Data from publicly available social media (to the extent it is publicly visible) and from third parties (e.g., Contractors, financial intermediaries, law enforcement authorities, administrative bodies, courts, etc.).

We also collect your Personal Data during visits to our Website or when using any functionalities or resources made available on or through the Website.During your visit, no Personal Data will be stored by the Controller without your prior explicit consent. Temporary storage of log files and cookies facilitates the use of our Website. For this reason, you may be asked to grant your consent. Such consent is optional and does not affect access to the Website, although certain functionalities may be limited without it.

Legal Bases for Processing

- Depending on the circumstances, your Personal Data may be processed under one or more of the following GDPR legal bases:

• Contract performance / pre-contractual steps (Art. 6(1)(b) GDPR) — applies to data such as name, business name, address, NIP/REGON, bank account number, and email address, to conclude and perform agreements with the Controller.

• Legal obligation (Art. 6(1)(c) GDPR) — applies to personal data required for the Controller to comply with legal obligations related to the performance of an agreement.

• Legitimate interest (Art. 6(1)(f) GDPR) — applies to data such as name, surname, business address, phone number, or email address, insofar as necessary for cooperation, contract performance, communication, establishing or defending claims, or direct marketing of the Controller’s services.

• Special categories of personal data (Art. 9(2)(f) GDPR) and data relating to criminal convictions (Art. 10 GDPR) — processed only when necessary and legally permitted.

• Marketing activities — including direct marketing, distribution of commercial information, use of telecommunications devices (e.g., calls, SMS, email), and newsletter distribution under the Controller’s legitimate interests (Art. 6(1)(f) GDPR) or — where required — your consent (Art. 6(1)(a) GDPR).

• Technical data — such as device type, operating system, browser type and settings, IP address, language settings, session timestamps, and other technical communication data processed under the Controller’s legitimate interest in operating and securing the Website (Art. 6(1)(f) GDPR).

“Legitimate interest” includes: asserting or defending legal claims, direct marketing of the Controller’s services, newsletter distribution, providing services, and communicating with Contractors.


Special Categories of Data Some personal data is classified as “special category data” under GDPR and receives enhanced protection:

race;

political views,;

religion;

trade union membership;

sexual orientation;

health data;

genetic and biometric data;

criminal convictions.

The Controller may only process such data in very limited cases, when necessary and legally permitted.

Provision of Personal Data

Providing your Personal Data is voluntary, but refusal may prevent the Controller from entering into or performing an agreement, or may limit the scope of services provided to you.

III. Disclosure of Personal Data to Third Parties

The Controller may disclose Personal Data to:

• administrative or judicial authorities upon request;

• accountants, auditors, lawyers, PR agencies, IT specialists (subject to confidentiality obligations);

• third-party processors acting on behalf of the Controller;

• entities involved in establishing, exercising or defending legal claims;

• authorities responsible for preventing or prosecuting offences or protecting public safety;

• acquiring entities in the event of sale, reorganisation or liquidation.

The Website may contain plugins or content from third parties. If used, your Personal Data may be shared with such entities, including social media platforms. You should consult the third party’s privacy policy before using such plugins.

Any third-party processor engaged by the Controller will be contractually required to process Personal Data only per the Controller’s written instructions and to apply appropriate security measures.

IV. International Transfers of Personal Data

If Personal Data is transferred to third countries (outside the EEA or Switzerland) that do not offer adequate data protection, the Controller will use legally compliant safeguards, such as:

• EU Standard Contractual Clauses (SCCs);

• Privacy Shield certification (for eligible U.S. entities);

• transfers to countries recognised by the European Commission as ensuring adequate protection.

More details can be obtained via the contact information in Section XII.

V. Data Security

The Controller has implemented appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

Contractors are responsible for ensuring that Personal Data submitted to the Controller is transmitted securely.

VI. Data Accuracy

The Controller takes reasonable steps to ensure that:

• Personal Data is accurate and, where necessary, up to date;

• inaccurate Personal Data is corrected or erased without undue delay. The Controller may request confirmation of accuracy at any time.

VII. Data Minimisation

The Controller ensures that Personal Data is processed only to the extent necessary for the purposes outlined in this Policy.

VIII. Data Retention

Personal Data is retained only for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required by law. Data may be retained for the duration necessary to establish, exercise, or defend legal claims.

IX. Rights of Contractors

Under GDPR, Contractors have the right to:

• access their personal data;

• rectify inaccurate data;

• erase data (“right to be forgotten”);

• restrict processing;

• data portability;

• object to processing;

• not be subject to automated decision-making.

If processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

You may lodge a complaint with the Polish

Supervisory Authority (President of the Personal Data Protection Office).

To exercise your rights, contact us as specified in Section XII.

X. Cookies

Cookies are small files stored on your device when browsing the Website. They may record device information, browser details, preferences, and browsing activities. The Controller may process Personal Data through cookies in accordance with the Controller’s Cookies Policy.

XI. Newsletter

If you voluntarily consent to receiving the Controller’s newsletter, we may send electronic commercial communications for promotional and informational purposes.

Data provided for the newsletter will be used only for this purpose. You may unsubscribe at any time via the opt-out link or by contacting the Controller.

Data is stored only as long as the subscription remains active. The legal basis is your consent (Art. 6(1)(a) GDPR).

XII. Contact Details

For any questions, concerns or requests regarding this Policy or personal data processing, please contact:

Controller:

•Enolya Investments Sp. z o.o.

•Enolya Investments Sp. z o.o. Enolya 1 alternative investment company sp. k.a.

is Enolya Investments Sp. z o.o.

Address for all entities:

Aleja Jana Pawła II 27, 00-867 Warsaw,

odo@enolya.pl

Contact Point:

Enolya Investments Sp. z o.o.

Aleja Jana Pawła II 27, 00-867 Warsaw

odo@enolya.pl

XIII. Definitions

• Controller — the entity determining how and for what purpose Personal Data is processed and responsible for GDPR compliance.

• Personal Data — any information relating to an identified or identifiable natural person.

• Processing . — any operation performed on Personal Data (e.g., collection, storage, use, transmission, deletion).

• Processor — any entity processing Personal Data on behalf of the Controller (other than its employees)