Exhibit C
EXHIBIT C
SUPPLY WISDOM DATA PROCESSING POLICY
Effective Date: April 2026
1. DATA PROTECTION
1.1
For the purposes of this Data Processing Policy ("Policy") between Supply Wisdom and Customer ("Data Controller"), "Data Protection Legislation" means the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR as retained in UK law, the California Consumer Privacy Act ("CCPA") as applicable, and all other applicable laws and regulations relating to the processing of personal data and privacy, including guidance and codes of practice issued by any competent supervisory authority ("Data Protection Legislation").
1.2
Supply Wisdom and/or its affiliates ("Company") shall comply with all applicable Data Protection Legislation in relation to its obligations under this Policy as a Data Processor. For the purposes of this Policy, "Personal Data" shall have the meaning ascribed to it in the applicable Data Protection Legislation and shall relate to Personal Data processed by Company for or on behalf of Data Controller or any of its affiliates. "Data Controller" and "Data Processor" have the meanings as defined in the applicable Data Protection Legislation. This Policy is approved by the Chief Financial Officer (CFO), who acts in the capacity of Chief Privacy Officer (CPO) for Supply Wisdom. Ultimate governance authority for all data protection matters rests with the Chief Executive Officer (CEO).
1.3
The Exhibit to this Policy sets out the scope, nature and purpose of processing of Personal Data by Company under this Policy ("Data Protection Purpose"), including details as to the duration of the processing, the types of Personal Data which will be processed by Company and categories of Data Subject (where "Data Subject" has the meaning as defined in the applicable Data Protection Legislation). Any changes to the Data Protection Purpose must be agreed in writing between the Parties.
1.4
Data Controllers must ensure that they have all necessary appropriate consents and approvals in place to enable lawful transfer of the Personal Data to Company for the duration and purposes of this Policy.
1.5
Without prejudice to the generality of clause 1.2, Company shall, in relation to any Personal Data processed in connection with the performance of its obligations under this Policy:
process that Personal Data only in accordance with the Data Protection Purpose and the written instructions of Data Controller from time to time in accordance with this Policy, and for no other purpose unless the Company is required by applicable law to process Personal Data. Where Company is relying on applicable law as the basis for processing Personal Data, Company shall promptly notify Data Controller of this before performing the processing required by applicable law, unless those laws prohibit such notification;
not disclose the Personal Data or information extracted from the Personal Data to third parties without the prior written approval of Data Controller and ensure that all Company personnel who have access to and/or process Personal Data are appropriately trained in compliance with the Data Protection Legislation and are aware of, and obliged to adhere to, the requirements to keep the Personal Data confidential;
ensure that it has in place appropriate technical and organizational measures against unauthorized or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, as if it were the Data Controller in respect of that Personal Data, in compliance with the Data Protection Legislation, and shall provide Data Controller with any information which Data Controller reasonably requests in relation to the technical and organisational measures which it has implemented, and promptly comply with any requirements made by Data Controller to ensure that the technical and organisational measures comply with the Data Protection Legislation;
not use a sub-processor unless expressly approved by Data Controller in writing or otherwise for a legitimate purpose. Where a sub-processor is used, Company will ensure that all such sub-processors who have access to and/or process Personal Data are appropriately trained in compliance with the Data Protection Legislation and are aware of, and obliged to adhere to, the requirements to keep the Personal Data confidential. Company must, as a pre-requisite to, and as an ongoing condition for, any sub-processing of Personal Data, have a written agreement in place with the third-party processor, providing no less protection than afforded to Data Controller under this Policy;
assist Data Controller in responding to requests and/or complaints from any Data Subjects exercising their rights in relation to the Data Protection Legislation;
(assist Data Controller in complying with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
at the request of Data Controller, delete or return to Data Controller all Personal Data and copies thereof on termination of the relevant agreement between Company and the Data Controller (or at any time as requested by Data Controller) unless and to the extent storage is required of the Data Processor by any applicable law;
make available to Data Controller, or any third party duly nominated by Data Controller, all information necessary to demonstrate Company's compliance with the requirements of this Policy and allow and reasonably assist with audits reasonably requested by Data Controller in relation to ascertaining Company's compliance with this Policy;
not transfer any Personal Data outside of the European Economic Area without the prior written consent of Data Controller and/or in contravention of a legitimate purpose and where such consent is given by Data Controller and/or such legitimate purpose has been determined, Company will ensure that any such transfer is made in accordance with the requirements of applicable Data Protection Legislation, including through the use of EU Standard Contractual Clauses or other approved transfer mechanisms where required; and
immediately inform Data Controller if any of Data Controller's instructions to Company infringe the Data Protection Legislation.
1.6
Where Company becomes aware of a data security breach, or any other relevant incident that affects the security or integrity of Personal Data (a "Personal Data Breach"), Company shall:
inform Data Controller promptly, and in any event within 24 hours of becoming aware of the relevant Personal Data Breach;
provide to Data Controller all relevant information about the Personal Data Breach to assist any investigation by Data Controller and/or relevant regulator; and
take any reasonable steps requested by Data Controller and/or relevant regulator in order to contain and respond to the Personal Data Breach.
Exhibit to Data Processing Policy
1. Description of the Processing Activities — Data Subjects
Data Controller may submit personal data to Company which may include but is not limited to, personal data related to the following categories:
● its clients or customers; and
● its staff.
2. Categories of Data
The personal data transferred may include but is not limited to the categories of data set out below.
Personal Data
Name
Email Address
Phone number
Address
IP address – recorded in system request/access logs; not actively tracked or stored as a separate data collection activity; accessible to authorized technical personnel for security, troubleshooting, and operational purposes
Sensitive Personal Data
None
3. Processing Operations
The personal data transferred will be processed in accordance with the Policy and may be subject to the following processing activities:
storage and other processing necessary to provide and maintain the Services provided to the Data Controller;
to provide services and technical support to the Data Controller.






