Kagan Logo
logo

APPROVED by Order of the General Director of LLC "Royal Pure Gold" No. 60 dated June 3, 2024 Version: No. 001 Kagan Invest dated April 1, 2026

PRIVACY POLICY (PERSONAL DATA POLICY) LLC "ROYAL PURE GOLD"

Bishkek

TABLE OF CONTENTS

CHAPTER 1.GENERAL PROVISIONS
CHAPTER 2.TERMS AND DEFINITIONS
CHAPTER 3.SUBJECT OF REGULATION
CHAPTER 4.PRINCIPLES FOR PROCESSING USER PERSONAL DATA
CHAPTER 5.PURPOSES OF COLLECTING PERSONAL DATA
CHAPTER 6.PROVISION OF PERSONAL DATA TO THIRD PARTIES
CHAPTER 7.LIST AND CATEGORIES OF USER PERSONAL DATA PROCESSED
CHAPTER 8.OBLIGATIONS OF PARTIES
CHAPTER 9.STORAGE OF PERSONAL DATA
CHAPTER 10.PERSONAL DATA SECURITY
CHAPTER 11.LIABILITY OF PARTIES
CHAPTER 12.DISPUTE RESOLUTION
CHAPTER 13.MISCELLANEOUS

CHAPTER 1. GENERAL PROVISIONS

1.1. The operator/provider of the digital service and owner of personal records is LLC “Royal Pure Gold” (hereinafter referred to as the “Company”). 1.2. This Privacy Policy (hereinafter referred to as the “Policy”) has been developed in accordance with the Digital Code of the Kyrgyz Republic, the requirements for ensuring security and protecting personal data approved by Resolution No. 760 of the Government of the Kyrgyz Republic dated November 21, 2017, and other applicable regulatory legal acts of the Kyrgyz Republic. In cases where particular processing operations require a Data Protection Impact Assessment (DPIA), the Company follows the lists approved by the authorized personal data authority. 1.3. This Policy is aimed at ensuring the protection of the rights and freedoms of the personal data subject when processing his/her personal data and applies to all operations involving personal data performed by the Company, whether automated or non-automated. 1.4. This Policy is intended to ensure and guarantee that all Users are informed about what personal data concerning Users and visitors is collected by the Company, how such data is collected, and for what purposes. 1.5. This Policy is an integral part of the Public Offer for the conclusion of a brokerage service agreement and use of the Kagan Invest platform (hereinafter referred to as the “Offer”). 1.6. This Policy applies to all information that Users transfer to the Company. 1.7. The Company processes personal data on the legal grounds provided for by the legislation of the Kyrgyz Republic, including the consent of the personal data subject where required, performance of a contract, taking steps at the request of the subject before entering into a contract, compliance with a legal obligation of the Company, and other grounds provided by law. 1.8. The consent of the personal data subject is executed in cases where the relevant processing cannot be justified by another lawful ground and is provided in a manner that enables confirmation of the subject’s expression of will. 1.9. This Policy applies only to the Company’s Website and Platform. The Company does not control and is not responsible for third-party websites that the User may access through links available on the Company’s website. 1.10. The Company does not verify the accuracy of personal data provided by the User; however, the Company assumes that the User provides accurate and sufficient personal data and keeps it up to date.

CHAPTER 2. TERMS AND DEFINITIONS

2.1. The following terms are used in this Policy: 2.1.1. Automated processing of personal data means processing of personal data (personal records) performed using computer equipment, software, and information systems. 2.1.2. Owner of personal records means the entity that determines the purposes and methods of personal data processing (for the purposes of this Policy, the Company). 2.1.3. “Authorized employees of the Company” means employees and representatives of the Company who, within the scope of their official duties, are granted access to personal data and act on behalf of the Company when organizing and carrying out personal data processing. 2.1.4. Processor means an entity that is entrusted, under an agreement/legal act, with processing records, operating systems, or providing services. 2.1.5. Personal information (personal data) means any information relating to a directly or indirectly identified or identifiable individual (personal data subject / data principal). 2.1.6. Personal records means digital records containing personal information. 2.1.7. “Processing of personal data” means any action (operation) or set of actions involving personal data / personal records, performed with or without automation tools, including collection, recording, systematization, accumulation, storage, clarification, retrieval, use, transfer, depersonalization, blocking, restriction, deletion, and destruction. 2.1.8. “Confidentiality of personal data” means the mandatory requirement for the Company or any other person who has obtained access to personal data not to allow its dissemination without the consent of the personal data subject or another lawful ground. 2.1.9. Collection of personal data means the Company’s receipt of personal data from the personal data subject, his/her representative, or other sources on lawful grounds. 2.1.10. Transfer of personal data means provision of personal data by the holder (possessor) of personal data to third parties in accordance with the Digital Code of the Kyrgyz Republic. 2.1.11. Cross-border transfer of personal data means transfer by the holder (possessor) of personal data to holders located under the jurisdiction of other states. 2.1.12. Blocking of personal data means temporary suspension of personal data processing, except for actions necessary for storage, verification of the lawfulness of processing, or compliance with legal requirements. 2.1.13. Destruction (erasure or demolition) of personal data means actions by the holder (possessor) of personal data to bring such data into a state that does not allow restoration of its content. 2.1.14. Automated decision means a decision made on the basis of digital data without human involvement that creates, changes, or terminates legal relations. 2.1.15. Incident in the digital environment means an event/action resulting in incompleteness, inaccuracy, or unavailability of records or disruption of the functioning of a service/system. 2.1.16. Personal data leak means unlawful processing in which personal data becomes available to persons who have no lawful basis for access. 2.1.17. Users means an individual using the Company’s Platform or Website. If the Platform functionality provides for acting on behalf of a legal entity, personal data is processed in relation to representatives, employees, beneficiaries, and other identifiable individuals connected with such legal entity. 2.1.18. Identification means establishing information about a client, his/her representative, beneficiary, and beneficial owner, and confirming the accuracy of such information in accordance with the requirements of the legislation of the Kyrgyz Republic, including AML/CFT requirements, and the Company’s internal documents. 2.1.19. “Cookies” means a small piece of data sent by a web server and stored on a user’s computer, which a web user or web browser sends back to the web server in an HTTP request whenever attempting to open a page of the relevant website. 2.1.20. “IP address” means a unique network address of a node in a computer network built using the IP protocol. 2.1.21. Platform means a set of graphic and informational materials, as well as computer programs and databases, ensuring their availability on the Internet at the network address [https://kaganinvest.com](https://kaganinvest.com) 2.2. This Policy also uses terms in accordance with the Offer, the Company’s internal documents, and the current legislation of the Kyrgyz Republic.

CHAPTER 3. SUBJECT OF REGULATION

3.1. The Company processes the User’s personal data on the legal grounds provided by the legislation of the Kyrgyz Republic, including performance of a contract, taking steps at the User’s request before entering into a contract, fulfillment of duties imposed on the Company by the legislation of the Kyrgyz Republic, and the consent of the personal data subject in cases where such consent is required. The User’s provision of personal data through the functionality of the Platform or Website, as well as actions to register, submit an application, send a request, undergo identification, use the Company’s services, or otherwise interact with the Company, means that such data is processed on the terms set forth in this Policy, the Company’s user documents, and the relevant legal ground for processing. If separate consent is required for a specific type of processing, it is requested by the Company in a form that enables confirmation of the personal data subject’s expression of will. 3.1.1. Legal grounds may include: - the consent of the personal data subject, in cases where such consent is required by the legislation of the Kyrgyz Republic; - the necessity of processing for the conclusion, performance, amendment, or termination of a contract to which the personal data subject is a party, or for taking steps at his/her request before entering into a contract; - the necessity of processing to fulfill obligations imposed on the Company by the legislation of the Kyrgyz Republic; - the necessity of processing to protect the rights and legitimate interests of the Company or third parties, provided that the rights and freedoms of the personal data subject are not violated; - other grounds directly provided by the legislation of the Kyrgyz Republic. 3.1.2. The Company determines the applicable legal ground for processing taking into account the processing purpose, the category of personal data, the category of the personal data subject, and the nature of the relationship between the subject and the Company. 3.1.3. If personal data is processed on the basis of consent, such consent must be specific, informed, conscious, and provided in a manner that enables confirmation of the personal data subject’s expression of will. 3.1.4. If personal data processing may be justified by another legal ground provided by the legislation of the Kyrgyz Republic, the consent of the personal data subject does not replace such ground and is not used as a universal ground for all types of processing. 3.2. The Company protects data that is automatically transmitted when viewing advertising blocks and visiting pages on which a statistical system script (“pixel”) is installed: - IP address; - information from cookies; - information about the browser or other program used to access advertising display; - access time; - the address of the page on which the advertising block is located; - referrer (address of the previous page). 3.3. Disabling cookies may make it impossible to access parts of the Company’s website that require authorization. The Company processes personal data of the following categories: individuals who are employees of the Company and their close relatives; individuals performing work and providing services who have entered into a civil-law contract with the Company; individuals who are clients of the Company; individuals who intend to purchase the Company’s services or third-party services through the Company; individuals who are not clients of the Company and who have entered into or intend to enter into contractual relations with the Company in connection with the Company’s business activities. 3.4. The Company uses cookies and similar technologies for operation of the Platform. Some of these files are mandatory because, without them, it is impossible to ensure account login, correct operation of basic functions, user security, and service stability. The Company may also use additional cookies and analytics or marketing tools, but only where there is an appropriate legal ground, generally the user’s consent. The User may refuse the use of non-essential cookies, and this must not prevent use of the core functions of the Platform, except where particular technical elements are objectively necessary for protection, security, or stable operation of the service.

CHAPTER 4. PRINCIPLES OF PROCESSING PERSONAL DATA OF USERS

4.1. The Company ensures the confidentiality protection regime for personal data provided by the User when registering on the Platform or Website, regardless of the methods or means of collecting such data, taking into account the following principles of processing: 4.1.1. Lawful, fair, and transparent collection and processing. Personal data is processed on the appropriate legal ground provided by the legislation of the Kyrgyz Republic. The consent of the personal data subject is used only where the processing cannot be justified by another lawful ground. Personal data must be accurate, reliable, complete, and up to date for the achievement of the purposes of processing. The Company takes measures to ensure the accuracy of processed personal data. At the User’s request, personal data that is inaccurate must be deleted or corrected. Where necessary, the Company will take measures to change or delete incorrect or incomplete data. 4.1.2. Collection and processing for specific, pre-declared lawful purposes. Processing of the User’s personal data, including the scope and content of data collected, must be adequate (proportionate) and relevant to the declared purposes and must ensure, at all stages of such processing, a fair balance of the interests of all interested parties. The Company strives to collect the minimum amount of information necessary to perform the relevant task. 4.1.3. Storage no longer than required by the purposes. Users’ personal data is stored for the period necessary to achieve the declared purposes. If the use of stored data is no longer necessary, the Company will take measures to destroy or cease processing Users’ personal data within reasonable time limits, taking into account functional and legal requirements relating to storage and confidentiality of personal data. 4.1.4. Integrity and confidentiality. Personal data must be processed in a manner ensuring its security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

CHAPTER 5. PURPOSES OF COLLECTING PERSONAL DATA

5.1. The Company processes the User’s personal data solely to the extent necessary to achieve lawful, specific, and pre-determined purposes, on the grounds and in the manner provided by the legislation of the Kyrgyz Republic and this Policy. The Company may use the User’s personal data for the following purposes: 5.1.1. establishing identity, conducting verification, authentication, and identification of Users, including for compliance with regulatory requirements relating to countering the financing of terrorist activities and legalization (laundering) of criminal proceeds; 5.1.2. providing Users with access to the Platform, provided services, and rendered services; 5.1.3. providing access to Users’ account/personal cabinet; 5.1.4. concluding, performing, amending, and terminating any civil-law contracts between the User and the Company; 5.1.5. offering the User financial products (financial services) of financial organizations; transferring the User’s data to financial organizations for the purpose of reviewing the User’s applications and requests; interacting with Users for the execution and performance of transactions and the provision of services; 5.1.6. establishing feedback with the User, including sending notifications and requests relating to use of the Platform or Website, and processing requests and applications from the User; 5.1.7. determining the User’s location to ensure security and prevent fraud; confirming the accuracy and completeness of personal data provided by the User; 5.1.8. providing the User with effective customer and technical support when problems arise in connection with use of the Platform or Website; 5.1.9. notifying the User about events, conducting advertising activities with the User’s consent; improving and developing services; providing personalized recommendations and offers, personalized content, and for commercial (advertising and marketing) purposes; 5.1.10. providing the User with access to websites or services of the Company’s partners in order to receive updates and services; 5.1.11. preparing responses as part of implementation of the Law of the Kyrgyz Republic “On the Procedure for Considering Citizens’ Appeals”; 5.1.12. maintaining records management in accordance with regulatory legal acts; 5.1.13. maintaining personnel records and accounting for the Company’s employees and interns in the manner established by regulatory legal acts. 5.2. The Company stores information provided by Users when contacting support or other Company services in order to be able to contact Users and respond to their inquiries. The Company stores all comments and suggestions sent by Users to the Company because they help improve the services provided. 5.3. From time to time, the Company may send Users marketing letters (mailings) by email or through other channels, for example, social networks, unless the User has opted out of receiving such mailings. Such mailings may contain information about special offers from third parties. 5.4. The Company uses Users’ personal data to provide personalized services corresponding to the User’s needs and interests, and to improve the interface of the Platform or Website. 5.5. The Company uses technical information and information about Users’ activity to limit various types of abuse of services and criminal activity on the Platform or Website. Abuse of services includes fraud, spam mailings, phishing, offers of an intimate nature, attempts to log in using other persons’ accounts (profiles), and other actions prohibited by law. 5.6. The Company collects and processes the User’s personal data to comply with legal requirements, including legislation on countering the financing of criminal activity and legalization (laundering) of criminal proceeds. In cases specified by law, the Company has the right to provide the User’s personal data to authorized persons.

CHAPTER 6. PROVISION OF PERSONAL DATA TO THIRD PARTIES

6.1. The Company provides personal data to third parties only where there is a legal ground, to the extent necessary to achieve the relevant processing purpose, and subject to compliance with the requirements of the legislation of the Kyrgyz Republic. 6.2. Personal data may be provided to authorized state bodies of the Kyrgyz Republic exclusively in the cases, on the grounds, and in the manner provided by the legislation of the Kyrgyz Republic. 6.3. The Company has the right to provide personal data to the Company’s partners where such provision is necessary to provide services to the User, fulfill the User’s request, enable the User’s participation in a partner program, or in other cases expressly provided by the agreement with the User, this Policy, or the User’s consent, if such consent is required. 6.4. The Company has the right to provide personal data to persons engaged by the Company to support operation of the Website or Platform, including but not limited to providers of technical infrastructure, hosting, cloud solutions, communication tools, technical support services, analytics, information security, identification, verification, AML/KYT monitoring, and payment and settlement services, provided that such persons process personal data on the basis of an agreement with the Company and undertake to maintain the confidentiality and security of personal data. 6.5. The Company has the right to provide personal data to banks, payment organizations, financial organizations, payment infrastructure providers, and other settlement participants to the extent necessary to conduct payments, execute financial transactions, refunds, settlements, identification, and comply with mandatory legal requirements. 6.6. In the event of unlawful transfer, loss, leakage, unauthorized access, or another incident affecting personal data, the Company acts in the manner established by Chapter 10 of this Policy and the Company’s internal documents. 6.7. The Company ensures that any third parties that obtain access to personal data process such data solely for pre-determined purposes, in the minimum necessary scope, and do not use it for their own purposes unless otherwise expressly provided by the legislation of the Kyrgyz Republic or a separate legal ground for processing. 6.8. If personal data processing is entrusted to a third party, the Company enters into an agreement or other binding document with such person, providing for the processing purpose, categories of data, categories of subjects, permitted operations, processing periods, confidentiality and security requirements, prohibition on using data for the processor’s own purposes, rules for engaging subprocessors, the duty to assist the Company in handling requests of personal data subjects, investigating incidents and interacting with authorized bodies, as well as the procedure for returning, deleting, or depersonalizing data upon completion of the assignment. 6.8.1. Engagement of a subprocessor is permitted only where there is a legal ground provided in the agreement, subject to the Company’s prior written authorization and provided that such subprocessor is subject to personal data protection requirements no lower than those established for the principal processor. 6.8.2. Where the Company jointly determines the purposes and means of personal data processing with another person, the parties determine the allocation of responsibilities for compliance with the legislation of the Kyrgyz Republic, including responsibilities for informing personal data subjects, ensuring the exercise of their rights, ensuring data security, and interacting with authorized bodies. If necessary, the Company discloses the main terms of such allocation in this Policy, special notices, or other user documents. 6.9. The Company does not sell or disclose Users’ personal data to third parties for purposes incompatible with the purposes specified in this Policy, unless otherwise provided by the legislation of the Kyrgyz Republic or by the User’s separate duly obtained consent. 6.10. Cross-border transfer of personal data is carried out by the Company only where there is a legal ground and in compliance with the requirements of the legislation of the Kyrgyz Republic. Before commencing such transfer, the Company takes reasonable measures to assess the lawfulness of the transfer, the status of the recipient state, applicable guarantees of personal data protection, and the permissibility of such transfer for the relevant processing purpose. For the purposes of this Policy, cross-border transfer also includes remote access to personal data from a foreign state if such access is granted to a processor, provider, or other recipient located under the jurisdiction of that state. 6.11. Where personal data is transferred to a foreign state that does not ensure proper protection of the rights of personal data subjects, such transfer is carried out only where there is a ground provided by law, including the consent of the personal data subject, the necessity of performing a contract, protection of the vital interests of the subject, or other cases directly permitted by the legislation of the Kyrgyz Republic. 6.12. The User or his/her legal representative may at any time change (update, supplement) the personal data provided by him/her or part of it by using the personal data editing function in the personal section of the Platform or Website or by sending the Company the relevant request. 6.13. Consent to personal data processing, if required and provided by the personal data subject, may be withdrawn at any time in a manner no more burdensome than the manner of granting it, including through profile (personal cabinet) settings, by email to the Company, through a feedback form on the Platform or Website, or by another method indicated by the Company when obtaining consent. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal and does not terminate processing carried out on other legal grounds provided by the legislation of the Kyrgyz Republic. 6.14. If the User withdraws consent to personal data processing or requests deletion, blocking, restriction of processing, or objects to processing, the Company ceases the transfer of personal data to third parties to the extent that such transfer no longer has a legal ground, except where further processing and transfer are permitted or required by the legislation of the Kyrgyz Republic. 6.15. The Company will not use, sell, transfer, or disclose Users’ personal data in any other manner or for any other purposes not specified in this Policy, unless provided by a court decision or upon receipt of prior explicit consent to do so. 6.16. If personal data is transferred to third parties in connection with the provision of services to the Company under an agreement, such third parties will be required to process the data confidentially and not use that information for any other purposes. 6.17. Upon a written request of the personal data subject, the Company must provide information on its personal data processing, reflecting the following information: - confirmation of the fact of personal data processing; - legal grounds and purposes of personal data processing; - purposes and methods of personal data processing applied by the Company; - processed personal data relating to the respective personal data subject and the source of its receipt; - periods of personal data processing, including storage periods; - information about any completed or contemplated cross-border data transfer; - other information provided by law. 6.18. If the User does not have access rights to the requested information, a reasoned refusal is sent to him/her. 6.19. Upon achievement of processing purposes, expiration of storage periods, or absence of other lawful grounds for further processing, personal data transferred to third parties must be deleted, destroyed, returned to the Company, or depersonalized in the manner provided by the agreement, the legislation of the Kyrgyz Republic, and the Company’s internal documents.

CHAPTER 7. LIST AND CATEGORIES OF USER PERSONAL DATA PROCESSED

7.1. The list and scope of personal data processed depend on the nature of the User’s relationship with the Company, the functions and services of the Platform or Website used by the User, the purposes of processing, the legal ground for processing, and the requirements of the legislation of the Kyrgyz Republic. The Company processes only personal data that is necessary and sufficient to achieve specific, pre-determined, and lawful processing purposes. 7.2. The Company may collect and process the following categories of personal data concerning Users when using the Website or Platform: 7.2.1. Registration and contact details of the User provided when creating an account, using the personal cabinet, submitting applications and requests, and otherwise interacting with the Company, including surname, first name, patronymic, telephone number, email address, registration and/or residence address, and other information necessary to identify the User, contact him/her, and provide access to the Company’s services. 7.2.2. Identification, verification, and compliance data processed for accepting the User for service, conducting identification and verification, and complying with the requirements of the legislation of the Kyrgyz Republic, including requirements on countering the financing of criminal activity and legalization (laundering) of criminal proceeds. Such data may include date and place of birth, gender, citizenship, residency information, residence and registration address, identity document details, identification number, and other information provided by law, the Company’s internal documents, and Appendix No. 1. 7.2.3. Depending on the type of obligations under the transaction, information requested or received by the Company in preparation for and/or during the User’s execution of certain financial transactions and/or other operations, whether using or not using the Website or Platform, is additionally provided and processed: - information specified by the User in questionnaires and/or other forms completed on the Website or Platform, including but not limited to using the Personal Cabinet; information about documents transferred by the User that contain personal data, including in image format; * information obtained from the Internet and/or other publicly available sources of personal data; - other personal data whose processing is necessary for the purposes specified in this Policy; - images of the User, including photographs and video recordings of the User himself/herself and photographs of the User’s passport or other identity document; - other information about the User necessary for processing in accordance with the Company’s internal documents governing the relevant type of activity. 7.3. The specific list of personal data, categories of personal data subjects, processing purposes, legal grounds, storage periods, and categories of recipients may be clarified in separate consents, agreements, user documents, data collection forms, notices, and Appendix A to this Policy. 7.4. The Company may process personal data of the following categories of subjects: - users and clients of the Platform and Website; - representatives, employees, and beneficiaries of legal-entity clients; - employees, candidates, interns, and contractors of the Company; - counterparties and other individuals interacting with the Company. 7.5. Processing of special categories of personal data 7.5.1. The Company does not process special categories of personal data unless otherwise expressly permitted by the legislation of the Kyrgyz Republic and required to achieve a lawful and pre-determined processing purpose. 7.5.2. Special categories of personal data include data for which the legislation of the Kyrgyz Republic establishes an enhanced protection regime, including biometric data and other categories of data whose processing may create an increased risk to the rights and legitimate interests of the personal data subject. 7.5.3. Processing of special categories of personal data is permitted only where there is a legal ground provided by the legislation of the Kyrgyz Republic, in the minimum necessary scope, with enhanced organizational and technical protection measures, access restrictions, and, where necessary, a Data Protection Impact Assessment (DPIA). 7.5.4. If special categories of personal data are used for statistical, research, or analytical purposes, such processing is carried out only where there is an appropriate legal ground and, as a rule, in depersonalized form unless otherwise expressly permitted by the legislation of the Kyrgyz Republic. 7.6. Processing of children’s personal data 7.6.1. The Company’s Platform and Website are not intended for independent use by children unless otherwise expressly indicated by the Company in relation to a specific service or function. 7.6.2. The Company does not knowingly collect children’s personal data without a legal ground provided by the legislation of the Kyrgyz Republic and, where required, without the consent of a legal representative. 7.6.3. If the Company determines that a child’s personal data was obtained without a proper legal ground or without the required involvement of a legal representative, the Company takes measures to cease such processing and delete or block the data in the manner provided by the legislation of the Kyrgyz Republic. 7.6.4. Where processing of children’s personal data is permitted by the legislation of the Kyrgyz Republic, the Company applies additional protection measures, takes into account the child’s age and capacity, and ensures that information is provided in an accessible and understandable form. 7.7. The full list of categories of personal data, processing purposes, legal grounds, storage periods, and categories of recipients is disclosed in Appendix A to this Policy.

CHAPTER 8. OBLIGATIONS OF THE PARTIES

8.1. The User has the right to: 8.1.1. receive information about the processing of his/her personal data, confirmation of the fact of such processing, access to personal data, and, in cases provided by the legislation of the Kyrgyz Republic, a copy of personal data or a record containing his/her personal data; 8.1.2. request clarification, correction, supplementation, blocking, restriction of processing, or deletion of his/her personal data if such data is incomplete, outdated, inaccurate, unlawfully obtained, excessive, or not required for the declared processing purpose; 8.1.3. apply for protection of his/her rights to the authorized state body for personal data, as well as to a court and other bodies in the manner provided by the legislation of the Kyrgyz Republic; 8.1.4. exercise other rights of a personal data subject provided by the legislation of the Kyrgyz Republic, including the right to data portability, the right to object to processing, the right to restriction of processing, and the right to request review of an automated decision with human involvement in cases provided by law; 8.1.5. receive from the Company information about the processing of his/her personal data, including: confirmation of the fact of processing; legal grounds and purposes of processing; information about the Company as the owner of personal records and, if applicable, processing locations; contact details of the responsible person, if such person has been appointed; categories of recipients or recipients of personal data; processing and storage periods or criteria for determining them; information about the rights of the personal data subject and the consequences of refusing to provide data; information about automated decisions, including the fact of their use, general logic, significance, and expected consequences for the subject, if such decisions are used; 8.1.6. object to personal data processing in whole or in relation to particular purposes, methods of processing, automated decisions, or individual processing operations if such processing violates his/her rights and legitimate interests or is carried out in cases provided by the legislation of the Kyrgyz Republic. 8.2. The User must: 8.2.1. provide the Company with accurate personal data to the extent necessary for use of the Website, Platform, services, and compliance with the requirements of the legislation of the Kyrgyz Republic; 8.2.2. timely inform the Company of changes to his/her personal data if such data is relevant to the provision of services, contract performance, identification, or compliance with legal requirements; 8.2.3. provide documents containing personal data to the extent necessary for the processing purpose; 8.2.4. be responsible for the relevance and accuracy of personal data provided to the Company to the extent such responsibility is provided by law and the nature of the service rendered. 8.3. The Company must: 8.3.1. obtain personal data directly from the personal data subject, his/her representative, or other lawful sources in cases provided by the legislation of the Kyrgyz Republic; 8.3.2. use personal data exclusively for the purposes specified in this Policy, the agreement, the subject’s consent, or the legislation of the Kyrgyz Republic; 8.3.3. ensure that confidential information is kept secret, not disclose it without the User’s prior written authorization, and not sell, exchange, publish, or otherwise disclose the User’s transferred personal data by any possible means; 8.3.4. take precautions to protect the confidentiality of the User’s personal data in accordance with the procedure generally used to protect such information in existing business practice; 8.3.5. ensure the preservation and accuracy of personal data, as well as the access regime established by regulation; 8.3.6. provide information and access to personal data at the request of the personal data subject no later than 7 business days from the date of receipt of the request, unless another period is established by the legislation of the Kyrgyz Republic; 8.3.7. in case of refusal to provide the subject, upon his/her request, with information on the existence of personal data concerning him/her, as well as the personal data itself, issue a written reasoned response within a period not exceeding one week from the subject’s request; 8.3.8. provide, at the request of the authorized state body or the Ombudsman (Akyikatchy) of the Kyrgyz Republic, within one week, information necessary for the exercise of their powers; 8.3.9. block personal data relating to the relevant User from the moment of the request or application by the User or his/her legal representative or by the authorized body for protection of the rights of personal data subjects for the verification period, if inaccurate personal data or unlawful actions are identified; 8.3.10. ensure the possibility of submitting a request for review of an automated decision with human involvement if such decision creates legal consequences for the subject or otherwise significantly affects him/her; 8.3.11. notify the personal data subject of the establishment or removal of a restriction on processing in the cases and within the periods provided by the legislation of the Kyrgyz Republic; 8.3.12. consider the personal data subject’s objection to processing and send a reasoned decision no later than 7 business days from receipt of such objection, unless another period is established by the legislation of the Kyrgyz Republic. During consideration of the objection, the Company restricts the relevant processing where necessary.

CHAPTER 9. STORAGE OF PERSONAL DATA

9.1. The Company stores personal data in a form enabling identification of the personal data subject for no longer than required by the processing purposes, unless another storage period is established by the legislation of the Kyrgyz Republic, an agreement, the Company’s obligations to comply with requirements of authorized bodies, or the need to protect the rights and legitimate interests of the Company and the personal data subject. Upon achievement of processing purposes or termination of the legal ground for processing, personal data must be deleted, destroyed, depersonalized, or transferred to a restricted processing (blocking) mode if immediate deletion is impossible or prohibited by law. 9.1.1. Another storage period may be established by an agreement to which the User is a party, beneficiary, surety, or other participant, if such period is necessary for performance of the agreement, protection of the parties’ rights, consideration of claims, settlement of disputes, or compliance with mandatory requirements of the legislation of the Kyrgyz Republic; 9.1.2. Another storage period may be established by a separate agreement between the Company and the User, provided that such agreement does not contradict the legislation of the Kyrgyz Republic, corresponds to the processing purpose, and does not violate the rights of the personal data subject. 9.2. Upon achievement of processing purposes, termination of the legal ground for processing, satisfaction of the personal data subject’s deletion request, or identification of unlawful or excessive processing, the Company, without undue delay, deletes, destroys, or depersonalizes personal data unless further storage is required by law. If immediate deletion is impossible for technical or legal reasons, the Company blocks the data, ceases its active processing, and notifies the subject of the measures taken. 9.2.1. Grounds for deletion of personal data include, in particular: - achievement of processing purposes; - termination of the legal ground for processing; - satisfaction of a justified objection of the subject to processing; - identification of unlawful or excessive processing; - expiration of the established storage period. 9.3. Documents, correspondence, transaction information, identification materials, compliance documents, action logs, customer service documents, and other information related to the provision of services, performance of an agreement, compliance with legal requirements, consideration of claims, investigation of incidents, and protection of the rights of the Company and personal data subjects are stored for the duration of the relevant relationship and, after its termination, for the period established by the legislation of the Kyrgyz Republic, regulatory requirements, the Company’s internal documents, and the applicable legal ground for processing. 9.3.1. Information related to identification, verification, AML/KYC, transactions, financial monitoring, investigation of suspicious activity, and fulfillment of obligations in the AML/CFT area must be stored for at least 5 years after termination of relations with the User or for a longer period if such period is directly established by applicable legislation or regulatory requirements or is necessary to protect the Company’s rights in an investigation, inspection, or dispute. 9.4. The Company regularly reviews applicable personal data storage periods and takes measures to delete, destroy, depersonalize, or restrict processing of data whose storage period has expired or whose legal ground for processing has terminated. Storage beyond the established period is permitted only where there is a documented lawful ground, including compliance with obligations under the legislation of the Kyrgyz Republic, protection of rights in a dispute, conducting an internal investigation, audit, or responding to an incident. 9.4.1. Review of storage periods is carried out taking into account: the category of personal data; processing purpose; legal ground for processing; category of personal data subject; existence of a valid agreement; limitation periods; mandatory storage periods under AML/KYC, accounting, tax, labor, and other legislation; and the existence of a claim, complaint, inspection, audit, or court dispute. 9.5. Specific storage periods for personal data, categories of subjects, processing purposes, legal grounds, categories of recipients, and the procedure for deletion or depersonalization are disclosed in Appendix A to this Policy. If no exact storage period is specified in Appendix A, the storage criterion “until achievement of the processing purpose and termination of the lawful ground” applies unless otherwise established by the legislation of the Kyrgyz Republic. 9.6. If personal data cannot be deleted immediately for technical, architectural, backup, evidentiary, or other lawful reasons, the Company restricts processing of such data, excludes its use for new purposes, ensures an enhanced access control regime, and completes deletion, destruction, or depersonalization within a period reasonably necessary to complete the relevant procedures. 9.7. Destruction of personal data is documented in a manner that confirms the fact of destruction. In cases provided by the Company’s internal procedures, legislation, or the nature of processing, destruction is formalized by an act. A copy of the act or other confirmation of destruction may be provided to the personal data subject upon request, provided that this does not contradict the requirements of the legislation of the Kyrgyz Republic, confidentiality regime, AML restrictions, or security interests. 9.8. A request of the personal data subject for deletion is not subject to satisfaction to the extent that further storage of data is necessary for the Company’s compliance with obligations established by the legislation of the Kyrgyz Republic, including AML/KYC, accounting, tax, labor, and other mandatory recordkeeping requirements, as well as for establishing, exercising, or protecting the Company’s rights in a claim, inspection, investigation, or court dispute. In such cases, the Company notifies the subject of the reasons for full or partial refusal of deletion and, if necessary, restricts further processing of data. In case of full or partial refusal of deletion, the Company sends the subject a reasoned response indicating the legal ground for further storage and, if necessary, restricts further processing of data.

CHAPTER 10. PERSONAL DATA SECURITY

10.1. The Company takes necessary legal, organizational, and technical measures to ensure the security of personal data during its processing, including protection against unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination, loss, unauthorized disclosure, and other unlawful actions in relation to personal data, taking into account the nature of the data processed, processing purposes, risk level, and applicable requirements of the legislation of the Kyrgyz Republic. Security measures are applied taking into account the principle of proportionality to risks and to the protection level of the relevant personal data information system. 10.2. Access to personal data is granted only to employees, contractors, processors, and other authorized persons for whom such access is objectively necessary to perform their duties, and is carried out in accordance with the Company’s internal documents governing personal data processing, information security, risk management, confidentiality, and access rights allocation. 10.2.1. The Company applies the principle of minimum necessary access, under which each person is granted only the scope of access to personal data necessary to perform his/her functions. 10.3. The Company regularly reviews and improves the personal data protection measures applied, processing procedures, access control procedure, logging of operations, backup, monitoring of security events, vulnerability management, incident response, and internal control over compliance with legislation and this Policy. The Company has the right to conduct internal and external inspections, testing, audits, and assessments of the effectiveness of personal data protection measures, taking into account the level of risk and nature of processing. 10.4. The Company ensures that employees, contractors, processors, service providers, partners, and other persons obtaining access to personal data are required to comply with confidentiality, security, and lawfulness requirements for personal data processing, including non-disclosure obligations, access restrictions, use of data only within assigned purposes, compliance with protection measures, and notification to the Company of security breaches and incidents. 10.5. Agreements with processors and other persons engaged in personal data processing include provisions on processing purposes, permitted operations, processing periods, prohibition on using data for their own purposes, security measures, rules for engaging subprocessors, return or deletion of data upon completion of the assignment, and incident notification periods. 10.5.1. In cases provided by the legislation of the Kyrgyz Republic, the Company determines a person responsible for organizing the processing and protection of personal data. Contact details of such person, if their disclosure is required by law or by the Company’s internal processing model, are indicated in this Policy, on the Website, on the Platform, or in another accessible notice. 10.6. The Company determines and applies personal data protection measures taking into account the nature and scope of the data processed, processing purposes, technologies used, the probability and severity of risk to the rights and legitimate interests of personal data subjects, and the requirements for levels of protection of personal data information systems. 10.7. When determining protection measures, the Company takes into account the list of current threats, information system architecture, number of personal data subjects, existence of special categories of data, biometrics, automated decisions, cross-border transfer, and participation of third parties in processing. 10.8. For the purpose of protecting personal data, depending on the nature of processing and risk level, the Company applies, in particular, the following measures: - approval and communication to employees of internal policies, instructions, and procedures; - appointment of responsible persons; - segregation and control of access; - identification and authentication of system users; - maintenance of logs of operations and security events; - backup and recovery of data; - use of antivirus protection and tools for detecting and preventing unauthorized access; - application of cryptographic and other information protection measures and secure data transmission channels where required by the nature of processing and risk level; - recordkeeping of information media and control over their handling; - employee training and internal control over compliance with security requirements. 10.9. The Company implements internal procedures for identifying, registering, investigating, and eliminating incidents in the digital environment, including incidents affecting personal data, information systems, user accounts, identification tools, payment infrastructure, and other elements of the digital service. 10.9.1. A processor or other person engaged by the Company in personal data processing must notify the Company of a security incident within the period established by the agreement, but no later than 48 hours from its detection. 10.9.2. The Company notifies the authorized body of an incident affecting digital resilience, confidentiality, integrity, availability of personal data, or the rights and interests of subjects no later than 72 hours after its detection; if this period is missed, the Company indicates the reasons for the delay. 10.9.3. If an incident creates a risk of harm to personal data subjects, the Company notifies the affected subjects without undue delay and, where necessary, communicates recommended protection measures. 10.9.4. The Company maintains internal records of incidents related to personal data, including information on their detection, investigation, notification of authorized bodies and personal data subjects, and measures to prevent recurrence of similar incidents. 10.10. An incident notification sent to an authorized body or to a personal data subject must contain, to the necessary extent, a description of the incident, an approximate assessment of the number of affected subjects and records, information on categories of affected data, possible consequences of the incident, measures taken or planned to eliminate it and minimize consequences, and contact details of the responsible person or another representative of the Company for additional information. The Company has the right to update an earlier notification as new information about the incident becomes available. 10.11. The Company conducts a Data Protection Impact Assessment (DPIA) in cases provided by the legislation of the Kyrgyz Republic and the lists approved by the authorized personal data authority, including cases of high-risk processing capable of affecting the rights and legitimate interests of personal data subjects. 10.11.1. The Company considers conducting a DPIA, in particular, in the following cases: - profiling, scoring, and other automated evaluations of personal aspects of a subject; - use of automated decisions capable of resulting in denial of service, restriction of access to the service, or other significant consequences; - mass processing of special categories or biometric data; - use of artificial intelligence, innovative technologies, or comparison of data from several digital resources for making decisions concerning a subject. 10.11.2. A Data Protection Impact Assessment is conducted before the start of the relevant high-risk processing or before substantial changes are made to such processing, is documented, and is reviewed when processing purposes, data composition, technologies used, categories of subjects, composition of recipients, nature of automated decisions, or the risk level for the rights and legitimate interests of personal data subjects change. 10.12. If the Company processes biometric data or special categories of personal data, such processing is carried out only where there is a legal ground provided by law, in the minimum necessary scope, for a specific and pre-determined purpose, with enhanced protection measures and restricted access. 10.13. The Company may use automated processing, profiling elements, anti-fraud models, AML/KYT monitoring, cybersecurity tools, and other technological solutions to detect anomalous activity, prevent abuse, analyze transactions, protect the service, and improve user experience, provided that such processing is permitted by the legislation of the Kyrgyz Republic and is carried out on an appropriate legal ground. 10.14. In order to ensure the security, stability, and integrity of the Platform, the Company may process technical data, including IP address, browser and device information, cookie identifiers, access time data, user actions in the interface, login logs, and other security events. Such data is processed to the extent necessary to ensure service operability, detect threats, prevent abuse, and investigate incidents. 10.15. The Company documents the protection measures applied, internal procedures, allocation of responsibility, results of checks, information on incidents, actions to eliminate them, and other information necessary to confirm compliance with the requirements of the legislation of the Kyrgyz Republic in the field of personal data processing and protection. 10.15.1. This Policy applies to both digital and non-automated processing of personal data, including storage and use of documents on paper media. The Company ensures restriction of access to such media, accounting for persons having access to them, and application of reasonable protection measures preventing unlawful familiarization, copying, loss, destruction, or other unlawful use of personal information contained therein.

CHAPTER 11. LIABILITY OF PARTIES

11.1. The Company is liable for violation of the requirements of the legislation of the Kyrgyz Republic on personal data, as well as for unlawful processing of personal data that caused harm or losses to the personal data subject, within the limits and in the manner provided by the legislation of the Kyrgyz Republic. The Company is liable for non-compliance with the requirements of this Policy, internal personal data processing procedures, rules for granting access to personal data, security measures, and obligations to notify subjects and authorized bodies in cases provided by the legislation of the Kyrgyz Republic. 11.2. The Company is not liable for disclosure, provision, or other use of personal data in cases where: - such data became publicly available through no fault of the Company; - such data was obtained by the Company from a lawful source on a lawful ground; - disclosure or provision of data was carried out with the consent of the personal data subject or on another lawful ground provided by the legislation of the Kyrgyz Republic; - disclosure of personal data was mandatory by virtue of requirements of the legislation of the Kyrgyz Republic, an act of an authorized body, a judicial act, or another prescription binding on the Company. 11.3. The Company is not liable for consequences of inaccuracy, incompleteness, or untimely updating of personal data provided by the User if the User was required to provide up-to-date data and failed to fulfill that obligation. 11.4. Persons engaged by the Company in personal data processing are liable to the extent established by the legislation of the Kyrgyz Republic, the agreement with the Company, and the nature of the assigned processing. Engagement of a processor does not release the Company from obligations to the personal data subject in cases provided by the legislation of the Kyrgyz Republic. 11.5. The Company is not liable for refusal to delete, block, restrict processing, or cease storage of personal data to the extent that such processing or storage is mandatory under the legislation of the Kyrgyz Republic, including requirements for identification, financial monitoring, tax, accounting, labor, or other mandatory recordkeeping, and in cases where it is necessary to protect the Company’s rights in a claim, inspection, investigation, or court dispute.

CHAPTER 12. DISPUTE RESOLUTION

12.1. The Company considers requests of the personal data subject for information about processing, access to data, correction, supplementation, objection to processing, restriction of processing, data portability, and review of an automated decision, and sends a response no later than 7 business days from receipt of the request unless another period is expressly established by the legislation of the Kyrgyz Republic. General claims and appeals not related to the exercise of special rights of the personal data subject are considered within up to 30 calendar days unless another period is established by the legislation of the Kyrgyz Republic. 12.2. The Company strives to resolve appeals of personal data subjects in a pre-trial manner, including by providing explanations, correcting or deleting data, restricting processing, reviewing decisions, sending a reasoned response, and taking other reasonable measures to restore violated rights. 12.3. This Policy does not restrict the subject’s right to: - file a complaint with the sectoral regulator in the field of personal data (DPA); - apply to a court for protection of his/her rights; - use of a claim procedure as a service-based settlement mechanism, which does not prevent application to the regulator or a court on personal data protection matters. 12.4. The recipient of a claim, no later than 30 calendar days from receipt of the claim, notifies the claimant in writing of the results of consideration of the claim. 12.5. Disputes related to the implementation of this Policy may, by agreement of the parties, be submitted for consideration to the International Arbitration Court under the Chamber of Commerce and Industry of the Kyrgyz Republic, if such submission is permitted by the legislation of the Kyrgyz Republic; at the same time, this provision does not restrict the right of the personal data subject to apply to the authorized state body for personal data or to a court for protection of his/her rights. 12.6. This Policy and the relationship between the User and the Company are governed by the current legislation of the Kyrgyz Republic.

CHAPTER 13. MISCELLANEOUS

13.1. The Company has the right to amend and supplement this Policy. The current version of the Policy is posted in free access on the Company’s Website and/or Platform, indicating the date of the last update. 13.2. In the event of material changes affecting processing purposes, legal grounds for processing, categories of recipients, cross-border transfer, use of automated decisions, channels for exercising subjects’ rights, or other significant aspects of processing, the Company takes reasonable measures to notify Users in advance at least 14 business days before such changes enter into force, unless another procedure follows from the legislation of the Kyrgyz Republic or the nature of the changes. 13.3. The Company reviews this Policy as the legislation of the Kyrgyz Republic changes, as the nature of the services provided changes, as the composition of technologies used, methods of personal data processing, categories of recipients, and security measures change, and as the need to clarify or improve internal personal data processing procedures is identified. 13.4. On matters related to personal data processing, exercising the rights of the personal data subject, withdrawing consent, filing an objection to processing, restricting processing, data portability, review of an automated decision, reporting a possible personal data leak, or any other request under this Policy, the User may contact the Company through the contact channels specified in this Policy, on the Website, or on the Company’s Platform. 13.5. Recognition by a court of any provision of this Policy as invalid does not entail invalidity of the remaining provisions of this Policy. 13.6. Forms of consent to personal data processing, if obtaining such consent is required in accordance with the legislation of the Kyrgyz Republic or a specific processing model, are approved by the Company and used as separate documents related to this Policy. Absence of consent to optional types of processing does not affect the lawfulness of mandatory processing based on a contract, law, or another legal ground provided by legislation. 13.7. Matters not regulated by this Policy are governed by the legislation of the Kyrgyz Republic, agreements and user documents of the Company, and the Company’s internal documents to the extent that they do not contradict the legislation of the Kyrgyz Republic and this Policy. 13.8. In the event of contradictions between the Russian and Kyrgyz texts of this Policy, the Russian version prevails.

APPENDIX A

Personal Data Processing Matrix

This appendix contains the personal data processing matrix for profile identification data.

Data category
Purpose
Legal ground (Digital Code of the Kyrgyz Republic)
Storage period
Recipients / processors
Country of processing / storage
Cross-border transfer
Ground for transfer
Profile identification data: full name, phone, email, address, account details
Registration, account creation and maintenance, provision of access to the personal cabinet, user identification, performance of the user agreement.
Performance of a contract and taking steps at the subject's request before entering into a contract
Up to 5 years after termination of relations, if required to protect rights/AML
Hosting/cloud: https://kaganinvest; CRM/support: Telegram chatbot, JivoChat
Kyrgyzstan
No
KYC documents: passport data, citizenship, address, TIN/PIN, residency, questionnaires.
KYC/AML, acceptance for service, compliance with AML/CFT requirements.
Legal obligation / contract.
At least 5 years after termination of relations.
AML/KYT provider: RANEX; auditor/compliance; state bodies as required by law.
Kyrgyzstan
No
Biometric data, photos, video selfie, and other remote identification data.
Remote identification/verification.
Legal obligation or separate consent (depending on processing) + DPIA where triggers apply.
At least 5 years after termination of relations.
Biometric provider: Sum and Substance LTD.
United Kingdom
Yes
Contractual relations.
Data on transactions and operations with virtual assets, wallet addresses, transaction history, action logs.
Execution of operations, accounting, AML/KYT monitoring, fraud investigation.
Contract; legal obligation; legitimate interest (anti-fraud).
Banks/payment providers: Fireblocks Trust Company LLC; AML/KYT: Chainalysis.
At least 5 years after termination of relations or according to regulatory/legal requirements.
USA
Yes
Contractual relations.
Payment data: account details, cards (if processed), e-wallets.
Payments, refunds, settlements.
Contract / legal obligation.
According to financial accounting/AML requirements, at least 5 years where relevant.
Acquirer/PSP: specify.
Technical data: IP address, device ID, login logs, events, cookies.
Security, fraud prevention, service improvement.
Legitimate interest (security) + consent for optional analytics.
Security logs: not specified; cookies: according to cookie periods/settings (not specified).
Internal information security services: specify.
Behavior analytics in the service.
UX improvement, product analytics.
Consent (if optional analytics) or legitimate interest, subject to minimization and no excessive interference.
Not specified.
Yandex Metrica; Google Analytics; Amplitude (specify countries/transfers).
Contact details and correspondence.
Support, responses to inquiries.
Contract / legitimate interest.
At least 5 years after termination of relations if related to AML/disputes; otherwise not specified.
Ticketing system: specify.
Marketing mailings.
Notifications about products/promotions.
Separate consent; withdrawal at any time.
Until withdrawal of consent or not specified.
Mailing provider: not specified.
Employee data.
HR records
Legal obligation/contract; DPIA is generally not required for standard HR records.
According to labor/tax legislation: not specified.

APPENDIX B

Security Measures

Security measure.
Minimum level (blue).
Enhanced (green).
High (yellow).
Critical (red).
Responsible
Policy and communication to employees/contractors.
Yes
Yes
Yes
Yes
Legal/compliance.
Appointment of persons responsible for security/personal data.
Yes
Yes
Yes
Yes
DPO/Information Security.
List of threats and review upon changes.
Yes
Yes
Yes
Yes
Information Security.
Access control, lists of admitted persons.
Yes
Yes
Yes
Yes
Information Security.
Operation logs and indication of who changed/deleted what and when.
Yes
Yes
Automatic log without possibility of retroactive change.
Automatic log + audit.
Information Security.
Backup
At least once per day.
Yes
High availability/redundancy.
Yes
IT
Encryption.
Based on threat assessment.
Mandatory (at least to prevent unauthorized access).
Yes
Yes + secure channels.
Information Security.
Physical protection of premises/equipment.
Recommended
Yes
Premises access control system.
Yes
Admin/Information Security.
Unauthorized access detection/prevention system.
Basic level
Yes
Automatic detection system.
Yes
Information Security.
Audit
As necessary
As necessary/before changes.
Yes
At least once per year.
Information Security/auditor not specified.
Employee training.
Yes
Yes
Yes
Yes
HR/compliance

APPENDIX 1

Form of Notification and Consent of the Personal Data Subject

I, ________________________, PIN/TIN/other identifier: ________________________, contact phone number: ________________________, email address: ________________________, confirm that I have read the Privacy Policy of Royal Pure Gold LLC (the “Company”) and have been notified of the procedure, purposes, legal grounds, and conditions for the processing of my personal data. 1. Notification of mandatory processing of personal data I have been notified that the Company may process my personal data without separate consent where such processing is necessary: to register, create, maintain, and use an account (personal profile) on the Company’s Platform or Website; to conclude, perform, amend, and terminate agreements, perform the user agreement, and process applications, requests, and inquiries; to provide me with services, digital services, and functional capabilities of the Platform or Website; to identify, verify, authenticate, and comply with the requirements of the laws of the Kyrgyz Republic, including AML/CFT and KYC/AML requirements; to perform other obligations imposed on the Company by the laws of the Kyrgyz Republic; to ensure the security of the Platform and prevent fraud, abuse, unlawful access, and other violations; to review inquiries, complaints, and claims, perform obligations to provide information, and protect the rights and legitimate interests of the Company and personal data subjects. 2. Categories of personal data that may be processed Depending on the purposes of processing and the service I use, the Company may process the following categories of my personal data: Registration and contact data: surname, first name, patronymic, sex, date and place of birth, phone number, email address, registered address, residential address, and postal address; Identification and verification data: citizenship, residency information, nationality, marital status, details of an identity document (series, number, date of issue, issuing authority), TIN/PIN (if available), information confirming the right of a foreign citizen to stay in the territory of the Kyrgyz Republic (where necessary), and other data required for KYC/AML and compliance; Financial and transaction data: account details, bank details, income/property information, transaction data, payment instruments (cards, wallets), and other data required for financial services and compliance; Technical and security data: IP address, device and browser information, technical parameters, access time, logs, cookies, and security events; Communication data: inquiries, applications, complaints, claims, support messages, attachments, correspondence history, and interaction data; Legal entity data (if applicable): company name, registration details, address, management structure, beneficiaries, corporate documents, and representative information; Biometric data: facial image, video image, voice, and other data used for remote identification or verification (if applicable and permitted by law); Other data: voluntarily provided or lawfully obtained data necessary for the purposes defined in the Privacy Policy. A. Mandatory processing not requiring separate consent ☐ I acknowledge that my data will be processed for registration, performance of the user agreement, and compliance with AML/CFT (KYC/AML) requirements, including storage for at least 5 years after termination of the relationship where required by law. B. Consent to marketing and informational messages ☐ I consent ☐ I do not consent C. Consent to optional analytics and cookies ☐ I consent ☐ I do not consent D. Consent to cross-border transfer of personal data ☐ I consent ☐ I do not consent Purpose: ________________________ E. Consent to processing of biometric data (if applicable) ☐ I consent ☐ I do not consent 3. Rights of the personal data subject I have been informed that I have the right to: access my personal data and information about its processing; request correction, updating, blocking, restriction, or deletion; object to processing; request data portability (where applicable); request human review of automated decisions; apply to the authorized authority or court for protection of rights. 4. Withdrawal of consent Consent may be withdrawn at any time via: personal account settings; email; feedback form; postal address of the Company. Withdrawal does not affect the legality of processing carried out before withdrawal and does not affect processing based on other legal grounds. Confirmation I confirm that: I have read the Privacy Policy of the Company; I understand the purposes and legal grounds of processing; I understand mandatory and optional processing; I am informed of my rights and procedures for exercising them. Date: “__________” __________ 20__ Full name: __________________________________________ Signature: __________________________________________

APPENDIX 2

Form 1

Notification to the Authorized State Body of an Incident Related to Personal Data

1. Company Information Full name: Limited Liability Company “Royal Pure Gold” TIN / registration number: _________________________ Location address: _________________________________ Contact phone: _________________________________ Email: __________________________________________ 2. Information on the Responsible Person Full name: ____________________________________________ Position: _____________________________________________ Telephone: ____________________________________________ Email: ________________________________________________ 3. General Information on the Incident Date of incident detection: _________________________ Time of incident detection: ________________________ Date of incident occurrence (if established): ________ Time of incident occurrence (if established): ________ Type of incident: ____________________________________ (leak / unauthorized access / destruction / alteration / blocking / loss / other) 4. Incident Description Brief description of the nature of the incident: Description of affected information systems, services, databases, processes, or media: 5. Affected Personal Data Categories of affected personal data: ☐ registration and contact data ☐ identification / verification data ☐ financial / payment data ☐ technical data ☐ biometric data ☐ correspondence / inquiry data ☐ other data: ______________________________________ Approximate number of affected personal data subjects: ______________________ Approximate number of affected records / files / documents: __________________ 6. Possible Consequences of the Incident ☐ risk of unauthorized access ☐ risk of fraud ☐ risk of financial losses ☐ risk of identity substitution ☐ risk of restricted access to the service ☐ reputational risk ☐ other consequences: ______________________________ Detailed description of possible consequences: 7. Measures Taken What measures have already been taken to localize, eliminate, and minimize the consequences: Date and time of initial measures taken: __________________ 8. Further Action Plan What additional measures are planned: Planned date for updating information: _______________ 9. Notification of Personal Data Subjects ☐ notification of subjects has already been sent ☐ notification of subjects is not required ☐ notification of subjects will be sent additionally Justification: 10. Attachments ☐ internal act / incident report ☐ technical conclusion ☐ list of affected data categories ☐ other documents: __________________________________ Notification date: “” ____________ 20 Full name and position of signatory: ______________________ Signature / electronic signature: _________________________

Form 2

Notification to the Personal Data Subject of an Incident

Notification Subject Notification of an incident related to your personal data Dear ____________________________, The Company informs you of an identified incident that may affect your personal data. 1. What Happened Date of incident detection: __________________________ Brief description of the incident: 2. What Data May Have Been Affected Based on the information currently available, the incident may have affected the following categories of your data: ☐ surname, first name, patronymic ☐ contact details ☐ account data ☐ identification / verification data ☐ financial / payment data ☐ technical data ☐ other data: ______________________________________ 3. Possible Consequences The incident may entail the following risks: 4. What the Company Has Already Done The Company has already taken the following measures: 5. What You Are Recommended to Do For additional protection, we recommend: ☐ change the account password ☐ enable additional access protection measures ☐ check login and transaction history ☐ be attentive to suspicious emails, calls, and messages ☐ contact the bank / payment service if necessary ☐ other measures: __________________________________ 6. Where to Contact for Additional Information Contact person / department: __________________________ Telephone: ___________________________________________ Email: _______________________________________________ Other communication channel: __________________________ 7. Additional Information If new significant information becomes available, the Company will send an updated notification where necessary. Notification date: “” ____________ 20 LLC “Royal Pure Gold”

Confidentiality Policy of Royal Pure Gold LLC

We use cookies. Learn more about cookies here