PRIVACY POLICY

This Privacy Policy has been prepared by Vimesoft A.Ş. in its capacity as data controller pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (the “Law”) and the Communiqué on the Procedures and Principles to Be Followed in Fulfillment of the Obligation to Inform. In order to fulfill its obligations regarding data security under Article 12 of the Law, Vimesoft A.Ş. takes the necessary technical and administrative measures, using its technological and infrastructural capabilities, to ensure that personal data is securely stored and processed in compliance with the law. Personal data is processed by Vimesoft A.Ş. in accordance with the Law and applicable legislation. Natural persons whose personal data is processed within the scope of the Law may obtain information about the personal data that may be processed by Vimesoft A.Ş. in its capacity as data controller, the purposes for which such data is processed, the recipient groups to whom it may be transferred, the method and legal basis of collection, and their rights regarding such personal data.

PERSONAL DATA PROCESSED OR THAT MAY BE PROCESSED

Although the personal data processed in connection with the products and services offered by Vimesoft A.Ş. may vary from person to person, all categories of personal data that may generally be processed by Vimesoft A.Ş. are listed below: Identity Data: The person’s first name and surname are processed in this data category. Contact Data: The person’s mobile phone number, e-mail address, address, province-district, postal code, tax office and tax number are processed in this data category. Personnel Data: Information regarding the institution/organization where the person works is processed in this data category. Transaction Security Data: The person’s user identification information, password and verification code are processed in this data category. Visual and Audio Records: The person’s photograph, camera image/video and audio data are processed in this data category. Financial Data: The cardholder’s first name and surname,

credit card number, credit card expiration date and credit card security code are processed in this data category.

PURPOSES OF PROCESSING PERSONAL DATA

The personal data listed below is processed in connection with the products and services offered by Vimesoft A.Ş. for the following purposes: Identity Data: The person’s first name and surname are processed for the purposes of carrying out service procurement processes and providing services. Contact Data: The person’s mobile phone number is processed for the purposes of carrying out service procurement processes and managing access authorizations; the e-mail address is processed for the purposes of carrying out service procurement processes, managing access authorizations and providing services; and the address, province-district information, postal code, tax office and tax number are processed for the purposes of carrying out finance and accounting activities and service sales processes. Personnel Data: Information regarding the institution/organization where the person works is processed for the purposes of carrying out service procurement processes and marketing products/services. Transaction Security Data: The person’s user identification information and verification code are processed for the purpose of managing access authorizations, while password information is processed for the purposes of carrying out service procurement processes and managing access authorizations. Visual and Audio Records: The person’s photograph, camera image/video and audio data are processed for the purpose of providing services. Financial Data: The cardholder’s first name and surname, credit card number, credit card expiration date and credit card security code are processed for the purposes of carrying out service sales processes and finance and accounting activities.

TRANSFER OF PERSONAL DATA

The personal data collected may, in accordance with the fundamental principles set forth in the Law and the conditions for the transfer of personal data specified in Articles 8 and 9 of the Law, and for the purposes stated below, be transferred to legally authorized public institutions and organizations, natural persons or private-law legal entities in Türkiye and abroad, suppliers with whom Vimesoft A.Ş. will enter into a contractual relationship, and service providers.

Identity Data: The person’s first name and surname may be transferred to suppliers providing the infrastructure through which the membership process is operated and to other users during the provision of the service. Contact Data: The person’s mobile phone number and e-mail address may be transferred to suppliers providing the infrastructure on which the system is hosted for the purposes of carrying out the membership registration process and application login procedures; to the SMS service provider for sending the membership initiation notification; and the invoice containing the person’s address, province-district information, postal code, tax office and tax number may be transferred to the e-mail service provider whose infrastructure is used to deliver the invoice to the relevant person following billing. Personnel Data: Information regarding the institution/organization where the person works may be transferred to suppliers providing the infrastructure on which the system is hosted for the purposes of carrying out the membership process and application login procedures. Transaction Security Data: The person’s user identification information and verification code may be transferred to the SMS service provider for the purpose of using the SMS service to enable the user to initiate membership, while the user password may be transferred to suppliers providing the infrastructure on which the system is hosted for the purpose of carrying out application login procedures.

Visual and Audio Records: The person’s photograph may be transferred to suppliers providing the infrastructure on which the system is hosted for the purpose of customizing the profile, while camera image/video and audio data may be transferred to other participants during the provision of the service. Financial Data: The cardholder’s first name and surname, credit card number, credit card expiration date and credit card security code may be transferred for the purpose of using the payment service during the membership process.

METHOD AND LEGAL BASIS FOR COLLECTING PERSONAL DATA

Personal data may be collected through electronic environments such as the application membership page, quotation request form, payment information page, profile page, conference creation and invitation page, and conference screen, as well as through voice communication, by fully automated, partially automated or non-automated methods, and may be processed and transferred for the purposes set out in this Policy. Pursuant to Article 5 of the

Law, Vimesoft A.Ş. may process personal data that it has lawfully collected without seeking explicit consent in the following cases:

· Where expressly provided for by law,

· Where processing of personal data is necessary for the protection of the life or physical integrity of the Data Subject or another person who is unable to express consent due to actual impossibility, or whose consent is not legally valid,

· Where processing of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the establishment or performance of a contract concluded between Vimesoft A.Ş. and the Data Subject,

· Where processing is necessary for Vimesoft A.Ş. to fulfill a legal obligation,

· Where the personal data has been made public by the Data Subject,

· Where data processing is necessary for the establishment, exercise or protection of a right,

· Where processing is necessary for the legitimate interests of Vimesoft A.Ş., provided that such processing does not prejudice the fundamental rights and freedoms of the Data Subject.

In addition, pursuant to Article 6 of the Law, Vimesoft A.Ş. may process special categories of personal data that it has lawfully obtained without seeking explicit consent in the following cases:

· Data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, constitute special categories of personal data.

· Special categories of personal data other than data relating to the Data Subject’s health and sexual life may be processed where such processing is provided for by law,

· Special categories of personal data relating to the Data Subject’s health and sexual life may be processed only for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing, by persons under an obligation of confidentiality or by authorized institutions and organizations.

RIGHTS OF THE DATA SUBJECT

Pursuant to Article 11 of the Law, the Data Subject may at any time apply to the data controller and exercise the following rights regarding himself/herself:

· To learn whether his/her personal data is being processed,

· To request information if his/her personal data has been processed,

· To learn the purpose of processing his/her personal data and whether such data is used in accordance with that purpose,

· To know the third parties to whom his/her personal data has been transferred in Türkiye or abroad,

· To request correction of personal data if it has been processed incompletely or inaccurately,

· To request the deletion or destruction of personal data where the reasons requiring its processing cease to exist, subject to an assessment within the principles of purpose, duration and legitimacy; and to request the deletion or destruction of personal data,

· To request the deletion, destruction or anonymization of personal data where the reasons requiring its processing cease to exist, even though such data has been processed in accordance with Law No. 6698 on the Protection of Personal Data and other applicable laws,

· To request that third parties to whom the personal data has been transferred be notified of the actions taken with respect to the correction, deletion or destruction of personal data,

· To object to a result arising against the person as a result of the analysis of processed data exclusively through automated systems,

· To claim compensation for damages suffered as a result of the unlawful processing of personal data.

HOW THE DATA SUBJECT MAY EXERCISE HIS/HER RIGHTS

In order to exercise the above-mentioned rights under Article 11 of the Law, the Data Subject must complete the application form in full and submit it to Vimesoft A.Ş. through the channels specified in the form. Depending on the nature of the request, Vimesoft A.Ş. will conclude the request free of charge as soon as possible and no later than thirty (30) days. However, if the process requires an additional cost, Vimesoft A.Ş. reserves the right to charge the fee specified in the tariff determined by the Personal Data Protection Board.

RETENTION PERIODS FOR PERSONAL DATA

In accordance with the Law, personal data processed for the purposes specified in this Privacy Policy, pursuant to Article 7 of the Law, when the purpose requiring its processing

ceases to exist and/or when the limitation periods during which Vimesoft A.Ş. is required by applicable legislation to process the data expire, will be deleted or destroyed by Vimesoft A.Ş. or will continue to be used after being anonymized.