SIXALIME PRIVACY POLICY


Sixalime S.A.U. CUIT: 30-71678854-3 (“Sixalime” and/or the “Company”) collects and processes Personal Data from individuals who use the services offered by the Company (hereinafter, the “Customers” and/or the “Data Subjects”, indistinctly). Sixalime’s main objective is to provide its Customers with a service that protects their privacy and intimacy, while ensuring service excellence.

This Privacy Statement is intended to transparently explain how Sixalime collects, accesses, processes, uses, discloses and/or transfers, where applicable, its Customers’ Personal Data, as well as the measures implemented to protect the security of such data and the way in which Data Subjects may exercise their rights. All of the foregoing is always carried out in compliance with the applicable personal data protection laws, and particularly Personal Data Protection Law No. 25,326 (the “LPDP”).

Finally, Customers must provide their voluntary, informed and express consent to this Privacy Statement as a prior and essential requirement to contract any of Sixalime’s services. Accordingly, this Privacy Statement must be accepted by Customers together with the Terms and Conditions of the services offered by the Company when registering on the platform.

1. DEFINITIONS According to the LPDP and the applicable regulations on the matter, the following terms shall be understood as follows:

• Personal Data: Information of any kind relating to identified or identifiable individuals or legal entities.

• Sensitive Data: Personal Data revealing racial or ethnic origin, political opinions, religious, philosophical or moral beliefs, union membership, income, and information concerning health or sex life.

• File, Registry, Database or Data Bank: Indistinctly, the organized set of Personal Data subject to treatment or processing, whether electronic or not, regardless of the method used for its creation, storage, organization or access.

• Data Processing: Systematic operations and procedures, electronic or otherwise, that allow the collection, preservation, ordering, storage, modification, relationship, evaluation, blocking, destruction and, in general, processing of Personal Data, as well as its disclosure to third parties through communications, consultations, interconnections or transfers.

• File, Registry, Database or Data Bank Controller: A public or private individual or legal entity that owns a File, Registry, Database or Data Bank.

• Computerized Data: Personal Data subject to electronic or automated treatment or processing.

• Data Subject: Any individual or legal entity with legal domicile, branches or offices in the country whose data is subject to the processing referred to in the LPDP.

• Data User: Any public or private person who processes Data at its discretion, whether in its own files, registries or data banks or through a connection with them.

• Data Dissociation: Any Processing of Personal Data in such a way that the information obtained cannot be associated with a specific or identifiable person.

2. GENERAL PROVISIONS Sixalime’s policies and procedures are based on the legal framework mentioned above, whose purpose is to protect the information entrusted to Sixalime by collecting only and exclusively the information voluntarily provided by the Data Subject, with the purpose of using it only for the purposes described in this Statement.

With respect to Customers, this information may be obtained by the Company, among other channels or means, through: (i) the commercial or professional relationship between Customers and the Company, collected through the Platform; (ii) the provision of services; (iii) the sending of emails requesting information; and (iv) Sixalime’s website. In all cases, the Data Subject’s consent will always be requested and will be expressed by Customers when accepting the Terms and Conditions upon registering on the platform.

It is hereby clarified that the Company may also access other data relating to Data Subjects from information available in public/private consultation databases (e.g., databases of the National Registry of Persons, AFIP, the Central Bank of the Republic, Veraz, and any other database that, due to its nature, may be relevant for the proper provision of the services offered by Sixalime and contracted by the Data Subject).

In any event, Sixalime does not collect, create and/or manage files, banks or registries that store information relating to personal data, except to contact its Data Subjects, comply with Sixalime’s legal or contractual obligations, or send information of interest or invitations to activities carried out by Sixalime in furtherance of its corporate purpose.

The data collected by the Company will be exclusively the data provided by the Customer through the Platform, as it is considered an essential requirement to use the service provided by Sixalime. Any inaccuracy or falsity in the personal data provided by the Customer may cause the suspension of the services and even their disabling, and the Customer shall be liable for any damages caused by such inaccuracy or falsity.

3. DATA COLLECTED AND USED Sixalime collects Personal Data that is deemed strictly necessary and mandatory under current regulations so that Customers may correctly use the services offered by the Company. To that end, Sixalime may request and/or process through the Platform the Personal Data listed below:

• Name

• Email

• CUIT

• Telephone

• Address

• Gender

• Marital status

• Activity

• CBU for peso-denominated account

• CBU for U.S. dollar-denominated account

• CVU

• Any other data that the Customer voluntarily provides to Sixalime and that is consistent with the purpose of the service provided by the Company.

It is expressly clarified that Sixalime will not request that its Customers provide biometric data and/or sensitive data in order to use its services, nor will it receive such data from third parties with which it maintains any type of commercial relationship.

As stated above and as provided by the applicable regulations, especially the LPDP, Sixalime collects data through the Platform with the Customer’s express and prior consent upon registration, or receives it voluntarily from Customers, always with their prior and express consent.

4. BASIC PRINCIPLES REGARDING HABEAS DATA The following are the different principles established by the LPDP and the other applicable regulations on the processing of Personal Data, which every Data Subject should know in order to safeguard their rights and to which Sixalime adheres:

4.1. Provision of Sensitive Data No person may be required to provide Sensitive Data. Sensitive Data may only be collected and processed when there are reasons of general interest authorized by law. It may also be processed for statistical or scientific purposes when its owners cannot be identified.

In this regard, under no circumstances will Sixalime request sensitive data from its Customers, except in cases where there are reasons of general interest authorized by law that justify its collection.

Likewise, the creation of files, banks or registries that store information directly or indirectly revealing Sensitive Data is prohibited, unless the Data Subjects give their consent.

Data relating to criminal or misdemeanor records may only be processed by the competent public authorities, within the framework of the LPDP and other applicable regulations.

4.2. Data collection and storage Personal Data collected for processing must be adequate, relevant and not excessive in relation to the scope and purpose for which it was obtained.

Data collection may not be carried out by unfair or fraudulent means or in a manner contrary to the provisions of the law. Data subject to processing may not be used for purposes other than or incompatible with those that motivated its collection.

Data that is wholly or partially inaccurate or incomplete must be deleted and replaced, or completed where appropriate, by the person responsible for the file or database upon becoming aware of the inaccuracy or incompleteness of the information in question.

Data must be stored in a manner that allows the Data Subject to exercise the right of access.

4.3. Consent and/or authorization to obtain data The Processing of Personal and/or Sensitive Data is unlawful when the Data Subject has not given free, express and informed consent, which must be given in writing or by another equivalent means according to the circumstances. Such consent, when given together with other statements, must appear expressly and prominently after prior notice to the data provider.

As clarified in the preceding sections, Sixalime requires prior authorization from its Customers for the Processing of Personal Data provided within the contractual relationship established with them.

Accordingly, Customers express their consent and authorize Sixalime to collect their Personal Data through the acceptance of the Terms and Conditions when registering on the Platform.

4.4. Exceptions to the Data Subject’s prior and express authorization Prior and express authorization from the Data Subject will not be necessary — and, therefore, Sixalime will not require such authorization from its Customers — when:

• The data is obtained from unrestricted public access sources;

• The data is collected for the exercise of functions inherent to state powers or by virtue of a legal obligation;

• The data consists of lists limited to name, national identity document, tax or social security identification, occupation, date of birth and address;

• The data derives from a contractual, scientific or professional relationship with the Data Subject and is necessary for its development or fulfillment;

• The data concerns transactions carried out by financial institutions and information received from their customers pursuant to Article 39 of the LPDP.

5. PROCESSING OF PERSONAL DATA Personal Data collected by Sixalime is used for lawful purposes, seeking continuous improvement in the activities it carries out and in its relationships with Customers, suppliers, employees, regulatory agencies and other third parties, while always ensuring the privacy and protection of Data Subjects. In addition, the Company collects Customer data for the following purposes (the “Processing Purposes”):

• To enable and manage the Customer’s relationship with Sixalime: The Customer’s Personal Data is used to (i) allow the Customer to contract services offered through the Platform; (ii) verify the Customer’s preferences regarding the services; and (iii) facilitate responses to the Customer’s requests and inquiries. All of this is intended to provide the Customer with excellent service so that transactions can be carried out quickly, effectively and securely.

• To ensure the authenticity and security of the Customer’s account: Sixalime may use the Customer’s Personal Data to verify their identity when (i) the Customer requests the opening of an account through the Platform; (ii) the Customer’s data is incomplete, irregular or outdated; and (iii) to monitor the use and operation of the services and transactions.

• To prevent fraud: Sixalime may use the Customer’s Personal Data as necessary for (i) fraud prevention activities; or (ii) compliance with mandatory “Know Your Customer” procedures, in accordance with current regulations on anti-money laundering and counter-terrorism financing (“AML/CFT”).

• To comply with legal and regulatory obligations: Sixalime may use the Customer’s data to comply with requests from competent agencies and authorities, such as the Central Bank of the Argentine Republic (“BCRA”), the Financial Information Unit (“UIF”) and/or any other competent agency and/or authority before which Sixalime is a regulated entity.

• To legitimately exercise its rights: Sixalime may use Customers’ Personal Data as necessary to legitimately initiate judicial, administrative and/or arbitration proceedings arising from its commercial relationship with Customers, or to defend itself in such proceedings.

• Legitimate commercial purposes: Sixalime may use the Customer’s Personal Data to offer personalized products, services and/or offers. Sixalime may also use the Customer’s Personal Data to generate statistical information and perform data analysis to improve its products and services.

• To protect the legality of transactions: Sixalime may use the Customer’s data as necessary to monitor transactions carried out and ensure their legality.

6. DISCLOSURE OR TRANSFER OF DATA In principle, Sixalime does not disclose its Customers’ Personal Data, as it is used solely to manage the Data Subject’s registration on the platform and to enable use of the services provided by the Company through it.

If a disclosure occurs in the future, it will be carried out solely to comply with the Processing Purposes and/or purposes directly related to the legitimate interest of the transferor (Sixalime) and the transferee (third party), always with the Data Subject’s prior express consent. In such case, the Customer will be informed of the purpose of the disclosure and the identity of the transferee through the communication channels indicated in this Statement.

Notwithstanding the foregoing, it is clarified that, in exceptional cases and always in accordance with the Processing Purposes, Personal Data may be shared by Sixalime with:

(i) Service providers that provide services on behalf of Sixalime, such as hosting and/or cloud storage services, to the extent applicable.

(ii) Public agencies and/or authorities with which Sixalime is legally required to share such Personal Data, including but not limited to the BCRA, UIF, AFIP, ANSES, among others.

(iii) In the context of judicial proceedings or in compliance with a request from a competent authority.

(iv) Law enforcement bodies or other public officials when legitimately requested, under the guidelines of the LPDP.

(v) When Sixalime considers such disclosure necessary or advisable to avoid physical harm and/or economic losses.

(vi) In connection with an investigation of fraudulent or illegal activities, or activities suspected of being fraudulent or illegal.

(vii) Buyers in the event of a sale or transfer of all or part of Sixalime or its assets (including cases of restructuring, dissolution or liquidation).

In any event, Sixalime does not authorize the aforementioned third parties to reveal or disclose Customers’ Personal Data, except for uses strictly necessary for the provision of services and compliance with the Processing Purposes, or to comply with legal obligations.

Sixalime understands the importance of maintaining the confidentiality of all Personal Data that may be collected and respects the LPDP and its applicable regulations. Accordingly, Sixalime and all those involved in any stage of Personal Data Processing are bound by professional secrecy regarding such data, and the Company signs confidentiality agreements and implements policies and processes to guarantee the secrecy of the Personal Data it processes.

Furthermore, Sixalime will not internationally transfer the Personal Data it holds about its Customers. If a transfer becomes necessary for reasons external to the Company, it will always be carried out with the prior consent of the Data Subjects and in accordance with the guidelines established in the LPDP and the other applicable regulations, providing the highest levels of protection to safeguard the privacy and intimacy of such Customers.

7. DATA RETENTION Sixalime will retain and use its Customers’ Personal Data to the extent and for the time necessary to fulfill the service provided by the Company to Customers. Once that service has been fulfilled, such Personal Data will be immediately deleted by Sixalime from its databases.

If the Customer requests deletion or requests cancellation of their Platform account, the data will be deleted. In such case, the Customer will no longer be able to continue using the services provided by Sixalime.

If legal and/or regulatory obligations require Sixalime to retain the data for a longer period than stated above, Sixalime will retain Customers’ Personal Data after the Processing Purposes have been fulfilled and may use it to legitimately exercise its rights in judicial, administrative and/or other proceedings.

8. RIGHTS OF PERSONAL DATA SUBJECTS Customers have the following rights regarding their Personal Data:

8.1. Right to information Customers have the right to request information from the supervisory authority regarding the existence of files, registries, databases or data banks containing Personal Data, their purposes and the identity of their controllers.

8.2. Right of access Customers have the right to request that Sixalime provide access to their Personal Data processed and/or stored by Sixalime, as well as information about the manner in which Sixalime processes their Personal Data.

8.3. Right to rectification and/or updating If Customers consider that their Personal Data is incorrect or incomplete, they may request that Sixalime rectify, complete and/or update their Personal Data. They may also request that such Personal Data be kept confidential.

8.4. Right to deletion and/or restriction of processing Where applicable, Customers may request the deletion of their Personal Data or the restriction and/or limitation of its processing. Deletion will not proceed when it could cause harm to the legitimate rights or interests of third parties or when there is a legal obligation to retain the data, which will be duly communicated to Customers.

8.5. Right to data portability Customers have the right to request that Sixalime send them the Personal Data they provided within the framework of their relationship with the Company, or that was provided to Sixalime with their consent, in a structured, commonly used and machine-readable format. They also have the right to request the transfer of their Personal Data to a third party. If Customers request that Sixalime transfer Personal Data directly to a third party, such action may only be carried out if that third party has means that ensure Customers’ privacy and intimacy, in accordance with the levels of protection required for the transfer of Personal Data under the LPDP.

8.6. Right to object Customers have the right to object to the processing of their Personal Data by Sixalime and to Sixalime’s use of their Personal Data in accordance with the Processing Purposes. In such case, the Company will analyze the request and determine whether processing of such Personal Data may cease, as doing so could make it impossible to properly provide the service.

8.7. Right to withdraw consent Customers may withdraw their consent for the processing of their Personal Data by Sixalime at any time, even when such consent was given for the specific processing of that data. From that moment, Sixalime may no longer process their Personal Data.

8.8. Right to file a complaint with the supervisory authority Customers have the right to file complaints related to the processing of their Personal Data by Sixalime before the supervisory authority on the matter, according to the procedure set forth in the following section.

9. AREA RESPONSIBLE FOR HANDLING QUESTIONS, REQUESTS, COMPLAINTS AND/OR CLAIMS

9.1. Sixalime contact and internal procedure In all cases in which the Personal Data Subject has any question, comment or request regarding the use of their Personal Data and/or this Privacy Statement, or wishes to exercise any of their rights, they may contact Sixalime by sending an email to info@manteca.dev or by appearing in person at the following address: República de la India 2781, 1st floor, CABA, ZIP Code 1425.

In order to protect the Customer’s Personal Data against unauthorized access or alteration by third parties, all requests relating to personal information will be subject to verification of the identity of the requesting person, and the applicant may be required to provide a photo of the front and back of their DNI and a “selfie” holding it.

Upon receipt of the notice, Sixalime will process such request within 10 (ten) business days after receiving it and will send its response to the Data Subject through the contact channels provided in the notice.

Furthermore, any interested Customer who considers that Sixalime does not comply with this Privacy Statement or the applicable data protection laws with respect to their Personal Data may contact the personal data protection compliance officer appointed by Sixalime by sending an email to info@manteca.dev.

9.2. Inquiries and/or claims before the Agency for Access to Public Information Likewise, the Personal Data Subject may contact the Agency for Access to Public Information — the national enforcement authority for data protection matters — (the “AAIP”), whose contact details are listed below:

• Agency for Access to Public Information;

• Address: Av. Pte. Gral. Julio A. Roca 710, 3rd floor - Autonomous City of Buenos Aires; ZIP Code: C1067ABP;

• Email: accesoalainformacion@aaip.gob.ar;

• Website: www.argentina.gob.ar/aaip The AAIP, as the Supervisory Authority of the LPDP, is obliged to address complaints and claims submitted by Data Subjects whose rights are affected by non-compliance with the regulations in force on personal data protection.

10. COMMITMENT OF CUSTOMERS, SUPPLIERS AND PERSONNEL Customers and suppliers who contract with Sixalime, as well as Sixalime employees, must act in full compliance with this Privacy Statement and with the LPDP, its amending and regulatory rules, as well as any other regulations applicable to personal data.

Likewise, Sixalime, its suppliers and its Customers must adjust their conduct to the recommendations contained in AAIP Resolution 47/2018 for the processing and retention of personal data in computerized and non-computerized media, as well as any AAIP Resolutions that may be applicable (the “Resolutions”).

11. SECURITY OF CUSTOMERS’ PERSONAL DATA Sixalime will make its best efforts to maintain the security of its Customers’ personal information, taking into account the practical, technical and organizational internal measures necessary to ensure the security, integrity and confidentiality of the data, diligently seeking to prevent unauthorized access, destruction, use, modification or disclosure of data, in accordance with Article 9 of the LPDP, complementary regulations and, in particular, the recommendations contained in the Resolutions.

Sixalime’s Technology and Systems area is responsible for compliance with information security regulations through the security policies, rules, manuals and procedures approved for that purpose.

Accordingly, in order to guarantee the security of its Customers, Sixalime has implemented technical, physical and administrative security measures strictly designed to guarantee an adequate level of security to protect the Personal Data processed from the Customer and to ensure compliance with the legal obligations of security and confidentiality established by the LPDP and its regulatory rules. These measures are intended to protect the ongoing security and confidentiality of the Customer’s Personal Data. The Company continuously evaluates and improves these measures together with the expert group that carries out this task.

In addition, Sixalime recommends that the Customer take additional measures to protect their Personal Data, such as (i) installing antivirus programs; (ii) keeping them updated; (iii) closing browsers after use; (iv) safeguarding access data and passwords and changing them when necessary; and (v) regularly updating applications that may be linked to transactions carried out with the Company, to ensure that the latest security updates are available.

In any event, Sixalime does not authorize service providers that may be related to the provision of its services to reveal or disclose Customers’ Personal Data, except for uses strictly necessary for the provision of services on behalf of Sixalime or to comply with their legal obligations.

Accordingly, Sixalime understands the importance of maintaining the confidentiality of all Personal Data that may be collected and respects the LPDP and the regulations in force applicable to such data. The Company and all those involved in any stage of Personal Data Processing are bound by professional secrecy regarding such data, and therefore the Company enters into confidentiality agreements and implements policies and processes to guarantee the secrecy of the Personal Data it processes.

12. CONTROL AND CONTINUOUS IMPROVEMENT Sixalime performs internal controls to ensure compliance with these policies and to suggest possible changes to improve mechanisms for the collection, security and processing of personal data.

If this Privacy Statement is modified, the Customer will be notified through the usual communication channels provided by the Customer, such as email. The latest version of the Privacy Statement will always be published on the Platform.

13. GOVERNING LAW AND JURISDICTION This Privacy Statement and the facts and acts arising from it shall be interpreted in accordance with the laws of the Republic of Argentina. Any dispute arising from this Statement, including its existence, validity, interpretation, scope or compliance, shall be submitted to the jurisdiction of the National Commercial Courts seated in the Autonomous City of Buenos Aires, and the Customer expressly waives any other venue or jurisdiction that may apply.

14. EFFECTIVE DATE This policy is effective as of the date of its publication.


Last updated: June 2026