GDPR

EAS Compliance

GDPR Compliance Statement

EAS is committed to protecting personal data and to processing it in accordance with Regulation (EU) 2016/679 (the “GDPR”). This statement explains how EAS meets its obligations as a data controller. It is a statement of compliance and does not create obligations or liabilities for any other party.

EAS GDPR Compliance Statement v1.0 Approved 30 July 2026 We open the world for commerce
1

Document control

Version 1.0
Status Approved
Document owner Chief Operating Officer, EAS
Approver [Management — on approval]
Date issued 30 July 2026
Next review July 2027
Applies to All personal data processed by EAS as a controller.
2

Contents

3

Data controllers

The following EAS group companies act as independent data controllers for the personal data described in this statement:

Entity Registration and address Role
Easy Access System Project OÜ Reg. 16244595 — Mustamäe tee 50, 10621 Tallinn, Estonia Controller; provider of the EAS Solution
Neman OÜ Reg. 14592263 — Mustamäe tee 50, 10621 Tallinn, Estonia Controller; IOSS intermediary under Directive 2006/112/EC
Contact for data-protection matters: [email protected] .
4

Our role

EAS acts as an independent controller within the meaning of Article 4(7) GDPR. It determines the purposes and means of its processing principally by reference to its own legal obligations under Union and Estonian law. Where a merchant provides personal data to EAS, the merchant is a separate controller in its own right; EAS is not a processor acting on its instructions.

5

Personal data we process

  • Contact details — name, email address, telephone number.
  • Business information — company name, registration number, address.
  • Account details — login credentials, account usage and service preferences.
  • Financial data — payment and invoicing details.
  • Technical data — IP address, browser type, cookies and similar information.
  • Transaction and fiscal data — order and shipment details, VAT treatment, and, for customs, sender data and identifiers such as IOSS number and EORI.
6

Purposes and lawful bases

  • Legal obligation (Art. 6(1)(c)) — VAT, IOSS and OSS reporting and filing, and statutory accounting and record-keeping.
  • Performance of a contract (Art. 6(1)(b)) — providing the EAS Solution and Services requested.
  • Legitimate interests (Art. 6(1)(f)) — maintaining the security of systems and improving services.
  • Consent (Art. 6(1)(a)) — optional cookies, which may be withdrawn at any time.
7

Data sharing

EAS shares personal data only where necessary and only with recipients bound by appropriate confidentiality and data-protection obligations: tax and customs authorities where required by law; appointed fiscal representatives and customs agents; and its processors under written contracts meeting Article 28 GDPR — Hetzner (hosting, Germany) and Amazon Web Services (backup, AWS eu-central-1, Frankfurt, Germany), both within the EU.

8

Retention and deletion

EAS keeps personal data only as long as necessary and no longer than the law requires. Certain fiscal records are subject to mandatory statutory retention:

Records Retention period Retention begins
IOSS and OSS records 10 years End of the year of the transaction
UK VAT records 6 years End of the relevant VAT period
Estonian accounting records 7 years End of the financial year
Other personal data As long as necessary for the purpose From last activity or account closure

When a retention period ends, personal data is securely deleted or irreversibly anonymised.

9

International transfers

EAS processes personal data within the European Union and the United Kingdom only. EU-to-UK transfers rely on the European Commission adequacy decisions for the United Kingdom. EAS does not transfer personal data to any other third country without an adequate safeguard under Chapter V GDPR.

10

Security

EAS applies appropriate technical and organisational measures under Article 32 GDPR, including:

  • Encryption of personal data in transit (TLS 1.2/1.3) and at rest (AES-256).
  • Multi-factor authentication, role-based access control and least privilege.
  • Network controls and monitoring with alerting.
  • Logging of data access, modification and deletion.
  • Regular data audits and security reviews.
  • Confidentiality undertakings for all authorised personnel.
11

Your rights

Subject to the conditions in the GDPR, individuals have the right to request access to their personal data, and to request its rectification, erasure, restriction or portability, to object to certain processing, and to withdraw consent. To exercise any of these rights, contact [email protected]. EAS responds within the time limits set by the GDPR.

12

Complaints

Individuals may lodge a complaint with a supervisory authority. The lead supervisory authority for EAS is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. Individuals may also complain to the authority in their country of residence.

13

Updates

EAS keeps this statement under review and updates it to reflect changes in its processing or in the law. The version and date are shown in the document control table.

—

Document history

Version Date Author Description
1.0 30 July 2026 EAS Initial issue.