Privacy and Data Security Annex

This English text is a translation provided for convenience. The Hebrew version is the legally binding one; in the event of any conflict between this translation and the Hebrew version, the Hebrew version prevails. עברית

This Annex shall constitute an integral part of the Terms of Use, the Standard Terms for Vendors, and any additional terms applicable to event vendors using The Runup platform to connect event organizers and event vendors, and to manage planning, customer management, and operations processes in the events field (the "Agreement" and the "Services" respectively), between the Event Vendor and The Runup LTD, Company No. 517340683 ("The Runup" or the "Company").

This Annex describes the manner in which The Runup will process information in the framework of providing the Services to the Event Vendor.

Approval of this Annex may be granted by electronic means, including by checking an approval box, approving on a registration screen, continuing to use the Platform as a vendor after this Annex has been presented, or by any other electronic method enabled by the Company. Such approval shall constitute binding consent to this Annex as if signed by hand.

1. Definitions

1.1. "Privacy Protection Law" - the Privacy Protection Law, 5741-1981.

1.2. "Data Security Regulations" - the Privacy Protection Regulations (Data Security), 5777-2017.

1.3. "Regulations on Transfer of Data Abroad" - the Privacy Protection Regulations (Transfer of Data to Databases Outside State Borders), 5761-2001.

1.4. "Information" - as the definition of "Personal Information" (or "Information") in the Privacy Protection Law.

2. The Information and the Purposes of Its Use

2.1. Within the framework of providing the Services to the Event Vendor by The Runup under the Agreement, The Runup may process information that reaches it from the Event Vendor or to which the Event Vendor grants it access regarding the Event Vendor's employees and/or authorized users on its behalf who use the Services, as well as information regarding potential customers of the Event Vendor, whether it is information that the Event Vendor uploaded or connected from its own external sources or leads delivered to the vendor through the Platform, all as entered, uploaded, or determined by the Event Vendor within the framework of using the Services.

2.2. The Personal Information processed regarding potential customers may include name, contact details, event details, correspondences, and messages (including through third-party applications and services connected to the Services), evaluation of the potential customer's level of interest based on their activity in the system and other platforms using artificial intelligence tools, and any additional information transferred about them by the Event Vendor ("Potential Customers Data").

2.3. The Event Vendor allows The Runup to access employee information and Potential Customers Data and to use it solely for the purposes specified in this Annex.

2.4. The Runup shall be entitled to process employee information and Potential Customers Data for the purpose of providing the Services to the Event Vendor in accordance with the Agreement, as well as for any other purpose permitted to it under applicable law and/or the Agreement.

2.5. The Runup as a Controller of Potential Customers Data. Without derogating from the foregoing, it is clarified that the Company shall be entitled to use Potential Customers Data for the purpose of formulating insights, metrics, and industry comparisons, and for this purpose, it shall be defined as an independent controller, and the provisions of this Annex shall not apply to it. The Event Vendor undertakes to obtain all authorizations and consents required by law for uploading the Potential Customers Data that was provided by it, uploaded by it, or to which access was granted to the Company on its behalf to the Platform and for its processing as aforesaid, and to indemnify the Company for any claim or damage resulting from the breach of its obligations under this section.

3. Duration of Data Retention

3.1. The duration of the engagement between the parties is set forth in the Agreement.

3.2. Subject to the provisions of applicable law and the Agreement, The Runup shall delete the information that reached it or was created by it in connection with the provision of the Services within a reasonable time from the date of termination of the Agreement period. The Runup shall provide the Event Vendor with confirmation within a reasonable time after performing such deletion.

3.3. Notwithstanding the foregoing, The Runup is entitled to retain information collected by it within the framework of providing the Services for the purpose of defending against claims, preventing fraud, complying with legal requirements, and for any other purpose permitted to it under applicable law.

4. Data Subjects' Rights

4.1. In the event that The Runup receives a request from a data subject regarding information about them processed by it for the Event Vendor in connection with the Services (including a request to inspect or correct the information), The Runup shall update the Event Vendor thereof within a reasonable time, provided there is no legal impediment to doing so.

4.2. Generally, the handling of such requests shall be carried out by the Event Vendor as the database owner/controller (as applicable), and The Runup shall assist and cooperate in a reasonable manner, to the extent required to respond to the request and in accordance with applicable law.

4.3. Notwithstanding the foregoing, The Runup is entitled to act independently in connection with these requests in order to comply with the legal provisions applicable to it, including the schedules set forth therein.

5. Confidentiality

5.1. The Runup and those authorized by it to access the information shall maintain the confidentiality of information that reaches them by virtue of their role in connection with the Agreement and shall not transfer it to a third party unless required for the purpose of providing the Services, at the request of the Event Vendor, pursuant to a court order, or by law.

5.2. Prior to receiving access to personal information within the framework of providing the Services to the Event Vendor, The Runup shall have its authorized access-holders sign a confidentiality undertaking document.

6. Subcontractors

6.1. The Runup may use the services of subcontractors as part of its provision of the Services.

6.2. To the extent that The Runup processes information under the Agreement through its subcontractors, it shall enter into an agreement with them that includes reference to the matters detailed in this Annex.

7. Transfer of Data Outside the State of Israel

7.1. The Event Vendor authorizes The Runup to transfer the Event Vendor's information, including through its affiliates and subprocessors, to any country in which they operate, including outside the State of Israel.

7.2. Without derogating from the foregoing, the Event Vendor undertakes to inform the relevant data subjects of the data processing regarding the transfer of information about them abroad, including to countries where privacy protection laws provide a lower level of protection than that under Israeli law.

8. Data Security

8.1. Within the framework of providing the Services, The Runup undertakes to act in accordance with the data security provisions set forth in the Privacy Protection Law and the regulations thereunder, all with the necessary modifications under the circumstances.

8.2. Upon the Event Vendor's written request, The Runup shall provide the Event Vendor with information regarding the performance of its obligations under the Data Security Regulations and this Annex, no more than once every 12 months.

8.3. The Runup shall report to the Event Vendor within a reasonable time after becoming aware of any case in which a severe security incident, as defined in the Data Security Regulations, occurred in its systems, to the extent the incident is relevant to the information processed for the Event Vendor under the Agreement.

8.4. The Runup undertakes to separate, to a reasonable and acceptable extent and degree, the information systems used by it for the purpose of providing the Services to the Event Vendor from other systems.

8.5. The Runup shall cooperate with the Event Vendor in a reasonable manner to enable it to audit its activities under the provisions of this Annex. Such audit shall be carried out in coordination in advance with The Runup and during customary working hours, shall relate to the actions of The Runup in connection with the processing of information by it under the Agreement for the Event Vendor, and shall be performed no more than once every 12 months.