Data Protection Statement for Cometgaze Limited trading as PinpointAI Last Updated: 19th November 2024

ABOUT US

This Data Protection Statement applies to Cometgaze Limited Trading as PinpointAI. Address: 8 Terenure Place Dublin 8, Ireland Email: dpo@pinpointai.com Our website is www.pinpointai.com This Data Protection Statement applies to PinpointAI. References to “We”, “Us” the “Company” and “PinpointAI” shall apply to PinpointAI which is processing your Personal Data. PinpointAI has global enterprise clients in predominantly, but not limited to, the Financial, Real Estate, Security, Travel, and Healthcare sectors. With these clients PinpointAI processes various types of data including pseudonymised, proprietary, market, synthetic, and public data. The data is processed by way of ingestions, indexing, data remediations and inference. PinpointAI’s focus is to always maintain fairness and avoid unintended bias. We promise to ensure that AI ethics and trustworthy AI is the absolute priority for PinpointAI and all the technology we create. AI has unlimited potential and PinpointAI are committed to deploying it responsibly. In order to provide our services, we need to process Personal Data. We are committed to protecting the rights and personal data of individuals in accordance with data protection legislation including the General Data Protection Regulation in Europe (the “GDPR”).

CONTACT DETAILS

We have appointed a Data Protection Officer. If you have any questions about this Data Protection Statement or the way in which your Personal Data is being used please contact: The Data Protection Officer Address: 68 Merrion Square Dublin 2, Ireland Email: dpo@pinpointai.com

THE PURPOSE OF THIS DATA PROTECTION STATEMENT

This Data Protection Statement applies to Personal Data. The definition of Personal Data is as follows: “Personal Data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. This Data Protection Statement describes our approach to data protection and sets out the basis on which any Personal Data we collect from you, or that you provide to us, will be used by us where we are controllers of that Personal Data for the purposes of the GDPR. Please read this Data Protection Statement carefully to understand our views and practices regarding the Personal Data we collect, as controllers under the GDPR, and how we will treat it.

WHO THIS DATA PROTECTION STATEMENT APPLIES TO

This Data Protection Statement provides specific information relating to the following individuals whose Personal Data we process: 1. Business contact data including our customers, suppliers, partners, shareholders, investors and business prospects “Business Contacts”; 2. Recruitment data which is covered under a separate Recruitment Data Protection Statement; and 3. Users/guests of our Website “Website Users”. Personal Data of employees of the Company is dealt with in a separate internal Data Protection notice.

SOURCES OF PERSONAL DATA BUSINESS CONTACT PERSONAL DATA

We collect Business Contact Personal Data from our business contacts including – customers, suppliers, partners, shareholders, board members, and business prospects. We source Business Contact Personal Data in order to serve the business relationship. We will only ever source Personal Data that is necessary and in a way that would be generally expected. We receive Personal Data about Business Contacts from a variety of sources, as follows: ● The Personal Data is often provided by the Business Contact as part of the business relationship; ● The Personal Data may be collected from public sources like LinkedIn; ● The Personal Data may be collected indirectly from another person within the company of the Business Contact; ● The Personal Data may be collected through our website; www.pinpointai.com ● The Personal Data may be collected indirectly from a website or from a third party.

WEB DATA

We may collect Website User Personal Data from all visitors to our website in order to improve our services and develop the Website. For more details please refer to our Cookie Notice.

CATEGORIES OF PERSONAL DATA

We process the following categories of Personal Data. For each category we have included an example of the type of Personal Data that may be part of that category:

OUR LEGAL BASIS FOR PROCESSING PERSONAL DATA

We process all Personal Data lawfully and in accordance with the requirements of the law. The GDPR sets out the legal grounds for processing Personal Data, which is either in line with, or more stringent than, local laws. By following the GDPR, we are ensuring that the protection of Personal Data is of utmost importance. When the Company processes Personal Data, it is generally on one of the following legal basis: 1. CONTRACT We will process Personal Data where necessary to perform our obligations relating to or in accordance with any contract that we may have with you or to take steps at your request prior to entering into that contract (e.g. our Client Services Agreement). 2. CONSENT For certain processing activities we may rely on your consent. Where we are unable to collect consent for a particular processing activity, we will only process the Personal Data if we have another lawful basis for doing so. You can withdraw consent provided by you at any time by contacting us at dpo@pinpointai.com

LEGITIMATE INTEREST

At times we will need to process your Personal Data to pursue our legitimate business interests, for example for administrative purposes, to collect debts owing to us, to provide information to you, to expand our business opportunities, to operate, evaluate, maintain, develop and improve our websites and services or to maintain their security and protect intellectual property rights. We will not process your Personal Data on a legitimate interest basis where the impact of the processing on your interests or fundamental rights and freedoms outweigh our legitimate interests. You may object to any processing we undertake on this basis. If you do not want us to process your Personal Data on the basis of our legitimate interests, contact us at dpo@pinpointai.com and we will review our processing activities.

LEGAL OBLIGATION

If we have a legal obligation to process Personal Data, such as the payment of taxes, we will process all applicable types of Personal Data listed in section 6 on this legal ground.

OUR PROCESSING ACTIVITIES

We use your Personal Data to provide you with our services and to assist us in the operation of our Company. Under data protection law, we must ensure that the purpose of processing is clear. We have set out below the general purpose of processing, the categories of Personal Data processed and the related lawful basis for processing.

DISCLOSURE OF PERSONAL DATA

In certain circumstances, we may disclose Personal Data to third parties as follows:

● to business partners and subcontractors for the performance of any contract relating to our services, including email, Skype, Communication Platforms, Customer Relationship Management system, web developers, payment processors, data aggregators, hosting service providers, external consultants, auditors, IT consultants and lawyers;

● to analytics and search engine providers that assist us in the improvement and optimisation of the Website;

● to the HSE (or any health authority) to facilitate any pandemic contact tracing activity; ● if we or substantially all of our company is merged with another company or acquired by a third party, in which case Personal Data held by us will be one of the transferred assets; ● if we are under a duty to disclose or share Personal Data in order to comply with any legal obligation (including tax, audit or other authorities), or in order to enforce or apply any contracts that we have;

● to protect our rights, property, or safety, or that of our Candidates or Business Contacts or others. This may include exchanging Personal Data with other companies and organisations for the purpose of fraud protection. When we engage another organisation to perform services for us, we may provide them with information including Personal Data, in connection with the performance of those functions. We do not allow third parties to use Personal Data except for the purpose of providing these services.