DATA PROCESSING AGREEMENT Marketing Express — Tradix app s.r.o. Version 2026-10-04, effective from 4 October 2026 1. PARTIES AND CONCLUSION 1.1 This agreement is concluded between the customer who is a business and the controller of the personal data contained in the materials (the “Controller”) and Tradix app s.r.o., Company ID (IČO) 24926370, with its registered office at Jana Zajíce 924/16, Bubeneč, 170 00 Praha 7, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 446092 (the “Processor”). 1.2 This agreement forms part of the contract for the provision of services under the terms and conditions (https://marketingexpress.app/legal/terms) and is concluded together with it, i.e. when the business customer submits their first order. In matters of personal data protection, this agreement takes precedence over the terms and conditions. 2. SUBJECT MATTER, NATURE, PURPOSE AND DURATION OF PROCESSING 2.1 The Processor processes the personal data contained in the materials, briefs and brand information entrusted to it by the Controller, solely for the purpose of creating, revising and delivering results according to the Controller’s orders. 2.2 Processing includes storage, viewing, modification, analysis and processing with AI tools, inclusion in the result, making the data available to the Controller, and erasure. 2.3 Processing lasts for the duration of the services contract and thereafter until the data are erased under Article 8. 3. CATEGORIES OF DATA AND DATA SUBJECTS 3.1 Categories of personal data: likeness (photographs, video), voice, name and other data that appear in the materials, for example contact details or information about a job position. 3.2 Categories of data subjects: employees and associates of the Controller, its customers, business partners and other persons captured in the materials. 3.3 The Processor is not to process special categories of personal data (Art. 9 GDPR) or data relating to criminal offences. The Controller includes such data in the materials only where necessary and where it has a legal basis for doing so. 4. INSTRUCTIONS AND OBLIGATIONS OF THE CONTROLLER 4.1 The Processor processes personal data only on documented instructions from the Controller. Instructions are in particular the order, its brief and the messages on the order. If the Processor considers that an instruction infringes data protection legislation, it informs the Controller without undue delay. 4.2 The Controller is responsible for having a legal basis for processing the personal data, for having fulfilled its information obligations towards the data subjects and for having their consent to the use of their likeness and voice where required. 5. OBLIGATIONS OF THE PROCESSOR 5.1 The Processor: a) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality; b) takes the technical and organisational measures under Art. 32 GDPR set out in Article 10; c) assists the Controller by appropriate measures in fulfilling its obligation to respond to requests for exercising data subjects’ rights; d) assists the Controller in complying with the obligations under Art. 32 to 36 GDPR, in particular in notifying security breaches and in impact assessments, taking into account the nature of processing and the information available to the Processor; e) makes available to the Controller the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for audits or inspections conducted by the Controller or an auditor mandated by the Controller who is bound by confidentiality, subject to at least 30 days’ prior notice, during working hours and at the Controller’s expense. 6. SUB-PROCESSORS 6.1 The Controller gives the Processor general authorisation to engage sub-processors. Their current list is in Article 5 of the privacy policy (https://marketingexpress.app/legal/privacy). 6.2 The Processor informs the Controller by e-mail or on the website at least 14 days in advance of any intended addition or replacement of a sub-processor. The Controller may object to the change on reasonable grounds; if the parties do not reach agreement, the Controller may terminate the services contract without penalty. 6.3 The Processor imposes on sub-processors the same data protection obligations as it has itself under this agreement and is responsible for their fulfilment. 7. TRANSFERS TO THIRD COUNTRIES 7.1 Some sub-processors process data outside the EU, in particular in the USA. Transfers are covered by the Commission’s adequacy decision (EU–US Data Privacy Framework) or by standard contractual clauses under Implementing Decision (EU) 2021/914, as set out in the privacy policy. 8. SECURITY BREACHES AND ERASURE 8.1 If the Processor becomes aware of a personal data breach, it notifies the Controller without undue delay and no later than 48 hours after becoming aware of it. It states the nature of the breach, the categories and approximate number of the data records and data subjects concerned, the likely consequences and the measures taken. 8.2 When the provision of services ends, or on the Controller’s instruction, the Processor erases the personal data. The Controller may download the results and materials from its account beforehand. Deleting the account erases the data immediately; copies in the providers’ backups expire in their normal cycle. Only data that the Processor must retain by law may be kept. 9. LIABILITY 9.1 The liability of the parties is governed by Art. 82 GDPR and by the provisions of the terms and conditions for businesses. 10. TECHNICAL AND ORGANISATIONAL MEASURES – encryption of all communication (HTTPS/TLS) and non-public file storage with access tied to the account; – passwords stored only as a salted cryptographic hash (scrypt); a separate administration password; blocking of repeated login attempts; – access to the data only for persons who strictly need it to process an order; – working copies of materials on the processing computer are deleted after each order is completed; files at the generative model provider (fal.ai) are deleted automatically within 24 hours; – selection of suppliers with adequate data protection guarantees and agreements under Art. 28 GDPR; – the customer can export their data and delete their account together with the data at any time. 10.1 Contact for personal data protection matters: support@tradixapp.com. This agreement is effective from 4 October 2026 (version 2026-10-04).