PERSONAL DATA PROTECTION POLICY

PERSONAL DATA PROTECTION POLICY (U.S. COMPLIANT)

Sugar Republic Limited (“we,” “us,” or “our”) values your trust and privacy. We are dedicated to safeguarding your personal information in compliance with applicable United States federal and state data protection laws, including (where applicable) the California Consumer Privacy Act (CCPA) and other relevant legislation.

This policy (“the Policy”) explains why and how Sugar Republic Limited may collect, process, and protect your personal data, as well as the rights and choices you may have regarding such information.

1. OUR COMMITMENT TO PERSONAL DATA PROTECTION

In order to provide the highest level of protection for your personal data, Sugar Republic Limited abides by the following guiding principles consistent with U.S. privacy laws and industry best practices:

1. Lawfulness, Fairness, and Transparency

• We collect and process your personal information in a lawful, fair, and transparent manner.

2. Purpose Limitation

• We use your personal data solely for specific, disclosed purposes and do not process it in ways that contradict those purposes without your knowledge or consent.

3. Data Minimization

• We collect only the data necessary for the stated purposes, ensuring that any additional collection is minimized.

4. Retention Limitation

• We retain your personal data only as long as needed to fulfill the intended business or legal requirements, in accordance with applicable federal and state laws.

5. Accuracy

• We strive to maintain up-to-date and accurate information. Should any data be found inaccurate or outdated, we make every reasonable effort to correct or delete it promptly.

6. Security

• We implement appropriate technical and organizational safeguards (encryption, access controls, employee training) to prevent unauthorized access, disclosure, alteration, or destruction of your personal information.

Additionally, “privacy by design” and “privacy by default” guide our internal processes. Where we engage service providers or partners, our contractual agreements require them to maintain stringent standards for data privacy and security.

2. TYPES OF PERSONAL DATA WE COLLECT

Depending on how you interact with us (e.g., visiting our website, submitting inquiries, or purchasing our products), we may collect the following categories of personal information:

Identifiers: Your name, email address, phone number, physical address.

Online Activity: IP address, browser type, operating system, browsing history on our site, and other details collected through cookies or similar technologies.

Commercial Information: Records of products or services purchased.

Communications: Inquiries or messages you send us through online forms or email.

Other Information: Any additional information you choose to provide, or that we may need to fulfill legal, contractual, or safety obligations.

3. PURPOSES AND LEGAL BASES FOR PROCESSING

We only process personal data for legitimate business or legal reasons, which may include:

Responding to inquiries: When you contact us, we use your data to address questions or provide requested information.

Fulfilling orders and providing services: We use your data to process orders, coordinate logistics, and deliver sugar products or related services.

Marketing and communications: With your consent (where required by law), we may send you promotional materials, newsletters, or updates about our products and services.

Operational and administrative purposes: This includes managing our website, conducting internal analytics, and ensuring the security and functionality of our systems.

Compliance with legal obligations: We may process your information to fulfill obligations under U.S. federal or state law (e.g., responding to lawful requests by public authorities).

4. YOUR PRIVACY RIGHTS

Depending on your state of residence and the nature of your interactions with Sugar Republic Limited, you may have certain rights regarding your personal data. For example, if you are a California resident, you may have the right to:

Know what personal information we collect, use, disclose, or sell (if applicable).

Access personal data we hold about you.

Request Deletion of certain personal data, subject to legal exceptions.

Opt-Out of the sale of your personal data (if any).

Non-Discrimination in terms of price or service if you choose to exercise your privacy rights.

Other states may provide similar or additional rights. We encourage you to contact us to discuss any privacy-related concerns or to assert any of these rights. We will respond in accordance with applicable state and federal laws.

5. HOW TO EXERCISE YOUR RIGHTS OR CONTACT US

Should you wish to access, modify, or delete your personal information—or if you have any questions or concerns about this Policy—you can reach our Data Protection Officer (DPO) or privacy team at:

Email: ContactPrivacy@SugarRepublicLtd.com

When submitting a request, please include:

Your Full Name

Nature of Your Request (e.g., access request, deletion request)

Any Relevant Details (such as the specific data you are requesting or wishing to update)

Proof of Identity (if required by law)

If you designate an authorized agent, please ensure they provide a valid power of attorney or relevant documentation verifying their authority.

6. DATA RETENTION AND DELETION

We retain personal data for only as long as necessary to fulfill the purposes outlined in this Policy or as required by law. Once data is no longer required, we securely delete or anonymize it. Retention times may vary based on contractual, legal, or operational obligations.

7. DATA SECURITY

We use industry-standard security measures to protect your personal data from unauthorized access, alteration, or disclosure. Measures include:

Encryption of data in transit (HTTPS/TLS) and at rest, where appropriate.

Access Controls ensuring only authorized personnel can access sensitive information.

Regular Security Assessments (e.g., vulnerability scans and penetration tests).

Employee Training regarding the importance of confidentiality and privacy.

Despite our efforts, no method of electronic transmission or storage can be 100% secure. Should a data breach occur, we will follow all applicable U.S. laws and regulations for notification and remediation.

8. COOKIES AND SIMILAR TECHNOLOGIES

Sugar Republic Limited uses cookies and similar tracking technologies to analyze website traffic, improve user experience, and for other operational purposes. You can manage your cookie preferences through your browser settings. Note that disabling cookies may affect certain functionalities of our site.

9. CHANGES TO THIS POLICY

We reserve the right to update or modify this Policy at any time to reflect changes in our business practices, technology, or legal obligations. When we do, we will revise the “Last Updated” date below. We encourage you to review this Policy periodically for the most current information on our privacy practices.

Last Updated: 1/1/2025

By using our website or submitting personal data to Sugar Republic Limited, you acknowledge that you understand and agree to the collection, processing, and sharing of your personal data as described in this Policy and in accordance with applicable U.S. laws.

Sugar Republic Limited

Committed to responsibly handling your data and safeguarding your privacy.