STRATMONT GLOBAL

PRIVACY POLICY

How Stratmont Global collects, uses and protects your personal data when you use our website and contact us about our commodity-intermediation services. Last updated: 23 June 2026

CONTENTS ==================================================================================== 1. Introduction 2. Who We Are and How to Contact Us 3. The Personal Data We Collect and Its Sources 4. How and Why We Use Your Personal Data (Purposes and Legal Bases) 5. No Solely Automated Decision-Making 6. Who We Share Your Personal Data With 7. International Transfers of Personal Data 8. How Long We Keep Your Personal Data 9. Your Data-Protection Rights 10. Security of Your Personal Data 11. Business Users and Children 12. Important Note on Sensitive and Third-Party Data 13. Changes to This Privacy Policy 14. Governing Law

1. Introduction

This Privacy Policy explains how Stratmont Global ("Stratmont Global", "we", "us" or "our") collects, uses, shares and protects your personal data when you visit https://stratmontglobal.com (the "Website"), submit an enquiry through our contact form, or otherwise correspond with us by email or telephone.

Stratmont Global is an independent advisory and intermediation business operating in international commodity and raw-materials markets (metals, energy and soft commodities). We act solely as an independent intermediary, introducer and adviser that facilitates communication and coordination between counterparties. We are not a principal, buyer, seller, broker-dealer, bank, financial institution, payment institution, e-money or money-services business; we do not take title to goods, hold or transmit client funds, or issue, confirm or guarantee any financial instrument. Our services are aimed exclusively at businesses and the professionals who represent them.

We are committed to protecting your personal data and to handling it in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), the Irish Data Protection Act 2018, and the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011) (the "ePrivacy Regulations").

This Privacy Policy should be read together with our Cookie Policy and our Terms and Conditions. Where this Policy describes the use of cookies and similar technologies, further detail is set out in the Cookie Policy.

2. Who We Are and How to Contact Us

The data controller responsible for your personal data is Oksana Kholieva, an individual trading as Stratmont Global — a business name registered in Ireland under the Registration of Business Names Act 1963 (Registered Business Name No. 786173), with a principal place of business at 40 Mill Street, Baltinglass, Co. Wicklow, W91 DK64, Ireland.

If you have any questions about this Privacy Policy, wish to exercise your data-protection rights, or have any concerns about how we handle your personal data, you can contact us using the following details:

• Email: Info@stratmontglobal.com (please use this address for all privacy and data-subject requests)

• Telephone: +353 89 605 2254

• Business hours: Monday to Friday, 08:00–18:00 CET

We have not appointed a dedicated Data Protection Officer, as we are not required to do so. Privacy enquiries are handled by our management using the contact details above.

3. The Personal Data We Collect and Its Sources

We collect and process the following categories of personal data. In most cases you provide this data to us directly; some technical data is collected automatically when you use the Website, as described below.

3.1 INFORMATION YOU PROVIDE THROUGH THE CONTACT FORM

Our contact form is the principal way in which you provide personal data to us. The fields are:

• Full name

• Company

• Email address

• Counterparty category (a dropdown selection: "Buyer / End-user", "Seller / Producer" or "Other")

• Mandate brief — a free-text field in which you may describe your cargo, routes and commercial needs

The Mandate brief is a free-text field. Please provide only the information that is necessary to enable us to understand and respond to your enquiry. Please do not submit unnecessary sensitive, confidential or third-party personal information through this field (see Section 12 below).

Providing this information is not a statutory or contractual requirement, and you are under no obligation to provide it. However, if you do not provide the information requested in the contact form (or the equivalent information by email or telephone), we may be unable to respond to your enquiry or to discuss our services with you.

3.2 CORRESPONDENCE

If you contact us by email or telephone, we collect the content of that correspondence, including any information you volunteer, and a record of our communications with you.

3.3 TECHNICAL AND USAGE DATA (COLLECTED AUTOMATICALLY)

When you use the Website, we and our service providers automatically collect certain technical and usage data, including:

• your IP address and approximate (derived) location;

• your device type, browser type and operating system;

• the referring URL;

• the pages and areas of the Website you view, and the time and date of your visit; and

• on-page interactions, such as clicks, scrolling and navigation.

3.4 ANALYTICS DATA

We use a first-party, privacy-oriented analytics tool called "Flock" (loaded from /~flock.js and proxied via /~api/analytics) to measure how our Website is used. This generates aggregated usage statistics and associated identifiers. We only deploy this tool where you have given your consent via our cookie banner. It does not operate, and no related identifiers are set, unless and until you consent, and you may withdraw your consent at any time (see our Cookie Policy).

3.5 SESSION-REPLAY AND ERROR-DIAGNOSTICS DATA

We use a session-recording and error-diagnostics tool (based on the rrweb library, loaded via /__l5e/events.js). On a sampled basis — approximately 10% of sessions, plus sessions in which a crash or error occurs — this tool records a reconstruction of page interactions such as clicks, scrolling and navigation in order to help us diagnose errors and improve the usability of the Website. Text you type into form fields is masked and is not captured by this tool. We only deploy this tool where you have given your consent via our cookie banner. It does not operate, and no related identifiers are set or recordings made, unless and until you consent, and you may withdraw your consent at any time. We consider this processing to be privacy-sensitive and we therefore disclose it to you plainly here and in our Cookie Policy.

3.6 COOKIES AND SIMILAR TECHNOLOGIES

We use a small number of cookies and similar technologies. Some of these are strictly necessary for the Website to function and are therefore not subject to consent — in particular, browser sessionStorage used to preserve your scroll position and router state during your visit, and a stored preference recording your chosen language (EN/FR/DE/RU). Other technologies — namely the identifiers set by our analytics and session-replay tools — are non-essential and are set only with your consent. Full details, including their purpose, type, duration and how to manage or withdraw consent, are set out in our Cookie Policy.

4. How and Why We Use Your Personal Data (Purposes and Legal Bases)

Under the GDPR, we must have a valid legal basis (a "lawful basis") for each purpose for which we process your personal data. The table below sets out each purpose and the corresponding lawful basis under Article 6(1) of the GDPR.

• Responding to your enquiries, discussing and providing our intermediation and advisory services, and taking steps at your request prior to entering into any contract - Legal basis (Article 6(1) GDPR): Article 6(1)(b) (performance of a contract or pre-contractual steps) and/or Article 6(1)(f) (our legitimate interests in operating and growing our business)

• Managing our business relationship with you and conducting business-to-business communications - Legal basis (Article 6(1) GDPR): Article 6(1)(f) (legitimate interests)

• Maintaining the security, integrity and proper functioning of the Website, and preventing fraud and misuse - Legal basis (Article 6(1) GDPR): Article 6(1)(f) (legitimate interests)

• Setting non-essential cookies and operating analytics and session-replay tools (which are activated only after, and for as long as, you have given consent) - Legal basis (Article 6(1) GDPR): Article 6(1)(a) (consent), which is required under the ePrivacy Regulations and may be withdrawn at any time

• Complying with our legal and regulatory obligations (for example, applicable anti-money-laundering and sanctions obligations, record-keeping, and responding to lawful requests from authorities) - Legal basis (Article 6(1) GDPR): Article 6(1)(c) (compliance with a legal obligation)

  • Establishing, exercising or defending legal claims
  • Legal basis (Article 6(1) GDPR): Article 6(1)(f) (legitimate interests)

Where we rely on legitimate interests, we have carried out a balancing exercise to ensure that our interests are not overridden by your interests or fundamental rights and freedoms. You have the right to object to processing based on legitimate interests (see Section 9). You may request further information about our legitimate-interests assessments by contacting us at Info@stratmontglobal.com. Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

5. No Solely Automated Decision-Making

We do not make decisions about you that are based solely on automated processing (including profiling) and that produce legal effects concerning you or that similarly significantly affect you, within the meaning of Article 22 of the GDPR.

We do not seek or intentionally collect special categories of personal data (sometimes called "sensitive" data), such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, or trade-union membership.

6. Who We Share Your Personal Data With

We do not sell your personal data, and we do not share it with third parties for their own independent marketing purposes. We share personal data only with the categories of recipients set out below, and only as necessary for the purposes described in this Policy.

6.1 SERVICE PROVIDERS (PROCESSORS AND SUB-PROCESSORS)

We engage trusted service providers who process personal data on our behalf and under our instructions. These act as our data processors (or sub-processors) and are bound by written contracts that include the data-protection terms required by Article 28 of the GDPR. They include:

• Hosting and website platform: our Website is built and served on the Lovable web platform, and static assets are served via a content delivery network (Cloudflare R2);

• Analytics provider: the provider of our first-party analytics tool ("Flock");

• Session-replay provider: the provider of our session-recording and error-diagnostics tool (rrweb-based);

• Email provider: the provider of our email and correspondence services.

6.2 PROFESSIONAL ADVISERS

We may share personal data with our professional advisers (such as lawyers, accountants, insurers and auditors) where necessary for the management of our business and the establishment, exercise or defence of legal claims.

6.3 AUTHORITIES AND OTHER THIRD PARTIES WHERE LEGALLY REQUIRED

We may disclose personal data to courts, regulators, law-enforcement agencies or other public authorities where we are required to do so by law, or where disclosure is necessary to comply with a legal or regulatory obligation, to respond to a lawful request, or to protect our rights, property or safety or those of others.

6.4 BUSINESS TRANSFERS

If we reorganise, sell or transfer all or part of our business, we may disclose personal data to a prospective or actual buyer and its advisers, subject to appropriate confidentiality and data-protection safeguards.

7. International Transfers of Personal Data

Some of our service providers may be located in, or may process personal data in, countries outside the European Economic Area (EEA) — for example, the United States and other third countries. A transfer of your personal data outside the EEA is therefore foreseeable. Where such a transfer takes place, we ensure that it is protected by an appropriate safeguard recognised under the GDPR, namely:

• an adequacy decision of the European Commission, confirming that the destination country provides an adequate level of data protection; or

• the European Commission's Standard Contractual Clauses (SCCs), together with any supplementary technical and organisational measures that may be necessary to ensure an essentially equivalent level of protection.

You may request further information about the safeguards we have put in place for international transfers by contacting us at Info@stratmontglobal.com.

8. How Long We Keep Your Personal Data

We retain personal data only for as long as is necessary for the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.

• Enquiry and business-relationship data: kept for as long as needed to deal with your enquiry and for the duration of our business relationship with you, and thereafter for the period necessary to meet relevant legal, tax and limitation periods (for example, periods within which legal claims may be brought).

• Analytics and session-replay data: retained in accordance with the retention settings applied by the relevant service providers.

When we no longer need your personal data, we will securely delete or anonymise it. Further details of our retention periods are available on request by contacting us at Info@stratmontglobal.com.

9. Your Data-Protection Rights

Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data:

• Right of access (Article 15) — to obtain confirmation of whether we process your personal data and a copy of that data;

• Right to rectification (Article 16) — to have inaccurate personal data corrected and incomplete data completed;

• Right to erasure (Article 17) — to have your personal data deleted in certain circumstances (the "right to be forgotten");

• Right to restriction of processing (Article 18) — to have our processing of your personal data restricted in certain circumstances;

• Right to data portability (Article 20) — to receive certain personal data in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible;

• Right to object (Article 21) — to object, on grounds relating to your particular situation, to processing based on our legitimate interests; and

• Right to withdraw consent (Article 7(3)) — where we rely on your consent (for example, for non-essential cookies, analytics and session replay), to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

You can exercise any of these rights by contacting us at Info@stratmontglobal.com. We will respond to your request without undue delay and in any event within one month of receipt; this period may be extended by up to two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you. There is normally no charge for exercising your rights.

RIGHT TO COMPLAIN TO THE DATA PROTECTION COMMISSION

If you are not satisfied with how we have handled your personal data or a request you have made, you have the right to lodge a complaint with the Irish supervisory authority, the Data Protection Commission (DPC):

• Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland

• Website: www.dataprotection.ie

We would, however, appreciate the opportunity to address your concerns directly before you approach the DPC, so we encourage you to contact us first.

10. Security of Your Personal Data

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures designed to protect it against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include the careful selection of service providers, the use of contractual safeguards, access controls, and the masking of text inputs in our session-replay tool.

No method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security, and any transmission of data to us is at your own risk. We encourage you not to send us confidential or sensitive information by unsecured means.

11. Business Users and Children

Our Website and services are directed at businesses and at the professionals who represent them (a business-to-business audience). They are not directed at consumers in their personal capacity, and they are not directed at or intended for children.

We do not knowingly collect personal data relating to children. If you believe that a child has provided us with personal data, please contact us at Info@stratmontglobal.com and we will take appropriate steps to delete it.

12. Important Note on Sensitive and Third-Party Data

When you complete the contact form — and in particular the free-text Mandate brief — or when you correspond with us, please share only the information that is necessary for us to understand and respond to your enquiry.

In particular, please do not submit:

• special categories of personal data (such as data revealing health, racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership);

• unnecessary confidential or commercially sensitive information; or

• personal data relating to other individuals (for example, colleagues, counterparties or their representatives) unless you have a lawful basis to share it and, where required, have informed them and obtained their consent.

If you do provide personal data about other individuals, you confirm that you are entitled to do so and that you have brought this Privacy Policy to their attention. We will process any third-party personal data you submit in accordance with this Policy.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or legal and regulatory requirements. When we make changes, we will revise the "Last updated" date at the top of this Policy and, where the changes are significant, we may take additional steps to bring them to your attention.

Any changes will apply from the date the revised Policy is posted on the Website. Where changes affect processing that relies on your consent (for example, non-essential cookies, analytics or session replay), we will obtain fresh consent from you as required. We encourage you to review this Policy periodically so that you remain informed about how we handle your personal data.

14. Governing Law

This Privacy Policy, and any matter or dispute arising out of or in connection with it or with our processing of your personal data, is governed by and construed in accordance with the laws of Ireland. The courts of Ireland have exclusive jurisdiction, without prejudice to your right to lodge a complaint with the Data Protection Commission or to any other right or remedy available to you under applicable data-protection law.

For related terms governing your use of the Website and our services, please see our Terms and Conditions. For details of the cookies and similar technologies we use, please see our Cookie Policy.

Stratmont Global — Oksana Kholieva (sole trader), Registered Business Name No. 786173 40 Mill Street, Baltinglass, Co. Wicklow, W91 DK64, Ireland Info@stratmontglobal.com | +353 89 605 2254 | https://stratmontglobal.com ====================================================================================