Recruitment Privacy Policy 1. GENERAL INFORMATION Epassi Group respects your privacy and is committed to protecting the privacy of persons interacting with us. This recruitmentprivacy policy applies to all applicants applying for a job with Epassi (“applicant” or “you”) and describes how Epassi processes applicants’ personal data; e.g., what kinds of personal data we collect, for which purposes the personal data is used and with whom your personal data can be shared. In this context, personal data refers to any information relating to you (“data subject”) that identifies or can be used to identify you directly or indirectly. Personal data, data subject, controller and other key terms have the same meaning as in the General Data Protection Regulation (2016/679, “GDPR”) Epassi complies with the GDPR in all processing of personal data together with other applicable national and EU level data protection legislation, which in Finland includes also e.g. the Act on the Protection of Privacy in Working Life (759/2004). 2. CONTROLLER For the purposes of this notice, the controller of your personal data is the Epassi group company conducting the recruitment jointly with Epassi Group Oy. If you choose to allow your application to be considered for other vacancies as well, each recruiting company which is processing your personal data is the controller jointly with Epassi Group Oy. If you have any questions relating to the recruitment process, please contact the recruiting manager stated in the job posting. 3. CONTACT INFORMATION Email: dataprivacy@epassi.com Controller representative: Selma Nieminen, DPO 4. PERSONAL DATA PROCESSED, PURPOSE OF PROCESSING AND LEGAL BASIS Epassi collects only such personal data that are relevant and necessary for the purposes of completing the recruitment process. As part of the said process, the following personal data will be processed, in the extent shared by the applicant: Basic and contact information of the applicant,such as name, date of birth, telephone number, e-mail address, nationality, gender, local address, postal code, city, photo. Identification data, such as your passport or other legitimate identification. Applicant's competences, such aseducational and other qualifications, employment history, completed trainings, language and other skills. Role information, such astype of employment and job roles applied. Application documents, such asyour cover letter and a curriculum vitae. The applicant determines the content of these documents. Other information, such as information on the progress of the recruitment process and email communications between the applicant and us. We may also have conversations with the applicant's referees and seek information from other sources indicated by the applicant.5. SOURCES OF PERSONAL DATA In general, we collect the information from the applicants themselves. With the applicant’s permission, we may also collect information from publicly available third-party data sources within the limits of applicable regulations, for example, from the LinkedIn -profile of the applicant, other publicly available skills profiles, recruitment consultants, our current employees and the referees named by the applicant. 6. THE BASIS AND PURPOSES OF THE PROCESSING OF PERSONAL DATA We process the personal data of the applicants to find suitable individuals for our open positions. This typically involves evaluation of your individual competences, professional background, as well as your personal characteristics and their suitability for the role applied. The processing of your personal data is based on your consent as well as our legitimate interest at the job search stage to recruit suitable candidates for the jobs we offer and to ensure the appropriateness of the application process. If the process leads to the conclusion of an employment agreement, we may also process the applicant's personal data in order to prepare the employment agreement and, for example, to establish access rights to our systems. In such cases, the processing of personal data is based on a contract between the controller and the data subject. We may also require your identification data to be checked and stored e.g. in order to manage work permits and access to certain systems. The processing is based on legal requirements and legitimate interests. 7. THE PARTIES INVOLVED IN THE PROCESSING OF PERSONAL DATA AND THE TRANSFER OF DATA OUTSIDE THE EU OR THE EEC Epassi uses Jobylon AB service in processing of applications. As a part of the recruitment process, we may ask you to register to Jobylon service or with your specific permission, we may upload the personal data we or our recruitment consultants have collected from you to the service. For more information about privacy in Jobylon, please see Jobylon’s privacy policy. In addition, Epassi uses outsourced cloud-based document management and email services for administrative tasks. Epassi may also share personal data of the applicant with its own group companies as part of the recruitment process. Epassi may disclose personal data as permitted and required by applicable law to entities that have a legal and/or contractual right to receive information from us. When using cloud-based services, your personal data may to some extent be processed or transferred outside the European Union or the European Economic Area (‘EEC’). The storage location of your data is, however, primarily within the EU/EEC. Where personal data is processed outside the EU/EEC, we will ensure that the subcontractor is bound by the Standard Contractual Clauses adopted by the European Commission for the processing of personal data, or other approved safeguards, as required by law and deemed appropriate by us. 8. RETENTION OF PERSONAL DATA In principle, we hold personal data of job applicants for the duration of the recruitment process andfor an additional two (2) years after the end of the process thereafter. If the applicant becomes our employee, we will keep the data provided as an applicant and related to the job search as part of the personnel profile in accordance with our Employee Data Protection Policy.We regularly assess the necessity of data retention in accordance with applicable laws. In addition, we will take reasonable steps to ensure that no personal data of data subjects are held that are incompatible, outdated or inaccurate for the purposes of the processing. We will also strive to correct or erase such data without undue delay. In some situations, personal data may be stored for longer than the above-mentioned retention periods if there is a specific reason to do so, for example in connection with administrative or court proceedings. 9. PROTECTION OF PERSONAL DATA Securing the confidentiality, integrity, and availability of personal data is important to Epassi. Epassi's Security Management System is based on the requirements from laws, regulations, contracts and certain standards (such as ISO 27001). Our Security Management System consists of appropriate technical, administrative, and organizational security measures to protect personal data against unauthorized access, disclosure, destruction, or other unauthorized processing. All parties processing personal data have a duty of confidentiality in matters related to the processing of personal data. Access to your recruitment data is limited to those persons, who take part in the recruitment process from our end. Other persons will not have access to your files or information. We also require our service providers to have appropriate methods in place to protect personal data. Nevertheless, considering the cyber threats in modern day online environment, we cannot give full guarantee that our security measures will prevent illegally and maliciously operating third parties from obtaining access to personal data or guarantee absolute security of the personal data during its transmission or storage on our systems. 10. YOUR RIGHTS AS THE DATA SUBJECT As a data subject you have the following rights: Your right as a data subjectIn which situations Check and receive a copy of the information stored about yourself Always Request the correction of incorrect or outdated information Always Request the deletion of dataWhere the applicant has withdrawn their consent or one of the other conditions set out in Article 17 of the GDPR is met. Withdraw your consentWhere processing is based on consent. Object to the processing of dataWhere the processing is based on our legitimate interests. Request restriction of processing (e.g., until requests for data are resolved and settled) If the accuracy of the data is contested or one of the other conditions set out in Article 18 of the GDPR is met.If you are dissatisfied with the processing of your request or any other matter relating to the processing of your personal data, you have the right to contact the supervisory authority for the processing of personal data, the Office of the Data Protection Ombudsman. However, please contact our Controller representative first to see if we can sort the matter out together. Please, submit requests for information and rectification of personal data in writing to the Controller representative (by post or e-mail) mentioned in section 3 of this policy. The identity of the person making the request will be verified before the request is executed. The controller will reply to the customer within the time limits laid down in the GDPR (as a general rule, within one month). The processing of requests is free of charge for the data subject. However, requests that are manifestly unfounded and unreasonable may be subject to a reasonable fee or refused (Article 12(5) of the GDPR). 11. CHANGES TO THIS PRIVACY POLICY Epassi may make changes to this privacy policy at any time by e.g. publishing a new version of this policy on our website or by other suitable means. The data subjects are highly recommended to review the privacy policy on our website every now and then. This privacy policy has been published on 10.3.2025, version 1.0 For internal use only: Version history Version numberChange descriptionDate 1.0Document created10.3.2025