Data Protection Policy

Green One Capital, SCR, S.A. (“Green One Capital” or “GOC”) is committed to protecting the privacy and personal data of individuals whose personal data it processes.

This Data Protection Policy applies to the collection and processing of personal data by Green One Capital, SCR, S.A., with registered office at Avenida da Liberdade, no. 245, 3.º B, 1250-143 Lisbon, Portugal, registered with the Lisbon Commercial Registry under the single registration and corporate taxpayer number 513 885 445, with a share capital of EUR 175,000.00.

This Policy is of a general nature and may be supplemented by specific privacy notices or policies applicable to particular processing activities or categories of personal data.

1. What is Personal Data?

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”).

An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

2. What is Processing of Personal Data?

“Processing” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means.

This includes, in particular, the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data.

3. Categories of Personal Data Processed

Personal data provided to or otherwise collected by GOC is processed in accordance with applicable data protection legislation and, in particular, the principles established under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”).

GOC ensures that personal data is:

a) processed lawfully, fairly and transparently in relation to the data subject;

b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes;

c) adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed;

d) accurate and, where necessary, kept up to date, with appropriate measures being taken to ensure that inaccurate personal data is erased or rectified without undue delay;

e) retained in a form permitting identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed; and

f) processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

The main categories of personal data that GOC may process include:

– Identification and contact data (Examples: name, identification document details, signature, address, telephone number and email address);

– Biographical data (Examples: date of birth, sex, nationality, place of birth, marital status, household information, academic qualifications and professional information);

– Financial data (Examples: assets, income, financial liabilities and remuneration information);

– Segments and profiles (Examples: client segmentation, investor profile and information relevant to the assessment or provision of financial products and services);

– Website and technical data (Examples: information generated through use of GOC’s website, which may include IP address, browser and device information and other technical information, where applicable);

4. Purposes and Legal Bases for Processing

GOC may process personal data for purposes including:

– Entering into and performing contracts and taking pre-contractual steps at the request of the data subject (Legal Basis: performance of a contract or pre-contractual measures; where applicable, legitimate interests);

– Accounting and financial reporting (Legal Basis: compliance with legal and regulatory obligations);

– Responding to requests from public, supervisory, regulatory or judicial authorities (Legal Basis: compliance with legal and regulatory obligations);

– Compliance with tax reporting, withholding, payment and record-keeping requirements (Legal Basis: compliance with legal and regulatory obligations);

– Prevention of money laundering and terrorist financing (Legal Basis: compliance with legal and regulatory obligations);

– Fraud prevention and detection (Legal Basis: compliance with legal obligations and/or legitimate interests, as applicable);

– Providing information and services to clients and investors (Legal Basis: performance of contractual obligations and/or compliance with legal and regulatory obligations);

– Client classification, segmentation and investor profiling where required (Legal Basis: compliance with legal and regulatory obligations and/or legitimate interests, as applicable);

– Development and improvement of products and services (Legal Basis: legitimate interests);

– Internal management, reporting and control (Legal Basis: legitimate interests);

– Monitoring and improving service quality (Legal Basis: legitimate interests);

– Operational risk management (Legal Basis: legitimate interests);

– Establishment, exercise or defence of legal claims (Legal Basis: legitimate interests and/or compliance with legal obligations);

– Use of non-essential cookies or similar technologies, where applicable (Legal Basis: consent, where required by applicable law);

Where processing is based on GOC’s legitimate interests, GOC will consider those interests against the rights, freedoms and interests of the relevant data subjects, as required by applicable law.

5. Retention of Personal Data

GOC retains personal data only for as long as necessary for the purposes for which it was collected and processed and in accordance with applicable legal and regulatory retention requirements.

Once the applicable retention period has expired, personal data will be securely erased or anonymised unless its continued retention is required or permitted for another lawful purpose.

Personal data may therefore be retained beyond the duration of a contractual relationship where necessary to comply with legal or regulatory obligations, establish, exercise or defend legal claims, or pursue other legitimate purposes permitted by applicable law.

The applicable retention period will depend on the nature of the personal data, the purposes for which it is processed and the legal and regulatory requirements applicable to GOC.

6. Disclosure of Personal Data

GOC may disclose personal data to third parties where necessary for the purposes described in this Policy.

Where third-party service providers process personal data on GOC’s behalf, GOC will implement appropriate contractual and organisational measures designed to ensure that such processors process personal data in accordance with GOC’s instructions, the GDPR and other applicable data protection requirements.

Personal data may, in particular, be disclosed to:

i. entities belonging to the same corporate group, where applicable, including where they provide services to GOC;

ii. public, regulatory, supervisory, judicial, tax or law-enforcement authorities where disclosure is required or permitted by law, including the Portuguese Securities Market Commission (CMVM) and the Portuguese Tax and Customs Authority;

iii. service providers and processors engaged by GOC, including, where applicable, depositaries, distributors, financial institutions, professional advisers, auditors, IT and technology providers and other entities involved in the operation and administration of GOC’s activities and the funds under its management; and

iv. other third parties where the data subject has consented to the disclosure or where another lawful basis applies.

GOC will only disclose personal data to the extent necessary and in accordance with applicable legal and regulatory requirements.

7. International Transfers of Personal Data

Where personal data is transferred to a country outside the European Economic Area (“EEA”) or to an international organisation, GOC will ensure that the transfer is carried out in accordance with the requirements of the GDPR.

Where required, appropriate safeguards will be implemented, which may include an adequacy decision adopted by the European Commission, standard contractual clauses approved by the European Commission or another legally recognised transfer mechanism.

Further information regarding the safeguards applicable to a particular transfer may be requested using the contact details set out below.

8. Automated Decision-Making and Profiling

GOC does not make decisions producing legal effects concerning data subjects, or similarly significantly affecting them, based solely on automated processing, including profiling, unless such processing is permitted by applicable law and the relevant safeguards have been implemented.

9. Rights of Data Subjects

Subject to the conditions and limitations established under applicable data protection law, data subjects may exercise the following rights in relation to their personal data:

Right of access — to obtain confirmation as to whether GOC processes their personal data and, where applicable, access to that data and relevant information concerning its processing.

Right to rectification — to request the correction of inaccurate personal data and the completion of incomplete personal data.

Right to erasure (“right to be forgotten”) — to request the erasure of personal data in the circumstances provided for by applicable law. This right does not apply where continued processing is necessary, including for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.

Right to restriction of processing — to request that processing be restricted in the circumstances provided for under the GDPR.

Right to data portability — where applicable, to receive personal data provided to GOC in a structured, commonly used and machine-readable format and to transmit that data to another controller.

Right to object — to object, on grounds relating to the data subject’s particular situation, to processing based on GOC’s legitimate interests. Data subjects have an unconditional right to object to processing of their personal data for direct marketing purposes.

Right to withdraw consent — where processing is based on consent, consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal.

Rights relating to automated decision-making — where applicable, to exercise the rights provided by the GDPR in relation to decisions based solely on automated processing which produce legal effects or similarly significantly affect the data subject.

Data subjects also have the right to lodge a complaint with the competent supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD).

10. Indirect Collection of Personal Data

GOC may, in certain circumstances, obtain personal data from sources other than the data subject.

Such sources may include counterparties, intermediaries, service providers, public registers, public authorities, publicly available sources or other third parties, where permitted by applicable law.

Where required under the GDPR, GOC will provide the relevant data subject with the information concerning such processing within the applicable statutory period.

11. Security of Personal Data

GOC implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing of personal data.

Such measures are intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Access to personal data is restricted to persons who require such access for legitimate professional purposes and subject to appropriate confidentiality obligations.

12. Cookies and Similar Technologies

GOC’s website may use technical technologies that are strictly necessary for the operation, functionality and security of the website.

GOC does not currently use cookies or similar technologies for analytics, behavioural advertising or profiling purposes.

Should GOC introduce non-essential cookies or similar technologies in the future, their use will be subject to the requirements of applicable law, including obtaining consent where required.

For further information, please consult our Cookies Policy.

13. Exercise of Rights and Data Protection Contact

The exercise of data protection rights is generally free of charge. However, where requests are manifestly unfounded or excessive, in particular because of their repetitive nature, GOC may charge a reasonable fee taking into account the administrative costs involved or may refuse to act on the request, as permitted by applicable law.

GOC will respond to requests without undue delay and, in principle, within one month of receipt. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests, in accordance with the GDPR.

Requests concerning personal data or the exercise of data protection rights may be addressed to Green One Capital through the appropriate contact channels made available by GOC.

By post:

Green One Capital, SCR, S.A.

Avenida da Liberdade, no. 245, 3.º B

1250-143 Lisbon

Portugal

By email: compliance@greenonecapital.com

Data subjects may also lodge a complaint with:

Comissão Nacional de Proteção de Dados (CNPD)

Portuguese Data Protection Authority

14. Changes to this Data Protection Policy

GOC may amend this Data Protection Policy from time to time, including to reflect changes to its processing activities, applicable legislation or regulatory requirements.

The most up-to-date version will be made available on GOC’s website.

Last updated: August 2026