Skalar Inc.

Privacy Policy

Last updated — 16 September 2026

1. WHO WE ARE AND HOW TO CONTACT US

Skalar Inc. ("Skalar," "we," "us," or "our") is a company incorporated in the State of Delaware, United States, engaged exclusively in commercial, business-to-business lending. We originate revenue-based financing and related credit facilities to technology and software companies and are repaid out of the borrower's future business receivables. All of our borrowers are legal entities; we do not lend to consumers or to natural persons. While our corporate headquarters are located in the United States, our primary operations and support team operate from Colombia.

Depending on your location and jurisdiction, Skalar Inc. acts as the Data Controller (or Responsable del Tratamiento) for the processing of personal data described in this Policy:

For any data-related inquiries, to exercise your privacy rights, or to contact our Compliance Officer, please reach out to:

Emailamlcompliance@skalar.club

Websitewww.skalar.club

EntitySkalar Inc. (Delaware, USA)

Address12639 White Coral Drive, Wellington, Florida 33414, United States

Phone+1 (650) 285-8774

2. SCOPE

This Privacy Policy applies to personal data collected and processed by Skalar Inc. (Delaware, USA) from and about:

Some members of our team are engaged through a third-party employer or contractor of record. Where that is the case, that provider is the controller of the personal data of the engagement and of the payroll it administers, and Skalar Inc. is the controller only of the data it holds for its own purposes, such as participation in its equity plan, signing authority and access to its systems.

3. PERSONAL DATA WE COLLECT

Contractors and Team Members

Business Client Representatives

Founders, Beneficial Owners and Control Persons of Borrowers

4. PURPOSES OF PROCESSING

We process personal data solely for the following purposes:

We will not use your personal data for purposes incompatible with those listed above without obtaining your prior consent.

5. LEGAL BASIS FOR PROCESSING

We process your personal data only when we have a valid legal basis under the law applicable to you. Where the GDPR applies, those bases are the following:

A. Compliance with Legal Obligations and Legitimate Interests: as a company incorporated in the United States, Skalar Inc. is bound by the U.S. economic sanctions programs administered by the Office of Foreign Assets Control, which apply on a strict liability basis, and by U.S. law on currency reporting and money laundering. Skalar Inc. is not a regulated financial institution and is not subject to the customer identification and beneficial ownership rules that apply to banks and similar institutions. It is nevertheless prohibited from dealing with a company that is owned, directly or indirectly and in the aggregate, fifty percent or more by one or more sanctioned persons, and such a company is restricted whether or not it appears on any sanctions list. This is known as the OFAC 50 Percent Rule. We can establish whether that is the case only by identifying the individuals who own and control our borrowers, which is why we identify and verify their representatives, authorized signatories, founders and beneficial owners. The twenty-five percent threshold at which we do so is set by our own AML/CFT Compliance Policy, because an aggregate holding of fifty percent may be made up of smaller individual holdings. Because these obligations arise under U.S. rather than Union or Member State law, where the GDPR applies this processing is carried out on the basis of our legitimate interests in preventing financial crime.

B. Performance of a Contract: To evaluate, execute, disburse, and manage commercial financing agreements entered into with our business clients.

C. Legitimate Interests: To conduct credit risk assessments, prevent operational fraud, maintain IT security, and manage B2B customer relationships.

D. Explicit Consent: Where specifically required by applicable law or when collecting data that is not strictly necessary for the performance of a contract.

E. Colombian law: where Colombian data protection law applies, we process personal data on the basis of the prior, express and informed authorization of the data subject, and in the cases in which that law does not require authorization, including data required by a public or administrative entity in the exercise of its legal functions and data ordered to be disclosed by a court.

6. INTERNATIONAL DATA TRANSFERS

Skalar Inc. is incorporated in the State of Delaware (U.S.), and its operational team operates primarily from Colombia and other jurisdictions. Personal data collected will be transferred to and processed in the United States.

7. DATA SHARING

We may share personal data with the following categories of third parties:

We do not sell personal data to third parties. We require third-party processors to maintain appropriate data protection standards consistent with this Policy.

8. DATA RETENTION

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy and to comply with applicable legal obligations:

When data is no longer needed, we delete or anonymize it in a secure manner.

9. YOUR RIGHTS

9.1 Rights Under Colombian Law

If you are located in Colombia, under Colombian data protection law, you have the following rights regarding your personal data:

To exercise any of these rights, send a written request to amlcompliance@skalar.club.

Inquiries. Requests to access, confirm or review your personal data are answered within ten (10) business days of receipt. If we cannot answer within that period, we will tell you why and set a new date, which will not exceed five (5) additional business days.

Claims. Requests to update, correct or delete your personal data, or to revoke your consent, are resolved within fifteen (15) business days from the business day following receipt. If we cannot resolve the claim within that period, we will tell you why and set a new date, which will not exceed eight (8) additional business days. If a claim is incomplete, we will ask you, within five (5) calendar days of receipt, for the missing information; if two (2) months pass without it, the claim is deemed abandoned. Once a complete claim is received, we record a legend stating that a claim is in process in the relevant database within two (2) business days.

9.2 Rights Under European Union and UK Law (GDPR)

If you are located in the European Union or the United Kingdom, you have the following rights regarding your personal data:

To exercise any of these rights, send a written request to amlcompliance@skalar.club.

10. SECURITY

We implement reasonable technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction. These include access controls, encryption of data in transit, and limited access on a need-to-know basis.

No method of transmission over the internet is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security.

In the event of a data breach that may affect your rights, we will notify relevant parties as required by applicable law.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify affected individuals of material changes via email or through a prominent notice on our website prior to the changes taking effect. The date at the top of this document reflects the most recent revision.

This Policy takes effect on the date stated at the top of this document and remains in force for as long as Skalar Inc. carries on its business. The databases described in this Policy are maintained for the retention periods set out in Section 8.

12. AUTOMATED DECISION-MAKING AND RISK PROFILING

Skalar Inc. uses automated tools and risk models to support its analysis of credit risk and its verification of KYC and AML compliance for business borrowers. We do not take decisions that produce legal effects concerning a natural person, or that similarly significantly affect a natural person, based solely on automated processing: the credit decision, and any decision to decline or exit a relationship on financial-crime grounds, is taken by a person. Where the GDPR applies and a decision is based solely on automated processing, the individual may request human intervention, express their point of view and contest the decision.

13. PERSONAL DATA WE DID NOT REQUEST

Our non-disclosure agreements and our credit agreements provide that a counterparty is not to make personal data available to us except where the agreement expressly contemplates it. Where personal data is nevertheless made available to us inadvertently, we do not use or process it for any purpose, we delete or destroy it promptly upon becoming aware, and for as long as it remains in our possession, we protect it to the standard we apply to confidential information. Copies held in routine electronic backup, archival or disaster recovery systems are not accessed or used and are overwritten or deleted in the ordinary course.

14. RELATIONSHIP WITH OUR OTHER DOCUMENTS

This Policy is read together with Skalar Inc.'s AML/CFT Compliance Policy, which governs the identification, screening and record retention obligations described above. The confidentiality obligations in our non-disclosure agreements and in our credit agreements are separate from and additional to this Policy, and nothing in this Policy limits them.

15. CONTACT

Skalar Inc. (Delaware, USA)

Emailamlcompliance@skalar.club

Websitewww.skalar.club

Address12639 White Coral Drive, Wellington, Florida 33414, United States

Phone+1 (650) 285-8774