OneCare

PRIVACY POLICY

FOR USE OF THE PLATFORMOneCare
Version No. 1/04.05.2026
Section I.

General Provisions and Identification of the Controller

Art. 1. (1) This Privacy Policy (the “Policy”) describes how “DocNow Medical Services” EOOD, UIC 208622091, with registered seat and management address: Sofia 1404, Triaditsa District, 109 Bulgaria Blvd., floor 2, office 2.5, email: [email protected], tel.: +359 889 999 955 (hereinafter referred to as the “Company”, “we”, “us” or “our”), collects, uses, stores, shares and protects the personal data of natural persons in connection with the OneCare online platform (the “Platform”), available at www.onecare.bg.

(2) The Company is a controller of Personal Data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”) for the Processing operations for which it independently determines the purposes and means of the Processing.

(3) For certain operations in which the Company processes Personal Data on behalf of and under the instructions of the relevant Service Provider (including, but not limited to, a medical establishment, veterinary practice and others), the Company acts as a Personal Data processor within the meaning of Article 28 GDPR. The allocation of roles is governed by a separate agreement between the Company and the Service Provider.

(4) For all matters related to the Processing of Personal Data, you may contact us by email at: [email protected].

(5) When Processing Personal Data, the Company complies with the following principles in accordance with Article 5 GDPR:

1. lawfulness, fairness and transparency - data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject;

2. purpose limitation - data shall be collected for specified, explicit and legitimate purposes and shall not be processed in a manner incompatible with those purposes;

3. data minimisation - only data that are adequate, relevant and limited to what is necessary in relation to the purposes of the Processing shall be processed;

4. accuracy - data shall be kept accurate and, where necessary, up to date;

5. storage limitation - data shall be kept in a form which permits identification of the data subject for no longer than is necessary for the purposes of the Processing;

6. integrity and confidentiality - data shall be processed in a manner that ensures an appropriate level of security;

7. accountability - the Company is responsible for and is able to demonstrate compliance with these principles.

Art. 2. (1) This Policy applies to the following categories of persons:

1. Users - natural persons who register on, browse or use the Platform;

2. Service Recipients - persons for whom the User requests a service, including children, third parties, as well as animals in the case of veterinary services;

3. Service Providers - traders, medical establishments, professionals and their employees or associates whose profiles have been created on the Platform (if functionality for such profiles is available);

4. Visitors - persons who visit the Platform without registering;

5. Contact Persons - persons who contact the Company through contact forms, email, telephone or another communication channel.

(2) This Policy applies together with the General Terms and Conditions for Use of the OneCare Platform. In the event of any conflict regarding personal data protection matters, this Policy shall prevail.

(3) This Policy is available at www.onecare.bg and is provided to Users and Service Providers upon registration on the Platform.

Section II.

Definitions

Art. 3. For the purposes of this Policy:

1. “Personal Data” means any information relating to an identified natural person or a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

2. “Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

3. “Special Categories of Personal Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.

4. “Data Concerning Health” means Personal Data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.

5. “Controller” means the Company where it independently determines the purposes and means of the Processing of Personal Data.

6. “Personal Data Processor” means the Company or another person which processes Personal Data on behalf of a controller.

7. All other definitions used but not expressly defined in this Policy shall have the meaning given to them in the General Terms and Conditions for Use of the OneCare Platform, in the GDPR or in the Bulgarian Personal Data Protection Act (“PDPA”).

Section III.

Categories of Personal Data We Collect

Art. 4. (1) Upon registration on the Platform, the Company collects the following Personal Data of the User:

1. full name;

2. email address;

3. telephone number;

4. address;

5. date of birth;

6. Bulgarian personal identification number (EGN) or personal number of a foreigner (LNC), or date of birth for foreign nationals without an EGN/LNC;

7. other data, at the discretion of the Company.

(2) When requesting a service through the Platform, the Company may additionally collect:

1. service performance address;

2. selected service category, specific service, date, time or time slot;

3. payment data and payment status, including transaction reference number, the last four digits and type of card, where applicable. Full card details (card number, expiry date, security code) are entered directly into the secure environment of the payment processor and are not stored by the Company in accordance with paragraph 5 of this Article;

4. notes, comments or additional information provided by the User;

5. information concerning health, where the User voluntarily provides such information in connection with a medical service;

6. animal data in the case of veterinary services, including species, sex, weight, age, breed, complaints and other relevant information.

(3) Where the User requests a service for a third person - a Service Recipient, the data under paragraphs 1 and 2, to the extent necessary for the relevant service, shall be provided by the User, who declares and warrants that he or she has obtained the third person’s consent for the Processing of his or her personal data in accordance with Article 9 of the General Terms and Conditions.

(4) The categories and scope of the Personal Data collected may be amended, expanded or narrowed by the Company in view of the type of service, legal requirements, the technical capabilities of the Platform and the specific needs of the relevant category of services, and the User shall be informed of any material change.

(5) When enabling online payment through the Platform, bank card data (card number, expiry date, security code) are entered by the User directly into the secure environment of the relevant payment processor (payment service provider) and are not stored, recorded or processed by the Company. The Company receives from the payment processor only information about the outcome of the transaction (successful/unsuccessful), a reference number and, where applicable, the last four digits of the card and the type of card, insofar as this is necessary to identify the payment, issue documents and Process any disputes, refunds or chargebacks. The Processing of full card details is carried out by the payment processor in compliance with the PCI DSS standard and with its own terms and privacy policy.

(6) The Personal Data collected pursuant to this Article may be processed in the Company’s environment, in the environment of the technical providers under Article 11(1)(2), or in a combined manner, depending on the specific purpose of the Processing and the technical requirements of the Platform.

Art. 5. (1) When creating a Service Provider profile on the Platform, the Company collects:

1. name (business name), UIC/BULSTAT, legal form;

2. registered seat and management address;

3. data of the representative - names, EGN, position;

4. email address, telephone, correspondence address;

5. data on registrations, permits, licences, professional rights, qualifications and insurance;

6. bank and/or payment data for the transfer of remuneration;

7. schedule, availability and scope of the services offered.

(2) For medical professionals, veterinarians and other employees or associates of the Service Provider whose profiles are displayed on the Platform, the Company may process:

1. full name, professional title, specialty, position;

2. unique identification number (UIN) or another professional identifier;

3. professional photograph, short biography, education and qualification data;

4. schedule, locations and availability.

(3) The Processing of data under paragraph 2 is carried out on the basis of the contractual relationship between the Company and the Service Provider, and where the

Processing exceeds what is minimally necessary for identification - on the basis of a separate consent declaration of the relevant professional or employee.

Art. 6. (1) When visiting and using the Platform, the following data are collected automatically:

1. IP address;

2. browser type and version, operating system;

3. date, time and duration of visits;

4. pages visited and actions performed on the Platform;

5. traffic source (referrer URL);

6. unique device identifiers (device IDs), where applicable;

7. data from cookies and similar technologies in accordance with Section VIII of this Policy.

(2) In the future, as the Platform develops, additional location data (with the User’s explicit consent), identifiers for sending notifications and other technical identifiers necessary for the functioning of mobile or other functionalities may be collected. Upon the introduction of such collection, the User shall be duly informed.

Art. 7. When you contact the Company by email, contact form, telephone or another communication channel, the Company processes the data provided by you (names, contact details, content of the message and any other information that you decide to provide) for the purposes of Processing your enquiry and maintaining correspondence. Communication may also take place through instant messaging applications (including Viber, WhatsApp, Telegram, Signal and others), as well as through an embedded chat (chat widget) on the Platform. Where the chat on the Platform is technically connected to an instant messaging application (e.g. WhatsApp), messages sent by the User through the chat are routed and processed through the infrastructure of the relevant application provider, of which the User is informed by a visible notice in the chat interface.

Art. 8. (1) Where you have given separate, freely given and explicit consent by signing a consent declaration, the Company and/or the Service Provider may record and use your photographs, video and audiovisual materials for marketing, representative and informational purposes described in detail in the relevant declaration.

(2) The taking and public use of photographs and video is not a condition for the provision of the service and does not affect your right to receive the service without such recording.

(3) Consent to recording may be withdrawn at any time with prospective effect, in the manner described in the relevant declaration and in Section X of this Policy.

Section IV.

Purposes and Legal Grounds for Processing

Art. 9. (1) The Company processes Personal Data for the following purposes and on the following legal grounds under the GDPR:

1. Registration and maintenance of a user account - legal ground: Article 6(1)(b) GDPR (performance of a contract);

2. Requesting, organising, administering and performing a specific service - legal ground: Article 6(1)(b) GDPR (performance of a contract);

3. Processing of Personal Data in connection with medical and healthcare services, including data concerning health - legal ground: Article 9(2)(h) GDPR (provision of health care) in conjunction with Article 6(1)(b) GDPR;

4. Processing of payments, issuance of fiscal, payment and accounting documents legal ground: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (legal obligation);

5. Provision of mandatory pre-contractual information under the Bulgarian Consumer Protection Act - legal ground: Article 6(1)(c) GDPR (legal obligation);

6. Fulfilment of accounting, tax, social security and other regulatory obligations legal ground: Article 6(1)(c) GDPR (legal obligation);

7. Sending marketing communications (newsletters, promotional emails, SMS, notifications and others) - legal ground: Article 6(1)(a) GDPR (consent);

8. Analytics, statistics and improvement of the Platform and user experience - legal ground: Article 6(1)(f) GDPR (the Company’s legitimate interest in improving its services);

9. Platform security, prevention of abuse, unauthorised access and fraud - legal ground: Article 6(1)(f) GDPR (legitimate interest);

10. Establishment, exercise or defence of legal claims - legal ground: Article 6(1)(f) GDPR (legitimate interest) and/or Article 9(2)(f) GDPR for special categories;

11. Recording and public use of photographs and video for marketing, representative and informational purposes - legal ground: Article 6(1)(a) GDPR (consent), and where the images reveal health information - Article 9(2)(a) GDPR (explicit consent);

12. Creation, maintenance and display of a Service Provider profile and of its professionals on the Platform - legal ground: Article 6(1)(b) GDPR (performance of a contract between the Company and the Service Provider), and for the public display of photographs and extended information - Article 6(1)(a) GDPR (consent of the professional);

13. Processing of complaints, reports, enquiries and communication - legal ground: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest);

14. Sending transactional and informational messages (including appointment reminders, notifications of service changes, request status and others), including via SMS, email, Viber, WhatsApp, Telegram, Signal or another instant messaging application - legal ground: Article 6(1)(b) GDPR (performance of a contract).

(2) Where the Processing is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of the Processing carried out before the withdrawal. Withdrawing consent is as easy as giving it.

(3) Where the Processing is based on the Company’s legitimate interest, you have the right to object to the Processing pursuant to Article 21 GDPR, in the manner set out in Section X of this Policy.

Section V.

Processing

Art. 10. (1) In the case of certain types of services offered through the Platform (medical, veterinary, child care-related and others), Special Categories of Personal Data, in particular data concerning health, may be Processed.

(2) The Processing of Special Categories of Personal Data is carried out on one or more of the following legal bases:

1. Article 9(2)(h) GDPR - where the Processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services;

2. Article 9(2)(a) GDPR - explicit consent of the data subject, where the other legal bases are not applicable;

3. Article 9(2)(f) GDPR - for the establishment, exercise or defence of legal claims.

(3) In the case of non-medical services (cleaning, gardening, household services and other similar services), Special Categories of Personal Data are generally not processed. If Processing of such data is required for a particular service, the User shall be expressly informed and consent shall be requested where necessary.

(4) The Company processes data concerning health under conditions of professional secrecy and in compliance with the technical and organisational protection measures provided for in this Policy and in the applicable legislation.

Section VI.

Recipients and Sharing of Personal Data

Art. 11. (1) The Company may share your Personal Data with the following categories of recipients, insofar as this is necessary to achieve the purposes described in this Policy:

1. Service Providers - medical establishments, medical professionals, veterinary practices, cleaning companies, child care specialists, gardeners and other persons providing services through the Platform, insofar as sharing is necessary for requesting, organising and performing the specific service;

2. Technical providers (Personal Data processors) - persons who provide the Company with technical, infrastructure, hosting, communication, application, payment, support and other services necessary for the functioning of the Platform, including, but not limited to:

a) platform infrastructure and application services provider (white-label) - this provider is granted access to Personal Data to the extent necessary for the technical functioning of the Platform, including for routing requests, sending transactional and informational messages, maintaining communication between the User and the Service Provider, as well as for other technical and application functionalities. Depending on the specific functionality and the technical architecture of the Platform, certain categories of Personal Data (including, but not limited to, telephone numbers, email addresses and physical addresses) may be processed both in the Company’s environment and in the white-label provider’s environment, in whole or in part, with the Company determining the scope of sharing in accordance with the principle of data minimisation under Article 5(1)(c) GDPR. The Company stores in its own environment, without providing them to the white-label provider, those categories of data which it has assessed are not necessary for the technical functioning of the Platform;

b) Amazon Web Services (AWS) - hosting and cloud infrastructure;

c) SendGrid - email sending services;

d) other technical providers that may be added, replaced or removed by the Company;

e) Viber Media S.à r.l. (Rakuten Group) - services for sending messages via Viber;

f) WhatsApp Ireland Limited (Meta Platforms Group) - services for sending messages via WhatsApp and/or technical routing of messages from the embedded chat on the Platform;

g) Telegram Messenger Inc. - services for sending messages via Telegram;

h) Signal Messenger LLC - services for sending messages via Signal.

3. Analytics and advertising providers - Google (Google Analytics), Meta Platforms (Facebook Pixel) and other similar providers used for analytics, measuring the effectiveness of advertising campaigns and improving the Platform, under the conditions of Section VIII of this Policy;

4. Professional advisers - lawyers, accountants, auditors, tax advisers and other persons providing the Company with legal, accounting, tax or audit services;

5. Marketing partners - marketing agencies, designers, content specialists and other persons supporting the Company in carrying out advertising and marketing activities, insofar as this is necessary and subject to the relevant legal ground;

6. Payment intermediaries and banks - banks, payment service providers, payment processors (including PayNovus, Stripe, PayPal or another provider indicated on the Platform), POS terminal operators, card schemes (Visa, Mastercard, etc.) and other persons involved in payment processing, to whom transaction data and, where applicable, bank card data are transmitted directly by the User through the secure environment of the payment processor;

7. Public authorities and institutions - the Commission for Personal Data Protection (CPDP), the Commission for Consumer Protection (CCP), the National Revenue Agency

(NRA), courts, prosecution authorities, police and other competent authorities, where disclosure is required by law or by an act of a competent authority.

(2) The Company does not sell, rent out or provide your Personal Data to third parties for remuneration for the independent marketing purposes of those parties.

Section VII.

Transfers of Data Outside the European Economic Area

Art. 12. (1) As a rule, personal data processed through the Platform are stored on servers located in the European Union (“EU”) / European Economic Area (“EEA”).

(2) Notwithstanding paragraph 1, in certain circumstances limited transfers of Personal Data outside the EEA may take place, including, but not limited to:

1. in the case of technical support by providers of infrastructure or application services whose personnel are outside the EEA, where access is necessary to resolve technical issues, for maintenance or to ensure continuity of the service;

2. during archiving, backup and disaster recovery operations;

3. when using analytics and advertising providers (e.g. Google, Meta) whose servers may be outside the EEA;

4. when publishing content on social networks (Facebook, Instagram, TikTok, YouTube, LinkedIn, etc.), where applicable;

5. when sending messages through instant messaging applications (Viber, WhatsApp, Telegram, Signal and others), whose infrastructure may include servers outside the EEA.

(3) Where a transfer of data outside the EEA is necessary, the Company ensures appropriate safeguards in accordance with the GDPR.

(4) The Company makes efforts to minimise transfers of data outside the EEA and, where possible, to limit access by personnel outside the EEA to Personal Data.

(5) You may obtain more information about the specific safeguards applied to transfers of data outside the EEA by contacting us at [email protected].

Section VIII.

Cookies and Similar Technologies

Art. 13. (1) The Platform uses cookies and similar tracking technologies. Detailed information about the types of cookies, the purposes for which they are used, the ways to manage your preferences and your rights in relation to them is contained in a separate Cookie Policy, available at www.onecare.bg.

(2) The Cookie Policy forms an integral part of this Privacy Policy.

Section IX.

Personal Data Retention Periods

Art. 14. (1) The Company stores personal data for a period no longer than necessary to achieve the purposes for which the data are processed, taking into account the applicable statutory retention periods.

(2) The main retention periods are as follows:

1. Data related to a user account - for the duration of the existence of the account and for up to 6 months after deletion of the account, unless a longer period is necessary for compliance with a legal obligation or for the defence of legal claims;

2. Data related to a specific request and performance of a service - for a period of 5 years from the date of performance or termination of the contract for the service, in accordance with the general limitation period under the Bulgarian Obligations and Contracts Act;

3. Accounting and tax documents, including invoices and payment documents - for a period of 10 years, counted from 1 January of the year following the year to which they relate, in accordance with the Bulgarian Accountancy Act and the Tax and Social Security Procedure Code;

4. Medical documentation uploaded through the Platform by a Service Provider - the Company stores such documentation in its capacity as a Personal Data processor under the instructions of the Service Provider. Retention periods are determined by the Service Provider in accordance with the applicable health legislation;

5. Data for marketing communications - until withdrawal of consent or unsubscribing from the relevant communication;

6. Cookie data - in accordance with the periods set in the settings of the relevant cookie, but no longer than 2 years;

7. Communication data (forms, complaints, correspondence) - for a period of 5 years from the last communication, unless a longer period is necessary for the defence of legal claims;

8. Data of Service Providers and their professionals - for the duration of the contractual relationship between the Company and the Service Provider and for a period of 5 years after its termination;

9. Photographs and video materials - until withdrawal of consent, except for materials that have already been lawfully published, indexed, archived or stored outside the Company’s factual control.

(3) After expiry of the applicable retention period, the Company deletes or anonymises the personal data, unless their storage is necessary for compliance with a legal obligation, for the defence of legal claims or on another applicable legal ground.

(4) The specific retention periods may vary depending on the type of service, the applicable legislation and the specific circumstances. Upon request, the Company provides information about the applicable retention period in respect of specific categories of data.

(5) The Company periodically reviews the necessity of storing Personal Data and the adequacy of the specified periods, taking into account legislative changes, the purposes of the Processing and the principle of data minimisation.

Section X.

Rights of Data Subjects

Art. 15. (1) Pursuant to the GDPR and the applicable legislation, you have the following rights in relation to your Personal Data:

1. Right of access (Article 15 GDPR) - to obtain confirmation as to whether the Company processes your Personal Data and, where this is the case, to obtain access to them and to information about the Processing;

2. Right to rectification (Article 16 GDPR) - to request rectification of inaccurate Personal Data or completion of incomplete data;

3. Right to erasure (“right to be forgotten”) (Article 17 GDPR) - to request erasure of your Personal Data where the grounds provided for in the GDPR are present, except where the Processing is necessary for compliance with a legal obligation, for the establishment, exercise or defence of legal claims or on another ground provided by law;

4. Right to restriction of Processing (Article 18 GDPR) - to request restriction of Processing in the cases provided for by the GDPR;

5. Right to data portability (Article 20 GDPR) - to receive your Personal Data in a structured, commonly used and machine-readable format and to transmit those data to another controller, where the Processing is based on consent or on a contract and is carried out by automated means;

6. Right to object (Article 21 GDPR) - to object to the Processing of your Personal Data where the Processing is based on the Company’s legitimate interest, including to Processing for direct marketing purposes;

7. Right not to be subject to a decision based solely on automated Processing, including profiling (Article 22 GDPR) - where applicable;

8. Right to withdraw consent - where the Processing is based on your consent, you have the right to withdraw it at any time, without affecting the lawfulness of the Processing carried out before the withdrawal.

(2) To exercise your rights under paragraph 1, you may send a request by email to: [email protected]. The Company may request additional information to verify your identity before taking action on the request.

(3) The Company responds to requests under paragraph 1 within 1 month of their receipt. This period may be extended by up to two additional months where necessary, taking into account the complexity and number of the requests, of which the Company shall inform the data subject.

(4) The exercise of the rights under paragraph 1 is free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the Company may charge a reasonable fee or refuse to act on the request.

(5) Where personal data are processed by the Company in its capacity as processor under the instructions of a Service Provider, the Company may forward the request to the relevant Service Provider, which is the controller of those data.

Section XI.

Marketing Communications

Art. 16. (1) The Company may send marketing communications to Users and Service Providers who have given their explicit consent to this. Consent may be withdrawn at any time, without affecting the lawfulness of the Processing carried out before the withdrawal.

(2) Detailed information about the types of marketing communications, channels, frequency, methods for unsubscribing and your rights is contained in a separate Marketing Policy, available at www.onecare.bg.

(3) The Marketing Policy forms an integral part of this Privacy Policy.

(4) Messages related to a request, payment, change, cancellation, rescheduling, service status, appointment reminder, security, policy updates and other essential elements of the legal relationship do not constitute marketing communications and do not require separate marketing consent. These messages may be sent by email, SMS, Viber, WhatsApp or through another communication channel specified by the User or used within the Platform.

Section XII.

Security of Personal Data

Art. 17. (1) The Company applies appropriate technical and organisational measures to protect personal data against unauthorised or unlawful access, accidental loss, destruction, damage, alteration or disclosure, including, but not limited to:

1. encryption of data in transit (SSL/TLS) and at rest (AES-256 or an equivalent standard);

2. data backup;

3. monitoring, logging and notification in the event of security incidents;

4. periodic review and update of security measures.

(2) The Company cannot guarantee absolute security of data, as no system for transmitting or storing data via the Internet is completely secure. In the event of a personal data breach, the Company notifies the competent supervisory authority and the affected data subjects in accordance with Articles 33 and 34 GDPR, where applicable.

(3) Users and Service Providers are obliged to keep their access credentials (username and password) confidential and to notify the Company immediately in the event of any suspicion of unauthorised access to their account.

(4) Where any Processing, in particular using new technologies or involving large-scale Processing of special categories of data, is likely to result in a high risk to the rights and freedoms of natural persons, the Company carries out a prior data protection impact assessment (DPIA) in accordance with Article 35 GDPR before commencing the Processing.

(5) The Company applies the principles of data protection by design and by default within the meaning of Article 25 GDPR, by integrating appropriate technical and organisational measures for the protection of Personal Data when designing and developing the Platform and by ensuring that, by default, only data necessary for each specific purpose are processed.

(6) The Company maintains a record of processing activities under Article 30 GDPR, which contains information about the purposes of the Processing, the categories of data subjects and data, the recipients, the retention periods and a description of the technical and organisational security measures.

(7) The Company ensures internal control over compliance with this Policy and the applicable Personal Data protection legislation, including through periodic internal checks, training of personnel with access to Personal Data and maintenance of documentation of the accountability activities carried out.

(8) The Company determines the scope of the Personal Data processed in its own environment and in the environment of the technical providers under Article 11(1)(2). This allocation may be changed by the Company over time depending on the development of the Platform, the introduction of new functionalities, security requirements and the applicable legislation, without this constituting an amendment to this Policy.

Section XIII.

Allocation of Roles Between the Company and the Service Provider

Art. 18. (1) The Platform acts as an online marketplace and intermediary between the User and the Service Provider. The allocation of roles with respect to the Processing of Personal Data is as follows:

1. The Company is an independent controller for the registration and maintenance of user accounts, its own general terms and policies, its own accounting, tax and legal servicing, the security and functioning of the Platform, marketing communications, analytics and any other operation for which it independently determines the purposes and means of the Processing;

2. The Service Provider is an independent controller for the provision of the service itself, the medical or other professional assessment, the creation and storage of medical and other professional documentation, the fulfilment of obligations to regulatory authorities and any other operation for which it independently determines the purposes and means;

3. The Company is a Personal Data processor on behalf of the Service Provider for the technical receipt and routing of requests, the hosting and storage of documents, the issuance of invoices on behalf of the Service Provider, the Processing of payments on behalf of the

Service Provider and other operations in which the Company acts under the instructions of the Service Provider;

4. For certain operations in which the Company and the Service Provider jointly determine the purposes and essential means of the Processing (e.g. management of the request process, patient access to documents, integrated invoicing and payment process), they may act as joint controllers within the meaning of Article 26 GDPR, with the internal allocation of responsibilities being governed by a separate agreement.

(2) The specific allocation of roles between the Company and each individual Service Provider is governed by a data protection agreement, which forms an integral part of the contractual relationship between them.

(3) Irrespective of the internal allocation of roles, the data subject may exercise his or her rights against each of the parties, insofar as this is permitted by the applicable legislation.

Section XIV.

Protection of Children’s Personal Data

Art. 19. (1) The Platform is intended for natural persons with full legal capacity. Minors may not independently create user accounts and may not independently request services through the Platform.

(2) Where the User requests a service for his or her minor child, he or she provides data about the child in his or her capacity as parent or legal representative, acts on the child’s behalf and is responsible for the lawfulness of providing the data.

(3) Where the provision of a service to a minor requires Processing of Special Categories of Personal Data (e.g. health data), the Processing is carried out on the basis of Article 9(2)(h) GDPR and/or on the basis of the consent of the parent/legal representative, where applicable.

(4) If the Company establishes that it has collected Personal Data of a minor without the consent of a parent or legal representative, it shall take steps to erase them as soon as possible.

Section XV.

Right to Lodge a Complaint

Art. 20. (1) If you consider that the Processing of your Personal Data infringes the GDPR or the applicable personal data protection legislation, you have the right to lodge a complaint with:

1. the Commission for Personal Data Protection (CPDP) - address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.; website: www.cpdp.bg; email: [email protected];

2. a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement, where applicable.

(2) The right to lodge a complaint is not conditional upon prior exercise of the rights under Section X of this Policy, but the Company encourages you first to contact us at [email protected] so that we can resolve the matter.

Section XVI.

Amendment of the Privacy Policy

Art. 21. (1) The Company has the right at any time to amend, supplement or replace this Policy, including in the event of changes to the applicable legislation, technical and organisational conditions, categories of data processed, providers or functionalities of the Platform.

(2) The current version of the Policy is published on the Platform at www.onecare.bg, indicating the date of the latest update.

(3) In the event of material changes affecting the rights of data subjects, the Company notifies Users and Service Providers by email, message in the account, notice on the Platform or by another appropriate means.

(4) Continued use of the Platform after the amendment enters into force shall be deemed acknowledgement of the current version of the Policy, insofar as this is permitted by the applicable legislation.

Section XVII.

Final Provisions

Art. 22. (1) This Policy has been adopted by the manager of the Company and enters into force as of 04.05.2026.

(2) Matters not regulated in this Policy shall be governed by the provisions of the GDPR, the PDPA, the General Terms and Conditions for Use of the OneCare Platform and the applicable Bulgarian and European legislation.

(3) The invalidity of an individual provision of this Policy shall not result in the invalidity of the remaining provisions.