Data Sharing Addendum (Controller-to-Controller)

Platform Operator (HK): LOTOFJEWELRY LIMITED, CR No.: 78809321-000-09-25-8.

Registered Address: RM 5058, 5/F YAU LEE CENTRE, 45 HOI YUEN RD, KWUN TONG, HONG KONG

Operations Center (Thailand): 919/1 Si Lom Rd, Si Lom, Bang Rak, Bangkok 10500, Thailand

Contacts: info@lotofjewelry.com | Phone: +66 80 713 0700

1. Roles & Interpretation

Parties act as independent controllers for personal data exchanged via the Platform for order fulfilment, unless agreed otherwise in writing.

2. Purpose & Lawful Basis

Seller processes data to: fulfil orders; warranty/returns; statutory accounting; respond to lawful requests; prevent fraud. Bases: contract, legal obligation, legitimate interests. Marketing/profiling requires proper legal basis and explicit consent where required.

3. Data Scope

Identity/contact data, shipping/billing addresses, order details, order communications, transaction identifiers (no payment card data if processed by a PSP).

4. Security & Confidentiality

Appropriate TOMs: encryption in transit, MFA & least privilege, logging, backups, secure development and vulnerability management. Personnel under confidentiality and training.

5. Data Subject Rights

Each Party handles rights requests for its processing; Parties reasonably assist each other for shared data requests.

6. Personal Data Breach

Notify the other Party without undue delay (preferably within 48 hours) about any breach affecting shared data with sufficient details for assessment and notifications.

7. International Transfers

Use EU 2021/914 SCCs — Module 1 (Controller↔Controller) and/or UK IDTA/UK Addendum; include transfer impact assessment and supplementary measures as necessary. Incorporated by reference.

8. Retention & Deletion

Retain only as necessary for clause 2 and statutory retention; thereafter delete/anonymize. Delete on Platform request where law permits.

9. Sub-recipients / Processors

As independent controllers, each Party remains responsible for its processors and contracts ensuring GDPR-level protections.

10. Audit & Assurance

On reasonable notice, Seller provides information on TOMs/policies and relevant attestations without exposing trade secrets.

11. Liability & Indemnity

Each Party is liable to data subjects for its processing. Between Parties, liability is governed by the Main B2B Agreement.

12. Term & Signatures

Effective date: [●]

Platform Signature: __________________ Name/Title: __________________ Date: ____

Seller Signature: _____________________ Name/Title: __________________ Date: ____