Personal Data Protection Policy for Taurus Marketing BTL LLC

Introduction

Taurus Marketing BTL LLC («Taurus,» «we,» «us,» or «the Company»), a limited liability company established in the state of Florida, United States of America, with its address at 1317 Edgewater Drive, #4195, Orlando, Florida, is committed to protecting the privacy and security of the personal data it collects and processes. This Personal Data Protection Policy («Policy») has been created in accordance with the laws of the state of Florida, including the Florida Digital Bill of Rights (FDBOR) and the Florida Information Protection Act (FIPA) of 2014, to ensure the integrity of the Company and that of the users who share their data in any activity carried out by Taurus for its clients.

This Policy details our practices regarding the collection, use, disclosure, retention, and protection of your personal information. It is essential for us that users and our clients understand how we handle personal information and how we ensure that data collected on behalf of our clients is used exclusively for the purposes they determine.

Scope of this Policy

This Policy applies to all personal information collected about individuals in the state of Florida and other jurisdictions where we operate, in the course of providing our BTL (Below The Line) marketing services to our clients. This includes data collected through promotional events, brand activations, direct marketing campaigns, websites, mobile applications, and any other activity in which Taurus participates on behalf of its clients.

Key Definitions

For the purposes of this Policy, the following definitions apply, in accordance with Florida legislation:

«Personal Data»: Any information relating to an identified or identifiable natural person.

«Sensitive Personal Data»: A category of personal data that reveals an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.

«Data Controller»: The natural or legal person who, alone or jointly with others,

determines the purposes and means of the processing of personal data. In the context of Taurus’s services, our clients are the Data Controllers.

«Data Processor»: The natural or legal person who processes personal data on behalf of the Data Controller. Taurus Marketing BTL LLC acts as a Data Processor.

«Processing»: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Core Principles of Our Data Policy

Taurus adheres to the following principles for the processing of personal data:

Lawfulness, Fairness, and Transparency: We process personal data lawfully, fairly, and in a transparent manner in relation to the data subject.

Purpose Limitation: We collect personal data for specified, explicit, and legitimate purposes and do not further process them in a manner that is incompatible with those purposes.

Data Minimization: We ensure that the personal data we collect is adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

Accuracy: We take reasonable steps to ensure that the personal data we process is accurate and, where necessary, kept up to date.

Storage Limitation: We keep personal data in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.

Integrity and Confidentiality: We ensure appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.

Exclusive Use by the Client: Taurus will not use personal data collected on behalf of a client for its own marketing purposes, nor will it share or sell it to third parties. The use of the collected data is restricted exclusively to the client for whom the marketing activity was conducted, who acts as the Data Controller.

Collection of Personal Data

Taurus collects personal data on behalf of its clients through various means, including, but not limited to:

● Registration forms at events and brand activations.

● Contests and sweepstakes.

● Surveys and market research.

● Campaign websites and landing pages.

● Mobile applications.

● Email and SMS communications.

The types of personal data we may collect include:

Contact Information: Name, postal address, email address, telephone number.

Demographic Information: Age, gender, date of birth, household income.

Preference and Interest Information: Product preferences, hobbies, and interests.

Technical Information: IP address, browser type, operating system, device identifiers.

Geolocation Data.

Photographs and Videos: At events, with due consent.

In the event we collect Sensitive Personal Data, we will obtain the individual’s explicit consent prior to collection, in accordance with the Florida Digital Bill of Rights.

Use of Personal Data

Taurus, in its capacity as a Data Processor, uses the personal data collected solely for the purposes specified by our clients (the Data Controllers). These purposes may include:

● Managing participation in contests, sweepstakes, or promotions.

● Sending marketing communications on behalf of our clients.

● Conducting market research and data analysis.

● Personalizing the consumer experience with our clients’ brands.

● Fulfilling contractual obligations with our clients.

It is the strict policy of Taurus Marketing BTL LLC that personal data collected for a client is the exclusive property of that client. Taurus will not use, sell, rent, or otherwise share such data with any other client, third party, or for its own internal marketing purposes.

Legal Basis for Processing

The processing of personal data is based on the consent of the individual, which will be obtained clearly and unambiguously at the time of data collection, in accordance with the Florida Digital Bill of Rights (FDBOR). Individuals will be informed of the specific client on whose behalf the data is being collected and the purpose of such collection.

User Rights

In accordance with the Florida Digital Bill of Rights, individuals have the following rights over their personal data:

Right of Access: The right to confirm whether a controller is processing their personal data and to access such personal data.

Right to Correct: The right to correct inaccuracies in their personal data.

Right to Delete: The right to request the deletion of their personal data.

Right to Data Portability: The right to obtain a copy of their personal data in a portable and, to the extent technically feasible, readily usable format.

Right to Opt-Out:

○ The right to opt out of the processing of personal data for purposes of targeted advertising.

○ The right to opt out of the sale of personal data.

○ The right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer.

Right to Opt-Out of Sensitive Data Collection: The right to opt out of the processing of their sensitive personal data.

Right to Opt-Out of Collection by Voice and Facial Recognition Devices.

To exercise any of these rights, individuals must direct their request to the client (the Data Controller) on whose behalf their data was collected. Taurus, as a Data Processor, will fully cooperate with its clients to respond to these requests in a timely manner, in accordance with Florida law. We will provide our clients with the necessary assistance to fulfill their obligations.

Data Security

Taurus implements reasonable technical, administrative, and physical security measures to protect personal data from unauthorized access, disclosure, alteration, and destruction, in compliance with the Florida Information Protection Act (FIPA) of 2014, Section 501.171 of the Florida Statutes. These measures include:

● Encryption of data in transit and at rest.

● Strict access controls to ensure only authorized personnel have access to personal data.

● Regular security audits and risk assessments.

● Staff training on the importance of data protection and security best practices.

Data Breach Notification

In the event of a data security breach affecting personal information, Taurus will notify the affected client (the Data Controller) without undue delay, and no later than 10 days after the

discovery of the breach, as required by FIPA. The client, as the Data Controller, is responsible for notifying the affected individuals and the Florida Department of Legal Affairs, if applicable, within 30 days of the determination of the breach. Taurus will provide the client with all necessary information and cooperation to meet its breach notification obligations.

Data Retention and Deletion

Taurus will retain personal data only for as long as necessary to fulfill the purposes for which it was collected, as instructed by our client, and in accordance with our contractual obligations. Once the data is no longer needed, it will be securely deleted or anonymized.

Data deletion will be carried out using methods that prevent the reconstruction of the information, such as shredding paper documents and securely erasing electronic data.

Email Communications and Telemarketing

Any email or telemarketing communications conducted by Taurus on behalf of its clients will comply with the Florida Electronic Mail Communications Act (Chapter 668, Part III of the Florida Statutes) and the Florida Telemarketing Act (Section 501.059 of the Florida Statutes). This includes:

● Not using false or misleading header information.

● Not using deceptive subject lines.

● Providing a clear and conspicuous mechanism to opt out of future communications.

● Adhering to permissible calling times for telemarketing.

● Obtaining prior express written consent for automated telephone sales calls.

International Data Transfers

In the event that personal data is transferred outside of the United States, Taurus will ensure that appropriate safeguards are in place to protect the personal information in accordance with applicable data protection laws.

Children's Privacy

Taurus does not knowingly collect personal data from children under the age of 13 without verifiable parental consent, in compliance with the Children’s Online Privacy Protection Act (COPPA). If we become aware that we have collected personal data from a child under 13

without parental consent, we will take steps to delete that information from our systems.

Changes to this Privacy Policy

Taurus reserves the right to amend this Policy at any time. Any changes will be effective immediately upon the posting of the revised Policy on our website. We encourage users and clients to periodically review this page for the latest information on our privacy practices.

Contact Us

If you have any questions or concerns about this Personal Data Protection Policy or our data practices, you may contact us at:

Taurus Marketing BTL LLC

1317 Edgewater Drive, #4195

Orlando, Florida

Contacto@taurusmkt.com

For requests related to your personal data rights, please contact the company (our client) on whose behalf your data was collected directly.