Panreal AB – Confidentiality Policy

1. Purpose

The purpose of this Confidentiality Policy (“Policy”) is to establish mandatory rules for the protection, handling, and disclosure of Confidential Information (as defined below) that is owned, received, or generated by Panreal AB (“Panreal”, “we”, “our”, or “us”).

2. Scope

This Policy applies to all employees, officers, directors, interns, contractors, consultants, temporary staff, and third-party service providers who access or process Confidential Information on behalf of Panreal (“Personnel”).

3. Definition of Confidential Information

“Confidential Information” means any non-public information—regardless of form (written, oral, electronic, or otherwise)—that relates to:

  • Panreal’s business, financials, strategies, forecasts, pricing, trade secrets, intellectual property, software, methodologies, or data models
  • Clients, prospective clients, investors, or business partners, including personal data, business plans, transactions, and due-diligence materials
  • Any information marked or otherwise designated as confidential, or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure

4. Legal and Regulatory Framework

Panreal is committed to compliance with, including but not limited to:

  • EU General Data Protection Regulation 2016/679 (“GDPR”)
  • Swedish Trade Secrets Act (2018:558)
  • Applicable contractual confidentiality and non-disclosure obligations

5. Classification of Information

Panreal classifies information into the following levels, each requiring progressively stricter safeguards:

  • Public – information approved for unrestricted disclosure
  • Internal – non-public operational information intended for internal use
  • Confidential – information that could harm Panreal or its stakeholders if disclosed
  • Highly Confidential – information whose unauthorised disclosure would cause significant competitive, financial, or regulatory damage

6. Responsibilities of Personnel

Personnel must follow these requirements:

  • Need-to-Know Access – Access only the information strictly necessary to perform assigned duties
  • Secure Storage – Store electronic files on encrypted drives or approved cloud services with multi-factor authentication; lock paper files in secure cabinets
  • Secure Transmission – Transmit Confidential Information via encrypted email, secure file-sharing portals, or other company-approved channels; never use personal email accounts
  • Non-Disclosure – Do not disclose Confidential Information to any unauthorised person inside or outside Panreal without prior written approval from the Managing Director or the Data Protection Officer (“DPO”)
  • Retention & Disposal – Retain only for as long as required by business needs or legal obligations; shred paper documents and permanently delete electronic files when no longer required
  • Incident Reporting – Immediately report any suspected or actual loss, theft, or unauthorised disclosure to security@panreal.se and the DPO

7. Third-Party Access

Confidential Information may be shared with external advisers, auditors, or suppliers only if:

  • A written non-disclosure agreement (“NDA”) or equivalent contractual obligation is in place
  • The recipient requires the information solely for the purpose for which access is granted

8. Legal Compulsion

If disclosure is required by law, regulation, or valid court order, Personnel must (unless legally prohibited) promptly notify the General Counsel or DPO and cooperate in seeking protective measures.

9. Breaches and Sanctions

Violation of this Policy may result in disciplinary measures up to and including termination of employment or contract, and may expose the individual to civil or criminal liability.

10. Review and Amendment

This Policy is reviewed at least annually and updated as necessary to reflect legal, regulatory, or organisational changes. Revised versions become effective upon publication on panreal.se or internal communication to Personnel.

11. Contact

Questions regarding this Policy should be directed to:
Data Protection Officerinfo@panreal.se
Panreal AB, Kungsgatan 46, 411 15 Gothenburg, Sweden

Last updated: 7 August 2025