RackWorks LLC GDPR Compliance Statement Effective Date: June 1, 2026 Last Updated: June 1, 2026 1. Introduction RackWorks LLC ("we," "us," or "our") recognizes the importance of protecting the personal data of individuals within the European Economic Area ("EEA") and is committed to compliance with the European Union's General Data Protection Regulation ("GDPR") (Regulation (EU) 2016/679). This GDPR Compliance Statement outlines how we process personal data in accordance with GDPR principles and requirements. 2. Data Controller and Processor 2.1 RackWorks LLC acts as the data controller with respect to personal data collected directly from customers and website visitors. 2.2 When providing hosting and infrastructure services, RackWorks LLC may act as a data processor on behalf of customers who determine the purposes and means of processing personal data. 3. Lawful Basis for Processing We process personal data only when we have a lawful basis including but not limited to: Consent Performance of a contract Compliance with a legal obligation Protection of vital interests Legitimate interests pursued by RackWorks LLC or a third party, provided such interests are not overridden by data subjects' rights. 4. Data Subject Rights Under GDPR, data subjects have the following rights regarding their personal data: Right to access and obtain a copy of their data Right to rectify inaccurate or incomplete data Right to erasure ("right to be forgotten") subject to legal obligations Right to restrict or object to processing Right to data portability Right to withdraw consent where processing is based on consent Right to lodge a complaint with a supervisory authority To exercise these rights, data subjects may contact RackWorks LLC at privacy@rackworks.net. 5. Data Security RackWorks LLC implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments. 6. Data Transfers Outside the EEA Where personal data is transferred outside the EEA, RackWorks LLC ensures adequate safeguards are in place, such as: Standard Contractual Clauses approved by the European Commission Compliance with applicable data protection laws 7. Data Retention We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law. 8. Data Breach Notification In the event of a personal data breach, RackWorks LLC will notify affected data subjects and supervisory authorities as required by GDPR without undue delay and within the statutory deadlines. 9. Subprocessors RackWorks LLC may engage subprocessors to perform certain processing activities. All subprocessors are contractually bound to comply with GDPR obligations. 10. Updates to This Statement RackWorks LLC may update this GDPR Compliance Statement periodically to reflect changes in regulations or business practices. Updates will be posted at rackworks.net. 11. Contact For GDPR inquiries or data protection concerns, please contact: RackWorks LLC Data Protection Officer Email: privacy@rackworks.net Address: 24700 Northwestern Hwy, Suite 533, Southfield, MI 48075