WYD Massive Multiplayer Online Game

Information Security Policy

INFORMATION SECURITY POLICY

RAID HUT LICENCIAMENTO DE JOGOS DIGITAIS LTDA.

CNPJ: 23.877.777/0001-34



Document Information Security Policy
Version 1.0
Approval date 08/10/2026
Approval Approved by the absolute majority of the partners comprising the company’s Share Capital.
Responsible ATILA VALGUEIRO MALTA MOREIRA
Next review 12 months from approval, or earlier (should a relevant event warrant a reassessment of its terms)


1. PURPOSE AND SCOPE

1.1. This Policy establishes the rules for the protection of the information processed by RAIDHUT LICENCIAMENTO DE JOGOS DIGITAIS LTDA. in connection with the operation of the electronic game With Your Destiny (WYD) - Global and Season servers, as well as any temporary, seasonal, test or event servers (hereinafter jointly referred to as “WYD Global”) and of the internal tools that support it, in compliance with Law No. 13,709/2018 (Brazilian General Data Protection Law - LGPD) and with the regulations of the Autoridade Nacional de Proteção de Dados (Brazilian National Data Protection Authority - ANPD).

1.2. The provisions of this Policy apply to all partners, employees, interns and service providers who access the company’s systems, administrative tools or databases, as well as to all technological environments used, whether owned by the company or contracted from third parties.

1.3. This Policy was drafted in a dimension proportional to the size of the company, qualified as a small-scale processing agent, prioritizing controls that are effectively enforceable and verifiable.

1.4. For the purposes of this Policy, “Management” means the manager or the group of managers designated in the articles of association of RAID HUT LICENCIAMENTO DE JOGOS DIGITAIS LTDA., to whom the acts of management and the resolutions provided for in this Policy are assigned.


2. RESPONSIBILITIES

2.1. It is incumbent upon Management to approve this Policy, to provide the resources necessary for its execution, to foster an information security culture throughout the organization and to decide on exceptions, which must be formalized in writing, and it is to Management that the person responsible for information security reports directly.

2.2. The person responsible for information security, a role performed by ATILA VALGUEIRO MALTA MOREIRA, keeps this Policy up to date, grants and revokes access, conducts the periodic reviews, coordinates incident response and preserves the documentation evidencing the controls.

2.3. All employees must use individual and non-transferable credentials, immediately report any suspected incident and refrain from accessing information unrelated to their duties. Consulting user data without a legitimate operational purpose constitutes a violation of this Policy, even if the employee has technical access to the information.


3. INFORMATION CLASSIFICATION

3.1. Information is classified as:

a) Public: intended for broad disclosure, such as official announcements and website content;

b) Internal: for internal operational use, accessible to all partners, employees, interns and service providers associated with the company, regardless of specific authorization, such as technical documentation and reports;

c) Confidential: information of strategic or economic value to the company, the unauthorized disclosure of which may cause business, reputational or competitive harm, such as source code and game architecture documentation, balancing parameters and undisclosed mechanics, launch and monetization plans, financial and accounting data, commercial information of licensors, suppliers and partners, contractual instruments and the respective negotiations, as well as material protected by a confidentiality obligation undertaken towards third parties, accessible only to those who need it for the performance of their duties, upon named authorization; and

d) Restricted: personal data of users and employees, credentials, transaction records, integration keys and addresses of internal administrative tools, accessible exclusively to the holders of specific authorization, limited to the minimum necessary for the performance of a given operational duty.

3.2. Access to confidential or restricted information depends on named authorization and is fully logged. As a measure aimed at safeguarding the greatest possible protection of information, whenever there is doubt as to the classification to be adopted, the information shall be treated as Restricted.

3.3. Information classified as Confidential may not be shared with third parties without the prior written authorization of Management and without the execution of a confidentiality instrument, and must be stored and transmitted exclusively through the company’s official channels.


4. ACCESS CONTROL

4.1. Access to administrative tools and to databases containing personal data is permitted exclusively to named and individual accounts linked to an e-mail address in the corporate domain. The use of generic or shared accounts, or of accounts linked to personal addresses or to addresses of third parties, is prohibited.

4.2. The existence of any self-service account creation flow in any administrative tool is prohibited. The creation of accounts depends on a formal request and on the approval of the person responsible for information security, and is carried out exclusively by an authorized administrator.

4.3. Access is granted in accordance with the principle of least privilege and is formalized in a record stating the requester, the justification, the profile granted and the date. Revocation is immediate upon termination, upon the end of the contract or upon a change of role that renders the access unnecessary.

4.4. The person responsible for information security shall review, every 6 (six) months, the active administrative accounts and the privileges assigned, revoking those that are unnecessary. In order to ensure compliance with the established frequency, the review shall be recorded in a dated document.

4.5. The read and write rules in the databases must restrict access exclusively to authenticated and previously authorized users, and any configuration allowing access by an unauthenticated user or without a specific privilege is prohibited. Changes to these rules depend on the approval of the person responsible and shall be recorded.


5. CREDENTIALS AND ACCESS KEYS

5.1. Internal access passwords must meet minimum complexity requirements and be individual, and their sharing by any means is prohibited.

5.2. Multi-factor authentication (MFA) is mandatory for access to the following critical tools and systems: (i) Game administration panels; (ii) Production database; (iii) Corporate e-mail of the administrators; (iv) Source code repositories (e.g.: GitHub/GitLab); (v) administrative panels of gateways; and, (vi) without limitation, administrative consoles of hardware and software infrastructure.

5.3. Integration keys and other secrets may not appear in published code or on pages accessible to the public, and must be kept in a storage mechanism with restricted access and immediately replaced in the event of suspected exposure.


6. SECURITY ON DEVICES AND REMOTE WORK

6.1. The storage of sensitive or restricted data on removable media (pen drives, external HDs) that are not duly encrypted is prohibited.

6.2. Devices used to access administrative systems must have up-to-date antivirus software and automatic screen lock after 5 minutes of inactivity.

6.3. Access to administrative tools outside the company’s physical premises must preferably be carried out over a secure network or corporate VPN, and the use of public Wi-Fi networks without additional protection is prohibited.

6.4. Clean Desk and Clear Screen Policy: The "clean desk" and "clear screen" policy applies to all employees, and it is mandatory to lock the workstation whenever the user leaves their physical desk or work environment, as well as not to expose passwords or documents containing user data in locations accessible to third parties.


7. EXPOSURE OF INTERNAL RESOURCES

7.1. Administrative tools, management panels and test environments may not be referenced, linked or made identifiable from public pages, from the source code of such pages or from any material accessible to end users.

7.2. The publication of new public pages or features must be preceded by verification as to the possible exposure of internal resources.

7.3. The protections against e-mail address enumeration must remain active, so as to prevent third parties from verifying, through successive registration or account recovery attempts, whether a given address is part of the user base.

7.4. Public pages that display user information, such as ranking listings, must present only the elements necessary for their purpose, and the display of registration data is prohibited.

7.5. The use of real personal data of users in development, test or staging environments is prohibited.


8. EVENT LOGGING AND MONITORING

8.1. All actions carried out in administrative tools, notably consultations of user records, account changes and operations on game assets, are recorded in a log containing the identification of the operator, the date and time of the event and the operation performed.

8.2. The records are retained for a period of no less than 12 (twelve) months and are protected against alteration and deletion, including by the administrative operators themselves.

8.3. The company maintains an automated alert for the detection of anomalous patterns of access to the administrative interfaces, notably access outside the usual hours of operation, an atypical volume of consultations and authentication attempts by an unauthorized account. The alerts are directed to the person responsible for information security, who records the verification carried out.


9. BACKUPS, RETENTION AND DISPOSAL

9.1. Backups of the production databases are maintained on a weekly basis, through an automated routine, with the copies being retained for a period of no less than 30 (thirty) days, stored in an environment with access control equivalent to that of production. It is mandatory to carry out and record a restoration test in an isolated environment at least once a year, in order to ensure the effectiveness of the recovery.

9.2. Personal data are retained only for the period necessary to fulfill the purposes that justified their collection, subject to the legal retention periods, and their deletion or anonymization is arranged at the end of that period.

9.3. The elimination of data must be carried out by a method that prevents the recovery of the information.

9.3.1. Equipment that has stored information classified as Confidential or Restricted, whenever it leaves the sphere of control of the user to which it was assigned, is previously submitted to a sanitization procedure by a method that prevents the recovery of the information, notably secure overwriting, destruction of the encryption key of the media or physical destruction, as appropriate to its destination. This requirement applies to the cases of definitive disposal, sale, donation, return to the lessor or to the owner, as well as of reallocation of the equipment to another employee or to another role.

9.4. The sending of equipment to a third party for maintenance, repair or technical assistance must be preceded by the removal or the sanitization of the storage media. Where the nature of the defect prevents the adoption of these measures, the shipment depends on the authorization of the person responsible for information security and on the execution of a confidentiality instrument with the professional who will be responsible for the maintenance, repair or technical assistance, stating the prohibition of access to, copying of or retention of the data and the obligation to return or destroy the replaced media.


10. CHANGES AND SUPPLIERS

10.1. Relevant changes to authentication or authorization configurations, database rules or resource exposure must be documented, indicating the change, the person responsible, the date and the result of the subsequent verification.

10.2. Every vulnerability fix is submitted to a validation test, including an unauthorized access attempt, before being considered complete.

10.3. The engagement of suppliers that process personal data on behalf of the company must provide for confidentiality obligations, the adoption of security measures compatible with this Policy and the immediate reporting of incidents. The access granted is named, limited to the contracted scope and revoked upon the end of the engagement - at which point the supplier shall be contractually obliged to delete the personal data processed.

10.4. The company maintains a simplified record of the personal data processing operations, pursuant to art. 37 of the LGPD (Brazilian General Data Protection Law) and art. 8 of the Regulation approved by Resolution CD/ANPD No. 2/2022, reviewed together with this Policy.


11. VULNERABILITIES REPORTED BY THIRD PARTIES

11.1. The company maintains a channel for receiving reports of vulnerabilities identified by users or external researchers, at the official support address.

11.2. Upon receipt of the report, the person responsible for information security records the report, assesses its merits within no more than 2 (two) business days and, where applicable, initiates the procedure provided for in Clause 11.

11.3. A report made in good faith, without exploitation beyond what is necessary to demonstrate the flaw, without public disclosure and without data extraction, does not give rise to any sanction against the reporting party. The company does not maintain a vulnerability bounty program.

11.4. Where the report reveals access to personal data, the company shall endeavor to execute a confidentiality instrument with the reporting party assuming the obligation to destroy the information viewed, without prejudice to the duty to report the incident to the competent authorities and to the data subjects, which shall remain in full force for all purposes.


12. MANAGEMENT OF SECURITY INCIDENTS

12.1. Any employee who identifies or suspects an incident must report it immediately to the person responsible for information security, by any available means, and it is prohibited to wait for business hours or for prior confirmation of the suspicion.

12.2. Once the incident is identified, the following are adopted, in this order of priority: (i) containment of the access vector, in order to cease the exposure in the shortest possible time; (ii) preservation of the access records, alteration or deletion being prohibited; (iii) determination of the extent, with identification of the data subjects and of the categories of data affected; (iv) definitive correction of the cause, validated by testing; and (v) notification of the Autoridade Nacional de Proteção de Dados (ANPD) and of the data subjects, within the periods established by the legal framework.

12.3. The person responsible shall record, on the first business day following becoming aware, the date and time of knowledge of the incident, being the milestone from which the periods shall be counted.

12.4. The notification of the Authority and of the data subjects shall observe the period set out in art. 6 of Resolution CD/ANPD No. 15/2024, counted twofold by reason of the company’s qualification as a small-scale processing agent.

12.5. The notification to the data subjects must contain, in clear language, the description and the date of the incident, the categories of data affected, the risks and consequences, the measures adopted and those recommended to the data subject, and the contact channel. Where there are groups with a distinct severity of exposure, the notification shall be segmented, ensuring that the response to the end user is personalized according to the severity of the incident that affected them, in accordance with the guidelines established in the company’s Privacy Policy.

12.6. The evidence of dispatch of the notifications shall be preserved, including records of the sending platform, copies of the individual messages and of the publications on public channels, provided that, as to records kept on third-party platforms, the preservation is conditioned upon the respective retention periods, as they are not within the company’s sphere of control.

12.7. Every incident, even if not reportable to the Authority, is recorded in an internal report containing the date of occurrence and of knowledge, the cause, the extent, the measures adopted and the resulting preventive actions.


13. AWARENESS AND NON-COMPLIANCE

13.1. Employees with access to personal data receive guidance on this Policy at the start of their engagement and, at least annually, on data protection, on the recognition of social engineering attempts and on the incident reporting procedure. Its delivery is recorded with the date and the list of participants.

13.2. The support team receives specific guidance as to the prohibition on requesting the password from the data subject and as to the identity verification procedure prior to providing information about the account.

13.3. Non-compliance with this Policy subjects the offender to the applicable disciplinary and contractual measures, without prejudice to the applicable civil and criminal liability.


14. REVIEW AND EFFECTIVENESS

14.1. This Policy enters into force on the date of its approval and shall be reviewed at least every 12 (twelve) months, or within a shorter period upon the occurrence of a relevant incident, of a material change to the infrastructure or of an amendment to the applicable legislation.

14.2. Each review shall give rise to a new version, with a record of the date of approval and of the person responsible, with the previous versions being preserved for the purpose of evidence before authorities, governing all events that materialized during their period of effectiveness.

14.3. The execution of the controls provided for in this Policy must produce dated documentary evidence, capable of demonstrating compliance before authorities, notably as regards the granting and review of access, the configuration of alerts, the correction of vulnerabilities, the training sessions and the handling of incidents.




Olinda/PE, 08/10/2026.