Third-Party Management Policy

Document Owner Lou Bonvarlet, General Counsel, ScorePlay Inc.
Version 2.0
Effective Date June 2026
Last Reviewed June 2026
Next Scheduled Review June 2027 (annual, or upon material change)
Classification Internal

1. Purpose

This Policy ensures the protection of ScorePlay Inc. data and assets that are shared with, accessible to, or managed by suppliers, including external parties or third-party organisations such as service providers, vendors, and customers, and maintains an agreed level of information security and service delivery in line with supplier agreements.

This Policy outlines a baseline of security controls that ScorePlay expects partners and other third-party companies to meet when interacting with ScorePlay Confidential data.

2. Scope

This Policy applies to all ScorePlay data and information systems that are business-critical or that process, store, or transmit Confidential data. It applies to all Personnel of ScorePlay and to all external parties, including ScorePlay consultants, contractors, business partners, vendors, suppliers, partners, outsourced service providers, and other third-party entities with access to ScorePlay data, systems, networks, or system resources.

3. Policy

Information security requirements between ScorePlay and third parties shall be agreed upon and documented.

For all service providers who may access ScorePlay Confidential data, systems, or networks, proper due diligence shall be performed prior to provisioning access or engaging in processing activities.

Information shall be maintained regarding which regulatory or certification requirements are managed by, or impacted by, each service provider, and which are managed by ScorePlay as required. Applicable regulatory or certification requirements may include ISO 27001, SOC 2, PCI DSS, CCPA, GDPR, or other frameworks, compliance standards, or regulations.

4. Information Security in Third-Party Relationships

4.1 Addressing Security in Agreements

Relevant information security requirements shall be established and agreed upon with each supplier that may access, process, store, transmit, or impact the security of ScorePlay Confidential data and systems, or provide physical or virtual IT infrastructure components for ScorePlay.

For all service providers who may have access to ScorePlay production systems, or who may impact the security of the ScorePlay production environment, written agreements shall be maintained that include the service provider's acknowledgment of their responsibilities for the confidentiality of ScorePlay and Customer Data, and any commitments regarding the integrity, availability, or privacy controls they manage in order to meet the standards and requirements that ScorePlay has established in accordance with ScorePlay's information security programme or any relevant framework.

4.2 Technology Supply Chain

ScorePlay will consider and assess risks associated with suppliers and the technology supply chain. Where warranted, agreements with suppliers shall include requirements to address the relevant information security risks associated with information and communications technology services and the product supply chain.

5. Third-Party Service Delivery Management

5.1 Monitoring and Review of Third-Party Services