Privacy Notice for U.S. Residents

Trium & Co (“we,” “us,” or “our”) is committed to protecting the privacy of your personal information. This Privacy Notice applies to individuals with whom we conduct business in the United States, including clients, prospective clients, counterparties, investors, and business contacts. It describes how we collect, use, disclose, and protect your personal information, and explains your rights under applicable U.S. privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Last updated: September 2026.

1. Personal Information We Collect

We collect personal information that is useful or necessary in the context of our M&A advisory relationships with you or our clients. This may include information you have directly provided to us, as well as information collected from other sources (public registries, company databases, tax authorities, regulatory authorities, fraud prevention agencies).

Identifiers and contact information: name, professional title, employer, professional contact details, and your relationship with Trium & Co. KYC/AML identification data: date of birth, address, tax identification number (TIN/EIN), and identification documents (passport, government-issued ID, proof of address) collected in compliance with applicable anti-money laundering laws.

Financial and transactional information: financial data relevant to an M&A transaction (asset and income information, investment history, transaction records). Communications data: content, date and time of our exchanges, meeting information, and business interests. In limited cases, and only to the extent required or permitted by applicable law, sensitive personal information may be collected in connection with KYC/AML compliance (e.g., politically exposed person status, sanctions history, criminal records).

2. How We Use Your Personal Information

We use your personal information to: operate our business and provide M&A advisory services (including executing transactions and fulfilling our contractual obligations); verify your identity and conduct KYC/AML due diligence in compliance with the Bank Secrecy Act, FinCEN regulations, and applicable OFAC sanctions screening requirements; analyze our business relationships and improve our services; conduct market research and B2B business development activities.

Respond to requests from regulatory authorities (SEC, FINRA, FinCEN, OFAC, DOJ) or judicial authorities; comply with our legal and regulatory obligations, including Suspicious Activity Report (SAR) filing and tax reporting obligations; receive and process complaints or requests; prevent fraud or criminal activity, real or potential.

The legal bases for these uses include: performance of a contract or pre-contractual measures; compliance with applicable legal obligations (including U.S. AML/BSA requirements); our legitimate business interests (including B2B business development and relationship management); and your consent, where required by applicable law.

3. Disclosure of Personal Information to Third Parties

We may share your personal information with third parties under appropriate confidentiality obligations in the following circumstances.

Service providers and sub-processors: IT providers, CRM platforms (including Microsoft Corporation, Microsoft 365), legal advisors, accountants, and auditors, engaged under data processing agreements. Our clients, in the ordinary course of business, where such sharing is necessary and lawful. Regulatory and governmental authorities: SEC, FINRA, FinCEN, OFAC, DOJ, and other regulatory or judicial authorities, where required by law.

Professional advisors involved in a transaction: attorneys, financial advisors, auditors, and other parties involved in an M&A transaction, to the extent strictly necessary and under confidentiality obligations. Any other party where required by law, regulation, or court order. Sharing your data with certain third parties may involve cloud storage, and some providers use services incorporating artificial intelligence.

4. International Transfers of Personal Information

As a France-based firm, your personal information may be transferred to and processed in jurisdictions outside the United States, including France and other countries in the European Union or European Economic Area. These jurisdictions operate under data protection frameworks that may differ from those in your state of residence.

Where such transfers occur, we apply appropriate safeguards consistent with applicable law, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions or the EU-US Data Privacy Framework. For more information on the safeguards applicable to your personal information, please contact us at privacy@triumandco.com.

5. Retention of Personal Information

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Retention periods are determined by: (a) the purpose for which we use the information — we retain data only as long as necessary to fulfill that purpose; and (b) applicable legal obligations — laws and regulations may impose minimum retention requirements.

As guidance: KYC/AML records are retained for a minimum of 5 years following the end of the business relationship, in compliance with BSA/FinCEN requirements; records relating to mandates and transactions are retained for 10 years following closing; B2B business development contacts for 3 years from last active contact. At the end of applicable retention periods, your personal information is deleted or irreversibly anonymized.

6. Security of Your Personal Information

We have implemented appropriate technical and organizational security measures designed to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, consistent with applicable U.S. law including the FTC Safeguards Rule where applicable.

These measures include encryption of sensitive data, access controls, secured IT environment (Microsoft 365 / Entra ID), and employee training on data protection practices. In the event of a data breach likely to result in harm, we will notify you and applicable regulatory authorities as required by applicable law.

7. Your Privacy Rights

Depending on your state of residence, you may have the following rights regarding your personal information. California residents have rights under the CCPA/CPRA. Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states may have similar rights under applicable state privacy laws.

Right to Know: request information about the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties with whom we share it. Right to Delete: request deletion of your personal information, subject to certain exceptions (e.g., where retention is required by law or necessary to complete a transaction). Right to Correct: request correction of inaccurate personal information we hold about you. Right to Opt-Out of Sale or Sharing: opt out of the “sale” or “sharing” of your personal information for cross-context behavioral advertising (we do not sell or share your personal information for these purposes).

Right to Limit Use of Sensitive Personal Information: where we process sensitive personal information, you may have the right to limit its use to what is necessary to perform the requested services or as otherwise permitted by law. Right to Non-Discrimination: we will not discriminate against you for exercising any of your privacy rights. To exercise any of these rights, please contact us at privacy@triumandco.com. We will respond within the timeframe required by applicable law (45 days for CCPA requests, extendable by 45 additional days for complex requests).

www.cnil.fr

8. Do Not Sell or Share My Personal Information

Trium & Co does not sell your personal information to third parties for monetary consideration, nor do we share your personal information for cross-context behavioral advertising purposes, as those terms are defined under the CCPA/CPRA.

If you believe your personal information has been processed in a manner inconsistent with this Privacy Notice, or if you wish to exercise your right to opt out of any future sale or sharing, please contact us at privacy@triumandco.com.

9. Changes to This Privacy Notice

We reserve the right to update this Privacy Notice at any time, including to reflect changes in applicable law or our data practices. We encourage you to review the current version periodically, available at www.triumandco.com/us-privacy-notice.

We will provide notice of material changes as required by applicable law. Your continued engagement with Trium & Co following posting of changes constitutes your acknowledgment of the updated Privacy Notice.

Contact Us

Personal Data — Trium & Co

To exercise your privacy rights, or for any questions regarding our collection, use, disclosure, or processing of your personal information, please contact us:

By email: privacy@triumandco.com

By mail: Trium & Co - Data Protection Officer, [Registered Address], France.

We will acknowledge receipt of your request and respond within the timeframe required by applicable law — generally 45 days for CCPA requests, with a possible 45-day extension for complex or numerous requests. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.

If you are not satisfied with our response, California residents may contact the California Privacy Protection Agency (CPPA) or the California Attorney General. Residents of other states may have the right to appeal our decision or submit a complaint to their state’s Attorney General or applicable data protection authority.