Legal
The full, authoritative text of BikeCheck's legal documents — the same text shown in the app. This page is provided so the documents can be read and linked to directly.
Terms & Conditions — Riders
Last updated: 22 July 2026
Terms And Conditions
Brief Notes
- By accessing and using this Platform, you accept, without limitation or any other qualification, these terms and conditions and understand that any other agreements between you and the Platform Operator (hereinafter, ‘BikeCheck’) are entirely governed by these Terms and Conditions.
- These “Terms and Conditions” constitute the legal agreement between you and BikeCheck. Before using this Platform and before creating a Rider account, we recommend that you read these Terms and Conditions in full beforehand. Accessing the Platform, as well as creating and customising a Rider account, constitutes your full and unconditional acceptance of these Terms and Conditions.
- These Terms and Conditions may be amended at any time by BikeCheck without the need for prior notice. Amendments and information regarding their validity will be posted on the Platform to inform BikeCheck users. We therefore recommend that you refer to this policy regularly to review its updated content. If, at any time, these Terms and Conditions become unacceptable to you, please cease accessing and using the Platform immediately.
Definition Of Terms
- BikeCheck/Platform Operator – refers to the legal entity CERC-D SRL, with its registered office at 7 Dinicu Golescu Boulevard, Ground Floor, Flat SP, COM. 3, Sector 1, with company registration number (CUI) 55196436 and tax identification number (J2026044124009), email: bikecheck@protonmail.me
- Platform – refers to the website https://bikecheck.io/, whose features are presented transparently and in detail, and which provides Users, Business Owners and Riders, an intuitive interface for the provision of repair, maintenance, sales and history reporting services for bicycles registered on the Platform.
- User Account – involves personalising a section within the Platform by entering an email address and a password, as well as a name and surname, a section containing information about the user and the bicycles included on the Platform. The data provided when creating the Account will remain confidential and is subject to the Privacy Policy;
- Contract – refers to the distance contract concluded between BikeCheck and Users, without their simultaneous physical presence; such contracts are concluded upon confirmation, on a durable medium (by email), by BikeCheck of the account’s creation, following the User’s acceptance of the terms set out in this document and the validation carried out in accordance with the conditions set out in Article 3.
- Document – this Terms and Conditions Policy, which governs the contractual relationship between BikeCheck and Users and which shall be interpreted in
accordance with Romanian law. Any inconsistency or invalidity of any part or clause of this Document with other applicable legal provisions shall not affect the validity and legality of the other provisions of this Document.
- The services facilitated through this Platform, in accordance with the law and which do not breach the limits set out in these Terms and Conditions, consist of servicing, maintenance, sales and the provision of historical records relating to the bicycles registered on the Platform.
- Platform – refers to the website https://bikecheck.io/, as well as any section or subpage thereof. Websites and/or web pages or other components thereof belonging to third parties and accessed by users or visitors as a result of links or redirects available on the website https://bikecheck.io/ are not covered by, nor do they fall within the scope of, this definition.
- Processing of personal data – see
- User – Rider – any natural person with full legal capacityPrivacy Policy.an Account on who creates the Platform, registers bicycles and requests services made by Businesses via the Platform.
- Visitor – any person who accesses this Platform without creating an account.
Terms Of Use Of The Platform
- Access to and use of the BikeCheck Platform is carried out in accordance with and is fully subject to the provisions of this Document.
- The Platform provides Rider account holders with the following main features:
- Dashboard – the central interface through which the Rider accesses account features, views relevant information and manage operations carried out on the Platform;
- Bike gallery – the section displaying the bikes registered on the Platform, together with their technical specifications and available information relating to them;
- Garage – the module for keeping track of the Rider’s own bicycles, which allows the registration of each unit, the management of , technical condition and the history of repair and maintenance work;
- Marketplace – the dedicated module within which the Rider can publish and view advertisements for the sale of bicycles, subject to the set out in this Document, with responsibility for the published content resting solely with the User uploading the advert;
- Transfers – the module that enables the management of transfers of registered bicycles between Platform Users, together with the related records;
- Activity – the module for recording operations carried out within the account;
- Notifications – a system of alerts and communications regarding events relevant to the Rider’s account (e.g. the status of service requests , messages from service providers, updates on listings or transfers);
- Settings – the section for configuring the account, specific data and usage preferences.
- The platform facilitates the connection between Business Users and Rider Users, with a view to scheduling and managing bicycle repair and maintenance services. BikeCheck acts solely as a provider of the technical solution/technological intermediary and is not a party to the contractual service agreements established directly between Businesses and Riders.
- BikeCheck does not carry out, supervise or take responsibility for repair and maintenance work, the quality thereof, the conformity of the parts used, or the technical condition of the bicycles handed over for servicing; these remain entirely the responsibility of the Businesses (Service Providers), in their capacity as service providers.
- Users of this Platform are fully responsible for the content of the information included on the Platform, such as: descriptions, photographs, location, facilities, house rules, regulations, contractual terms, etc. (non-exhaustive list). In all circumstances, the information made available to the Platform by Users must be accurate, complete and non-misleading.
- Activities that are unlawful, dangerous or that undermine the community’s trust are prohibited. We may suspend or remove listings and accounts in the event of breaches or a risk to the safety of the Platform or other Users.
- In order to ensure the security of the Platform, prevent fraud and comply with applicable legal obligations, all Platform users – both Business Owners, and Riders – are subject to a mandatory identity verification process, carried out by a specialised external provider, namely DIDIT (hereinafter referred to as the ‘Verification Provider’).
- The verification is carried out on the basis of the following principles:
- ‘Know Your Business’ (KYB) – for Business Owners, consisting of verifying the existence and identity of the business operator, the registration details, the legal representative and, where applicable, supporting documents relating to the business activity carried out;
- ‘Know Your Customer’ (KYC) – for Riders, consisting of verifying the end-user’s identity on the basis of the documents and information requested as part of process.
- For the purposes of carrying out the verification, the User undertakes to provide the information and documents requested by the Verification Provider and guarantees that these are genuine, accurate, complete and valid.
- The account is activated and becomes operational only after the verification procedures have been fully completed and successfully validated by DIDIT. Until confirmation of validation, access to the Platform’s features is restricted or suspended, and the User may not initiate or accept service requests.
- In the event that the Verification Provider does not validate the completion of the verifications, or identifies discrepancies, false or incomplete information, it may refuse to activate the account, or to suspend or close the account, without this giving rise to any liability for compensation on the part of BikeCheck.
- Identity verification via DIDIT does not constitute a guarantee by BikeCheck regarding the solvency, reliability, professional competence or of any user; responsibility for the contractual relationships established between Business Owners and Riders rests entirely with them.
- The processing of personal data as part of the verification process is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and the the Platform’s Privacy Policy.
Intermediation Policy
- The information used to describe the services available and the features integrated into the Platform (text, images, multimedia presentations) is informative in nature and do not constitute contractual obligations on the part of BikeCheck.
- The Rider-User understands and accepts that:
- all amounts, prices, rates or estimates displayed on the Platform are strictly for information and estimation purposes only. They do not constitute a firm offer on the part of the Platform or the Business Users and may be subject to subsequent adjustments. The amounts displayed may be modified, updated or revised unilaterally and at any time directly by the Business Users, without prior notice and without the intervention or consent of the Platform.
- The Platform does not collect, process or manage the amounts or payments relating to the services/products offered by Business Users. Any financial transaction takes place directly between the Rider and the Business User.
- The Platform accepts no liability for any discrepancies between the amounts displayed on the website and the final amounts charged by Business Users, for any made by them, or for any losses arising from the estimated nature of the information displayed.
- The Rider User has the option to synchronise their account with the third-party service Strava, in order to retrieve and display certain data relating to their , subject to the User’s prior and express consent. Synchronisation is carried out via the interfaces provided by Strava and is subject, in relation to that service, to Strava’s own terms and privacy policies, for which BikeCheck accepts no liability. The user may revoke synchronisation at any time via the account settings section.
- Riders can submit a service request via the Platform by selecting the business owner they wish to contact from among those
available on the Platform.
- The choice of service provider rests solely with the Rider; BikeCheck does not intervene in this selection and accepts no liability whatsoever in respect of the work requested or the contractual relationship thus established.
- THE USER DASHBOARD. THE UNIQUE ACCOUNT IDENTIFIER. FURTHER DETAILS REGARDING THE USER ACCOUNT
- Each account, regardless of the user type (Business Owner or Rider), is automatically assigned, upon creation, a unique identifier (hereinafter referred to as hereinafter “Account ID”), generated by the Platform and which cannot be modified by the user.
- The Account ID ensures the user’s unique identification within the Platform and is used for administrative, record-keeping, billing and resolution of any enquiries or complaints.
- Each account, regardless of the user’s type, is provided with a personalised control panel (Dashboard), through which the user can access the features relevant to their account type, view relevant information and manage operations carried out on the Platform.
- The Platform provides a dedicated section where users, both Business Owners and Riders, can post advertisements for the sale of bicycles, including descriptions, photographs and the relevant terms and conditions.
- The user who posts an advert is fully responsible for its content, including the accuracy of the information, the legality of the sale and for the rights to the item offered for sale.
- Sales and purchase arrangements are made directly between users of the Platform, with BikeCheck not acting as a party, commercial intermediary or guarantor of transaction.
- The Platform offers Users the opportunity to obtain, free of charge, an informative report on registered bicycles, comprising the available information within the Platform regarding the registered request. The report generated is for information purposes only and is produced on the basis of data existing within the Platform and/or provided by Users. BikeCheck does not guarantee that the information contained in the report is complete, accurate or up to date, and accepts no liability for decisions taken by Users on the basis of the report.
Warranties. Limitation Of Liability.
- BikeCheck shall not be liable for:
- losses arising from the acts or omissions of Users (Business Owners or Riders), including those arising from contractual relationships established directly between them;
- the quality, conformity, safety or outcome of repair and
carried out by Business Owners, nor for their compliance with technical or other regulations applicable to the service provider’s activity;
- content published by Users on the Platform, including sales advertisements and materials uploaded as part of these, subject to the terms of this Document;
- the accuracy, completeness or up-to-date nature of the information contained in the bicycle report, which is provided for information purposes only;
- data obtained from third-party services integrated into the Platform, which is subject to the terms and policies of those providers;
- indirect losses, including, but not limited to, lost profits, loss of data, loss of business opportunities or damage to reputation.
- BikeCheck shall not be liable for any circumstances detrimental to the User arising from the User’s failure to comply with this Document, the related Policies, the instructions provided via the Platform and/or the applicable legislation in force.
- BikeCheck cannot be held liable for any losses suffered by the User, whether directly or indirectly, arising from the non-use or incorrect use of the information and features made available on the Platform.
- The services provided by BikeCheck constitute obligations of means, not of result. BikeCheck acts solely as a provider of the technical solution and as a that facilitates the connection between Business Owners and Riders, and is not a party to the service provision or sale-purchase relationships established between them. Consequently, BikeCheck is not liable for the results arising from Users’ activity on the Platform; its liability is limited to ensuring optimal operating conditions and access to the Platform’s services, as described in this policy.
- The User verification process via DIDIT (KYB/KYC), as described above, does not constitute a guarantee by BikeCheck regarding the solvency, reliability, professional competence or future conduct of any User; the risks associated with the relationships established between Business Owners and Riders rest solely with them.
Intellectual Property
- BikeCheck holds full and complete title to the files, photographs and materials published on the platform, as well as all intellectual property rights arising therefrom.
- All trademarks and logos are owned by BikeCheck, and no person or entity is authorised to copy or use them in any way.
- The use, reproduction, copying or modification without BikeCheck’s consent of any graphic, design or structural elements, etc., present on the Platform is strictly prohibited. Any infringement of these rights is subject to the law and will be dealt with by the relevant authorities.
- No content transmitted to Users, by any means of communication (electronic, telephone, etc.) or obtained by them through accessing, visiting and/or viewing does not constitute a contractual obligation on the part of BikeCheck.
- In certain situations, we do not hold intellectual property rights to the images and photographs used on this website, but only rights of use. In this regard, certain images and photographs found on our website are used in accordance with the terms and conditions of their source.
Privacy
- BikeCheck will keep confidential any information of any kind provided by Users. The information provided may be shared only under the conditions set out in the Privacy Policy.
- If there are any suspicions regarding data security or possible misuse in relation to an Account created by a User, BikeCheck will immediately take the necessary measures (for example, it will ask the account holder to change their password) or even delete the account, subject to prior notification of the person concerned.
- The processing of personal data and the rules governing its protection can be found in the relevant policy on the Platform.
- BikeCheck respects and protects the right to the security of personal data of the Users of this website and is obliged to manage secure conditions and solely for the specified purposes. The purpose of data collection is to provide Platform Users with information and services of the highest quality.
- In order to provide access to the Platform and to facilitate service requests from User-Riders, personal data is processed by BikeCheck, as the Platform provider, together with the service provider (Business Owner) chosen by the Rider. With regard to the service request, BikeCheck and the Business Owner act as joint controllers within the meaning of Article 26 of the GDPR: BikeCheck provides the digital infrastructure, the initial collection of data and communication via the interface, whilst the Business Owner manages the direct relationship with the Rider (collection and handover of the bicycle, carrying out the work) and fulfils its own legal obligations.
- Depending on how the Rider-User utilises the Platform, we process: identification and contact details (name, email, telephone number); details of the service request (type of bicycle, its identification details, nature of the requested intervention, repair history); data regarding bicycles registered in the Garage and any transfers; listings published on the Marketplace and uploaded content; correspondence conducted via the Platform; proof of payment; reports and support requests.
- We use Rider User data for: managing the account and the Platform’s features; facilitating service requests and
communication with the chosen service provider; settlement and invoicing of the subscription; identity verification (KYC); fraud prevention and ensuring user safety; resolving enquiries and any disputes; and compliance with legal obligations.
- We process the Rider’s data on the basis of: the performance of the contract between the Rider and BikeCheck [Article 6(1)(b) of the GDPR], for the management of the service request and the provision of the Platform’s services; compliance with legal obligations [Article 6(1)(c) of the GDPR], for example tax and accounting obligations; legitimate interests [Article 6(1)(f) of the GDPR], for the secure operation of the Platform, the prevention of fraud and the protection of users’ rights, in accordance with the principle of data minimisation; and, where necessary, the consent of the data subject/Rider [Article 6(1)(a) of the GDPR], for example for marketing communications.
- To the extent strictly necessary, personal data provided by Riders may be disclosed to service providers acting as data processors (for example, cloud hosting, email services, anti-fraud tools), as well as to public authorities, in accordance with the law. Payments are processed via Paddle, acting as Merchant of Record, and identity verification is carried out via DIDIT, with both providers operating in accordance with their own terms and privacy policies. Where data is stored or accessed outside the European Economic Area, we ensure that there are adequate safeguards in place in accordance with Chapter V of the GDPR (for example, Standard Contractual Clauses 2021/914).
- We implement technical and organisational measures in accordance with Article 32 of the GDPR, including access control, encryption of data in transit and, where possible, at otherwise, logging of actions, backup and recovery procedures, anti-malware protection and security incident response procedures.
- As a data subject, the Rider-User is entitled to the rights set out in the GDPR: the right of access, rectification, erasure, restriction of processing, data portability and the right to object. These rights may be exercised either directly via the Platform or by contacting any of the associated operators. The Platform serves as the single operational point of contact for receiving requests, which will then be resolved within the timeframes provided for by law. Furthermore, the right to lodge a complaint with the National Supervisory Authority for the Processing of Personal Data (ANSPDCP) is respected.
- Data relating to service requests is retained for the period necessary to perform the services and for the periods required by law (for example, tax and and those relating to the warranty on the work), after which it is deleted or anonymised.
- The selected Business Owner may also process personal data for its own purposes (e.g. records of work carried out, tax obligations or the ), acting as an independent data controller for such processing, in accordance with its own privacy policy. We recommend consulting the information provided by the chosen service provider.
Security
- When using the Platform, you are responsible for ensuring the confidentiality of the details relating to your access account (username and password) and you agree to accept full responsibility for the activities/actions carried out within the application using your account and password. We recommend that you do not disclose the details you use to log in.
- Should the confidentiality of these login details be compromised, you are obliged to notify BikeCheck as soon as possible so that we can restrict access to the account and to arrange, as quickly as possible, a way for you to regain access to your account.
- Carrying out unauthorised actions such as: misuse, fraudulent use, unauthorised access, modification, copying of information for the purpose of selling it, or blocking access, etc., on the Platform, will be punished in accordance with the law.
Useful Information For Users
- As a User, you understand and agree to the following:
- To receive occasional communications from BikeCheck, in accordance with the GDPR Policy, regarding specific one-off campaigns (with the option to withdraw your consent at any time);
- To provide true, accurate and complete data;
- To maintain and update, where necessary, your registration details so that they remain true, accurate and complete.
- It is prohibited to use the Platform in the following ways or for the following purposes:
- In breach of the Terms and Conditions set out in this document;
- In breach, in any way, of the applicable legal provisions or in ways that may lead to a breach, in any way, of the applicable legal provisions;
- In any way that involves acting on behalf of or in the name of another person, in particular by using false names, false email addresses, , etc.
- To promote or conceal activities of an illegal or immoral nature;
- To reproduce, in any way, the website’s interface, with a view to misleading BikeCheck Users or potential Users;
- To gain unauthorised access to data that other Users have voluntarily provided to us;
- To introduce malicious programmes or lines of code into the system;
- To request illegal information, products or services, or to request information intended to conceal an illegal activity;
- To gain access to various sections or subsections of the website or to the products or services we offer using unlawful methods.
- As a User, you undertake not to engage in the following activities:
- Publishing copyrighted material unless you are the author or have the author’s permission to publish that material;
- Publishing material that is obscene, defamatory, threatening or malicious towards another user, a natural or legal person, or material or information prohibited by the legal provisions in force;
- Publish an image or statement that contravenes the legal provisions in force or public decency.
Applicable Law And Jurisdiction
- These Terms and Conditions and the use of the Platform are governed by the laws in force in Romania. In the event of any dispute arising in relation to the or arising out of or in connection with its conclusion, interpretation, performance or termination, it shall be resolved either by bringing proceedings before the courts having subject-matter jurisdiction in Bucharest – Sector 1, or by arbitration before the Court of Arbitration attached to the Bucharest Chamber of Commerce and Industry, in accordance with its procedures and by a sole arbitrator. The award shall be final and binding on the parties. Either party is entitled to choose one of the two methods of dispute resolution.
- With regard to alternative dispute resolution or referral to the ANPC, we would like to inform you that these two methods of amicable dispute resolution are intended exclusively for consumers.
This document was updated on 22 July 2026.
Terms & Conditions — Business Accounts
Last updated: 22 July 2026
Terms And Conditions
Brief Notes
- By accessing and using this Platform, you accept, without limitation or any other qualification, these terms and conditions and understand that any other agreements between you and the Platform Operator (hereinafter, ‘BikeCheck’) are entirely governed by these Terms and Conditions.
- These “Terms and Conditions” constitute the legal agreement between you and BikeCheck. Before using this Platform and before creating a business account [as a a professional and business owner, together with associated accounts (team members) such as mechanic, receptionist, courier/fleet rider], we recommend that you read these Terms and Conditions in advance. Accessing the Platform, as well as creating and customising a business account, constitutes your full and unconditional acceptance of these Terms and Conditions.
- These Terms and Conditions may be amended at any time by BikeCheck without prior notice. Any amendments and information regarding their validity will be posted on the Platform to inform BikeCheck users. We therefore recommend that you refer to this policy regularly to review its updated content. If, at any time, these Terms and Conditions become unacceptable to you, please cease accessing and using the Platform immediately.
Definition Of Terms
- BikeCheck/Platform Operator – refers to the legal entity CERC-D SRL, with its registered office at 7 Dinicu Golescu Boulevard, Ground Floor, Flat SP, COM. 3, Sector 1, with company registration number 55196436 and tax identification number J2026044124009, email:bikecheck@protonmail.me .
- Platform – refers to the website https://bikecheck.io/, whose features are presented transparently and in detail, and which provides Users, Business Owners and Riders, an intuitive interface for the provision of repair, maintenance and sales services, as well as for reporting the history of bicycles registered on the Platform.
- User Account – involves personalising a section within the Platform by entering an email address and a password, as well as a name and surname, a section containing information about the user and the bicycles included on the Platform. The data provided when creating the Account will remain confidential and is subject to the Privacy Policy;
- Contract – refers to the distance contract concluded between BikeCheck and users, without their simultaneous physical presence; such contracts are concluded upon confirmation, on a durable medium (by email), by BikeCheck of the account’s creation, following the User’s acceptance of the terms set out in this
document and the validation carried out in accordance with the conditions set out in Article 3.
- Document – this Terms and Conditions Policy, which governs the contractual relationship between BikeCheck and Users and which shall be interpreted in accordance with Romanian law. Any inconsistency or invalidity of any part or clause of this Document with other applicable legal provisions shall not affect the validity and legality of the other provisions of this Document.
- The services provided via this Platform, in accordance with the law and without breaching the limits set out in these Terms and Conditions, consist of servicing, maintenance, sale and reporting of the history of bicycles registered on the Platform.
- Platform – refers to the website https://bikecheck.io/, as well as any section or subpage thereof. Websites and/or web pages or other components thereof belonging to third parties and accessed by users or visitors as a result of links or redirects available on the website https://bikecheck.io/ are not covered by, nor do they fall within the scope of, this definition.
- Processing of personal data – see Privacy Policy.
- Transaction – means the operation by which the payment for the subscription relating to the use of the Platform by Users is processed.
- User-Rider – any natural person with full legal capacity who creates an Account on the Platform, registers bicycles and requests services made by Businesses via the Platform.
- Visitor – any person who accesses this Platform without creating an account.
Terms Of Use Of The Platform
- Access to and use of the BikeCheck Platform is carried out in accordance with and is fully subject to the provisions of this Document.
- The Platform provides Business account holders, based on their selected subscription plan, with the following main features:
- Showroom – a module for presenting the repair and maintenance services offered, together with a description of the work involved, the rates and the relevant commercial terms ;
- Fleet – a module for tracking bicycles in for servicing, which allows the registration of each unit, its assessed technical condition, the work carried out and the progress of the work;
- Metrics (Statistics) – the reporting and analysis module that provides indicators regarding the volume of work, types of repairs, turnaround times and other statistical data relevant to the account holder’s activity;
- Billing – the module for managing payments, subscriptions and financial documents issued via the Platform. The amounts displayed may be amended, updated or revised unilaterally and at any time directly by Business Users, without prior notice and without the Platform’s intervention or consent, during the processing of the booking request; the final amount is solely that actually paid at the service counter.
- Bike gallery – the section displaying the bicycles registered on the Platform, together with their technical specifications and the available information relating to them;
- Bookings – the module dedicated to the management, processing and recording of requests made by Riders for the bicycles or services listed by Business Users, providing the details relating to each request;
Kan Ban -
- Activity – the module for recording operations carried out within the account;
- Notifications – a system of alerts and communications regarding events relevant to the account holder’s account (e.g. new requests, work status, due dates);
- Settings – the module for configuring the account, specific data and usage preferences.
- The platform facilitates the connection between Business Users and end users (hereinafter referred to as ‘Riders’), for the purpose of scheduling and managing bicycle repair and maintenance services. BikeCheck acts solely as a provider of the technical solution/technological intermediary and is not a party to the contractual service agreements established directly between Businesses and Riders.
- BikeCheck does not carry out, supervise or take responsibility for repair and maintenance work, the quality thereof, the suitability of the parts used or the technical condition of the bicycles handed over for servicing; these remain entirely the responsibility of the Businesses (Service Providers), in their capacity as service providers.
- Users of this Platform are fully responsible for the content of the information included on the Platform, such as: descriptions, photographs, location, facilities, house rules, regulations, contractual terms, etc. (non-exhaustive list). In all circumstances, the information made available to the Platform by Users must be accurate, complete and non-misleading.
- Business Users are obliged to promptly update essential information regarding the services provided, as well as any other elements that might affect existing or future relationships.
- The Business User shall refrain from any activity carried out in bad faith, which may consist of manipulating reviews, altering the flow of booking requests , moving transactions off the Platform, etc.
- Activities that are unlawful, dangerous or that undermine the community’s trust are prohibited. We may suspend or remove listings and accounts in the event of breaches or a risk to the safety of the Platform or other Users.
- In order to ensure the security of the Platform, prevent fraud and comply with applicable legal obligations, all Platform users – both Business Owners and Riders – are subject to a mandatory identity verification process, carried out by a specialised external provider, namely DIDIT (hereinafter referred to as the ‘Verification Provider’).
- The verification is carried out on the basis of the following principles:
- ‘Know Your Business’ (KYB) – for Business Owners, consisting of verifying the existence and identity of the business operator, the registration details, the legal representative and, where applicable, supporting documents relating to the business activity carried out;
- ‘Know Your Customer’ (KYC) – for Riders, consisting of verifying the end- user’s identity on the basis of the documents and information requested as part of the process.
- For the purposes of carrying out the verification, the user undertakes to provide the information and documents requested by the Verification Provider and guarantees that these are genuine, accurate, complete and valid.
- The account is activated and becomes operational only after the verification procedures have been fully completed and successfully validated by DIDIT. Until confirmation of validation, access to the Platform’s features is restricted or suspended, and the user cannot initiate or accept service requests.
- In the event that the Verification Provider does not validate the completion of the verifications, or identifies discrepancies, false or incomplete information, it may refuse to activate the account, or to suspend or close the account, without this giving rise to any liability for compensation on the part of BikeCheck.
- Identity verification via DIDIT does not constitute a guarantee by BikeCheck regarding the solvency, reliability, professional competence or of any user; responsibility for the contractual relationships established between Business Owners and Riders rests entirely with them.
- The processing of personal data as part of the verification process is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and the the Platform’s Privacy Policy.
Intermediation Policy And Subscription For Platform Services
- Access to the Platform’s features and to the intermediation services made available to Business Users is provided on a subscription basis, payable periodically (monthly or annually, depending on the selected plan), at the rates displayed on the Platform at the time of subscription. The subscription covers the right to use the Platform and the features associated with the account type, as described in this document.
- BikeCheck reserves the right to amend the subscription rates, expressed in EURO, excluding VAT, as a result of circumstances likely to affect the amounts displayed on the Platform, subject to prior notification to the Business User. Subscriptions and transactions already confirmed remain subject to the rates in force on the date of confirmation, and changes take effect from the next billing period.
- The information used to describe the available services and the features
integrated into the Platform (text, images, multimedia presentations) is for information purposes only and does not constitute a contractual obligation on the part of BikeCheck.
- Payments for subscriptions and services paid for via the Platform are processed through the provider PADDLE (Paddle.com Market Limited), which acts as the Merchant of Record (registered merchant/reseller). In this capacity, Paddle is the legal seller of the subscription to the User, processes the payment, calculates, collects and remits the applicable taxes (VAT/indirect taxes) to the relevant tax authorities, and issues the tax documents corresponding to the transaction. The name ‘Paddle’ may appear on the User’s bank statement instead of ‘BikeCheck’.
- As Paddle acts as the Merchant of Record, the management of VAT and other indirect taxes relating to the subscription price is the responsibility of Paddle, in accordance with the applicable legislation in the User’s jurisdiction. The Business User, however, remains solely responsible for the tax treatment of their own income derived from the services provided to Riders (issuing tax documents, declaring and paying the relevant taxes and contributions).
- As online payments are used, BikeCheck is not, and under no circumstances can it be held, liable for any additional costs incurred by Users, including, but not limited to, currency conversion fees charged by banks or card issuers. Responsibility for bearing these costs lies solely with the Users.
- In the event of refunds, chargebacks, billing errors or amounts determined for documented damages, the amounts shall be settled via Paddle, in accordance with the information set out in the Terms and terms Conditions of the provider.
- The contract between BikeCheck and the Business User is deemed to have been concluded upon confirmation, on a durable medium (by email), by the Platform, of the acceptance of the account creation, validation of the checks set out in this Document (KYB/KYC via DIDIT) and activation of the selected subscription.
- Transactions are highly secure. Card data is processed exclusively on the infrastructure of the payment processor Paddle and its processing partners. BikeCheck does not store and does not have access to confidential card details, as these are transmitted in encrypted form via a secure connection to the payment processing infrastructure. Payment processing via Paddle is subject, in respect of the relevant service, Paddle’s ownprivacy terms and policy Paddle’s own terms and
- USER DASHBOARD. UNIQUE ACCOUNT ID. FURTHER DETAILS REGARDING THE USER ACCOUNT
- Each account, regardless of the user type (Business Owner or Rider), is
automatically assigned, upon creation, a unique identifier (hereinafter referred to as the ‘Account ID’), generated by the Platform and which cannot be modified by the user.
- The Account ID ensures the user’s unique identification within the Platform and is used for administrative, record-keeping, billing and resolution of any enquiries or complaints.
- Each account, regardless of the user’s type, is provided with a personalised control panel (Dashboard), through which the user can access the features specific to their account type, view relevant information and manage operations carried out on the Platform.
- In addition to the account ID, for each Business Owner account a unique code and an identification label are automatically generated, intended identifying the business operator in dealings with Riders and within the Platform’s features.
- The Business code and label may not be assigned, transferred or used by another business operator and remain associated with the account for the entire duration of .
- The Platform provides a dedicated section where users, both Business Owners and Riders, can post advertisements for the sale of bicycles, including descriptions, photographs and the relevant terms and conditions.
- The user who posts an advert is fully responsible for its content, including the accuracy of the information, the legality of the sale and for the rights to the item offered for sale.
- Sales and purchase arrangements are made directly between users of the Platform, with BikeCheck not acting as a party, commercial intermediary or guarantor of transaction.
- The Platform offers Users the opportunity to obtain, free of charge, an informative report on registered bicycles, comprising the information available on the Platform regarding the registered enquiry. The report generated is for information purposes only and is produced on the basis of data existing on the Platform and/or provided by Users. BikeCheck does not guarantee that the information contained in the report is complete, accurate or up to date, and accepts no liability for decisions taken by Users on the basis of the report.
Warranties. Limitation Of Liability.
- BikeCheck shall not be liable for:
- losses arising from the acts or omissions of Users (Business Owners or Riders), including those arising from contractual relationships established directly between them;
- the quality, conformity, safety or outcome of repair and maintenance work carried out by Business Owners, or for the compliance with the technical or other regulations applicable to the service provider’s activity;
- content published by Users on the Platform, including sales advertisements and materials uploaded as part of them, subject to the terms of this Document;
- the accuracy, completeness or up-to-date nature of the information contained in the bicycle report, which is provided for information purposes only;
- data obtained from third-party services integrated into the Platform, which is subject to the terms and policies of those providers;
- indirect losses, including, but not limited to, lost profits, loss of data, loss of business opportunities or damage to reputation.
- BikeCheck shall not be liable for any circumstances detrimental to the User arising from the User’s failure to comply with this Document, the related Policies, the instructions provided via the Platform and/or the applicable legislation in force.
- BikeCheck cannot be held liable for any losses suffered by the User, whether directly or indirectly, arising from the non-use or incorrect use of the information and features made available on the Platform.
- The services provided by BikeCheck constitute obligations of means, not of result. BikeCheck acts solely as a provider of the technical solution and as a that facilitates the connection between Business Owners and Riders, and is not a party to the service provision or sale-purchase relationships established between them. Consequently, BikeCheck is not liable for the results arising from Users’ activity on the Platform; its liability is limited to ensuring optimal operating conditions and access to the Platform’s services, as described in this policy.
- The User verification process via DIDIT (KYB/KYC), described above, does not constitute a guarantee by BikeCheck regarding the solvency, reliability, professional competence or subsequent conduct of any User; the risks associated with the relationships established between Business Owners and Riders rest exclusively with them.
- BikeCheck’s liability, to the extent that it may be incurred, is in any event limited to the value of the subscription paid by the User for the period during which the event giving rise to the loss occurred, within the limits permitted by applicable law. These limitations do not apply in the case of damage caused intentionally or through gross negligence, injury to life or physical integrity, or in other situations where the law prohibits the limitation of liability.
Intellectual Property
- BikeCheck holds full and complete title to the files, photographs and materials published on the platform, as well as all intellectual property rights arising therefrom.
- All trademarks and logos are owned by BikeCheck, and no person or entity is authorised to copy or use them in any way.
- The use, reproduction, copying or modification, without BikeCheck’s consent, of any graphic, design or structural elements, etc., present on the Platform is strictly prohibited. Any infringement of these rights is subject to legal action and will be dealt with by the relevant authorities.
- No content transmitted to Users, by any means of communication (electronic, telephone, etc.) or acquired by them through accessing, visiting and/or viewing does not constitute a contractual obligation on the part of BikeCheck.
- In certain situations, we do not hold intellectual property rights to the images and photographs used on this website, but only rights of use. In this regard, certain images and photographs found on our website are used in accordance with the terms and conditions of their source.
Privacy
- BikeCheck will keep confidential any information of any kind provided by Users. The information provided may be shared only under the conditions set out in the Privacy Policy.
- If there are any suspicions regarding data security or possible misuse in relation to an Account created by a User, BikeCheck will immediately take the necessary measures (for example, it will ask the account holder to change their password) or even delete the account, subject to prior notification of the person concerned.
- The processing of personal data and the rules governing its protection can be found in the relevant policy on the Platform.
- BikeCheck respects and protects the right to the security of personal data of Users of this website and is obliged to manage secure conditions and solely for the specified purposes. The purpose of data collection is to provide Platform Users with information and services of the highest quality.
- In the context of Business accounts, each Business User acts jointly with BikeCheck as joint controllers within the meaning of Article 26 of the GDPR. The parties jointly determine the purposes and means of the data processing necessary for the operation of the Platform and the management of service requests, and responsibilities are allocated as follows: the Platform provides the digital infrastructure, the initial collection of data relating to service requests and accounts, communication via the interface, technical security measures and records of activities carried out on Users’ accounts; The Business User manages the direct relationship with the Rider (receipt and handover of the bicycle, carrying out repair and maintenance work, compliance with the workshop’s internal rules), as well as fulfilling its own legal obligations (tax and accounting, warranty for the work carried out, reports required by the authorities). Each party remains an independent controller for any additional processing it initiates (for example, the Business User’s own marketing or the publication of
) and is responsible for the compliance of such processing.
- The data processed includes, where applicable: Riders’ identification and contact details (name, email, telephone number), service request details (type of bicycle, identifying it, the nature of the requested intervention, work history), operational preferences, correspondence conducted via the Platform, proof of payment, incident reports and support requests. The main purposes are: managing accounts and Platform features, facilitating service requests and communication between Business Owners and Riders, settlement and invoicing, verifying Users (KYB/KYC) via the DIDIT provider, preventing fraud and ensuring User safety, resolving enquiries and any disputes, as well as complying with legal obligations.
- From a legal basis perspective, the processing is based on: the performance of the contract [Article 6(1)(b) of the GDPR] for the management of service requests and the provision of the Platform’s services; the fulfilment of the Parties’ legal obligations [Article 6(1)(c) of the GDPR], for example tax and accounting obligations or responses to authorities; the legitimate interests of the Parties [Article 6(1)(f) of the GDPR] for the secure operation of the Platform, the prevention of fraud and the protection of Users’ rights, in accordance with the principle of data minimisation; consent [Article 6(1)(a) of the GDPR] only where necessary (for example, commercial communications). Business Users undertake not to request or store special categories of data (Article 9 of the GDPR) unless there is a clear legal obligation or legal basis to do so, and to inform Riders transparently.
- To the extent strictly necessary, data may be disclosed to suppliers acting as data processors (e.g. cloud hosting, email services, payment processor, anti-fraud tools, identity verification provider), as well as to public authorities in accordance with the law. Business Users acknowledge that payment processing is carried out by Paddle, acting as Merchant of Record, and identity verification by DIDIT, both providers operating in accordance with their own terms and policies. To the extent that data is stored or accessed outside the European Economic Area, the Parties shall ensure that adequate safeguards are in place in accordance with Chapter V of the GDPR (for example, Standard Contractual Clauses 2021/914 and additional measures, where applicable). Business Users undertake to use only providers that offer sufficient security and confidentiality safeguards and to maintain a record of such processors.
- Both BikeCheck and Business Users shall implement measures in accordance with Article 32 of the GDPR, including: access control and authorisation of relevant personnel; and regular training; logical separation of data and proportionate access based on the ‘need-to-know’ principle; password management and access lifecycle management (prompt deactivation upon termination of the collaboration); encryption of data in transit and, where possible, at rest; secure electronic transfers (transmission of passwords via a separate channel); patch management, anti-malware/EDR protection, logging of
authentications and privileged actions, with logs retained for a reasonable period; backup and restoration procedures; periodic testing and reassessment of the effectiveness of the measures; incident response procedures, including notification of the other
Party without undue delay (as a rule, within 24 hours of becoming aware of the incident) and cooperation regarding notifications to the supervisory authority and to data subjects, where applicable.
- Data subjects, including Riders, may exercise their rights under the GDPR (access, rectification, erasure, restriction, portability, objection) either via the Platform, or by contacting any of the associated operators. The Parties agree that the Platform shall be the single operational point of contact for receiving requests; Business Users shall cooperate promptly, providing the information necessary to resolve the request within the prescribed timeframe. Each Party remains responsible for demonstrating the compliance of its own processing activities and for retaining the documentation required by the GDPR (including, where applicable, records of processing activities).
- Data relating to service requests is retained for the period necessary to perform the services and for the periods required by law (for example, tax and those relating to the warranty on the work), after which they are deleted or anonymised. The Business User shall not retain local copies of Riders’ documents unless there is a clear legal or contractual requirement to do so, and shall apply to them the same security standards as those applicable on the Platform.
- By using the Platform, Business Users confirm their status as associated data controllers, accepting the allocation of responsibilities described above, and undertake to maintain a level of protection at least equivalent to that applied by BikeCheck, including in their dealings with their own authorised representatives and collaborators. Any breach of these obligations may result in proportionate measures (including suspension of the account or listing) to protect the integrity and trust in the Platform.
Security
- When using the Platform, you are responsible for ensuring the confidentiality of the details relating to your access account (username and password) and you agree to accept full responsibility for any activities or actions carried out on the Platform using your account and password. We recommend that you do not disclose the details you use to log in.
- Should the confidentiality of this login information be compromised, you are obliged to notify BikeCheck as soon as possible in order to restrict access to your account and to provide you as quickly as possible with a way to regain access to your account.
- Carrying out unauthorised actions such as: misuse, fraudulent use, unauthorised access, modification, copying of information for the purpose of selling it, or blocking access, etc., on the Platform, will be punished in accordance with the law.
Useful Information For Users
- As a User, you understand and agree to the following:
- To receive occasional communications from BikeCheck, in accordance with the GDPR Policy, regarding specific one-off campaigns (with the option to withdraw your consent at any time);
- To provide true, accurate and complete data;
- To maintain and update, where necessary, your registration details so that they remain true, accurate and complete.
- It is prohibited to use the Platform in the following ways or for the following purposes:
- In breach of the Terms and Conditions set out in this document;
- In breach, in any way, of the applicable legal provisions or in ways that may lead to a breach, in any way, of the applicable legal provisions;
- In any way that involves acting on behalf of or in the name of another person, in particular by using false names, false email addresses, , etc.
- To promote or conceal activities of an illegal or immoral nature;
- To reproduce, in any way, the website’s interface, with a view to misleading BikeCheck Users or potential Users;
- To gain unauthorised access to data that other Users have voluntarily provided to us;
- To introduce malicious programmes or lines of code into the system;
- To request illegal information, products or services, or to request information intended to conceal an illegal activity;
- To gain access to various sections or subsections of the website or to the products or services we offer using unlawful methods.
- As a User, you undertake not to engage in the following activities:
- Publishing copyrighted material unless you are the author or have the author’s permission to publish such material;
- Publishing material that is obscene, defamatory, threatening or malicious towards another user, a natural or legal person, or material or information prohibited by the legal provisions in force;
- Publish an image or statement that contravenes the legal provisions in force or public decency.
Applicable Law And Jurisdiction
- These Terms and Conditions and the use of the Platform are governed by the laws in force in Romania. In the event of any dispute arising in relation to the or arising out of or in connection with its conclusion, interpretation, performance or termination, it shall be resolved either by bringing proceedings
to the courts having subject-matter jurisdiction in Bucharest – Sector 1, or by arbitration before the Court of Arbitration attached to the Bucharest Chamber of Commerce and Industry, in accordance with its rules and by a single arbitrator. The award shall be final and binding on the parties. Either party is entitled to choose one of the two methods of dispute resolution.
- With regard to alternative dispute resolution or referral to the ANPC, please note that these two methods of amicable dispute resolution are intended exclusively for consumers.
This document was updated on 22 July 2026.
Privacy & Cookie Policy
Last updated: 22 July 2026
Privacy Policy
General Information
Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter – GDPR, the Regulation or RGPD) was adopted by the European Parliament and the Council of the European Union on 27 April 2016, and its provisions have been directly applicable since 25 May 2018. This Regulation expressly repeals Directive 95/46/EC, thereby also replacing the provisions of Law No 677/2001 (now repealed).
The Regulation is directly applicable in all Member States, protecting the rights of all natural persons within the territory of the European Union. In substance, the Regulation applies to all controllers who process personal data. The Regulation does not apply to the processing of personal data relating to legal persons and, in particular, undertakings with legal personality, including the name and type of the legal person and the contact details of the legal person.
Personal data is defined as any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. The processing of personal data means any operation or set of operations which is carried out on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data Controller
Having regard to Article 4(7) of the Regulation, which defines the term ‘controller’ as a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, this Privacy Policy is drawn up and applied by:
CERC-D SRL
- Registered office: Bucharest, 7 Dinicu Golescu Boulevard, Ground Floor, Flat SP, COM. 3, gdpr-bikecheck@gmail.com Sector 1
- Email:
What Data We Collect
Personal data is collected only to the extent necessary to provide the requested services, in accordance with the principles of lawfulness, fairness and transparency. Data is collected via:
- Account creation forms;
- The contact form or booking requests (data provided voluntarily by
users);
- Cookies and similar technologies;
- Server log files.
Data collected via account creation forms When creating an account on the Platform, the data collected varies depending on the type of account chosen. For Rider accounts, the data collected via the registration form may include: first name and surname, email address, telephone number, password, country, county/region and town, as well as date of birth — used exclusively for age verification, without being stored as such. For Business accounts, the data collected via the registration form may include: business name, business identification number (EUID), business telephone number, country, county/region and town/city, as well as the account holder’s identification and contact details (first name and surname, email address, password). This data is processed for the purposes of creating and managing the account, providing the Platform’s features corresponding to the account type and, where applicable, establishing the contractual relationship. The legal basis is Article 6(1)(b) of the GDPR (performance of a contract and/or pre-contractual measures), as well as, where applicable, Article 6(1)(c) of the GDPR (compliance with a legal obligation, including in the context of identity verification). (1)(c) of the GDPR (compliance with legal obligations, including in the context of identity verification). The identity of account holders is verified via the external provider DIDIT (KYB/KYC), following which the account is activated.
Data collected via contact forms or booking enquiries Data collected via the contact form may include: first name and surname, email address, telephone number, message, and relevant information provided voluntarily by users. This data is processed for the purpose of providing a response and, where applicable, entering into a contractual relationship. The legal basis is Article 6(1)(b) of the GDPR (pre-contractual measures) and/or Article 6(1)(a) of the GDPR (consent).
Given that the Regulation primarily prohibits “the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the unique identification of a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation’ (in accordance with Article 9(1)), the situations in which the processing of such data is permitted are then set out: a. the data subject has given their explicit consent; b. processing is necessary for the purposes of fulfilling the obligations and exercising specific rights of the controller or of the data subject in the field of employment, social security and social protection; c. the processing is necessary to protect the vital interests of the data subject or of another natural person, where the data subject is physically or legally incapable of giving consent; d. the processing is carried out in the course of their legitimate activities and with appropriate safeguards by a foundation, an association or any other non-profit-making body with a political, philosophical, religious or trade-union purpose, provided that the processing relates solely to members or former members of that body or to persons with whom it has
in connection with its purposes, and that personal data are not disclosed to third parties without the consent of the data subjects; e. the processing relates to personal data which have been manifestly made public by the data subject; f. the processing is necessary for the establishment, exercise or defence of legal claims in court or whenever the courts are acting in the exercise of their judicial functions; g. the processing is necessary for reasons of substantial public interest, on the basis of Union or national law, which is proportionate to the aim pursued, respects the essence of the right to data protection and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject; h. the processing is necessary for purposes relating to preventive or occupational medicine, the assessment of an employee’s fitness for work, the establishment of a medical diagnosis, the provision of medical or social care or medical treatment, or the management of health or social care systems and services, pursuant to Union or national law or pursuant to a contract concluded with a healthcare professional, and subject to compliance with the conditions and safeguards laid down in the Regulation; i. the processing is necessary for reasons of public interest in the area of public health, such as protection against serious cross-border threats to health or ensuring high standards of quality and safety of healthcare, medicines or medical devices, pursuant to Union or national law, which provides for appropriate and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; or j. the processing is necessary for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, in a manner that is proportionate to the objective pursued, whilst respecting the essence of the right to data protection, and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject.
Legal Basis For Processing
The processing of personal data is carried out on the basis of the following legal grounds set out in Regulation (EU) 2016/679 (GDPR):
- Article 6(1)(a) – Consent of the data subject (non-essential cookies);
- Article 6(1)(b) – Performance of a contract or pre-contractual measures at the data subject’s request (for information, account creation);
- Article 6(1)(c) – Compliance with a legal obligation (where legislation requires the retention of data);
- Article 6(1)(f) – The controller’s legitimate interests (for website security and fraud prevention).
Purpose Of Processing The Data Collected
Some of the data collected on this website is used for:
- Providing the services we offer via our website (for example, to resolve any issues relating to our services, to provide support services, etc.)
- Ensuring the optimal functioning and optimisation of the website (statistical and analytical purposes) – We are constantly striving to offer you the best possible experience on our website, which is why we may collect and use certain information regarding your level of satisfaction whilst browsing this site; we may invite you to complete
feedback questionnaires or similar.
- Online advertising and promotional activities. You may request at any time, via the means described in this document, that we cease processing your personal data for marketing purposes, and we will comply with your request as soon as possible.
- Regular updates for users – We want to keep you informed about our activities by providing free materials and up-to-date information on our projects and activities. To this end, we may send you any type of message containing general and topic-specific information, details of offers or promotions, as well as other communications such as market research and opinion polls. For communications of this kind, we rely on the consent obtained in advance. You may change your mind and withdraw your consent at any time.
- To protect our legitimate interests. There may be situations where we use or disclose information to protect our rights and business. These may include: measures to protect our website and its users from cyber-attacks; measures to prevent and detect attempts at fraud, including the transmission of information to the relevant public authorities; and measures to manage other types of risk.
The processing of personal data is carried out in accordance with the provisions of the General Data Protection Regulation, based both on the data subject’s consent and on the need to fulfil contracts or to pursue the controller’s legitimate interests (unless the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, take precedence, in particular where the data subject is a child).
Processing of minors’ personal data The services offered via this website are intended exclusively for persons aged 16 or over. In accordance with Article 8 of the GDPR, consent to the processing of personal data in the context of information society services is valid for persons aged 16 or over. For individuals under the age of 16, processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility. The operator of this website does not intentionally collect personal data from individuals under the age of 16 and does not sell products to individuals under this age without the consent of a parent or legal guardian. If you are a child under the age of 16, please do not use this website or provide us with any personal data without the consent and supervision of a parent or legal guardian. If you are aware that a minor under the age of 16 has provided us with personal data without the consent of a parent or legal guardian, please contact us by email at .............................., and we will delete this data as soon as possible.
Obtaining Consent
For the processing of personal data to be lawful, the GDPR stipulates that it must be carried out on the basis of a legitimate ground, such as the performance or conclusion of a contract, compliance with a legal obligation, or on the basis of valid consent previously given by the data subject. In the latter case, the controller is required
to be able to demonstrate that the data subject has given their consent to the processing in question. Consent given under Directive 95/46/EC remains valid provided it meets the conditions set out in the GDPR.
Consent must be given by means of a statement or an unambiguous action constituting a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of their personal data. Where the data subject’s consent is given in the context of a statement, whether in electronic or written form, which also relates to other matters, the request for consent must be presented in a form that clearly distinguishes it from the other matters, which may be achieved, for example, by ticking a box.
Data Retention Period
Personal data is stored for as long as is necessary to fulfil the purposes for which it was collected or for as long as required by applicable legislation. In the absence of specific legal requirements, the data is stored:
- Contact details (forms): 6 years from the last interaction;
- Newsletter data: for the duration of the subscription, and in accordance with the provider’s policy after unsubscription;
- Server log files: in accordance with internal security policies, usually for a maximum of 12 months;
- Cookies: in accordance with the specific duration of each cookie (where applicable, as detailed in the following sections). We review the data collected, assessing the extent to which its retention is necessary for the stated purposes, the legitimate interests of the data subjects, or the fulfilment of the Controller’s legal obligations. Once the periods mentioned above have expired, the data will be deleted or anonymised, unless there is a legal obligation to retain it for a longer period or another legal basis for continuing the processing.
Disclosure Of Personal Data To Other Recipients
The Controller discloses personal data (only where required and strictly to the extent necessary) to public bodies and authorities, including, by way of example: ANAF (National Agency for Fiscal Administration), ISU (Inspectorate for Emergency Situations), the Police, Public Prosecutors’ Offices, Courts, the City Council, the Local Council, the County Council, Ministries, ANPC (National Authority for Consumer Protection), ANSPDCP (National Supervisory Authority for the Processing of Personal Data) in the exercise of its supervisory and control functions, accountants, auditors, lawyers and other external consultants acting as authorised representatives or independent processors, as applicable. We do not transfer data to third countries or international organisations, except where required by an existing cooperation agreement. Thus, on the basis of existing collaborative relationships and in order to be able to carry out the activities undertaken to the highest standards, we will share the data provided with:
- our partners and collaborators (billing services, marketing services, web hosting services, account verification services, online payment services, etc.),
- as well as to other online service providers (various tools and plugins), as set out in this Policy.
Server Log Files
This platform automatically collects and stores the information that your browser automatically transmits to us via log files. These are:
- Browser type and version
- Operating system used
- The URL of the page that originally generated the request to display the current page or object (Referrer URL)
- The hostname of the computer accessing the site
- Time stamps relating to the server access
- IP address The legal basis for the processing of such data is Article 6(1)(b) b) of the GDPR, which permits the processing of data where it is necessary for the performance of a contract to which the data subject is a party or to take steps, at the data subject’s request, prior to entering into a contract.
Contact Form
If you contact us via the contact form, we will collect the data you enter into the form, including the contact details you provide, in order to respond to your enquiries and any subsequent enquiries. We do not pass on this information without your permission. We will therefore process all data you enter in the contact form only with your consent [in accordance with Article 6(1)(a) of the GDPR]. You may withdraw your consent at any time; an informal email to that effect is sufficient. Data processed prior to receiving your request may still be processed lawfully. We will retain the data you provide via the contact form until:
- you request the deletion of the data;
- you withdraw your consent to its storage; or
- the purpose for which it was stored no longer applies. Any mandatory legal provisions, in particular those relating to mandatory data data retention are not affected by the above.
Contact By E-Mail Or Telephone
If you contact us by email or telephone, your enquiry, including any personal data you provide, will be stored and processed by us for the purpose of dealing with your enquiry, on the basis of your consent. We will therefore process all the data you provide in accordance with the following legal provisions of the GDPR, namely:
- only with your consent – in accordance with Article 6(1)(a) of the GDPR
- for the performance of a contract or during the pre-contractual stage – in accordance with Article 6(1)(b) of the GDPR
- to fulfil our legitimate interests, namely the efficient processing of enquiries you have submitted – in accordance with Article 6(1)(f) of the GDPR.
We will retain the data you provide in this way until:
- you request the erasure of the data;
- you withdraw your consent to its storage; or
- the purpose for which it was stored no longer applies, in all cases except where there are mandatory data retention periods.
Registration On The Platform
You can register as a User, either as a Rider or a Business Owner, to access the features and services of the Platform corresponding to your chosen account type — including registering and managing bicycles, sending or receiving service requests, posting listings on the Marketplace, and receiving updates and relevant communications. To this end, the data you provide will be used and processed for the purposes mentioned. The mandatory data requested during registration must be provided in full; otherwise, the registration process will be rejected. Account activation is also subject to the validation of identity checks (KYB/KYC) carried out via the DIDIT provider. To keep you informed about important matters, such as changes to the Platform’s operation or technical changes, we will use the email address you provided at the time of registration. The processing of personal data provided during the registration process is carried out on a contractual basis, in accordance with Article 6(1)(b) of the GDPR, as it is necessary for the creation and administration of your account and for the provision of the Platform’s services, as well as, where applicable, on the basis of your consent, in accordance with Article 6(1)(a) of the GDPR (for example, for promotional communications). You may withdraw your consent at any time, where this legal basis has been relied upon; an informal email to that effect is sufficient; the withdrawal of consent does not affect processing based on other legal grounds, nor does it affect the lawfulness of processing carried out prior to the withdrawal. We will continue to store the data collected during registration for as long as you remain registered as a User, whilst the mandatory retention periods laid down by law remain in force and are complied with.
Rights Of Data Subjects
Your rights regarding personal data and the means of exercising them are: the right to information, the right of access, the right to rectification, the right to erasure, the right to restriction of processing, The right to data portability, The right to object, The right not to be subject to a decision based solely on automated processing, The right to lodge a complaint and to bring the matter before the courts, The right to withdraw consent.
- Right to information – you may request information regarding the processing of your personal data, the identity of the controller and their representative, or the recipients of your data;
- Right of access – you may obtain from the controller confirmation as to whether or not personal data concerning you are being processed and, if so, access to those data and to the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or are to be disclosed, in particular recipients in third countries or international organisations; where possible, the period
for which the personal data are expected to be stored or, if this is not possible, the criteria used to determine that period; the right to request the controller to rectify or erase the personal data, or to restrict the processing of the personal data, or the right to object to the processing, etc.
- Right to rectification – you may rectify inaccurate personal data or have it completed;
- Right to erasure – you may request the erasure of your data where its processing was unlawful or in other cases provided for by law;
- Right to restriction of processing – you may request that processing be restricted if you contest the accuracy of the data, as well as in other cases provided for by law;
- The right to data portability – under certain conditions, you may receive the personal data you have provided to us in a machine-readable format, or you may request that such data be transferred to another controller;
- Right to object – you may object, in particular, to data processing based on the controller’s legitimate interests;
- The right not to be subject to a decision based solely on automated processing – you may request and obtain human intervention regarding such processing or express your own views on this type of processing;
- The right to lodge a complaint and to bring the matter before the courts – you may lodge a complaint regarding the manner in which your personal data is processed with the National Supervisory Authority for Personal Data Processing and / or you may bring a case before the courts to ensure your rights are upheld;
- The right to withdraw consent – where processing is based on your consent, you may withdraw it at any time. Withdrawal of consent will only take effect for the future; processing carried out prior to withdrawal remains valid.
To exercise any of these rights, please contact us at: ........................ Your request does not need to follow any specific format, but it must include: your first name and surname, the contact details where you wish to receive a reply, as clear a description as possible of the right you wish to exercise and, if possible, a copy of an identity document (to verify your identity and prevent unauthorised access to your data). We will respond to your request within a maximum of 30 calendar days from the date of receipt. In particularly complex cases or where there is a high volume of simultaneous requests, this period may be extended by a further 60 days, provided that we inform you of this extension and the reasons for it within 30 days of receiving your request, in accordance with Article 12(3) of the GDPR. Our response to your request is free of charge. If your requests are manifestly unfounded or excessive (in particular because of their repetitive nature), we may either charge a reasonable fee taking into account the administrative costs, or refuse to comply with the request, providing the grounds for the refusal and informing you of your right to lodge a complaint with the ANSPDCP.
If you are not satisfied with the response you have received or if you believe that your rights have been infringed, you have the right to lodge a complaint with: the National Supervisory Authority for Personal Data Processing (ANSPDCP) 28–30 General Gheorghe Magheru Boulevard, Sector 1, Bucharest Telephone: +40 318 059 211 Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro You also have the right to bring a case before the competent courts in Romania or in the EU Member State where you have your habitual residence.
Cookie Policy
What are cookies? Cookies are small text files stored on your device (computer, mobile phone, tablet) when you visit a website. They enable the website to recognise you on your next visit, remember your selected preferences and provide a personalised experience.
Categories of cookies This website may use the following categories of cookies:
- Strictly necessary cookies – essential for the basic functioning of the website. They do not require consent;
- Functional cookies – these remember the user’s preferences (e.g. selected language). They may require consent depending on their nature;
- Analytical cookies – collect data on how the site is used, for statistical purposes. These require consent;
- Marketing/advertising cookies – used to personalise adverts and profile interests. Consent is required;
- Security cookies – used to prevent fraud and protect sessions. They do not usually require consent, but some may be linked to third-party services.
The BikeCheck platform does not use cookies. We do not use functionality, analytics, tracking or advertising cookies, and we do not place third-party cookies on your device.
For authentication and to keep your session active, the Platform uses local browser storage mechanisms (localStorage/sessionStorage), which are strictly necessary for the service to function. This information is stored exclusively on your device; it is not used to track your activity or for marketing purposes, and is essential for providing the requested service, which is why it does not require your consent.
Managing Consent For Cookies
On your first visit to our website, which uses cookies that require consent, you will be informed via a dedicated banner. You can choose to:
- Accept all cookies;
- Reject non-essential cookies;
- Customise your preferences regarding the categories of cookies you accept. Strictly necessary cookies are enabled by default, as they are essential for the website to function. Withdrawing your consent for optional cookies does not affect the lawfulness of any previous processing. You can also manage or delete cookies directly from your browser. Detailed instructions are available on the websites of the main browser providers: Chrome,
Firefox, Safari, Edge.
Obligations Of The Hosting Data Controller
This Platform operates through several infrastructure providers, who act as the controller’s data processors, each for the component they provide: a) Vercel Inc. – hosting the Platform’s front-end component; b) Railway Corp. – hosting the Platform’s backend; c) Supabase Inc. – hosting and managing the database in which personal data is stored; d) Resend (Plus Five Five Inc.) – sending email communications relating to the operation of the Platform (e.g. notifications, confirmations, transactional messages).
The processing of data provided and stored through these providers complies with the following legal provisions:
- Article 6(1)(b) of the GDPR – processing is necessary for the performance of the contract between the user and BikeCheck, or between the Supplier and BikeCheck, specifically for the provision of the Platform’s functionalities;
- Article 6(1)(f) of the GDPR – processing is carried out for the purposes of our legitimate interests, namely the secure, stable and continuous operation of the Platform;
- Article 6(1)(a) of the GDPR – where applicable, processing is based on your consent, obtained following fair and full disclosure.
The hosting providers mentioned are companies based outside the European Economic Area (USA). To the extent that the storage or access to data involves a transfer outside the EEA, BikeCheck ensures that this is carried out on the basis of appropriate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional safeguards, as well as on the basis of data processing agreements (DPAs) concluded with each provider.
Regardless of the purpose for which personal data is processed, the principles of lawfulness, fairness and transparency are observed, as well as the principle that the data processed is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. For further information on data processing by hosting providers, please consult their policies, available on their official websites.
Data Encryption
This website uses SSL encryption for security reasons and to protect the transmission of confidential information. You can recognise this encryption by the padlock icon that appears in the browser bar and by the change in the browser address from http:// to https://. Once this type of encryption is activated, the data transmitted or transferred cannot be viewed by third parties.
In accordance with the GDPR, where a personal data breach is likely to result in a high risk to your rights and freedoms, the controller of this website will inform you, without undue delay, of this breach, unless the supplementary provisions of the same Regulation (Article 34(3)) apply.
Data Protection Officer
As the provisions of the GDPR (Article 37(1) – according to which the Controller and the person authorised by the Controller shall designate a Data Protection Officer whenever: a. processing is carried out by a public authority or body, with the exception of courts acting in their judicial capacity; b. the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale; or c. the main activities of the controller or the processor consist of the large-scale processing of special categories of data pursuant to Article 9 or of personal data relating to criminal convictions and offences, as referred to in Article 10) concerning the obligation to appoint a Data Protection Officer, For any information or clarification regarding the operation of this website, please contact us using the following details:
- Email address: ..................
- Postal address: Bucharest, 7 Dinicu Golescu Boulevard, Ground Floor, Flat SP., COM. 3, Sector 1
Records Of Processing Activities
In accordance with the GDPR, the controller or the processor should keep, for a reasonable period, records of the processing activities for which they are responsible. These records shall include the following information:
- the name and contact details of the controller;
- the purposes of the processing;
- a description of the categories of data subjects and the categories of personal data;
- the categories of recipients to whom the personal data have been or will be disclosed;
- where applicable/possible:
- transfers of personal data
- the envisaged time limits for the erasure of the various categories of data
- a general description of the technical and organisational security measures The obligation set out above does not apply to an undertaking or organisation with fewer than 250 employees, unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing involves special categories of data or personal data relating to criminal convictions and offences.
Appropriate Technical And Organisational Measures
Taking into account the current state of the art, the context and the purposes of the processing, as well as the risks to the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure that, by default, only personal data necessary for each specific purpose of the processing are processed.
NOTIFICATION TO THE SUPERVISORY AUTHORITY IN THE EVENT OF A PERSONAL DATA BREACH In accordance with Article 33(1) of the GDPR, in the event of a personal data breach, we will notify the National Supervisory Authority for the Processing of Personal Data without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to the rights and freedoms of natural persons.
INFORMING THE DATA SUBJECT OF A PERSONAL DATA BREACH In accordance with the provisions of Article 34 of the GDPR, where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, we will inform the data subject without undue delay of the breach, except where:
- appropriate technical and organisational protection measures have been implemented, and these measures have been applied to the personal data affected by the personal data breach, in particular measures ensuring that the personal data becomes unintelligible to any person not authorised to access it, such as encryption;
- further measures have been taken to ensure that the high risk to the rights and freedoms of the data subjects referred to above is no longer likely to materialise;
- it would require a disproportionate effort. In this situation, a public notice shall be issued or a similar measure taken to inform data subjects in an equally effective manner.
Tools & Plug-Ins
Facebook Plug-ins (API) This website uses social plugins (“plugins”) managed by the social network facebook.com. The plugins can be identified by a Facebook logo (a white “f” on a blue background or a “thumbs up” symbol) or are labelled with the phrase “Facebook Social Plugin”. The list and appearance of Facebook plugins can be viewed here: https://developers.facebook.com/docs/plugins/. If you use the ‘Like’ button, you will be able to ‘like’ our website’s Facebook page without having to leave it. If you use the Share extension, you will share our website or specific content from it on your personal Facebook page without having to leave the website. Through the plugin, Facebook receives information about the content you access on our website. If you are logged into Facebook at the same time, Facebook may attribute
the actions you take on the page to your account and, by extension, to you personally. When you interact with the plugins – for example, by clicking the ‘Like’ button or sharing specific content from the site – the relevant information is transferred directly from your browser to Facebook and stored there. Even if you are not a Facebook member, there is still a possibility that the social network may obtain and store your IP address. By clicking on one of these buttons, you consent to the use of this plugin and, consequently, to the transfer of personal data to Facebook. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing. In light of the judgment of 16 July 2020 (delivered in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union ruled that the protection afforded by the EU–US Privacy Shield is not adequate. Consequently, the transfer of personal data to the US and other countries outside the European Economic Area (EEA) is based on the European Commission’s Standard Contractual Clauses (SCCs). The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from data controllers in the EU to data processors established outside the EU or the EEA. For more more information on these Clauses, we recommend that you visit https://ec.europa.eu/info/law/law- topic/data-protection/international-dimension-data-protection/standard-contractual- clauses-scc_ro. Facebook uses Standard Contractual Clauses as an appropriate safeguard for data protection, in line with the level of protection guaranteed by the GDPR. With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so the transfer of data may be based, where applicable, on this adequacy decision, in addition to or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification can be found at: https://www.dataprivacyframework.gov/s/participant-search For more further details, you visit: https://www.facebook.com/legal/EU_data_transfer_addendum, regarding the purpose and scope of data collection, the processing and subsequent use of data by Facebook, as well as permissions and settings for protecting your privacy.
This website uses social plugins (“plugins”) operated by the social network Instagram, a service provided by Instagram Inc., with its registered office at 1601 Willow Road, Menlo Park, CA 94025, USA. The plugins can be identified by an Instagram logo or are labelled with the phrase ‘Instagram Social Plugin’. Through the plugin, Instagram is informed of the actions you take on our website. If you are logged into your personal social media account at the same time, Instagram may attribute the actions taken on the page to your Instagram account and, by extension, to you personally. When you access the plugins, the relevant information
is transferred from your browser to the social media platform and stored there. Even if you are not an Instagram user, there is still a possibility that Instagram may obtain and store your IP address. By clicking on one of these buttons, you consent to the use of this plugin and, consequently, to the transfer of personal data to Instagram. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing. For information regarding the purpose and scope of data collection, the processing and further use of data by Instagram, as well as the permissions and settings for protecting users’ privacy, please refer to Instagram’s privacy policy at: https://help.instagram.com/519522125107875. In light of the judgment of 16 July 2020 (delivered in Case C-311/18 – Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union ruled that the protection afforded by the EU–US Privacy Shield is not adequate. Consequently, the transfer of personal data to the US and other countries outside the European Economic Area (EEA) is based on the European Commission’s Standard Contractual Clauses (SCCs). The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from data controllers in the EU to data processors established outside the EU or the EEA. For more more information on these Terms and Conditions, we recommend that you visit https://ec.europa.eu/info/law/law-topic/data-protection/international- dimension-data-protection/standard-contractual-clauses-scc_ro. Instagram uses Standard Contractual Clauses as an appropriate safeguard for data protection, in line with the level of protection guaranteed by the GDPR. With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so the transfer of data may be based, where applicable, on this adequacy decision, in addition to or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification can be found at: https://www.dataprivacyframework.gov/s/participant-search. For more further details, please visit: https://www.facebook.com/legal/EU_data_transfer_addendum.
WEB FONTS – OPEN SANS This website uses the Open Sans font to ensure consistent text display across all pages of the Platform. Open Sans is a freely licensed font (Open Font Licence), which is hosted locally on the Platform’s own infrastructure. Therefore, when you access a page on this website, your browser loads the font files directly from the Platform’s servers, without establishing a connection to third-party servers and without your data (including your IP address) being transmitted to external providers for the purpose of displaying the font. The use of the Open Sans font is based on Article 6(1)(f) of the GDPR, as there is a legitimate interest in the uniform and legible presentation of text on this website. As
the font is hosted locally, this functionality does not involve any transfer of data to third parties and does not require any additional legal basis for processing.
Identity verification via DIDIT (KYB/KYC) The Platform uses the services provided by DIDIT, a specialised identity verification solution, in order to fulfil its obligations regarding the identification of customers and business partners (KYC – Know Your Customer and KYB – Know Your Business), as well as to prevent fraud and ensure the security of the Platform. The activation of any account is conditional upon the successful completion and validation of the checks carried out via DIDIT. For users and businesses based in the European Union, the United Kingdom, the European Economic Area and Switzerland, the contracting entity and the operator of the European data processing infrastructure is Didit Identity Spain, S.L., with its registered office at Calle Nápoles 227, P. 1, 08013 Barcelona, Spain (CIF B22929327). As part of the verification process, depending on the account type and the applicable data flow configuration, the following may be processed: identification and contact details (surname, first name, email address, telephone number, postal address, date of birth), images of identity documents, data extracted from these, and, in certain data flows, biometric data resulting from liveness verification and, respectively, facial comparison, as well as, in the case of Business accounts, the identification data of the economic operator and the verification of such data in public registers. In its relationship with the Platform, DIDIT acts as a data processor, processing the data exclusively on the basis of the controller’s instructions and for the purpose of carrying out the requested verification. The decision to approve, reject or repeat the verification, as well as to activate the account, rests with the Platform, with DIDIT providing the verification technology and the associated analysis. The processing is based on Article 6(1)(b) of the GDPR (pre-contractual measures and performance of the contract), on Article 6(1)(c) of the GDPR (compliance with legal obligations, including fraud prevention), and, with regard to biometric data, to the extent that such data is processed, on the applicable basis under Article 9 of the GDPR, with the data subject being informed and, where appropriate, their explicit consent being obtained. DIDIT allows the controller to configure the data storage region so that, for users in the European Union, verification data may be processed and stored within the European Economic Area. To the extent that, depending on the configuration of the service, a transfer of data takes place to an entity within the DIDIT group or to sub-processors established outside the European Economic Area (including Didit Identity, Inc., with its registered office in Dover, Delaware, United States), this is carried out on the basis of appropriate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional safeguards. For further information on the Standard , you can visit https://ec.europa.eu/info/law/law-topic/data-protection/international- dimension-data-protection/standard-contractual-clauses-scc_ro. Data processing by DIDIT is carried out in accordance with its own privacy policies, available at https://didit.me/terms/privacy-policy/, as well as with the specific notes applicable to identity verification. For further details regarding the nature, purpose and scope of the processing, as well as the security measures in place, please refer to the documentation provided by DIDIT.
Online payments – PADDLE Payments for subscriptions and services paid for via the Platform are processed through the provider Paddle, which acts as the Merchant of Record (registered merchant/reseller). From a legal perspective, this means that Paddle is the legal seller of the digital products and services to the user, processes the payment and assumes responsibility for compliance with applicable legislation and for managing the relevant taxes (VAT/indirect taxes), in place of BikeCheck. The name ‘Paddle’ may appear on the user’s bank statement instead of ‘BikeCheck’. Unlike a simple payment processor, in this configuration Paddle acts, with regard to the data processed in connection with the transaction and the resale relationship, as an independent controller, with processing carried out in accordance with its own privacy policy. The Paddle entities relevant to users and businesses in the European Union, the United Kingdom and the European Economic Area are Paddle.com Market Limited, with its registered office at 30 Old Bailey, London, United Kingdom, EC4M 7AU, and Paddle Payments Limited, with its registered office at The Academy, 42 Pearse Street, Dublin 2, D02 HV59, Ireland. According to the Regulation, ‘in order to maintain security and prevent processing that infringes this Regulation, the controller or the processor should assess the risks inherent in the processing and implement measures to mitigate those risks, such as encryption’ – Recital 83. The availability of strong and effective encryption is therefore essential to guarantee the protection, confidentiality and integrity of personal data. Bank details provided for the purpose of making payments are transmitted via secure connections, using appropriate encryption methods, to the payment processing infrastructure. BikeCheck does not collect, store or have access to the user’s full card details, which are managed exclusively by Paddle and its processing partners. According to the information available at https://www.paddle.com/legal/privacy, Paddle’s IT system provides appropriate measures to protect users’ personal data, as well as the operations and transactions carried out through it. The purposes of processing, the data processed, the conditions for their transfer and distribution, the security of operations and of the data processed and stored, as well as the other information provided by Paddle, are based on the mechanisms for ensuring the lawfulness of processing provided for by the GDPR, namely: the data subject’s consent [Article 6(1)(a)], the performance of a contract [Article 6(1)(b)] and the controller’s legitimate interests [Article 6(1)(f)]. To the extent that Paddle processes data outside the European Economic Area, the transfer is carried out on the basis of appropriate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 or, where applicable, on the basis of an applicable adequacy decision.
Conclusion
This policy on the processing of personal data has been drawn up in accordance with the provisions of Regulation No 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as with other applicable national legal provisions.
We reserve the right to make any additions or amendments to this policy. We recommend that you consult the Policy regularly to ensure you have accurate and up-to- date information regarding the processing of personal data. For further details regarding this GDPR Policy, as well as to exercise any of the rights mentioned above, a written notification may be sent to the contact details provided.
Contact And Complaints
For any questions, requests or complaints regarding the processing of personal data, please contact us:
CERC-D SRL
- Head office: Bucharest, 7 Dinicu Golescu Boulevard, Ground Floor, Flat SP, Block 3, Sector 1
- Email: ..........................
Last updated: 22 July 2026