Legal
The full, authoritative text of BikeCheck's legal documents — the same text shown in the app. This page is provided so the documents can be read and linked to directly.
Terms & Conditions — Riders
Last updated: 15 August 2026
Terms And Conditions
Brief Notes
- By accessing and using this Platform, you accept, without limitation or any other qualification, these terms and conditions, and you understand that any other agreements between you and the Platform Operator (hereinafter, BikeCheck) are governed in their entirety by these Terms and Conditions.
- The “Terms and Conditions” constitute the legal agreement between you and BikeCheck. Before using this Platform and before creating a Rider Account, we recommend that you first read these Terms and Conditions. Accessing the Platform, as well as creating and personalising a Rider Account, means the full and unconditional acceptance of these Terms and Conditions.
- The terms and conditions may be amended at any time by BikeCheck, without prior notice being required. The amendments and the information regarding their validity will be posted on the Platform, for the purpose of informing BikeCheck users. Accordingly, we recommend that you refer to this policy regularly in order to review its updated content. If, at any time, these Terms and Conditions become unacceptable to you, please cease accessing and using the Platform immediately.
Definition Of Terms
- BikeCheck/the Platform Operator – means the legal person CERC-D SRL, with its registered office in Bucharest Municipality, Bd. Dinicu Golescu, No. 7, Ground Floor, Ap. SP., COM. 3, Sector 1, having tax identification number 55196436 and J2026044124009, e-mail: cerc-d@proton.me
- Platform – means the website https://bikecheck.io/, whose functionalities are presented transparently and in detail and which makes available to Users, Business Owners and Riders an intuitive interface for the intermediation of servicing, maintenance, sale and history-reporting services in respect of the bicycles registered on the Platform.
- The Users’ Account – means the personalisation of a section within the Platform, by entering the e-mail address and a password, the name/first name and surname, a section which contains information about the user and about the bicycles included on the Platform. The data provided upon creation of the Account will remain confidential and is subject to the Privacy Policy;
- Contract – means the distance contract concluded between BikeCheck and Users, without their simultaneous physical presence, contracts which are concluded at the moment of confirmation, on a durable medium (by e-mail), by BikeCheck of the creation of the account, following the User’s acceptance of the conditions in this document and the validation carried out in accordance with the conditions set out in Article 3.
- Document – this Terms and Conditions Policy, which governs the contractual relationship between BikeCheck and Users and which shall be interpreted in accordance with Romanian law. Any non-compliance or invalidity of a part or clause of this Document with other applicable legal provisions has no effect on the validity and lawfulness of the other provisions of this Document.
- The services intermediated through this Platform, in accordance with the law and which do not exceed the limits imposed by these Terms and Conditions, consist of servicing, maintenance, sale and history-reporting services in respect of the bicycles registered on the Platform.
- Platform – means the site https://bikecheck.io/, as well as any section or subpage thereof. Websites and/or internet pages or other components thereof belonging to third parties and which are accessed by users or visitors as a result of the links or redirections available on the site https://bikecheck.io/ are neither the object of, nor do they fall within the scope of, this definition.
- Processing of personal data – see the Privacy Policy.
- Rider User – any natural person with full legal capacity who creates an Account on the Platform and registers bicycles and requests services made available by Businesses through the Platform.
- Visitor – any person who accesses this Platform without creating an account.
Terms Of Use Of The Platform
- Access to and use of the BikeCheck Platform is carried out in accordance with, and is fully subject to, the provisions of this Document.
- The Platform makes available to Rider account holders the following principal functionalities:
- Dashboard – the central interface through which the Rider accesses the account functionalities, views the relevant information and manages the operations carried out within the Platform;
- Bike gallery – the module for presenting the bicycles registered on the Platform, together with their technical specifications and the available information relating to them;
- Garage – the module for recording the Rider’s own bicycles, which allows the registration of each unit, the management of identification data, of technical condition and of the history of repair and maintenance interventions;
- Marketplace – the dedicated module within which the Rider may publish and consult bicycle sale listings, under the conditions provided for in this Document, liability for the published content resting exclusively with the User who uploads the listing;
- Transfers – the module which allows the management of the transfer of registered bicycles between Platform Users, together with the corresponding records;
- Activity – the module for recording the operations carried out within the account;
- Notifications – a system of alerts and communications regarding events relevant to the Rider’s account (e.g. the status of service requests, messages from service providers, updates regarding listings or transfers);
- Settings – the module for configuring the account, the specific data and the usage preferences.
- The Platform facilitates the connection between Business Users and Rider Users, for the purpose of scheduling and managing bicycle repair and maintenance services. BikeCheck acts exclusively as a provider of the technical solution/technological intermediary and is not a party to the contractual service relationships established directly between Businesses and Riders.
- BikeCheck does not carry out, supervise or take responsibility for repair and maintenance works, their quality, the conformity of the parts used or the technical condition of the bicycles handed over for servicing, these remaining entirely the responsibility of the Businesses (Service Providers), in their capacity as providers of the services.
- The User of this Platform is fully responsible for the content of the information included on the Platform, such as: descriptions, photographs, location, facilities, own rules, regulations, contractual conditions, etc. (illustrative enumeration). In any event, the information made available to the Platform by Users must be correct, complete and not misleading.
- Unlawful or dangerous activities, or activities which affect the trust of the community, are prohibited. We may suspend/remove listings and accounts in the event of breaches or of a risk to the safety of the Platform or of the other Users.
- In order to ensure the security of the Platform, to prevent fraud and to fulfil the applicable legal obligations, all users of the Platform – both Business Owners and Riders – are subject to a mandatory identity verification process, carried out through a specialised external provider, namely DIDIT (hereinafter the “Verification Provider”).
- The verification is carried out on the basis of the following principles:
- “Know Your Business” (KYB) – for Business Owners, consisting of verifying the existence and identity of the economic operator, the registration data, the legal representative and, where applicable, the supporting documents regarding the activity carried out;
- “Know Your Customer” (KYC) – for Riders, consisting of verifying the identity of the end user on the basis of the documents and information requested during the process.
- For the purpose of carrying out the verification, the User undertakes to provide the information and documents requested by the Verification Provider and warrants that these are genuine, accurate, complete and within their period of validity.
- The account is activated and becomes functional only after the verification procedures have been completed in full and successfully validated by DIDIT. Until the moment of confirmation of validation, access to the Platform’s functionalities is restricted or suspended, and the user may neither initiate nor accept service requests.
- In the event that the Verification Provider does not validate the completion of the verifications, or identifies inconsistencies, false or incomplete information, the situation may arise of refusing the activation of the account, of suspending or of closing the account, without this giving rise to any obligation of compensation on the part of BikeCheck.
- Identity verification through DIDIT does not constitute a warranty on the part of BikeCheck as to the solvency, reliability, professional competence or subsequent conduct of any user, liability for the contractual relationships established between Business Owners and Riders resting entirely with them.
- The processing of personal data within the verification process is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and with the Privacy Policy of the Platform.
Intermediation Policy
- The information used to describe the available services and the functionalities integrated into the Platform (texts, images, multimedia presentations) is of an informative nature and does not represent contractual obligations on the part of BikeCheck.
- The Rider User understands and accepts that:
- all amounts, prices, tariffs or estimates displayed on the Platform are strictly informative and estimative in nature. They do not constitute a firm offer on the part of the Platform or of the Business Users and may be subject to subsequent adjustments. The amounts displayed may be modified, updated or revised unilaterally and at any time directly by the Business Users, without prior notice and without the intervention or agreement of the Platform.
- The Platform does not collect, process or manage the amounts or payments relating to the services/products offered by the Business Users. Any financial transaction takes place directly between the Rider and the Business User.
- The Platform assumes no liability for the differences between the amounts displayed on the site and the final amounts requested by the Business Users, for the price changes made by them, or for any damage arising from the estimative nature of the information displayed.
- The Rider User has the option of synchronising their account with the third-party service Strava, for the purpose of retrieving and displaying certain data regarding sporting activity, with the prior and express consent of the user. Synchronisation is carried out through the interfaces made available by Strava and is subject, as regards that service, to Strava’s own terms and privacy policies, for which BikeCheck is not liable. The user may revoke the synchronisation at any time from the account settings section.
- The Rider may submit a service request through the Platform, selecting the economic operator (Business Owner) to whom it is addressed, from among those available on the Platform.
- The choice of service provider belongs exclusively to the Rider, BikeCheck not intervening in that selection and assuming no liability in respect of the works requested or of the contractual relationship thus established.
The User’s Dashboard. The Unique Account Identifier. Other Details Regarding The User Account
- Each account, regardless of the type of user (Business Owner or Rider), is automatically assigned, at the moment of creation, a unique identifier (hereinafter the “Account ID”), generated by the Platform and not modifiable by the user.
- The Account ID ensures the unique identification of the user within the Platform and is used for the purposes of administration, record-keeping, invoicing and the resolution of any requests or complaints.
- Each account, regardless of the type of user, is provided with a personalised control panel (Dashboard), through which the user accesses the functionalities corresponding to their account type, views the relevant information and manages the operations carried out within the Platform.
- The Platform makes available a dedicated section within which users, both Business Owners and Riders, may publish bicycle sale listings, with their description, photographs and the corresponding commercial conditions.
- The User who publishes a listing is fully liable for its content, including for the truthfulness of the information, for the lawfulness of the sale and for the rights over the goods offered for sale.
- Sale and purchase relationships are established directly between the Users of the Platform, BikeCheck not having the capacity of party, commercial intermediary or guarantor of the transaction.
- The Platform offers Users the possibility of obtaining, free of charge, an informative report regarding the registered bicycles, comprising the information available within the Platform in respect of the registered request. The report generated is purely informative in nature and is generated on the basis of the data existing on the Platform and/or provided by Users. BikeCheck does not warrant the complete, accurate or up-to-date nature of the information contained in the report and is not liable for the decisions taken by Users on the basis of it.
Warranties. Limitation Of Liability.
- BikeCheck is not liable for:
- losses caused by the acts or omissions of Users (Business Owners or Riders), including those arising from the contractual relationships established directly between them;
- the quality, conformity, safety or outcome of the repair and maintenance works carried out by Business Owners, as well as for their conformity with the technical or other regulations applicable to the provider’s activity;
- the content published by Users on the Platform, including sale listings and the materials uploaded within them, under the conditions of this Document;
- the accuracy, completeness or up-to-date nature of the information contained in the report regarding the bicycle, which is purely informative in nature;
- data retrieved from third-party services integrated into the Platform, which are subject to the own terms and policies of those providers;
- indirect losses, including but not limited to loss of profit, loss of data, loss of business opportunities or reputational damage.
- BikeCheck shall not be responsible for any situations prejudicial to the User which result from the User’s failure to comply with this Document, with the adjacent Policies, with the instructions provided through the Platform and/or with the applicable legislation in force.
- BikeCheck cannot be held responsible for the damage suffered by the User, directly or indirectly, resulting from the non-use or the incorrect use of the information and functionalities made available on the Platform.
- The services offered by BikeCheck represent obligations of means, and not of result. BikeCheck has exclusively the role of provider of the technical solution and of technological intermediary which facilitates the connection of Business Owners with Riders, not being a party to the service provision or sale and purchase relationships established between them. Consequently, BikeCheck is not liable for the results generated as a consequence of the activity of Users on the Platform, its liability being limited to ensuring optimal conditions of operation of, and access to, the services of the Platform, as described in the body of this policy.
- The process of verifying Users through DIDIT (KYB/KYC), described above, does not constitute a warranty by BikeCheck as to the solvency, reliability, professional competence or subsequent conduct of any User, the risks relating to the relationships established between Business Owners and Riders resting exclusively with them.
Intellectual Property
- BikeCheck holds full and complete title over the files, images and materials published on the platform, as well as all the intellectual property rights arising from them.
- All trade marks and logos are owned by BikeCheck and no person or entity has the right to copy or use them in any way.
- The use, taking, copying or modification, without BikeCheck’s agreement, of any graphic/design/structural elements, etc. present on the Platform is strictly prohibited. Any infringement of rights falls under the law and will be resolved by the entities empowered for this purpose.
- No element of content transmitted to Users, by any means of communication (electronic, telephone, etc.) or acquired by them through accessing, visiting and/or viewing, constitutes a contractual obligation on the part of BikeCheck.
- In certain situations, for the images and photographs used on this website, we do not hold intellectual property rights, but only rights of use. In this regard, certain images and photographs found on our website are used in compliance with the terms and conditions relating to their source of origin.
Privacy
- BikeCheck will maintain the confidentiality of information of any nature which Users provide. The sharing of the information provided may be carried out only under the conditions set out in the Privacy Policy.
- If, in respect of the Account created by a User, there are suspicions regarding data security or regarding possible abusive use, BikeCheck will immediately take the measures required (for example, it will request the account holder to change the password) or will even delete the account, with prior notification of the person concerned.
- The processing of personal data and the rules for its protection may be accessed in the corresponding policy on the Platform.
- BikeCheck respects and protects the right to security of the personal data of the Users of this website and has the obligation to administer, under conditions of safety and only for the purposes specified, the personal data provided. The purpose of collecting the data is to ensure that Platform Users receive information and services of the highest quality.
- In order to provide access to the Platform and to facilitate the service requests of Rider Users, personal data is processed by BikeCheck, in its capacity as provider of the Platform, together with the service provider (Business Owner) chosen by the Rider. As regards the service request, BikeCheck and the Business Owner act as joint controllers within the meaning of Article 26 GDPR: BikeCheck provides the digital infrastructure, the initial collection of data and the communication through the interface, while the Business Owner manages the direct relationship with the Rider (receipt and handover of the bicycle, carrying out the works) and fulfils its own legal obligations.
- Depending on the manner in which the Platform is used by the Rider User, we process: identification and contact data (name, e-mail, telephone); the details of the service request (the type of bicycle, its identification elements, the nature of the intervention requested, the history of the works); the data regarding the bicycles registered in the Garage and any transfers; the listings published in the Marketplace and the content uploaded; the correspondence conducted through the Platform; proofs of payment; complaints and support requests.
- We use the Rider User’s data for: the administration of the account and of the Platform’s functionalities; the intermediation of service requests and of communication with the chosen provider; the settlement and invoicing of the subscription; identity verification (KYC); the prevention of fraud and ensuring the safety of users; the resolution of requests and of any disputes; as well as compliance with legal obligations.
- We process the Rider User’s data on the basis of: the performance of the contract between the Rider and BikeCheck [Article 6(1)(b) GDPR], for managing the service request and providing the Platform’s services; compliance with legal obligations [Article 6(1)(c) GDPR], for example fiscal and accounting obligations; legitimate interest [Article 6(1)(f) GDPR], for the safe operation of the Platform, the prevention of fraud and the protection of users’ rights, in compliance with the principle of data minimisation; and, where necessary, the consent of the data subject/Rider [Article 6(1)(a) GDPR], for example for commercial communications.
- Within the limits of what is strictly necessary, the personal data entered by Riders may be disclosed to providers acting as processors (for example, cloud hosting, e-mail services, anti-fraud tools), as well as to public authorities, on the basis of the law. Payments are processed through Paddle, in its capacity as Merchant of Record, and identity verification is carried out through DIDIT, both providers acting in accordance with their own terms and privacy policies. Where data is stored or accessed outside the European Economic Area, we ensure that adequate safeguards exist in accordance with Chapter V of the GDPR (for example, the Standard Contractual Clauses 2021/914).
- We apply technical and organisational measures in accordance with Article 32 GDPR, including access control, encryption of data in transit and, where possible, at rest, logging of actions, backup and restoration procedures, anti-malware protection and procedures for responding to security incidents.
- In their capacity as a data subject, the Rider User benefits from the rights provided for by the GDPR: the right of access, of rectification, of erasure, of restriction of processing, of data portability and of objection. These rights may be exercised either directly through the Platform or by contacting either of the joint controllers. The Platform represents the single operational point of contact for receiving requests, which will subsequently be resolved within the time limits provided for by law. Likewise, the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) is respected.
- The data relating to service requests is kept for the period necessary for the performance of the services and for the periods required by law (for example, the fiscal and accounting periods and those relating to the warranty on the works), after which it is deleted or anonymised.
- The selected Business Owner may also process personal data for its own purposes (for example, the record of the works carried out, fiscal obligations or the warranty on the works), in its capacity as an independent controller for those processing operations, in accordance with its own privacy policy. We recommend consulting the information notices made available by the chosen provider.
Security
- When using the Platform, you are responsible for ensuring the confidentiality of the data relating to your access account (username and password) and you agree to assume full responsibility for the activities/actions carried out in the application on the basis of your account and password. We recommend that you do not disclose the data by which you authenticate.
- In the event that the confidentiality of these access details has been compromised, you have the obligation to notify BikeCheck as soon as possible in order to restrict access to the account and to generate for you, as quickly as possible, a means by which you may regain possession of your account.
- The carrying out of unauthorised operations such as: abusive use, fraudulent use, unauthorised access, modification, copying of information with a view to its commercialisation, blocking of access, etc. in respect of the Platform, will be punished in accordance with the law.
Useful Information For Users
- As a User, you understand and agree to the following information:
- To receive occasional information notices from BikeCheck, in accordance with the GDPR Policy, for certain specific campaigns (having the possibility of withdrawing your agreement at any time);
- To provide true, accurate and complete data;
- To maintain and update, where appropriate, the registration data so that it is true, accurate and complete.
- It is prohibited to use the Platform in the following ways or for the following purposes:
- In breach of the Terms and Conditions in this document;
- In breach, in any manner, of the applicable legal provisions, or by means which may lead to the breach, in any manner, of the applicable legal provisions;
- In any manner by which one acts in the name and on behalf of another person, in particular through the use of false names, false e-mail addresses, false telephone numbers, etc.
- For the promotion or concealment of activities of an unlawful or immoral nature;
- To reproduce, in any way, the interface of the site, with a view to misleading Users or potential Users of BikeCheck;
- To obtain unauthorised access to the data which other Users have voluntarily provided to us;
- To introduce malicious programs or lines of code into the system;
- To request unlawful information, products or services, or to request information which would cover an unlawful activity;
- To obtain access to various sections or subsections of the site, or to the products or services offered by us, using unlawful procedures.
- As a User, you undertake the obligation not to carry out the following activities:
- To publish copyrighted materials, if you are not the author or if you do not have the author’s permission to publish that material;
- To publish obscene, defamatory, threatening or malicious materials towards another user, natural or legal person, materials or information prohibited by the legal provisions in force;
- To publish an image or a statement which is contrary to the legal norms in force or to public morals.
Applicable Law And Jurisdiction
- These Terms and Conditions and the use of the Platform are governed by the laws in force in Romania. In the event of any dispute relating to the contractual relationship, or arising from or in connection with its conclusion, interpretation, performance or termination, it shall be resolved either by claims addressed to the courts having material jurisdiction in Bucharest – Sector 1, or by arbitration before the Court of Arbitration attached to the Bucharest Chamber of Commerce and Industry, in accordance with its procedure and by a sole arbitrator. The award is final for the parties. Each party is recognised as having the possibility of choosing one of the two methods of dispute resolution.
- As regards alternative dispute resolution or applying to the ANPC, we inform you that these two methods of amicable resolution of disputes which arise are addressed exclusively to consumers.
This document was updated on 15.08.2026.
Language And Prevailing Version
These Terms and Conditions were drafted and adopted in Romanian. The Romanian version, updated on 15.08.2026, is the sole authoritative version and the only one which produces legal effects between the parties.
This English text is an unofficial translation provided for convenience only. It was produced by automated (machine) translation and has not been reviewed or certified by an authorised translator. It does not constitute a separate agreement, is not a sworn or legalised translation, and creates no rights or obligations of its own.
In the event of any divergence, ambiguity, omission or inconsistency between this English text and the Romanian version, the Romanian version shall prevail and shall be the version applied in the interpretation and performance of these Terms and Conditions and in any dispute arising from them.
The authoritative Romanian version is available on request at bikecheck-platform@proton.me and is provided to Users free of charge.
Terms & Conditions — Business Accounts
Last updated: 15 August 2026
Terms And Conditions
Brief Notes
- By accessing and using this Platform, you accept, without limitation or any other qualification, these terms and conditions and understand that any other agreements between you and the Platform Operator (hereinafter, BikeCheck) are entirely subject to these Terms and Conditions.
- These “Terms and Conditions” constitute the legal agreement between you and BikeCheck. Before using this Platform and before creating a business account [as a professional and business owner, together with associated accounts (team members) for mechanics, receptionists and fleet riders], we recommend that you read these Terms and Conditions in full. Accessing the Platform, as well as creating and customising a business account, constitutes your full and unconditional acceptance of these Terms and Conditions.
- These Terms and Conditions may be amended at any time by BikeCheck without prior notice. Any amendments and information regarding their validity will be posted on the Platform to inform BikeCheck users. We therefore recommend that you refer to this policy regularly to review its updated content. If, at any time, these Terms and Conditions become unacceptable to you, please cease accessing and using the Platform immediately.
Definition Of Terms
- BikeCheck/Platform Operator – refers to the legal entity CERC-D SRL, with its registered office at 7 Dinicu Golescu Boulevard, Ground Floor, Flat SP, Block 3, Sector 1, Bucharest, with company registration number 55196436 and J2026044124009, with email address: cerc-d@proton.me.
- Platform – refers to the website https://bikecheck.io/, whose features are presented transparently and in detail, and which provides Users, Business Owners and Riders with an intuitive interface for the provision of services relating to the servicing, maintenance, sale and reporting of the history of bicycles registered on the Platform.
- User Account – involves personalising a section within the Platform by entering an email address and a password, as well as a first name and surname; this section contains information about the user and the bicycles listed on the Platform. The data provided when creating the Account will remain confidential and is subject to the Privacy Policy;
- Contract – means the distance contract concluded between BikeCheck and users, without their simultaneous physical presence; such contracts are concluded upon confirmation, on a durable medium (by email), by BikeCheck of the account’s creation, following the User’s acceptance of the terms set out in this document and validation carried out in accordance with the conditions set out in Article 3.
- Document – this Terms and Conditions Policy, which governs the contractual relationship between BikeCheck and Users and which shall be interpreted in accordance with Romanian law. Any inconsistency or invalidity of any part or clause in this Document with other applicable legal provisions shall not affect the validity and legality of the other provisions of this Document.
- The services provided via this Platform, in accordance with the law and without breaching the restrictions set out in these Terms and Conditions, consist of servicing, maintenance, sales and the provision of history reports for bicycles registered on the Platform.
- Platform – refers to the website https://bikecheck.io/, as well as any section or subpage thereof. Websites and/or web pages, or other components thereof, belonging to third parties and accessed by users or visitors as a result of links or redirects available on the website https://bikecheck.io/ are not covered by, nor do they fall within the scope of, this definition.
- Processing of personal data – see the Privacy Policy.
- Transaction – means the operation by which payment for the subscription relating to the use of the Platform by Users is processed.
- User-Rider – any natural person with full legal capacity who creates an Account on the Platform, registers bicycles and requests services provided by Businesses via the Platform.
- Visitor – any person who accesses this Platform without creating an account.
Terms Of Use Of The Platform
- Access to and use of the BikeCheck Platform is subject to and must comply fully with the provisions of this Document.
- The platform provides Business account holders, depending on their chosen subscription plan, with the following key features:
- Showroom – a module for presenting the repair and maintenance services offered, together with a description of the work involved, the rates and the relevant terms and conditions;
- Fleet – a module for tracking bicycles in for servicing, which allows the registration of each unit, its assessed technical condition, the work carried out and the progress of the work;
- Metrics – the reporting and analysis module that provides indicators on the volume of work, types of repairs, turnaround times and other statistical data relevant to the account holder’s business;
- Billing – the module for managing payments, subscriptions and financial documents issued via the Platform. The amounts displayed may be amended, updated or revised unilaterally and at any time directly by Business Users, without prior notice and without the Platform’s intervention or consent, whilst the booking request is being processed; the final amount is solely that actually paid at the service counter.
- Bike gallery – the module for displaying the bicycles registered on the Platform, together with their technical specifications and related information;
- Kanban – the module dedicated to the management, processing and recording of requests made by Riders for the bicycles or services listed by Business Users, providing details relating to each request;
- Activity – the module for recording operations carried out within the account;
- Notifications – a system of alerts and communications regarding events relevant to the account holder’s account (e.g. new requests, work status, deadlines);
- Settings – the section for configuring the account, specific data and usage preferences.
- Legal – the section for accessing information relating to the relevant legislation.
- The platform facilitates the connection between Business Users and end users (hereinafter referred to as “Riders”) for the purpose of scheduling and managing bicycle repair and maintenance services. BikeCheck acts solely as a provider of the technical solution/technological intermediary and is not a party to the contractual service agreements established directly between Businesses and Riders.
- BikeCheck does not carry out, supervise or take responsibility for repair and maintenance work, the quality thereof, the suitability of the parts used or the technical condition of the bicycles handed over for servicing; these remain entirely the responsibility of the Businesses (Service Providers), in their capacity as service providers.
- Users of this Platform are fully responsible for the content of the information included on the Platform, such as: descriptions, photographs, location, facilities, their own rules, regulations, contractual terms, etc. (illustrative list). In all circumstances, the information made available to the Platform by Users must be accurate, complete and not misleading.
- The Business User is obliged to promptly update essential information regarding the services provided, as well as any other elements that could affect existing or future relationships.
- Business Users shall refrain from any activity carried out in bad faith, which may include manipulating reviews, altering the flow of booking requests, or moving transactions off the Platform, etc.
- Activities that are unlawful, dangerous or undermine the community’s trust are prohibited. We may suspend or remove listings and accounts in the event of breaches or risks to the safety of the Platform or other Users.
- In order to ensure the security of the Platform, prevent fraud and comply with applicable legal obligations, all users of the Platform – both Business Owners and Riders – are subject to a mandatory identity verification process, carried out by a specialist external provider, namely DIDIT (hereinafter referred to as the “Verification Provider”).
- The verification is carried out on the basis of the following principles:
- ‘Know Your Business’ (KYB) – for Business Owners, consisting of verifying the existence and identity of the business operator, registration details, the legal representative and, where applicable, supporting documents relating to the business activity carried out;
- ‘Know Your Customer’ (KYC) – for Riders, consisting of verifying the end user’s identity on the basis of the documents and information requested during the process.
- For the purposes of carrying out the verification, the user undertakes to provide the information and documents requested by the Verification Provider and guarantees that these are genuine, accurate, complete and valid.
- The account is activated and becomes operational only after DIDIT has fully completed and successfully validated the verification procedures. Until confirmation of validation is received, access to the Platform’s features is restricted or suspended, and the user cannot initiate or accept service requests.
- In the event that the Verification Provider does not validate the completion of the verification checks, or identifies discrepancies, false or incomplete information, BikeCheck may refuse to activate the account, or may suspend or close the account, without this giving rise to any obligation on the part of BikeCheck to pay compensation.
- Identity verification via DIDIT does not constitute a guarantee by BikeCheck regarding the creditworthiness, reliability, professional competence or future conduct of any user; liability for the contractual relationships established between Business Owners and Riders rests entirely with them.
- The processing of personal data as part of the verification process is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and the Platform’s Privacy Policy.
Intermediation Policy And Subscription For Platform Services
- Access to the Platform’s features and the intermediation services made available to Business Users is provided on a subscription basis, payable periodically (monthly or annually, depending on the selected plan), at the rates displayed on the Platform at the time of subscription. The subscription covers the right to use the Platform and the features associated with the account type, as described in this document.
- BikeCheck reserves the right to amend subscription fees, expressed in euros, excluding VAT, in response to circumstances that may affect the amounts displayed on the Platform, subject to prior notification to the Business User. Subscriptions and transactions that have already been confirmed remain subject to the rates in force on the date of confirmation, and any changes take effect from the next billing period.
- The information used to describe the available services and the features integrated into the Platform (text, images, multimedia presentations) is for information purposes only and does not constitute a contractual obligation on the part of BikeCheck.
- Payments for subscriptions and services paid for via the Platform are processed through the provider PADDLE (Paddle.com Market Limited), which acts as the Merchant of Record (registered merchant/reseller). In this capacity, Paddle is the legal seller of the subscription to the User, processes the payment, calculates, collects and remits the applicable taxes (VAT/indirect taxes) to the relevant tax authorities, and issues the tax documents corresponding to the transaction. The name ‘Paddle’ may appear on the User’s bank statement instead of ‘BikeCheck’.
- As Paddle acts as the Merchant of Record, the management of VAT and other indirect taxes relating to the subscription price is the responsibility of Paddle, in accordance with the applicable legislation in the User’s jurisdiction. The Business User, however, remains solely responsible for the tax treatment of their own income derived from the services provided to Riders (issuing tax documents, declaring and paying the relevant taxes and contributions).
- As online payments are used, BikeCheck is not, and under no circumstances can it be held, liable for any additional costs incurred by Users, including, but not limited to, currency conversion fees charged by banks or card issuers. Responsibility for bearing these costs lies solely with the Users.
- In the event of refunds, chargebacks, billing errors or amounts determined for documented damages, such amounts shall be settled via Paddle, in accordance with the information set out in the provider’s Terms and Conditions.
- The contract between BikeCheck and the Business User is deemed to have been concluded upon confirmation, in a durable medium (by email), by the Platform, of the acceptance of the account creation, the validation of the checks set out in this Document (KYB/KYC via DIDIT) and the activation of the selected subscription.
- Transactions are highly secure. Card data is processed exclusively via the infrastructure of the payment processor Paddle and its processing partners. BikeCheck does not store or have access to confidential card details, which are transmitted in encrypted form via a secure connection to the payment processing infrastructure. Payment processing via Paddle is subject, in relation to this service, to Paddle’s own terms and privacy policy.
User Dashboard. Unique Account Identifier. Further Details Regarding The User Account
- Each account, regardless of the user type (Business Owner or Rider), is automatically assigned, upon creation, a unique identifier (hereinafter referred to as the “account ID”), generated by the Platform and which cannot be modified by the user.
- The Account ID ensures the user’s unique identification within the Platform and is used for administrative, record-keeping, billing and resolution of any requests or complaints.
- Each account, regardless of the user type, is provided with a personalised control panel (Dashboard), through which the user can access the features relevant to their account type, view relevant information and manage operations carried out on the Platform.
- In addition to the account ID, a unique code and an identification label are automatically generated for each Business Owner account, intended to identify the business operator in dealings with Riders and within the Platform’s features.
- The Business code and label may not be assigned, transferred or used by another business operator and remain associated with the account for the entire duration of its existence.
- The Platform provides a dedicated section where users – both Business Owners and Riders – can post advertisements for the sale of bicycles, including descriptions, photographs and the relevant terms and conditions.
- The user posting an advert is fully responsible for its content, including the accuracy of the information, the legality of the sale and the rights to the item offered for sale.
- Sales and purchase arrangements are made directly between users of the Platform; BikeCheck is not a party to, commercial intermediary for, or guarantor of the transaction.
- The Platform offers Users the opportunity to obtain, free of charge, an informative report on registered bicycles, comprising the information available on the Platform regarding the registered request. The report generated is for information purposes only and is based on data existing on the Platform and/or provided by Users. BikeCheck does not guarantee that the information contained in the report is complete, accurate or up to date, and accepts no liability for decisions taken by Users on the basis of this report.
Warranties. Limitation Of Liability.
- BikeCheck shall not be liable for:
- losses arising from the actions or omissions of Users (Business Owners or Riders), including those arising from contractual relationships established directly between them;
- the quality, conformity, safety or outcome of repair and maintenance work carried out by Business Owners, as well as their compliance with technical or other regulations applicable to the service provider’s activity;
- the content published by Users on the Platform, including sales advertisements and the materials uploaded therein, subject to the terms of this Document;
- the accuracy, completeness or up-to-date nature of the information contained in the bicycle report, which is provided for information purposes only;
- data obtained from third-party services integrated into the Platform, which is subject to the terms and policies of those providers;
- indirect losses, including, but not limited to, lost profits, loss of data, loss of business opportunities or damage to reputation.
- BikeCheck shall not be liable for any circumstances detrimental to the User arising from the User’s failure to comply with this Document, the related Policies, the instructions provided via the Platform and/or the applicable legislation in force.
- BikeCheck cannot be held liable for any losses suffered by the User, whether directly or indirectly, arising from the non-use or incorrect use of the information and features made available on the Platform.
- The services provided by BikeCheck are obligations of means, not of result. BikeCheck acts solely as a provider of the technical solution and as a technological intermediary facilitating contact between Business Owners and Riders; it is not a party to the service provision or sale and purchase agreements established between them. Consequently, BikeCheck is not liable for the results arising from Users’ activities on the Platform; its liability is limited to ensuring optimal operating conditions and access to the Platform’s services, as described in this policy.
- The User verification process via DIDIT (KYB/KYC), as described above, does not constitute a guarantee by BikeCheck regarding the solvency, reliability, professional competence or subsequent conduct of any User; the risks associated with the relationships established between Business Owners and Riders rest exclusively with them.
- BikeCheck’s liability, to the extent that it may be incurred, is in any event limited to the value of the subscription paid by the User for the period during which the event giving rise to the loss occurred, within the limits permitted by applicable law. These limitations do not apply in the case of damage caused intentionally or through gross negligence, injury to life or physical integrity, or in other situations where the law prohibits the limitation of liability.
Intellectual Property
- BikeCheck holds full and complete title to the files, photos and materials published on the platform, as well as all intellectual property rights arising therefrom.
- All trademarks and logos are owned by BikeCheck, and no person or entity is entitled to copy or use them in any way.
- The use, reproduction, copying or modification without BikeCheck’s consent of any graphic, design or structural elements, etc., present on the Platform is strictly prohibited. Any infringement of these rights is subject to the law and will be dealt with by the relevant authorities.
- No content transmitted to Users via any means of communication (electronic, telephone, etc.) or acquired by them through accessing, visiting and/or viewing the Platform constitutes a contractual obligation on the part of BikeCheck.
- In certain cases, we do not hold intellectual property rights to the images and photographs used on this website, but only rights of use. In this regard, certain images and photographs found on our website are used in accordance with the terms and conditions of their source.
Privacy
- BikeCheck will keep confidential any information of any kind provided by Users. The information provided may only be shared under the conditions set out in the Privacy Policy.
- If there are any concerns regarding data security or possible misuse in relation to an Account created by a User, BikeCheck will immediately take the necessary measures (for example, it will ask the account holder to change their password) or even delete the account, having first notified the person concerned.
- The processing of personal data and the rules governing its protection can be found in the relevant policy on the Platform.
- BikeCheck respects and protects the right to the security of personal data of the Users of this website and is obliged to manage the personal data provided securely and solely for the specified purposes. The purpose of data collection is to provide Platform Users with information and services of the highest quality.
- In the context of Business accounts, each Business User acts jointly with BikeCheck as joint controllers within the meaning of Article 26 of the GDPR. The parties jointly determine the purposes and means of the data processing necessary for the operation of the Platform and the management of service requests, and responsibilities are allocated as follows: the Platform provides the digital infrastructure, the initial collection of data relating to service requests and accounts, communication via the interface, technical security measures and records of activities carried out on Users’ accounts; The Business User manages the direct relationship with the Rider (receipt and handover of the bicycle, carrying out repair and maintenance work, compliance with the workshop’s internal rules), as well as fulfilling its own legal obligations (tax and accounting, warranty for the work carried out, reports required by the authorities). Each party remains an independent controller for any additional processing it initiates (for example, the Business User’s own marketing or the publication of sales advertisements) and is responsible for ensuring the compliance of such processing.
- The data processed includes, where applicable: Riders’ identification and contact details (name, email, telephone number), details of the service request (type of bicycle, its identification details, nature of the requested service, service history), operational preferences, correspondence via the Platform, proof of payment, incident reports and support requests. The main purposes are: managing accounts and the Platform’s features, facilitating service requests and communication between Business Owners and Riders, settlement and invoicing, verifying Users (KYB/KYC) via the DIDIT provider, preventing fraud and ensuring User safety, resolving enquiries and any disputes, as well as complying with legal obligations.
- From a legal basis perspective, the processing is based on: the performance of the contract [Article 6(1)(b) of the GDPR] for the management of service requests and the provision of the Platform’s services; compliance with the Parties’ legal obligations [Article 6(1)(c) of the GDPR], for example tax and accounting obligations or responses to authorities; the legitimate interests of the Parties [Article 6(1)(f) of the GDPR] in the secure operation of the Platform, the prevention of fraud and the protection of Users’ rights, in accordance with the principle of data minimisation; consent [Article 6(1)(a) of the GDPR] only where necessary (for example, commercial communications). Business Users undertake not to request or store special categories of data (Article 9 of the GDPR) unless there is a clear legal obligation or legal basis, and to inform Riders transparently.
- To the extent strictly necessary, data may be disclosed to suppliers acting as data processors (e.g. cloud hosting, email services, the payment processor, anti-fraud tools, the identity verification provider), as well as to public authorities in accordance with the law. Business Users acknowledge that payment processing is carried out by Paddle, acting as Merchant of Record, and identity verification by DIDIT, with both providers operating in accordance with their own terms and policies. To the extent that data is stored or accessed outside the European Economic Area, the Parties shall ensure that adequate safeguards are in place in accordance with Chapter V of the GDPR (for example, Standard Contractual Clauses 2021/914 and additional measures, where applicable). Users— Business—undertake to use only providers that offer sufficient security and confidentiality safeguards and to maintain a record of such processors.
- Both BikeCheck and Business Users implement measures in accordance with Article 32 of the GDPR, including: access control and authorisation of relevant personnel; privacy policies and regular training; logical separation of data and proportionate access based on the ‘need-to-know’ principle; password management and access lifecycle management (prompt deactivation upon termination of the working relationship); encryption of data in transit and, where possible, at rest; secure electronic transfers (transmission of passwords via a separate channel); patch management, anti-malware/EDR protection, logging of authentications and privileged actions, with logs retained for a reasonable period; back-up and recovery procedures; periodic testing and reassessment of the effectiveness of the measures; incident response procedures, including notification of the other Party without undue delay (as a rule, within 24 hours of becoming aware of the incident) and cooperation regarding notifications to the supervisory authority and to data subjects, where applicable.
- Data subjects, including Riders, may exercise their rights under the GDPR (access, rectification, erasure, restriction, data portability, objection) either via the Platform or by contacting any of the associated controllers. The Parties agree that the Platform shall be the single operational point of contact for receiving requests; Business Users shall cooperate promptly, providing the information necessary to resolve the request within the required timeframe. Each Party remains responsible for demonstrating the compliance of its own processing activities and for retaining the documentation required by the GDPR (including, where applicable, records of processing activities).
- Data relating to service requests shall be retained for the period necessary to perform the services and for the periods required by law (for example, tax and accounting periods and those relating to the warranty for the works), after which it shall be deleted or anonymised. The Business User shall not retain local copies of Riders’ documents unless there is a clear legal or contractual requirement to do so, and shall apply to them the same security standards as those applicable on the Platform.
- By using the Platform, Business Users confirm their status as joint controllers, accepting the division of responsibilities described above, and undertake to maintain a level of protection at least equivalent to that applied by BikeCheck, including in their dealings with their own authorised representatives and collaborators. Any breach of these obligations may result in proportionate measures (including suspension of the account or listing) to protect the integrity of and trust in the Platform.
Security
- When using the Platform, you are responsible for ensuring the confidentiality of the details relating to your login account (username and password) and you agree to accept full responsibility for any activities or actions carried out within the application using your account and password. We recommend that you do not disclose the details you use to log in.
- Should the confidentiality of these login details be compromised, you are obliged to notify BikeCheck as soon as possible so that access to your account at can be restricted and a way for you to regain access to your account can be arranged as quickly as possible.
- Carrying out unauthorised actions such as: misuse, fraudulent use, unauthorised access, modification, copying of information for commercial purposes, blocking access, etc., on the Platform will be punished in accordance with the law.
Useful Information For Users
- As a User, you understand and agree to the following:
- To receive occasional communications from BikeCheck, in accordance with the GDPR Policy, regarding specific campaigns (with the option to withdraw your consent at any time);
- To provide true, accurate and complete data;
- To maintain and update, where necessary, your registration details so that they remain true, accurate and complete.
- It is prohibited to use the Platform in the following ways or for the following purposes:
- In breach of the Terms and Conditions set out in this document;
- In breach, in any way, of the applicable legal provisions or in ways that may lead to a breach, in any way, of the applicable legal provisions;
- In any way that involves acting on behalf of or for the account of another person, in particular by using false names, false email addresses, false telephone numbers, etc.
- To promote or conceal illegal or immoral activities;
- To reproduce, in any way, the website’s interface, with a view to misleading BikeCheck Users or potential Users;
- To gain unauthorised access to data that other Users have voluntarily provided to us;
- To introduce malicious programmes or lines of code into the system;
- To request illegal information, products or services, or to request information that covers up an illegal activity;
- To gain access to various sections or subsections of the website or to the products or services we offer using unlawful methods.
- As a User, you undertake not to engage in the following activities:
- Publishing copyrighted material unless you are the author or have the author’s permission to publish such material;
- Publishing material that is obscene, defamatory, threatening or malicious towards another user, a natural or legal person, or material or information prohibited by the legal provisions in force;
- Publish an image or statement that contravenes the applicable legal provisions or public decency.
Applicable Law And Jurisdiction
- These Terms and Conditions and the use of the Platform are governed by the laws in force in Romania. In the event of any dispute arising out of or in connection with the contractual relationship, or resulting from or in connection with its conclusion, interpretation, performance or termination, such dispute shall be resolved either by bringing proceedings before the courts having jurisdiction over the subject matter in Bucharest – Sector 1, or by arbitration before the Court of Arbitration attached to the Bucharest Chamber of Commerce and Industry, in accordance with its procedures and by a sole arbitrator. The award shall be final and binding on the parties. Each party is entitled to choose one of the two methods of dispute resolution.
- With regard to alternative dispute resolution or referral to the ANPC, please note that these two methods of amicable settlement of disputes are intended exclusively for consumers.
This document was updated on 15 August 2026.
Privacy & Cookie Policy
Last updated: 15 August 2026
Privacy Policy
General Information
Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, in this document – GDPR, the Regulation or RGPD) was adopted by the European Parliament and the Council of the European Union on 27 April 2016, its provisions being directly applicable from 25 May 2018. This Regulation expressly repeals Directive 95/46/EC, thereby also replacing the provisions of Law No 677/2001 (now repealed).
The Regulation is directly applicable in all Member States, protecting the rights of all natural persons within the territory of the European Union. In material terms, the Regulation applies to all controllers who process personal data. The Regulation does not apply to the processing of personal data concerning legal persons and, in particular, undertakings with legal personality, including the name and type of the legal person and the contact details of the legal person.
Personal data is defined as any information relating to an identified or identifiable natural person (the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
The processing of personal data means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
The Data Controller
Having regard to Article 4(7) of the Regulation, which defines the notion of “controller” as the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, this Privacy Policy is drawn up and applied by:
CERC-D SRL
- Registered office: Bucharest, Bd. Dinicu Golescu, No. 7, Ground Floor, Ap. SP., COM. 3, Sector 1
- Email: bikecheck-gdpr@proton.me
What Data We Collect
Personal data is collected only to the extent necessary for the provision of the services requested, under conditions of lawfulness, fairness and transparency. The data is collected through:
- The account creation forms;
- The contact form or booking requests (data provided voluntarily by users);
- Cookies and similar technologies;
- Server log files.
Data collected through the account creation forms
When creating an account on the Platform, the data collected varies according to the type of account chosen.
For Rider accounts, the data collected through the registration form may include: first name and surname, e-mail address, telephone number, password, country, county/region and locality, as well as the date of birth — used exclusively for age verification, without being stored as such.
For Business accounts, the data collected through the registration form may include: the business name, the commercial identification code (EUID), the business telephone number, the country, the county/region and the locality, as well as the identification and contact data of the account holder (first name and surname, e-mail address, password).
This data is processed for the purpose of creating and administering the account, of providing the Platform’s functionalities corresponding to the type of account and, where applicable, of initiating the contractual relationship. The legal basis is Article 6(1)(b) GDPR (performance of the contract and/or pre-contractual measures), as well as, where applicable, Article 6(1)(c) GDPR (compliance with legal obligations, including in the context of identity verification). The identity of account holders is verified through the external provider DIDIT (KYB/KYC), following which the account is activated.
Data collected through contact forms or booking requests
The data collected through the contact form may include: first name and surname, e-mail address, telephone number, message, relevant information provided voluntarily by users. This data is processed for the purpose of providing a response and, where applicable, of initiating a contractual relationship. The legal basis is Article 6(1)(b) GDPR (pre-contractual measures) and/or Article 6(1)(a) GDPR (consent).
Given that the Regulation prohibits, in principle, “the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation” (in accordance with Article 9(1)), the situations in which the processing of such data is permitted are then established:
a. the data subject has given explicit consent;
b. processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law;
c. processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent;
d. processing is carried out in the course of its legitimate activities and with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim, on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data is not disclosed outside that body without the consent of the data subjects;
e. processing relates to personal data which is manifestly made public by the data subject;
f. processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;
g. processing is necessary for reasons of substantial public interest, on the basis of Union or national law which is proportionate to the aim pursued, respects the essence of the right to data protection and provides for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;
h. processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or national law or pursuant to a contract with a health professional and subject to the conditions and safeguards provided for in the Regulation;
i. processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or national law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; or
j. processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, proportionate to the aim pursued, respecting the essence of the right to data protection and providing for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.
Legal Basis For Processing
The processing of personal data is carried out on the basis of the following legal grounds provided for by Regulation (EU) 2016/679 (GDPR):
- Article 6(1)(a) – The consent of the data subject (non-essential cookies);
- Article 6(1)(b) – The performance of a contract or pre-contractual measures at the request of the data subject (for information notices, account creation);
- Article 6(1)(c) – Compliance with a legal obligation (where the legislation requires the retention of data);
- Article 6(1)(f) – The legitimate interest of the controller (for the security of the site and the prevention of fraud).
Purpose Of Processing The Data Collected
Some of the data collected on this site is used for:
Providing the services which we offer through our website (for example, for resolving problems of any nature relating to our services, for ensuring support services, etc.)
The optimal functioning and optimisation of the site (statistical and analytical) - We constantly wish to offer you the best experience on our site, which is why we may collect and use certain information in connection with the degree of satisfaction you had while browsing this site; we may invite you to complete suggestion questionnaires or similar.
Advertising and promotional activities in the online environment. You may ask us at any time, by the means described in this document, to stop processing your personal data for marketing purposes, and we will act upon your request as soon as possible.
Periodic information notices to users - We want to keep you up to date regarding our activity, by providing free materials and current information about our projects and activities. In this regard, we may send you any type of message containing general and thematic information, information regarding offers or promotions, as well as other communications such as market research and opinion surveys. For communications of this type, our legal basis is consent obtained in advance. You may change your mind and withdraw your consent at any time.
For the defence of our legitimate interests. There may be situations in which we will use or transmit information in order to protect our rights and our activity. These may include: measures to protect the website and the user of our site against cyber attacks; measures to prevent and detect attempted fraud, including the transmission of information to the competent public authorities; measures to manage other types of risk.
The processing of personal data is carried out in accordance with the provisions of the General Data Protection Regulation, based both on the consent of the data subject and on grounds of the proper performance of contracts or the pursuit of the legitimate interests of the controller (except where the interests or fundamental rights and freedoms of the data subject which require the protection of personal data override those interests, in particular where the data subject is a child).
Processing of minors’ personal data
The services offered through this website are intended exclusively for persons who have reached the age of 16. In accordance with Article 8 GDPR, consent to the processing of personal data in the context of information society services is valid for persons who have reached the age of 16. For persons under the age of 16, processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility.
The operator of this website does not intentionally collect personal data of persons under the age of 16 and does not sell products to persons below that age without the consent of a parent or legal guardian. If you are a minor under the age of 16, please do not use this website and do not transmit personal data to us without the consent and supervision of a parent or legal guardian.
If you become aware that a minor under the age of 16 has transmitted personal data to us without the consent of a parent or legal guardian, please contact us at the e-mail address bikecheck-gdpr@proton.me, and we will proceed to delete this data as soon as possible.
Obtaining Consent
In order for the processing of personal data to be lawful, the GDPR provides that it must be carried out on the basis of a legitimate ground, such as the performance or conclusion of a contract, compliance with a legal obligation, or on the basis of consent validly expressed in advance by the data subject. In the latter case, the controller is under an obligation to be able to demonstrate that the person concerned gave their consent to that processing. Consent expressed under Directive 95/46/EC remains valid if it fulfils the conditions provided for by the GDPR.
The giving of consent must be carried out by a statement or by a clear affirmative action which constitutes a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of their personal data. Where the data subject’s consent is given in the context of a declaration, in electronic form or in writing, which also concerns other matters, the request for consent must be presented in a form which clearly distinguishes it from the other matters, and may be effected even by ticking a box.
Data Retention Period
Personal data is stored for as long as is necessary for the fulfilment of the purposes for which it was collected or for as long as is required by the applicable legislation. In the absence of specific legal requirements, the data is stored as follows:
- Contact data (forms): 6 years from the last interaction;
- Newsletter data: for the duration of the subscription, and in accordance with the provider’s policy after unsubscribing;
- Server log files: in accordance with internal security policies, as a rule a maximum of 12 months;
- Cookies: in accordance with the specific duration of each cookie (where applicable, as detailed in the following sections).
We review the data collected, analysing to what extent its retention is necessary for the purposes mentioned, for the legitimate interests of the natural persons concerned or for the fulfilment of the controller’s legal obligations. After the expiry of the periods mentioned above, the data will be deleted or anonymised, unless there is a legal obligation to archive it for a longer period or another legal basis for continuing the processing.
Disclosure Of Personal Data To Other Recipients
The Controller discloses personal data (only where required and strictly to the extent necessary) to public bodies and authorities, including, by way of example: ANAF (National Agency for Fiscal Administration), ISU (Inspectorate for Emergency Situations), the Police, Public Prosecutors’ Offices, Courts, the City Hall, the Local Council, the County Council, Ministries, ANPC (National Authority for Consumer Protection), ANSPDCP (National Supervisory Authority for the Processing of Personal Data) in the exercise of its supervisory and control functions, accountants, auditors, lawyers and other external consultants acting in the capacity of processors or independent controllers, as applicable.
We do not transfer data to third countries or international organisations, except in situations where the existing collaborative relationship requires it.
Thus, on the basis of the existing collaborative relationships and in order to be able to carry out the activities undertaken to the highest standards, we will disclose the data provided to:
- our partners and collaborators (invoicing services, marketing services, web hosting services, account validation services, online payment services, etc.),
- as well as to other online service providers (various tools and plugins), as those are mentioned in this Policy.
Server Log Files
This platform automatically collects and stores the information which your browser automatically transmits to us through log files. These are:
- The browser type and version
- The operating system used
- The URL of the page which initially generated the request to display the current page or object (Referrer URL)
- The host name of the accessing computer
- Time data regarding access to the server
- The IP address
The legal basis for the processing of such data is Article 6(1)(b) GDPR, which permits the processing of data where it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Contact Form
If you contact us through the contact form, we will collect the data entered in the form, including the contact details which you provide, in order to answer your questions and any subsequent ones. We do not transmit this information without your permission. Accordingly, we will process all the data which you enter in the contact form only with your consent [in accordance with the provisions of Article 6(1)(a) GDPR]. You may withdraw your agreement at any time, an informal e-mail to that effect being sufficient. The data processed before we receive your request may be lawfully processed.
We will retain the data which you provide on the contact form until:
- you request the deletion of the data;
- you withdraw your consent to its storage; or
- the purpose for its storage is no longer valid.
Any mandatory legal provisions, in particular those relating to mandatory data retention periods, are not affected by the above.
Contact By E-mail Or Telephone
If you contact us by e-mail or telephone, your request, including all the personal data which you provide, will be stored and processed by us for the purpose of resolving your request, on the basis of the consent expressed by you.
Accordingly, we will process all the data which you provide on the basis of the following legal provisions of the GDPR, namely:
- only with your consent – in accordance with the provisions of Article 6(1)(a) GDPR;
- for the performance of a contract or at the pre-contractual stage – in accordance with the provisions of Article 6(1)(b) GDPR;
- for the fulfilment of the purpose and legitimate interest pursued by us, namely the efficient processing of the requests sent by you – in accordance with the provisions of Article 6(1)(f) GDPR.
We will retain the data which you provide in this way until:
- you request the deletion of the data;
- you withdraw your consent to its storage; or
- the purpose for its storage is no longer valid, in all cases with the exception of the mandatory data retention periods.
Registration On The Platform
You may register as a User, in the capacity of Rider or of Business Owner, in order to access the functionalities and services of the Platform corresponding to the type of account chosen — including the registration and management of bicycles, the sending or receipt of service requests, the publication of listings in the Marketplace and the receipt of information notices regarding news and relevant communications. To this end, the data entered by you will be used and processed for the purposes mentioned. The mandatory data requested at registration must be provided in full, failing which the registration operation will be rejected. The activation of the account is additionally conditional upon the validation of the identity checks (KYB/KYC) carried out through the provider DIDIT.
In order to inform you regarding important matters, such as changes in the operation of the Platform or changes of a technical nature, we will use the e-mail address specified by you at the time of registration.
The processing of the personal data provided in the registration procedure is carried out on a contractual basis, in accordance with Article 6(1)(b) GDPR, being necessary for the creation and administration of the account and for the provision of the Platform’s services, as well as, where applicable, on the basis of your consent, in accordance with Article 6(1)(a) GDPR (for example, for communications of a promotional nature). You may withdraw your consent at any time, where this basis has been relied upon, an informal e-mail to that effect being sufficient; the withdrawal of consent does not affect processing based on other grounds, nor the lawfulness of the processing carried out prior to the withdrawal. We will continue to store the data collected during registration for as long as you remain registered as a User, the mandatory storage periods provided for by law remaining valid and being observed.
Rights Of Data Subjects
Your rights regarding personal data and the means of exercising them are: the Right to be informed, the Right of access, the Right to rectification, the Right to erasure of data, the Right to restriction of processing, the Right to data portability, the Right to object, the Right not to be subject to a decision based solely on automated processing of data, the Right to lodge a complaint and to apply to the courts, the Right to withdraw consent.
- The right to be informed - you may request information regarding the activities of processing your personal data, regarding the identity of the controller and of its representative, or regarding the recipients of your data;
- The right of access – you may obtain from the controller confirmation as to whether or not personal data concerning you is being processed and, if so, access to that data and to the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organisations; where possible, the period for which the personal data is expected to be stored or, if that is not possible, the criteria used to determine that period; the right to request from the controller the rectification or erasure of personal data or the restriction of processing of personal data, or the right to object to the processing, etc.
- The right to rectification - you may rectify inaccurate personal data or complete it;
- The right to erasure of data - you may obtain the erasure of the data, where its processing was not lawful or in other cases provided for by law;
- The right to restriction of processing - you may request the restriction of processing where you contest the accuracy of the data, as well as in other cases provided for by law;
- The right to data portability - you may receive, under certain conditions, the personal data which you have provided to us, in a machine-readable format, or you may request that that data be transmitted to another controller;
- The right to object - you may object, in particular, to processing operations based on the legitimate interest of the controller;
- The right not to be subject to a decision based solely on automated processing of data - you may request and obtain human intervention in respect of that processing, or you may express your own point of view regarding this type of processing;
- The right to lodge a complaint and to apply to the courts - you may lodge a complaint regarding the manner of processing personal data with the National Supervisory Authority for Personal Data Processing and/or you may apply to the courts for the observance of your rights;
- The right to withdraw consent – in cases where processing is based on your consent, you may withdraw it at any time. The withdrawal of consent will have effects only for the future, the processing carried out prior to the withdrawal remaining valid.
To exercise any of these rights, please contact us at: bikecheck-gdpr@proton.me. Your request need not follow a special form, but it must contain: your first name and surname, the contact details at which you wish to receive the reply, as clear a description as possible of the right which you wish to exercise and, if possible, a copy of an identity document (for the verification of identity and the prevention of unauthorised access to your data).
We will respond to your request within a maximum of 30 calendar days from the date of its receipt. In cases of particular complexity or in the situation of a high number of simultaneous requests, this period may be extended by a further 60 days, provided that we inform you of this extension and of its reasons within 30 days of receipt of the request, in accordance with Article 12(3) GDPR.
The response to your request is free of charge. If your requests are manifestly unfounded or excessive (in particular because of their repetitive character), we may either charge a reasonable fee taking into account the administrative costs, or refuse to act on the request, with justification of the refusal and with information to you regarding the right to lodge a complaint with the ANSPDCP.
If you are not satisfied with the response received or if you consider that your rights have been infringed, you have the right to lodge a complaint with: the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru No. 28-30, Sector 1, Bucharest. Telephone: +40.318.059.211. E-mail: anspdcp@dataprotection.ro. Website: www.dataprotection.ro
Likewise, you have the right to apply to the competent courts in Romania or in the EU Member State in which you have your habitual residence.
Cookie Policy
What are cookies?
Cookies are small text files, stored on your device (computer, telephone, tablet) when you visit a website. They allow the site to recognise you on your next visit, to remember the preferences selected and to offer a personalised experience.
Categories of cookies
This website may use the following categories of cookies:
- Strictly necessary cookies – indispensable for the basic functioning of the site. They do not require consent;
- Functional cookies – they retain the user’s preferences (e.g. selected language). They may require consent depending on their nature;
- Analytical cookies – they collect data about how the site is used, for statistical purposes. They require consent;
- Marketing/advertising cookies – used for the personalisation of advertisements and the profiling of interests. They require consent;
- Security cookies – used for the prevention of fraud and the protection of sessions. As a rule they do not require consent, but some may be linked to third-party services.
The BikeCheck Platform does not use cookies. We do not use functionality, analytics, tracking or advertising cookies and we do not place third-party cookies on your device.
For authentication and for maintaining the active session, the Platform uses local storage mechanisms in the browser (localStorage/sessionStorage), strictly necessary for the functioning of the service. This information remains stored exclusively on your device, is not used for tracking your activity or for marketing purposes and is essential for the provision of the service requested, which is why it does not require consent.
Managing Consent For Cookies
On your first visit to our site which uses cookies requiring consent, you will be informed by means of a dedicated banner. You may choose to:
- Accept all cookies;
- Refuse non-essential cookies;
- Personalise the options regarding the categories of cookies accepted.
Strictly necessary cookies are enabled by default, as they are indispensable to the functioning of the site. The withdrawal of consent for optional cookies does not affect the lawfulness of the prior processing.
Likewise, you may manage or delete cookies directly from your browser. Detailed instructions are available on the sites of the manufacturers of the main browsers: Chrome, Firefox, Safari, Edge.
Obligations Of The Data Controller
Hosting
This Platform operates through several infrastructure providers, who act in the capacity of processors of the controller, each for the component which it provides:
- a) Vercel Inc. – hosting the interface (frontend) component of the Platform;
- b) Railway Corp. – hosting the application (backend) component of the Platform;
- c) Supabase Inc. – hosting and administering the database in which personal data is stored;
- d) Resend (Plus Five Five Inc.) – transmitting the e-mail communications relating to the operation of the Platform (for example, notifications, confirmations, transactional messages);
- e) Functional Software, Inc. (Sentry) – error monitoring and performance diagnostics, by recording the technical details of malfunctions, for their identification and remediation. For performance diagnostics, a sample of requests made to our servers is also recorded irrespective of whether the request resulted in a malfunction, comprising the timings of the application’s own operations, including database queries. This sampling concerns the operation of our servers; it does not record your activity within the Platform’s interface, and it is subject to the same removal of directly identifying data described below. Error-monitoring data is stored in the provider’s European region (Germany). The reports transmitted to this provider are stripped of directly identifying data: no names, e-mail addresses, authentication tokens or IP addresses are transmitted — only the internal account identifier, the technical description of the error and the request context necessary to reproduce it. These reports are transmitted to this provider through an endpoint on the Platform’s own domain, which forwards them unchanged; this routing concerns only the network path and neither adds to nor alters the categories of data described above.
The processing of the data provided and stored through these providers complies with the following legal provisions:
- Article 6(1)(b) GDPR – the processing is necessary for the performance of the contract between the user and BikeCheck, or between the Supplier and BikeCheck, specifically for the provision of the Platform’s functionalities;
- Article 6(1)(f) GDPR – the processing is carried out for the purposes of the legitimate interests pursued by us, namely the safe, stable and continuous operation of the Platform;
- Article 6(1)(a) GDPR – where applicable, the processing is based on your consent, obtained following correct and complete information.
The hosting providers mentioned are companies with their registered office outside the European Economic Area (USA). To the extent that the storage or accessing of data involves a transfer outside the EEA, BikeCheck ensures that this is carried out on the basis of adequate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional protective measures, as well as on the basis of the data processing agreements (DPAs) concluded with each provider.
Regardless of the purpose for which the processing of personal data takes place, the principles of lawfulness, fairness and transparency are observed, as well as the principle according to which the data processed is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
For more information regarding the processing of data by the hosting providers, you may consult their policies, available on their official pages.
Data Encryption
This site uses SSL encryption for reasons of security and for the protection of the transmission of confidential information. This encryption can be recognised by you by the lock icon which appears in the browser bar and by the change from http:// to https:// in the address of that browser.
Once encryption of this type is activated, the data transmitted or transferred cannot be seen by third parties.
In accordance with the GDPR, where the personal data breach is likely to result in a high risk to your rights and freedoms, the operator of this website will inform you, without undue delay, of that breach, unless the supplementary provisions of the same Regulation become applicable (Article 34(3)).
Data Protection Officer
The provisions of the GDPR not being applicable (Article 37(1) - according to which the controller and the processor shall designate a data protection officer whenever:
- a. the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- b. the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- c. the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10) regarding the obligation to appoint a Data Protection Officer, for any information or clarifications regarding the operation of this website, please contact us at the following details:
- E-mail address: cerc-d@proton.me
- Correspondence address: Bucharest, Bd. Dinicu Golescu, No. 7, Ground Floor, Ap. SP., COM. 3, Sector 1
Records Of Processing Activities
In accordance with the GDPR, the controller or the processor should maintain, for a reasonable period, records of the processing activities under its responsibility. Thus, these records will comprise the following information:
- the name and contact details of the controller;
- the purposes of the processing;
- a description of the categories of data subjects and of the categories of personal data;
- the categories of recipients to whom the personal data has been or will be disclosed;
- where applicable/possible: transfers of personal data; the envisaged time limits for erasure of the different categories of data; a general description of the technical and organisational security measures.
The obligation detailed above does not apply to an enterprise or organisation with fewer than 250 employees, unless the processing which it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data or personal data relating to criminal convictions and offences.
Appropriate Technical And Organisational Measures
Taking into account the state of the art, the context and the purposes of the processing, as well as the risks to the rights and freedoms of natural persons, the controller implements appropriate technical and organisational measures to ensure that, by default, only personal data which is necessary for each specific purpose of the processing is processed.
Notification Of The Supervisory Authority In The Event Of A Personal Data Breach
In accordance with Article 33(1) GDPR, in the event of a personal data breach, we will notify the National Supervisory Authority for Personal Data Processing of it without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless it is unlikely to result in a risk to the rights and freedoms of natural persons.
Communication Of A Personal Data Breach To The Data Subject
With reference to the provisions of Article 34 GDPR, where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, we will inform the data subject of that breach without undue delay, except in situations where:
- appropriate technical and organisational protection measures have been implemented, and those measures were applied to the personal data affected by the personal data breach, in particular measures which render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
- subsequent measures have been taken which ensure that the high risk to the rights and freedoms of data subjects referred to above is no longer likely to materialise;
- it would involve disproportionate effort. In that situation, a public communication is made or a similar measure is taken whereby data subjects are informed in an equally effective manner.
Tools & Plug-ins
Facebook Plug-ins (API)
This website uses social plugins (“plugins”) managed by the social network facebook.com. The plugins can be identified by a Facebook logo (a white “f” on a blue tile or a “thumbs up” sign) or are labelled by the addition of the phrase “Facebook Social Plugin”. The list and appearance of the Facebook plugins can be seen here: https://developers.facebook.com/docs/plugins/. To the extent that you use the Like extension, you will like our site’s Facebook page without needing to leave it. To the extent that you use the Share extension, you will share our site or certain content from it on your personal Facebook page, without needing to leave the site.
Through the plugin, Facebook receives the information which you access on our site. If you are also logged in to Facebook at the same time, Facebook may attribute the actions carried out on the page to your account and, by extension, to you personally. When you interact with the plugins, for example by clicking the Like button or sharing certain content from the site, the corresponding information is transferred directly from your browser to Facebook and stored there. Even if you are not a Facebook member, there is nevertheless the possibility that the social network may obtain and store your IP address.
By clicking on one of these buttons, you agree to the use of this plugin and, accordingly, to the transfer of personal data to Facebook. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing.
Having regard to the Judgment of 16 July 2020 (delivered in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union held that the protection afforded by the EU–US Privacy Shield is not adequate.
Accordingly, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from controllers in the EU to processors established outside the EU or the EEA. For more information regarding these Clauses, we recommend that you visit https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.
Facebook uses Standard Contractual Clauses as an adequate safeguard regarding data protection, in accordance with the level of protection guaranteed by the GDPR.
With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so that the transfer of data may be based, where applicable, on this adequacy decision, in addition or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification may be consulted at: https://www.dataprivacyframework.gov/s/participant-search
For further details, you may visit: https://www.facebook.com/legal/EU_data_transfer_addendum, as regards the purpose and scope of the collection of data, the processing and subsequent use of the data by Facebook, as well as the permissions and settings for protecting privacy.
This website uses social plugins (“plugins”) managed by the social network Instagram, functions offered by Instagram Inc., with its registered office at 1601 Willow Road, Menlo Park, CA 94025, USA. The plugins can be identified by an Instagram logo or are labelled by the addition of the phrase “Instagram Social Plugin”.
Through the plugin, Instagram is informed of the actions carried out by you on our page. If you are also logged in to your personal account on the social network at the same time, it may attribute the actions carried out on the page to your Instagram account and, by extension, to you personally. When you access the plugins, the corresponding information is transferred from your browser to the social network and stored there. Even if you are not an Instagram member, there is nevertheless the possibility that it may obtain and store your IP address.
By clicking on one of these buttons, you agree to the use of this plugin and, accordingly, to the transfer of personal data to Instagram. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing. As regards the purpose and scope of the collection of data, the processing and subsequent use of the data by Instagram, as well as the permissions and settings for protecting users’ privacy, you may consult the Instagram privacy policies at: https://help.instagram.com/519522125107875.
Having regard to the Judgment of 16 July 2020 (delivered in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union held that the protection afforded by the EU–US Privacy Shield is not adequate.
Accordingly, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from controllers in the EU to processors established outside the EU or the EEA. For more information regarding these Clauses, we recommend that you visit https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.
Instagram uses Standard Contractual Clauses as an adequate safeguard regarding data protection, in accordance with the level of protection guaranteed by the GDPR.
With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so that the transfer of data may be based, where applicable, on this adequacy decision, in addition or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification may be consulted at: https://www.dataprivacyframework.gov/s/participant-search.
For further details, you may visit: https://www.facebook.com/legal/EU_data_transfer_addendum.
Web Fonts – Open Sans
This site uses the Open Sans font in order to ensure a uniform presentation of the text on all pages of the Platform.
Open Sans is a freely licensed font (Open Font License), which is hosted locally, on the Platform’s own infrastructure. Thus, when accessing a page on this website, your browser loads the font files directly from the Platform’s servers, without a connection being established with third-party servers and without your data (including your IP address) being transmitted to external providers for the purpose of displaying the font.
The use of the Open Sans font is based on Article 6(1)(f) GDPR, there being a legitimate interest in the uniform and legible presentation of the text on this website. Since the font is local, this functionality does not involve a transfer of data to third parties and does not require an additional basis for processing.
Identity Verification Through DIDIT (kyb/kyc)
The Platform uses the services provided by DIDIT, a specialised identity verification solution, in order to fulfil the obligations of knowing the clientele and business partners (KYC – Know Your Customer and KYB – Know Your Business), as well as for the prevention of fraud and ensuring the security of the Platform. The activation of any account is conditional upon the completion and successful validation of the verifications carried out through DIDIT.
For users and businesses established in the European Union, the United Kingdom, the European Economic Area and Switzerland, the contracting entity and the one which operates the European data processing infrastructure is Didit Identity Spain, S.L., with its registered office at Calle Nápoles 227, P. 1, 08013 Barcelona, Spain (CIF B22929327).
Within the verification process, depending on the type of account and the configuration of the applicable flow, the following may be processed: identification and contact data (first name, surname, e-mail address, telephone number, postal address, date of birth), images of identity documents, data extracted from them, and, in certain flows, biometric data resulting from the verification of real presence (liveness) and, respectively, from facial comparison, as well as, in the case of Business accounts, the identification data of the economic operator and its verification in public registers.
In its relationship with the Platform, DIDIT acts in the capacity of processor, processing the data exclusively on the basis of the controller’s instructions and for the purpose of carrying out the verification requested. The decision regarding the approval, rejection or repetition of the verification, as well as the activation of the account, belongs to the Platform, DIDIT providing the verification technology and the associated analysis. The processing is based on Article 6(1)(b) GDPR (pre-contractual measures and performance of the contract), on Article 6(1)(c) GDPR (compliance with legal obligations, including the prevention of fraud), and, as regards biometric data, to the extent that it is processed, on the applicable basis under Article 9 GDPR, with information being provided to and, where applicable, the explicit consent obtained from the data subject.
DIDIT allows the controller to configure the data storage region, such that, for users in the European Union, the verification data may be processed and stored within the European Economic Area. To the extent that, depending on the configuration of the service, a transfer of data were to occur to an entity of the DIDIT group or to sub-processors established outside the European Economic Area (including Didit Identity, Inc., with its registered office in Dover, Delaware, United States), this is carried out on the basis of adequate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional protective measures. For more information regarding the Standard Contractual Clauses, you may visit https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.
The processing of data by DIDIT is carried out in accordance with its own privacy policies, available at https://didit.me/terms/privacy-policy/, as well as with the specific notices applicable to identity verification. For more details regarding the nature, purpose and scope of the processing, as well as the security measures applied, you may consult the documentation made available by DIDIT.
Online Payments – PADDLE
The payments relating to subscriptions and services paid for through the Platform are processed through the provider Paddle, which acts in the capacity of Merchant of Record (registered merchant/reseller). From a legal point of view, this means that Paddle is the seller of record of the digital products and services to the user, processes the payment and assumes responsibility for compliance with the applicable legislation and for the management of the related taxes (VAT/indirect taxes), in place of BikeCheck. The name Paddle may appear on the user’s bank statement instead of the name BikeCheck.
Unlike a simple payment processor, in this configuration Paddle acts, as regards the data processed in connection with the transaction and with the resale relationship, in the capacity of independent controller, the processing being carried out in accordance with its own privacy policy. The Paddle entities relevant for users and businesses in the European Union, the United Kingdom and the European Economic Area are Paddle.com Market Limited, with its registered office at 30 Old Bailey, London, United Kingdom, EC4M 7AU, and Paddle Payments Limited, with its registered office at The Academy, 42 Pearse Street, Dublin 2, D02 HV59, Ireland.
In accordance with the Regulation, “in order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption” – Recital 83. The availability of strong and effective encryption thus represents a necessity for guaranteeing the protection, confidentiality and integrity of personal data.
The banking data provided for the purpose of making payments is transmitted through secure connections, using appropriate methods of encryption, to the payment processing infrastructure. BikeCheck does not collect, does not store and has no access to the user’s complete card data, this being managed exclusively by Paddle and its processing partners.
According to the information available at https://www.paddle.com/legal/privacy, Paddle’s information system makes available appropriate methods for the protection of users’ personal data, as well as of the operations and transactions carried out through it. The purposes of the processing, the data processed, the conditions of its transfer and distribution, the ensuring of the security of the operations and of the data processed and stored, as well as the other information made available by Paddle, are based on the mechanisms for ensuring the lawfulness of processing provided for by the GDPR, namely: the consent of the data subject [Article 6(1)(a)], the performance of a contract [Article 6(1)(b)] and the legitimate interest of the controller [Article 6(1)(f)].
To the extent that Paddle processes data outside the European Economic Area, the transfer is carried out on the basis of adequate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 or, where applicable, on the basis of an applicable adequacy decision.
Conclusion
This policy regarding the processing of personal data is drawn up in accordance with the provisions of Regulation No 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as with the other applicable national legal provisions.
We reserve the right to make any additions or amendments to this policy. We recommend consulting the Policy regularly for correct and up-to-date information as regards the processing of personal data.
For more details regarding this GDPR Policy, as well as for the exercise of any of the rights mentioned above, a written notification may be sent to the contact details indicated.
Contact And Complaints
For any questions, requests or complaints relating to the processing of personal data, you may contact us:
CERC-D SRL
- Registered office: Bucharest, Bd. Dinicu Golescu, No. 7, Ground Floor, Ap. SP., COM. 3, Sector 1
- E-mail: cerc-d@proton.me
This document was updated on 15.08.2026.
Language And Prevailing Version
This Policy was drawn up and adopted in Romanian. The Romanian version, updated on 15.08.2026, is the sole authoritative version.
This English text is an unofficial translation provided for convenience only. It was produced by automated (machine) translation and has not been reviewed or certified by an authorised translator. It is not a sworn or legalised translation and creates no rights or obligations of its own.
In the event of any divergence, ambiguity, omission or inconsistency between this English text and the Romanian version, the Romanian version shall prevail and shall be the version applied in the interpretation of this Policy.
The authoritative Romanian version is available on request at bikecheck-platform@proton.me and is provided to data subjects free of charge.