Legal

The full, authoritative text of BikeCheck's legal documents — the same text shown in the app. This page is provided so the documents can be read and linked to directly.

Terms & Conditions — Riders

Last updated: 15 August 2026

Terms And Conditions

Brief Notes

Definition Of Terms

Terms Of Use Of The Platform

Intermediation Policy

The User’s Dashboard. The Unique Account Identifier. Other Details Regarding The User Account

Warranties. Limitation Of Liability.

Intellectual Property

Privacy

Security

Useful Information For Users

Applicable Law And Jurisdiction

This document was updated on 15.08.2026.

Language And Prevailing Version

These Terms and Conditions were drafted and adopted in Romanian. The Romanian version, updated on 15.08.2026, is the sole authoritative version and the only one which produces legal effects between the parties.

This English text is an unofficial translation provided for convenience only. It was produced by automated (machine) translation and has not been reviewed or certified by an authorised translator. It does not constitute a separate agreement, is not a sworn or legalised translation, and creates no rights or obligations of its own.

In the event of any divergence, ambiguity, omission or inconsistency between this English text and the Romanian version, the Romanian version shall prevail and shall be the version applied in the interpretation and performance of these Terms and Conditions and in any dispute arising from them.

The authoritative Romanian version is available on request at bikecheck-platform@proton.me and is provided to Users free of charge.


Terms & Conditions — Business Accounts

Last updated: 15 August 2026

Terms And Conditions

Brief Notes

Definition Of Terms

Terms Of Use Of The Platform

Intermediation Policy And Subscription For Platform Services

User Dashboard. Unique Account Identifier. Further Details Regarding The User Account

Warranties. Limitation Of Liability.

Intellectual Property

Privacy

Security

Useful Information For Users

Applicable Law And Jurisdiction

This document was updated on 15 August 2026.


Privacy & Cookie Policy

Last updated: 15 August 2026

Privacy Policy

General Information

Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, in this document – GDPR, the Regulation or RGPD) was adopted by the European Parliament and the Council of the European Union on 27 April 2016, its provisions being directly applicable from 25 May 2018. This Regulation expressly repeals Directive 95/46/EC, thereby also replacing the provisions of Law No 677/2001 (now repealed).

The Regulation is directly applicable in all Member States, protecting the rights of all natural persons within the territory of the European Union. In material terms, the Regulation applies to all controllers who process personal data. The Regulation does not apply to the processing of personal data concerning legal persons and, in particular, undertakings with legal personality, including the name and type of the legal person and the contact details of the legal person.

Personal data is defined as any information relating to an identified or identifiable natural person (the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.

The processing of personal data means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

The Data Controller

Having regard to Article 4(7) of the Regulation, which defines the notion of “controller” as the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, this Privacy Policy is drawn up and applied by:

CERC-D SRL

What Data We Collect

Personal data is collected only to the extent necessary for the provision of the services requested, under conditions of lawfulness, fairness and transparency. The data is collected through:

Data collected through the account creation forms

When creating an account on the Platform, the data collected varies according to the type of account chosen.

For Rider accounts, the data collected through the registration form may include: first name and surname, e-mail address, telephone number, password, country, county/region and locality, as well as the date of birth — used exclusively for age verification, without being stored as such.

For Business accounts, the data collected through the registration form may include: the business name, the commercial identification code (EUID), the business telephone number, the country, the county/region and the locality, as well as the identification and contact data of the account holder (first name and surname, e-mail address, password).

This data is processed for the purpose of creating and administering the account, of providing the Platform’s functionalities corresponding to the type of account and, where applicable, of initiating the contractual relationship. The legal basis is Article 6(1)(b) GDPR (performance of the contract and/or pre-contractual measures), as well as, where applicable, Article 6(1)(c) GDPR (compliance with legal obligations, including in the context of identity verification). The identity of account holders is verified through the external provider DIDIT (KYB/KYC), following which the account is activated.

Data collected through contact forms or booking requests

The data collected through the contact form may include: first name and surname, e-mail address, telephone number, message, relevant information provided voluntarily by users. This data is processed for the purpose of providing a response and, where applicable, of initiating a contractual relationship. The legal basis is Article 6(1)(b) GDPR (pre-contractual measures) and/or Article 6(1)(a) GDPR (consent).

Given that the Regulation prohibits, in principle, “the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation” (in accordance with Article 9(1)), the situations in which the processing of such data is permitted are then established:

a. the data subject has given explicit consent;

b. processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law;

c. processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent;

d. processing is carried out in the course of its legitimate activities and with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim, on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data is not disclosed outside that body without the consent of the data subjects;

e. processing relates to personal data which is manifestly made public by the data subject;

f. processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;

g. processing is necessary for reasons of substantial public interest, on the basis of Union or national law which is proportionate to the aim pursued, respects the essence of the right to data protection and provides for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;

h. processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or national law or pursuant to a contract with a health professional and subject to the conditions and safeguards provided for in the Regulation;

i. processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or national law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; or

j. processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, proportionate to the aim pursued, respecting the essence of the right to data protection and providing for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

The processing of personal data is carried out on the basis of the following legal grounds provided for by Regulation (EU) 2016/679 (GDPR):

Purpose Of Processing The Data Collected

Some of the data collected on this site is used for:

Providing the services which we offer through our website (for example, for resolving problems of any nature relating to our services, for ensuring support services, etc.)

The optimal functioning and optimisation of the site (statistical and analytical) - We constantly wish to offer you the best experience on our site, which is why we may collect and use certain information in connection with the degree of satisfaction you had while browsing this site; we may invite you to complete suggestion questionnaires or similar.

Advertising and promotional activities in the online environment. You may ask us at any time, by the means described in this document, to stop processing your personal data for marketing purposes, and we will act upon your request as soon as possible.

Periodic information notices to users - We want to keep you up to date regarding our activity, by providing free materials and current information about our projects and activities. In this regard, we may send you any type of message containing general and thematic information, information regarding offers or promotions, as well as other communications such as market research and opinion surveys. For communications of this type, our legal basis is consent obtained in advance. You may change your mind and withdraw your consent at any time.

For the defence of our legitimate interests. There may be situations in which we will use or transmit information in order to protect our rights and our activity. These may include: measures to protect the website and the user of our site against cyber attacks; measures to prevent and detect attempted fraud, including the transmission of information to the competent public authorities; measures to manage other types of risk.

The processing of personal data is carried out in accordance with the provisions of the General Data Protection Regulation, based both on the consent of the data subject and on grounds of the proper performance of contracts or the pursuit of the legitimate interests of the controller (except where the interests or fundamental rights and freedoms of the data subject which require the protection of personal data override those interests, in particular where the data subject is a child).

Processing of minors’ personal data

The services offered through this website are intended exclusively for persons who have reached the age of 16. In accordance with Article 8 GDPR, consent to the processing of personal data in the context of information society services is valid for persons who have reached the age of 16. For persons under the age of 16, processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility.

The operator of this website does not intentionally collect personal data of persons under the age of 16 and does not sell products to persons below that age without the consent of a parent or legal guardian. If you are a minor under the age of 16, please do not use this website and do not transmit personal data to us without the consent and supervision of a parent or legal guardian.

If you become aware that a minor under the age of 16 has transmitted personal data to us without the consent of a parent or legal guardian, please contact us at the e-mail address bikecheck-gdpr@proton.me, and we will proceed to delete this data as soon as possible.

In order for the processing of personal data to be lawful, the GDPR provides that it must be carried out on the basis of a legitimate ground, such as the performance or conclusion of a contract, compliance with a legal obligation, or on the basis of consent validly expressed in advance by the data subject. In the latter case, the controller is under an obligation to be able to demonstrate that the person concerned gave their consent to that processing. Consent expressed under Directive 95/46/EC remains valid if it fulfils the conditions provided for by the GDPR.

The giving of consent must be carried out by a statement or by a clear affirmative action which constitutes a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of their personal data. Where the data subject’s consent is given in the context of a declaration, in electronic form or in writing, which also concerns other matters, the request for consent must be presented in a form which clearly distinguishes it from the other matters, and may be effected even by ticking a box.

Data Retention Period

Personal data is stored for as long as is necessary for the fulfilment of the purposes for which it was collected or for as long as is required by the applicable legislation. In the absence of specific legal requirements, the data is stored as follows:

We review the data collected, analysing to what extent its retention is necessary for the purposes mentioned, for the legitimate interests of the natural persons concerned or for the fulfilment of the controller’s legal obligations. After the expiry of the periods mentioned above, the data will be deleted or anonymised, unless there is a legal obligation to archive it for a longer period or another legal basis for continuing the processing.

Disclosure Of Personal Data To Other Recipients

The Controller discloses personal data (only where required and strictly to the extent necessary) to public bodies and authorities, including, by way of example: ANAF (National Agency for Fiscal Administration), ISU (Inspectorate for Emergency Situations), the Police, Public Prosecutors’ Offices, Courts, the City Hall, the Local Council, the County Council, Ministries, ANPC (National Authority for Consumer Protection), ANSPDCP (National Supervisory Authority for the Processing of Personal Data) in the exercise of its supervisory and control functions, accountants, auditors, lawyers and other external consultants acting in the capacity of processors or independent controllers, as applicable.

We do not transfer data to third countries or international organisations, except in situations where the existing collaborative relationship requires it.

Thus, on the basis of the existing collaborative relationships and in order to be able to carry out the activities undertaken to the highest standards, we will disclose the data provided to:

Server Log Files

This platform automatically collects and stores the information which your browser automatically transmits to us through log files. These are:

The legal basis for the processing of such data is Article 6(1)(b) GDPR, which permits the processing of data where it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

Contact Form

If you contact us through the contact form, we will collect the data entered in the form, including the contact details which you provide, in order to answer your questions and any subsequent ones. We do not transmit this information without your permission. Accordingly, we will process all the data which you enter in the contact form only with your consent [in accordance with the provisions of Article 6(1)(a) GDPR]. You may withdraw your agreement at any time, an informal e-mail to that effect being sufficient. The data processed before we receive your request may be lawfully processed.

We will retain the data which you provide on the contact form until:

Any mandatory legal provisions, in particular those relating to mandatory data retention periods, are not affected by the above.

Contact By E-mail Or Telephone

If you contact us by e-mail or telephone, your request, including all the personal data which you provide, will be stored and processed by us for the purpose of resolving your request, on the basis of the consent expressed by you.

Accordingly, we will process all the data which you provide on the basis of the following legal provisions of the GDPR, namely:

We will retain the data which you provide in this way until:

Registration On The Platform

You may register as a User, in the capacity of Rider or of Business Owner, in order to access the functionalities and services of the Platform corresponding to the type of account chosen — including the registration and management of bicycles, the sending or receipt of service requests, the publication of listings in the Marketplace and the receipt of information notices regarding news and relevant communications. To this end, the data entered by you will be used and processed for the purposes mentioned. The mandatory data requested at registration must be provided in full, failing which the registration operation will be rejected. The activation of the account is additionally conditional upon the validation of the identity checks (KYB/KYC) carried out through the provider DIDIT.

In order to inform you regarding important matters, such as changes in the operation of the Platform or changes of a technical nature, we will use the e-mail address specified by you at the time of registration.

The processing of the personal data provided in the registration procedure is carried out on a contractual basis, in accordance with Article 6(1)(b) GDPR, being necessary for the creation and administration of the account and for the provision of the Platform’s services, as well as, where applicable, on the basis of your consent, in accordance with Article 6(1)(a) GDPR (for example, for communications of a promotional nature). You may withdraw your consent at any time, where this basis has been relied upon, an informal e-mail to that effect being sufficient; the withdrawal of consent does not affect processing based on other grounds, nor the lawfulness of the processing carried out prior to the withdrawal. We will continue to store the data collected during registration for as long as you remain registered as a User, the mandatory storage periods provided for by law remaining valid and being observed.

Rights Of Data Subjects

Your rights regarding personal data and the means of exercising them are: the Right to be informed, the Right of access, the Right to rectification, the Right to erasure of data, the Right to restriction of processing, the Right to data portability, the Right to object, the Right not to be subject to a decision based solely on automated processing of data, the Right to lodge a complaint and to apply to the courts, the Right to withdraw consent.

To exercise any of these rights, please contact us at: bikecheck-gdpr@proton.me. Your request need not follow a special form, but it must contain: your first name and surname, the contact details at which you wish to receive the reply, as clear a description as possible of the right which you wish to exercise and, if possible, a copy of an identity document (for the verification of identity and the prevention of unauthorised access to your data).

We will respond to your request within a maximum of 30 calendar days from the date of its receipt. In cases of particular complexity or in the situation of a high number of simultaneous requests, this period may be extended by a further 60 days, provided that we inform you of this extension and of its reasons within 30 days of receipt of the request, in accordance with Article 12(3) GDPR.

The response to your request is free of charge. If your requests are manifestly unfounded or excessive (in particular because of their repetitive character), we may either charge a reasonable fee taking into account the administrative costs, or refuse to act on the request, with justification of the refusal and with information to you regarding the right to lodge a complaint with the ANSPDCP.

If you are not satisfied with the response received or if you consider that your rights have been infringed, you have the right to lodge a complaint with: the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru No. 28-30, Sector 1, Bucharest. Telephone: +40.318.059.211. E-mail: anspdcp@dataprotection.ro. Website: www.dataprotection.ro

Likewise, you have the right to apply to the competent courts in Romania or in the EU Member State in which you have your habitual residence.

What are cookies?

Cookies are small text files, stored on your device (computer, telephone, tablet) when you visit a website. They allow the site to recognise you on your next visit, to remember the preferences selected and to offer a personalised experience.

Categories of cookies

This website may use the following categories of cookies:

The BikeCheck Platform does not use cookies. We do not use functionality, analytics, tracking or advertising cookies and we do not place third-party cookies on your device.

For authentication and for maintaining the active session, the Platform uses local storage mechanisms in the browser (localStorage/sessionStorage), strictly necessary for the functioning of the service. This information remains stored exclusively on your device, is not used for tracking your activity or for marketing purposes and is essential for the provision of the service requested, which is why it does not require consent.

On your first visit to our site which uses cookies requiring consent, you will be informed by means of a dedicated banner. You may choose to:

Strictly necessary cookies are enabled by default, as they are indispensable to the functioning of the site. The withdrawal of consent for optional cookies does not affect the lawfulness of the prior processing.

Likewise, you may manage or delete cookies directly from your browser. Detailed instructions are available on the sites of the manufacturers of the main browsers: Chrome, Firefox, Safari, Edge.

Obligations Of The Data Controller

Hosting

This Platform operates through several infrastructure providers, who act in the capacity of processors of the controller, each for the component which it provides:

The processing of the data provided and stored through these providers complies with the following legal provisions:

The hosting providers mentioned are companies with their registered office outside the European Economic Area (USA). To the extent that the storage or accessing of data involves a transfer outside the EEA, BikeCheck ensures that this is carried out on the basis of adequate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional protective measures, as well as on the basis of the data processing agreements (DPAs) concluded with each provider.

Regardless of the purpose for which the processing of personal data takes place, the principles of lawfulness, fairness and transparency are observed, as well as the principle according to which the data processed is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.

For more information regarding the processing of data by the hosting providers, you may consult their policies, available on their official pages.

Data Encryption

This site uses SSL encryption for reasons of security and for the protection of the transmission of confidential information. This encryption can be recognised by you by the lock icon which appears in the browser bar and by the change from http:// to https:// in the address of that browser.

Once encryption of this type is activated, the data transmitted or transferred cannot be seen by third parties.

In accordance with the GDPR, where the personal data breach is likely to result in a high risk to your rights and freedoms, the operator of this website will inform you, without undue delay, of that breach, unless the supplementary provisions of the same Regulation become applicable (Article 34(3)).

Data Protection Officer

The provisions of the GDPR not being applicable (Article 37(1) - according to which the controller and the processor shall designate a data protection officer whenever:

Records Of Processing Activities

In accordance with the GDPR, the controller or the processor should maintain, for a reasonable period, records of the processing activities under its responsibility. Thus, these records will comprise the following information:

The obligation detailed above does not apply to an enterprise or organisation with fewer than 250 employees, unless the processing which it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data or personal data relating to criminal convictions and offences.

Appropriate Technical And Organisational Measures

Taking into account the state of the art, the context and the purposes of the processing, as well as the risks to the rights and freedoms of natural persons, the controller implements appropriate technical and organisational measures to ensure that, by default, only personal data which is necessary for each specific purpose of the processing is processed.

Notification Of The Supervisory Authority In The Event Of A Personal Data Breach

In accordance with Article 33(1) GDPR, in the event of a personal data breach, we will notify the National Supervisory Authority for Personal Data Processing of it without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless it is unlikely to result in a risk to the rights and freedoms of natural persons.

Communication Of A Personal Data Breach To The Data Subject

With reference to the provisions of Article 34 GDPR, where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, we will inform the data subject of that breach without undue delay, except in situations where:

Tools & Plug-ins

Facebook Plug-ins (API)

This website uses social plugins (“plugins”) managed by the social network facebook.com. The plugins can be identified by a Facebook logo (a white “f” on a blue tile or a “thumbs up” sign) or are labelled by the addition of the phrase “Facebook Social Plugin”. The list and appearance of the Facebook plugins can be seen here: https://developers.facebook.com/docs/plugins/. To the extent that you use the Like extension, you will like our site’s Facebook page without needing to leave it. To the extent that you use the Share extension, you will share our site or certain content from it on your personal Facebook page, without needing to leave the site.

Through the plugin, Facebook receives the information which you access on our site. If you are also logged in to Facebook at the same time, Facebook may attribute the actions carried out on the page to your account and, by extension, to you personally. When you interact with the plugins, for example by clicking the Like button or sharing certain content from the site, the corresponding information is transferred directly from your browser to Facebook and stored there. Even if you are not a Facebook member, there is nevertheless the possibility that the social network may obtain and store your IP address.

By clicking on one of these buttons, you agree to the use of this plugin and, accordingly, to the transfer of personal data to Facebook. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing.

Having regard to the Judgment of 16 July 2020 (delivered in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union held that the protection afforded by the EU–US Privacy Shield is not adequate.

Accordingly, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from controllers in the EU to processors established outside the EU or the EEA. For more information regarding these Clauses, we recommend that you visit https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.

Facebook uses Standard Contractual Clauses as an adequate safeguard regarding data protection, in accordance with the level of protection guaranteed by the GDPR.

With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so that the transfer of data may be based, where applicable, on this adequacy decision, in addition or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification may be consulted at: https://www.dataprivacyframework.gov/s/participant-search

For further details, you may visit: https://www.facebook.com/legal/EU_data_transfer_addendum, as regards the purpose and scope of the collection of data, the processing and subsequent use of the data by Facebook, as well as the permissions and settings for protecting privacy.

Instagram

This website uses social plugins (“plugins”) managed by the social network Instagram, functions offered by Instagram Inc., with its registered office at 1601 Willow Road, Menlo Park, CA 94025, USA. The plugins can be identified by an Instagram logo or are labelled by the addition of the phrase “Instagram Social Plugin”.

Through the plugin, Instagram is informed of the actions carried out by you on our page. If you are also logged in to your personal account on the social network at the same time, it may attribute the actions carried out on the page to your Instagram account and, by extension, to you personally. When you access the plugins, the corresponding information is transferred from your browser to the social network and stored there. Even if you are not an Instagram member, there is nevertheless the possibility that it may obtain and store your IP address.

By clicking on one of these buttons, you agree to the use of this plugin and, accordingly, to the transfer of personal data to Instagram. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing. As regards the purpose and scope of the collection of data, the processing and subsequent use of the data by Instagram, as well as the permissions and settings for protecting users’ privacy, you may consult the Instagram privacy policies at: https://help.instagram.com/519522125107875.

Having regard to the Judgment of 16 July 2020 (delivered in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union held that the protection afforded by the EU–US Privacy Shield is not adequate.

Accordingly, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from controllers in the EU to processors established outside the EU or the EEA. For more information regarding these Clauses, we recommend that you visit https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.

Instagram uses Standard Contractual Clauses as an adequate safeguard regarding data protection, in accordance with the level of protection guaranteed by the GDPR.

With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so that the transfer of data may be based, where applicable, on this adequacy decision, in addition or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification may be consulted at: https://www.dataprivacyframework.gov/s/participant-search.

For further details, you may visit: https://www.facebook.com/legal/EU_data_transfer_addendum.

Web Fonts – Open Sans

This site uses the Open Sans font in order to ensure a uniform presentation of the text on all pages of the Platform.

Open Sans is a freely licensed font (Open Font License), which is hosted locally, on the Platform’s own infrastructure. Thus, when accessing a page on this website, your browser loads the font files directly from the Platform’s servers, without a connection being established with third-party servers and without your data (including your IP address) being transmitted to external providers for the purpose of displaying the font.

The use of the Open Sans font is based on Article 6(1)(f) GDPR, there being a legitimate interest in the uniform and legible presentation of the text on this website. Since the font is local, this functionality does not involve a transfer of data to third parties and does not require an additional basis for processing.

Identity Verification Through DIDIT (kyb/kyc)

The Platform uses the services provided by DIDIT, a specialised identity verification solution, in order to fulfil the obligations of knowing the clientele and business partners (KYC – Know Your Customer and KYB – Know Your Business), as well as for the prevention of fraud and ensuring the security of the Platform. The activation of any account is conditional upon the completion and successful validation of the verifications carried out through DIDIT.

For users and businesses established in the European Union, the United Kingdom, the European Economic Area and Switzerland, the contracting entity and the one which operates the European data processing infrastructure is Didit Identity Spain, S.L., with its registered office at Calle Nápoles 227, P. 1, 08013 Barcelona, Spain (CIF B22929327).

Within the verification process, depending on the type of account and the configuration of the applicable flow, the following may be processed: identification and contact data (first name, surname, e-mail address, telephone number, postal address, date of birth), images of identity documents, data extracted from them, and, in certain flows, biometric data resulting from the verification of real presence (liveness) and, respectively, from facial comparison, as well as, in the case of Business accounts, the identification data of the economic operator and its verification in public registers.

In its relationship with the Platform, DIDIT acts in the capacity of processor, processing the data exclusively on the basis of the controller’s instructions and for the purpose of carrying out the verification requested. The decision regarding the approval, rejection or repetition of the verification, as well as the activation of the account, belongs to the Platform, DIDIT providing the verification technology and the associated analysis. The processing is based on Article 6(1)(b) GDPR (pre-contractual measures and performance of the contract), on Article 6(1)(c) GDPR (compliance with legal obligations, including the prevention of fraud), and, as regards biometric data, to the extent that it is processed, on the applicable basis under Article 9 GDPR, with information being provided to and, where applicable, the explicit consent obtained from the data subject.

DIDIT allows the controller to configure the data storage region, such that, for users in the European Union, the verification data may be processed and stored within the European Economic Area. To the extent that, depending on the configuration of the service, a transfer of data were to occur to an entity of the DIDIT group or to sub-processors established outside the European Economic Area (including Didit Identity, Inc., with its registered office in Dover, Delaware, United States), this is carried out on the basis of adequate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional protective measures. For more information regarding the Standard Contractual Clauses, you may visit https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.

The processing of data by DIDIT is carried out in accordance with its own privacy policies, available at https://didit.me/terms/privacy-policy/, as well as with the specific notices applicable to identity verification. For more details regarding the nature, purpose and scope of the processing, as well as the security measures applied, you may consult the documentation made available by DIDIT.

Online Payments – PADDLE

The payments relating to subscriptions and services paid for through the Platform are processed through the provider Paddle, which acts in the capacity of Merchant of Record (registered merchant/reseller). From a legal point of view, this means that Paddle is the seller of record of the digital products and services to the user, processes the payment and assumes responsibility for compliance with the applicable legislation and for the management of the related taxes (VAT/indirect taxes), in place of BikeCheck. The name Paddle may appear on the user’s bank statement instead of the name BikeCheck.

Unlike a simple payment processor, in this configuration Paddle acts, as regards the data processed in connection with the transaction and with the resale relationship, in the capacity of independent controller, the processing being carried out in accordance with its own privacy policy. The Paddle entities relevant for users and businesses in the European Union, the United Kingdom and the European Economic Area are Paddle.com Market Limited, with its registered office at 30 Old Bailey, London, United Kingdom, EC4M 7AU, and Paddle Payments Limited, with its registered office at The Academy, 42 Pearse Street, Dublin 2, D02 HV59, Ireland.

In accordance with the Regulation, “in order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption” – Recital 83. The availability of strong and effective encryption thus represents a necessity for guaranteeing the protection, confidentiality and integrity of personal data.

The banking data provided for the purpose of making payments is transmitted through secure connections, using appropriate methods of encryption, to the payment processing infrastructure. BikeCheck does not collect, does not store and has no access to the user’s complete card data, this being managed exclusively by Paddle and its processing partners.

According to the information available at https://www.paddle.com/legal/privacy, Paddle’s information system makes available appropriate methods for the protection of users’ personal data, as well as of the operations and transactions carried out through it. The purposes of the processing, the data processed, the conditions of its transfer and distribution, the ensuring of the security of the operations and of the data processed and stored, as well as the other information made available by Paddle, are based on the mechanisms for ensuring the lawfulness of processing provided for by the GDPR, namely: the consent of the data subject [Article 6(1)(a)], the performance of a contract [Article 6(1)(b)] and the legitimate interest of the controller [Article 6(1)(f)].

To the extent that Paddle processes data outside the European Economic Area, the transfer is carried out on the basis of adequate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 or, where applicable, on the basis of an applicable adequacy decision.

Conclusion

This policy regarding the processing of personal data is drawn up in accordance with the provisions of Regulation No 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as with the other applicable national legal provisions.

We reserve the right to make any additions or amendments to this policy. We recommend consulting the Policy regularly for correct and up-to-date information as regards the processing of personal data.

For more details regarding this GDPR Policy, as well as for the exercise of any of the rights mentioned above, a written notification may be sent to the contact details indicated.

Contact And Complaints

For any questions, requests or complaints relating to the processing of personal data, you may contact us:

CERC-D SRL

This document was updated on 15.08.2026.

Language And Prevailing Version

This Policy was drawn up and adopted in Romanian. The Romanian version, updated on 15.08.2026, is the sole authoritative version.

This English text is an unofficial translation provided for convenience only. It was produced by automated (machine) translation and has not been reviewed or certified by an authorised translator. It is not a sworn or legalised translation and creates no rights or obligations of its own.

In the event of any divergence, ambiguity, omission or inconsistency between this English text and the Romanian version, the Romanian version shall prevail and shall be the version applied in the interpretation of this Policy.

The authoritative Romanian version is available on request at bikecheck-platform@proton.me and is provided to data subjects free of charge.