Legal

The full, authoritative text of BikeCheck's legal documents — the same text shown in the app. This page is provided so the documents can be read and linked to directly.

Terms & Conditions — Riders

Last updated: 22 July 2026

Terms And Conditions

Brief Notes

Definition Of Terms

accordance with Romanian law. Any inconsistency or invalidity of any part or clause of this Document with other applicable legal provisions shall not affect the validity and legality of the other provisions of this Document.

Terms Of Use Of The Platform

Intermediation Policy

available on the Platform.

Warranties. Limitation Of Liability.

carried out by Business Owners, nor for their compliance with technical or other regulations applicable to the service provider’s activity;

Intellectual Property

Privacy

communication with the chosen service provider; settlement and invoicing of the subscription; identity verification (KYC); fraud prevention and ensuring user safety; resolving enquiries and any disputes; and compliance with legal obligations.

Security

Useful Information For Users

Applicable Law And Jurisdiction

This document was updated on 22 July 2026.


Terms & Conditions — Business Accounts

Last updated: 22 July 2026

Terms And Conditions

Brief Notes

Definition Of Terms

document and the validation carried out in accordance with the conditions set out in Article 3.

Terms Of Use Of The Platform

Kan Ban -

Intermediation Policy And Subscription For Platform Services

integrated into the Platform (text, images, multimedia presentations) is for information purposes only and does not constitute a contractual obligation on the part of BikeCheck.

automatically assigned, upon creation, a unique identifier (hereinafter referred to as the ‘Account ID’), generated by the Platform and which cannot be modified by the user.

Warranties. Limitation Of Liability.

Intellectual Property

Privacy

) and is responsible for the compliance of such processing.

authentications and privileged actions, with logs retained for a reasonable period; backup and restoration procedures; periodic testing and reassessment of the effectiveness of the measures; incident response procedures, including notification of the other

Party without undue delay (as a rule, within 24 hours of becoming aware of the incident) and cooperation regarding notifications to the supervisory authority and to data subjects, where applicable.

Security

Useful Information For Users

Applicable Law And Jurisdiction

to the courts having subject-matter jurisdiction in Bucharest – Sector 1, or by arbitration before the Court of Arbitration attached to the Bucharest Chamber of Commerce and Industry, in accordance with its rules and by a single arbitrator. The award shall be final and binding on the parties. Either party is entitled to choose one of the two methods of dispute resolution.

This document was updated on 22 July 2026.


Privacy & Cookie Policy

Last updated: 22 July 2026

Privacy Policy

General Information

Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter – GDPR, the Regulation or RGPD) was adopted by the European Parliament and the Council of the European Union on 27 April 2016, and its provisions have been directly applicable since 25 May 2018. This Regulation expressly repeals Directive 95/46/EC, thereby also replacing the provisions of Law No 677/2001 (now repealed).

The Regulation is directly applicable in all Member States, protecting the rights of all natural persons within the territory of the European Union. In substance, the Regulation applies to all controllers who process personal data. The Regulation does not apply to the processing of personal data relating to legal persons and, in particular, undertakings with legal personality, including the name and type of the legal person and the contact details of the legal person.

Personal data is defined as any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. The processing of personal data means any operation or set of operations which is carried out on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Data Controller

Having regard to Article 4(7) of the Regulation, which defines the term ‘controller’ as a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, this Privacy Policy is drawn up and applied by:

CERC-D SRL

What Data We Collect

Personal data is collected only to the extent necessary to provide the requested services, in accordance with the principles of lawfulness, fairness and transparency. Data is collected via:

users);

Data collected via account creation forms When creating an account on the Platform, the data collected varies depending on the type of account chosen. For Rider accounts, the data collected via the registration form may include: first name and surname, email address, telephone number, password, country, county/region and town, as well as date of birth — used exclusively for age verification, without being stored as such. For Business accounts, the data collected via the registration form may include: business name, business identification number (EUID), business telephone number, country, county/region and town/city, as well as the account holder’s identification and contact details (first name and surname, email address, password). This data is processed for the purposes of creating and managing the account, providing the Platform’s features corresponding to the account type and, where applicable, establishing the contractual relationship. The legal basis is Article 6(1)(b) of the GDPR (performance of a contract and/or pre-contractual measures), as well as, where applicable, Article 6(1)(c) of the GDPR (compliance with a legal obligation, including in the context of identity verification). (1)(c) of the GDPR (compliance with legal obligations, including in the context of identity verification). The identity of account holders is verified via the external provider DIDIT (KYB/KYC), following which the account is activated.

Data collected via contact forms or booking enquiries Data collected via the contact form may include: first name and surname, email address, telephone number, message, and relevant information provided voluntarily by users. This data is processed for the purpose of providing a response and, where applicable, entering into a contractual relationship. The legal basis is Article 6(1)(b) of the GDPR (pre-contractual measures) and/or Article 6(1)(a) of the GDPR (consent).

Given that the Regulation primarily prohibits “the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the unique identification of a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation’ (in accordance with Article 9(1)), the situations in which the processing of such data is permitted are then set out: a. the data subject has given their explicit consent; b. processing is necessary for the purposes of fulfilling the obligations and exercising specific rights of the controller or of the data subject in the field of employment, social security and social protection; c. the processing is necessary to protect the vital interests of the data subject or of another natural person, where the data subject is physically or legally incapable of giving consent; d. the processing is carried out in the course of their legitimate activities and with appropriate safeguards by a foundation, an association or any other non-profit-making body with a political, philosophical, religious or trade-union purpose, provided that the processing relates solely to members or former members of that body or to persons with whom it has

in connection with its purposes, and that personal data are not disclosed to third parties without the consent of the data subjects; e. the processing relates to personal data which have been manifestly made public by the data subject; f. the processing is necessary for the establishment, exercise or defence of legal claims in court or whenever the courts are acting in the exercise of their judicial functions; g. the processing is necessary for reasons of substantial public interest, on the basis of Union or national law, which is proportionate to the aim pursued, respects the essence of the right to data protection and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject; h. the processing is necessary for purposes relating to preventive or occupational medicine, the assessment of an employee’s fitness for work, the establishment of a medical diagnosis, the provision of medical or social care or medical treatment, or the management of health or social care systems and services, pursuant to Union or national law or pursuant to a contract concluded with a healthcare professional, and subject to compliance with the conditions and safeguards laid down in the Regulation; i. the processing is necessary for reasons of public interest in the area of public health, such as protection against serious cross-border threats to health or ensuring high standards of quality and safety of healthcare, medicines or medical devices, pursuant to Union or national law, which provides for appropriate and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; or j. the processing is necessary for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, in a manner that is proportionate to the objective pursued, whilst respecting the essence of the right to data protection, and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject.

The processing of personal data is carried out on the basis of the following legal grounds set out in Regulation (EU) 2016/679 (GDPR):

Purpose Of Processing The Data Collected

Some of the data collected on this website is used for:

feedback questionnaires or similar.

The processing of personal data is carried out in accordance with the provisions of the General Data Protection Regulation, based both on the data subject’s consent and on the need to fulfil contracts or to pursue the controller’s legitimate interests (unless the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, take precedence, in particular where the data subject is a child).

Processing of minors’ personal data The services offered via this website are intended exclusively for persons aged 16 or over. In accordance with Article 8 of the GDPR, consent to the processing of personal data in the context of information society services is valid for persons aged 16 or over. For individuals under the age of 16, processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility. The operator of this website does not intentionally collect personal data from individuals under the age of 16 and does not sell products to individuals under this age without the consent of a parent or legal guardian. If you are a child under the age of 16, please do not use this website or provide us with any personal data without the consent and supervision of a parent or legal guardian. If you are aware that a minor under the age of 16 has provided us with personal data without the consent of a parent or legal guardian, please contact us by email at .............................., and we will delete this data as soon as possible.

For the processing of personal data to be lawful, the GDPR stipulates that it must be carried out on the basis of a legitimate ground, such as the performance or conclusion of a contract, compliance with a legal obligation, or on the basis of valid consent previously given by the data subject. In the latter case, the controller is required

to be able to demonstrate that the data subject has given their consent to the processing in question. Consent given under Directive 95/46/EC remains valid provided it meets the conditions set out in the GDPR.

Consent must be given by means of a statement or an unambiguous action constituting a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of their personal data. Where the data subject’s consent is given in the context of a statement, whether in electronic or written form, which also relates to other matters, the request for consent must be presented in a form that clearly distinguishes it from the other matters, which may be achieved, for example, by ticking a box.

Data Retention Period

Personal data is stored for as long as is necessary to fulfil the purposes for which it was collected or for as long as required by applicable legislation. In the absence of specific legal requirements, the data is stored:

Disclosure Of Personal Data To Other Recipients

The Controller discloses personal data (only where required and strictly to the extent necessary) to public bodies and authorities, including, by way of example: ANAF (National Agency for Fiscal Administration), ISU (Inspectorate for Emergency Situations), the Police, Public Prosecutors’ Offices, Courts, the City Council, the Local Council, the County Council, Ministries, ANPC (National Authority for Consumer Protection), ANSPDCP (National Supervisory Authority for the Processing of Personal Data) in the exercise of its supervisory and control functions, accountants, auditors, lawyers and other external consultants acting as authorised representatives or independent processors, as applicable. We do not transfer data to third countries or international organisations, except where required by an existing cooperation agreement. Thus, on the basis of existing collaborative relationships and in order to be able to carry out the activities undertaken to the highest standards, we will share the data provided with:

Server Log Files

This platform automatically collects and stores the information that your browser automatically transmits to us via log files. These are:

Contact Form

If you contact us via the contact form, we will collect the data you enter into the form, including the contact details you provide, in order to respond to your enquiries and any subsequent enquiries. We do not pass on this information without your permission. We will therefore process all data you enter in the contact form only with your consent [in accordance with Article 6(1)(a) of the GDPR]. You may withdraw your consent at any time; an informal email to that effect is sufficient. Data processed prior to receiving your request may still be processed lawfully. We will retain the data you provide via the contact form until:

Contact By E-Mail Or Telephone

If you contact us by email or telephone, your enquiry, including any personal data you provide, will be stored and processed by us for the purpose of dealing with your enquiry, on the basis of your consent. We will therefore process all the data you provide in accordance with the following legal provisions of the GDPR, namely:

We will retain the data you provide in this way until:

Registration On The Platform

You can register as a User, either as a Rider or a Business Owner, to access the features and services of the Platform corresponding to your chosen account type — including registering and managing bicycles, sending or receiving service requests, posting listings on the Marketplace, and receiving updates and relevant communications. To this end, the data you provide will be used and processed for the purposes mentioned. The mandatory data requested during registration must be provided in full; otherwise, the registration process will be rejected. Account activation is also subject to the validation of identity checks (KYB/KYC) carried out via the DIDIT provider. To keep you informed about important matters, such as changes to the Platform’s operation or technical changes, we will use the email address you provided at the time of registration. The processing of personal data provided during the registration process is carried out on a contractual basis, in accordance with Article 6(1)(b) of the GDPR, as it is necessary for the creation and administration of your account and for the provision of the Platform’s services, as well as, where applicable, on the basis of your consent, in accordance with Article 6(1)(a) of the GDPR (for example, for promotional communications). You may withdraw your consent at any time, where this legal basis has been relied upon; an informal email to that effect is sufficient; the withdrawal of consent does not affect processing based on other legal grounds, nor does it affect the lawfulness of processing carried out prior to the withdrawal. We will continue to store the data collected during registration for as long as you remain registered as a User, whilst the mandatory retention periods laid down by law remain in force and are complied with.

Rights Of Data Subjects

Your rights regarding personal data and the means of exercising them are: the right to information, the right of access, the right to rectification, the right to erasure, the right to restriction of processing, The right to data portability, The right to object, The right not to be subject to a decision based solely on automated processing, The right to lodge a complaint and to bring the matter before the courts, The right to withdraw consent.

for which the personal data are expected to be stored or, if this is not possible, the criteria used to determine that period; the right to request the controller to rectify or erase the personal data, or to restrict the processing of the personal data, or the right to object to the processing, etc.

To exercise any of these rights, please contact us at: ........................ Your request does not need to follow any specific format, but it must include: your first name and surname, the contact details where you wish to receive a reply, as clear a description as possible of the right you wish to exercise and, if possible, a copy of an identity document (to verify your identity and prevent unauthorised access to your data). We will respond to your request within a maximum of 30 calendar days from the date of receipt. In particularly complex cases or where there is a high volume of simultaneous requests, this period may be extended by a further 60 days, provided that we inform you of this extension and the reasons for it within 30 days of receiving your request, in accordance with Article 12(3) of the GDPR. Our response to your request is free of charge. If your requests are manifestly unfounded or excessive (in particular because of their repetitive nature), we may either charge a reasonable fee taking into account the administrative costs, or refuse to comply with the request, providing the grounds for the refusal and informing you of your right to lodge a complaint with the ANSPDCP.

If you are not satisfied with the response you have received or if you believe that your rights have been infringed, you have the right to lodge a complaint with: the National Supervisory Authority for Personal Data Processing (ANSPDCP) 28–30 General Gheorghe Magheru Boulevard, Sector 1, Bucharest Telephone: +40 318 059 211 Email: anspdcp@dataprotection.ro

Website: www.dataprotection.ro You also have the right to bring a case before the competent courts in Romania or in the EU Member State where you have your habitual residence.

What are cookies? Cookies are small text files stored on your device (computer, mobile phone, tablet) when you visit a website. They enable the website to recognise you on your next visit, remember your selected preferences and provide a personalised experience.

Categories of cookies This website may use the following categories of cookies:

The BikeCheck platform does not use cookies. We do not use functionality, analytics, tracking or advertising cookies, and we do not place third-party cookies on your device.

For authentication and to keep your session active, the Platform uses local browser storage mechanisms (localStorage/sessionStorage), which are strictly necessary for the service to function. This information is stored exclusively on your device; it is not used to track your activity or for marketing purposes, and is essential for providing the requested service, which is why it does not require your consent.

On your first visit to our website, which uses cookies that require consent, you will be informed via a dedicated banner. You can choose to:

Firefox, Safari, Edge.

Obligations Of The Hosting Data Controller

This Platform operates through several infrastructure providers, who act as the controller’s data processors, each for the component they provide: a) Vercel Inc. – hosting the Platform’s front-end component; b) Railway Corp. – hosting the Platform’s backend; c) Supabase Inc. – hosting and managing the database in which personal data is stored; d) Resend (Plus Five Five Inc.) – sending email communications relating to the operation of the Platform (e.g. notifications, confirmations, transactional messages).

The processing of data provided and stored through these providers complies with the following legal provisions:

The hosting providers mentioned are companies based outside the European Economic Area (USA). To the extent that the storage or access to data involves a transfer outside the EEA, BikeCheck ensures that this is carried out on the basis of appropriate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional safeguards, as well as on the basis of data processing agreements (DPAs) concluded with each provider.

Regardless of the purpose for which personal data is processed, the principles of lawfulness, fairness and transparency are observed, as well as the principle that the data processed is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. For further information on data processing by hosting providers, please consult their policies, available on their official websites.

Data Encryption

This website uses SSL encryption for security reasons and to protect the transmission of confidential information. You can recognise this encryption by the padlock icon that appears in the browser bar and by the change in the browser address from http:// to https://. Once this type of encryption is activated, the data transmitted or transferred cannot be viewed by third parties.

In accordance with the GDPR, where a personal data breach is likely to result in a high risk to your rights and freedoms, the controller of this website will inform you, without undue delay, of this breach, unless the supplementary provisions of the same Regulation (Article 34(3)) apply.

Data Protection Officer

As the provisions of the GDPR (Article 37(1) – according to which the Controller and the person authorised by the Controller shall designate a Data Protection Officer whenever: a. processing is carried out by a public authority or body, with the exception of courts acting in their judicial capacity; b. the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale; or c. the main activities of the controller or the processor consist of the large-scale processing of special categories of data pursuant to Article 9 or of personal data relating to criminal convictions and offences, as referred to in Article 10) concerning the obligation to appoint a Data Protection Officer, For any information or clarification regarding the operation of this website, please contact us using the following details:

Records Of Processing Activities

In accordance with the GDPR, the controller or the processor should keep, for a reasonable period, records of the processing activities for which they are responsible. These records shall include the following information:

Appropriate Technical And Organisational Measures

Taking into account the current state of the art, the context and the purposes of the processing, as well as the risks to the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure that, by default, only personal data necessary for each specific purpose of the processing are processed.

NOTIFICATION TO THE SUPERVISORY AUTHORITY IN THE EVENT OF A PERSONAL DATA BREACH In accordance with Article 33(1) of the GDPR, in the event of a personal data breach, we will notify the National Supervisory Authority for the Processing of Personal Data without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to the rights and freedoms of natural persons.

INFORMING THE DATA SUBJECT OF A PERSONAL DATA BREACH In accordance with the provisions of Article 34 of the GDPR, where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, we will inform the data subject without undue delay of the breach, except where:

Tools & Plug-Ins

Facebook Plug-ins (API) This website uses social plugins (“plugins”) managed by the social network facebook.com. The plugins can be identified by a Facebook logo (a white “f” on a blue background or a “thumbs up” symbol) or are labelled with the phrase “Facebook Social Plugin”. The list and appearance of Facebook plugins can be viewed here: https://developers.facebook.com/docs/plugins/. If you use the ‘Like’ button, you will be able to ‘like’ our website’s Facebook page without having to leave it. If you use the Share extension, you will share our website or specific content from it on your personal Facebook page without having to leave the website. Through the plugin, Facebook receives information about the content you access on our website. If you are logged into Facebook at the same time, Facebook may attribute

the actions you take on the page to your account and, by extension, to you personally. When you interact with the plugins – for example, by clicking the ‘Like’ button or sharing specific content from the site – the relevant information is transferred directly from your browser to Facebook and stored there. Even if you are not a Facebook member, there is still a possibility that the social network may obtain and store your IP address. By clicking on one of these buttons, you consent to the use of this plugin and, consequently, to the transfer of personal data to Facebook. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing. In light of the judgment of 16 July 2020 (delivered in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union ruled that the protection afforded by the EU–US Privacy Shield is not adequate. Consequently, the transfer of personal data to the US and other countries outside the European Economic Area (EEA) is based on the European Commission’s Standard Contractual Clauses (SCCs). The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from data controllers in the EU to data processors established outside the EU or the EEA. For more more information on these Clauses, we recommend that you visit https://ec.europa.eu/info/law/law- topic/data-protection/international-dimension-data-protection/standard-contractual- clauses-scc_ro. Facebook uses Standard Contractual Clauses as an appropriate safeguard for data protection, in line with the level of protection guaranteed by the GDPR. With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so the transfer of data may be based, where applicable, on this adequacy decision, in addition to or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification can be found at: https://www.dataprivacyframework.gov/s/participant-search For more further details, you visit: https://www.facebook.com/legal/EU_data_transfer_addendum, regarding the purpose and scope of data collection, the processing and subsequent use of data by Facebook, as well as permissions and settings for protecting your privacy.

Instagram

This website uses social plugins (“plugins”) operated by the social network Instagram, a service provided by Instagram Inc., with its registered office at 1601 Willow Road, Menlo Park, CA 94025, USA. The plugins can be identified by an Instagram logo or are labelled with the phrase ‘Instagram Social Plugin’. Through the plugin, Instagram is informed of the actions you take on our website. If you are logged into your personal social media account at the same time, Instagram may attribute the actions taken on the page to your Instagram account and, by extension, to you personally. When you access the plugins, the relevant information

is transferred from your browser to the social media platform and stored there. Even if you are not an Instagram user, there is still a possibility that Instagram may obtain and store your IP address. By clicking on one of these buttons, you consent to the use of this plugin and, consequently, to the transfer of personal data to Instagram. We have no control over the nature and purpose of this transmitted data, nor over its subsequent processing. For information regarding the purpose and scope of data collection, the processing and further use of data by Instagram, as well as the permissions and settings for protecting users’ privacy, please refer to Instagram’s privacy policy at: https://help.instagram.com/519522125107875. In light of the judgment of 16 July 2020 (delivered in Case C-311/18 – Data Protection Commissioner v Facebook Ireland Limited, Maximillian Schrems), the Court of Justice of the European Union ruled that the protection afforded by the EU–US Privacy Shield is not adequate. Consequently, the transfer of personal data to the US and other countries outside the European Economic Area (EEA) is based on the European Commission’s Standard Contractual Clauses (SCCs). The Commission has issued two sets of Standard Contractual Clauses for data transfers from data controllers in the EU to data controllers established outside the EU or the European Economic Area (EEA). It has also issued a set of contractual clauses for data transfers from data controllers in the EU to data processors established outside the EU or the EEA. For more more information on these Terms and Conditions, we recommend that you visit https://ec.europa.eu/info/law/law-topic/data-protection/international- dimension-data-protection/standard-contractual-clauses-scc_ro. Instagram uses Standard Contractual Clauses as an appropriate safeguard for data protection, in line with the level of protection guaranteed by the GDPR. With effect from 10 July 2023, the European Commission adopted Adequacy Decision No 2023/1795 on the EU-US Data Privacy Framework (DPF), which constitutes a new legal basis for the transfer of personal data from the European Union to companies in the United States certified under the DPF. Meta Platforms is certified under the DPF, so the transfer of data may be based, where applicable, on this adequacy decision, in addition to or as an alternative to the Standard Contractual Clauses mentioned above. Information regarding the certification can be found at: https://www.dataprivacyframework.gov/s/participant-search. For more further details, please visit: https://www.facebook.com/legal/EU_data_transfer_addendum.

WEB FONTS – OPEN SANS This website uses the Open Sans font to ensure consistent text display across all pages of the Platform. Open Sans is a freely licensed font (Open Font Licence), which is hosted locally on the Platform’s own infrastructure. Therefore, when you access a page on this website, your browser loads the font files directly from the Platform’s servers, without establishing a connection to third-party servers and without your data (including your IP address) being transmitted to external providers for the purpose of displaying the font. The use of the Open Sans font is based on Article 6(1)(f) of the GDPR, as there is a legitimate interest in the uniform and legible presentation of text on this website. As

the font is hosted locally, this functionality does not involve any transfer of data to third parties and does not require any additional legal basis for processing.

Identity verification via DIDIT (KYB/KYC) The Platform uses the services provided by DIDIT, a specialised identity verification solution, in order to fulfil its obligations regarding the identification of customers and business partners (KYC – Know Your Customer and KYB – Know Your Business), as well as to prevent fraud and ensure the security of the Platform. The activation of any account is conditional upon the successful completion and validation of the checks carried out via DIDIT. For users and businesses based in the European Union, the United Kingdom, the European Economic Area and Switzerland, the contracting entity and the operator of the European data processing infrastructure is Didit Identity Spain, S.L., with its registered office at Calle Nápoles 227, P. 1, 08013 Barcelona, Spain (CIF B22929327). As part of the verification process, depending on the account type and the applicable data flow configuration, the following may be processed: identification and contact details (surname, first name, email address, telephone number, postal address, date of birth), images of identity documents, data extracted from these, and, in certain data flows, biometric data resulting from liveness verification and, respectively, facial comparison, as well as, in the case of Business accounts, the identification data of the economic operator and the verification of such data in public registers. In its relationship with the Platform, DIDIT acts as a data processor, processing the data exclusively on the basis of the controller’s instructions and for the purpose of carrying out the requested verification. The decision to approve, reject or repeat the verification, as well as to activate the account, rests with the Platform, with DIDIT providing the verification technology and the associated analysis. The processing is based on Article 6(1)(b) of the GDPR (pre-contractual measures and performance of the contract), on Article 6(1)(c) of the GDPR (compliance with legal obligations, including fraud prevention), and, with regard to biometric data, to the extent that such data is processed, on the applicable basis under Article 9 of the GDPR, with the data subject being informed and, where appropriate, their explicit consent being obtained. DIDIT allows the controller to configure the data storage region so that, for users in the European Union, verification data may be processed and stored within the European Economic Area. To the extent that, depending on the configuration of the service, a transfer of data takes place to an entity within the DIDIT group or to sub-processors established outside the European Economic Area (including Didit Identity, Inc., with its registered office in Dover, Delaware, United States), this is carried out on the basis of appropriate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 and, where applicable, additional safeguards. For further information on the Standard , you can visit https://ec.europa.eu/info/law/law-topic/data-protection/international- dimension-data-protection/standard-contractual-clauses-scc_ro. Data processing by DIDIT is carried out in accordance with its own privacy policies, available at https://didit.me/terms/privacy-policy/, as well as with the specific notes applicable to identity verification. For further details regarding the nature, purpose and scope of the processing, as well as the security measures in place, please refer to the documentation provided by DIDIT.

Online payments – PADDLE Payments for subscriptions and services paid for via the Platform are processed through the provider Paddle, which acts as the Merchant of Record (registered merchant/reseller). From a legal perspective, this means that Paddle is the legal seller of the digital products and services to the user, processes the payment and assumes responsibility for compliance with applicable legislation and for managing the relevant taxes (VAT/indirect taxes), in place of BikeCheck. The name ‘Paddle’ may appear on the user’s bank statement instead of ‘BikeCheck’. Unlike a simple payment processor, in this configuration Paddle acts, with regard to the data processed in connection with the transaction and the resale relationship, as an independent controller, with processing carried out in accordance with its own privacy policy. The Paddle entities relevant to users and businesses in the European Union, the United Kingdom and the European Economic Area are Paddle.com Market Limited, with its registered office at 30 Old Bailey, London, United Kingdom, EC4M 7AU, and Paddle Payments Limited, with its registered office at The Academy, 42 Pearse Street, Dublin 2, D02 HV59, Ireland. According to the Regulation, ‘in order to maintain security and prevent processing that infringes this Regulation, the controller or the processor should assess the risks inherent in the processing and implement measures to mitigate those risks, such as encryption’ – Recital 83. The availability of strong and effective encryption is therefore essential to guarantee the protection, confidentiality and integrity of personal data. Bank details provided for the purpose of making payments are transmitted via secure connections, using appropriate encryption methods, to the payment processing infrastructure. BikeCheck does not collect, store or have access to the user’s full card details, which are managed exclusively by Paddle and its processing partners. According to the information available at https://www.paddle.com/legal/privacy, Paddle’s IT system provides appropriate measures to protect users’ personal data, as well as the operations and transactions carried out through it. The purposes of processing, the data processed, the conditions for their transfer and distribution, the security of operations and of the data processed and stored, as well as the other information provided by Paddle, are based on the mechanisms for ensuring the lawfulness of processing provided for by the GDPR, namely: the data subject’s consent [Article 6(1)(a)], the performance of a contract [Article 6(1)(b)] and the controller’s legitimate interests [Article 6(1)(f)]. To the extent that Paddle processes data outside the European Economic Area, the transfer is carried out on the basis of appropriate safeguards in accordance with Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 or, where applicable, on the basis of an applicable adequacy decision.

Conclusion

This policy on the processing of personal data has been drawn up in accordance with the provisions of Regulation No 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as with other applicable national legal provisions.

We reserve the right to make any additions or amendments to this policy. We recommend that you consult the Policy regularly to ensure you have accurate and up-to- date information regarding the processing of personal data. For further details regarding this GDPR Policy, as well as to exercise any of the rights mentioned above, a written notification may be sent to the contact details provided.

Contact And Complaints

For any questions, requests or complaints regarding the processing of personal data, please contact us:

CERC-D SRL

Last updated: 22 July 2026