Personal data protection policy – v. Août 2024 – p.1/7

AXXÈS PERSONAL DATA PROTECTION POLICY

1.WHO IS THE DATA CONTROLLER? …………………………………………………………………………………………………….. 1

2.WHICH PERSONAL DETAILS DO WE PROCESS? ……………………………………………………………………………………. 1

3.WHAT ARE THE PURPOSES OF THE PROCESSING? ……………………………………………………………………………….. 2

4.WHAT IS THE LEGAL BASIS FOR OUR PROCESSING OF YOUR PERSONAL DATA? …………………………………………. 3

5.WHO RECEIVES YOUR PERSONAL DATA? …………………………………………………………………………………………… 3

6.HOW LONG IS YOUR PERSONAL DATA CONSERVED? ……………………………………………………………………………. 3

7.WHAT ARE YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA? ………………………………………………………. 4

8.WHAT ABOUT DISCLOSURE OF YOUR PERSONAL DATA? ……………………………………………………………………….. 6

9.HOW CAN YOU CONTACT OUR DATA PROTECTION OFFICER (DPO)? ……………………………………………………… 6

10.WHAT IS YOUR COOKIE POLICY? ……………………………………………………………………………………………………. 6

11.WHAT SECURITY MEASURES ARE IN PLACE? ……………………………………………………………………………………… 7

12.WHAT ABOUT CHANGES TO THIS POLICY? ……………………………………………………………………………………….. 7

1. WHO IS THE DATA CONTROLLER?

The data controller is Axxès, a French simplified joint-stock company (société par actions simplifiée) registered with the Lyon Trade and Companies Registry (France) under number 482 930 385, located at 15 Rue des Cuirassiers, 69003 Lyon, France.

2. WHICH PERSONAL DETAILS DO WE PROCESS?

At Axxès, we believe you can enjoy excellent products or services, in a confidential manner. For this reason, we process all data relating to an individual who is identified or identifiable, and all data associated or that may be associated with an individual by Axxès, as “personal data”, regardless of where the individual resides. This means that any data that may be used to identify you directly, such as your surname, is personal data. Data that does not identify you personally, but could reasonably be used to identify you, such as the serial number of your device, is also personal data.

The Axxès Policy does not apply to how third parties define or use personal data. You should read their privacy policies and find out about your privacy rights before interacting with them.

We collect and process the following personal data about you:

Identification data (first name and surname, email address, postal address and telephone number);

Connection data (IP address and connection logs);

Commercial data (communication with the customer services team and data required to provide subscribed services or manage customer relationships, conduct satisfaction surveys or produce statistics);

Personal data protection policy – v. Août 2024 – p.2/7

Invoicing and payment data (data about your invoicing address and method of payment, such as bank details, credit and debit data or other payment card information or your bank account identification slip); Transaction data (data about purchases of Axxès products and services or transactions managed by Axxès, including purchases through Axxès customer areas);

Behavioural data (services subscribed to or considered, behaviour when using websites or tools (pages viewed, time connected, number of views)); User data (data relating to your activity on and use of our products, such as the launch of apps in our services, including browsing history, search history, product interaction, error data, performance data and other diagnostic data, and any other user data);

Location data (exact position for services only, if authorised by you);

Recruitment data (CV, supporting letter);

Personal and professional data (registrations for events, colleague testimonials).

Only the personal data strictly necessary for the purposes described below is collected.

You do not have to provide us with the personal data we request. However, if you decide not to provide this information, we may not always be able to provide you with our products and services, or answer your questions.

3. WHAT ARE THE PURPOSES OF THE PROCESSING?

Your personal data is processed for the following purposes:

Managing our relationship with you; Performing or providing the subscribed services; Axxès collects the personal data required to provide its services, which may include personal data collected to personalise or improve its products, as well as data collected for in-house purposes such as data analysis or audits, or for troubleshooting purposes;

Running marketing campaigns and organising events;

Increasing our knowledge of your profile and analysing behaviour;

Downloading files;

Personalising our services based on your profile to improve your experience; Managing invoices; to process your transactions, Axxès needs to collect data such as your first name and surname, your purchase and your payment information;

Statistics, analyses and audience measurements;

Producing statistical data and anonymised information about the behaviour of road users and the state of motorway traffic;

Satisfaction surveys about our services;

Improving and optimising the quality of our services and our website;

Managing data subject rights and requests to exercise data subject rights;

Information about the products you transport;

Managing recruitment operations.

Personal data protection policy – v. Août 2024 – p.3/7

Security and fraud prevention; to protect customers, Axxès employees and Axxès, and for loss and fraud prevention purposes (including to protect customers, Axxès employees and Axxès for the benefit of all users), and to screen or analyse any uploads to ensure that they do not contain any illegal content, such as content relating to child sexual abuse;

Compliance with the law; to comply with the applicable laws, for example to fulfil tax or reporting obligations, or comply with a legitimate government request.

Accordingly, we use your personal data to provide our services to you, process your transactions, communicate with you, protect security and prevent fraud and comply with the law etc. We may also use personal data for other purposes, but only with your consent.

Depending on the circumstances, Axxès may rely on your consent or the fact that the data needs to be processed to perform a contract with you, protect your interests or those of third parties or comply with the law. We may also process your personal data if we believe it is in our legitimate interests or those of third parties, taking into account your interests, rights and expectations.

Axxès does not use algorithms or profiling to make decisions that could materially affect you, without an option for human verification.

4. WHAT IS THE LEGAL BASIS FOR OUR PROCESSING OF YOUR PERSONAL DATA?

Your personal data is collected and processed on the following legal bases:

On the basis of your consent;

For the performance of a contract;

For legitimate interests;

To ensure compliance with our legal and regulatory obligations.

5. WHO RECEIVES YOUR PERSONAL DATA?

The following people receive your personal data, depending on the processing carried out:

Axxès in-house teams;

Providers acting on our behalf for the purposes listed above;

Road operating companies, as relevant for the services provided;

Commercial partners of Axxès for the purposes listed above, but geolocation data is always transmitted in an anonymised form.

That data is never transferred to countries outside the European Union. If this were nevertheless to occur, we undertake to ensure that these transfers take place in compliance with the regulations in force or with regulations offering an adequate and equivalent level of protection.

6. HOW LONG IS YOUR PERSONAL DATA CONSERVED?

Your personal data is conserved solely for the time strictly necessary to achieve the purposes for which it has been collected and processed.

By default: Personal data protection policy – v. Août 2024 – p.4/7

The customer account accessed via the customer area is not conserved for more than three (3) years from the last connection;

Identification data is conserved for the period of performance of the contract;

Vehicle data is conserved for the period of performance of the contract;

Geolocation data and journey histories are conserved for two (2) months from the date of collection;

Invoicing data is conserved for ten (10) years from the invoice date; – Connection and browsing data is not conserved for more than one (1) year from the last connection;

Behavioural data is conserved for thirteen (13) months;

Your credit or debit card details, when requested, are only conserved for the time required to complete the transaction;

Connection data for Mobile Applications will only be conserved for the time strictly necessary for the purpose for which it has been collected.

However, personal data is conserved for a longer time in the form of archives whenever we are required to do so under our legal or regulatory obligations or if this is necessary, given the applicable limitation period, to allow us to assert our rights, unless this can be proven using another means.

Once your Personal Data is no longer required for the relevant purposes or for archiving purposes under our legal obligations or the applicable limitation period, we will ensure that it is either completely destroyed or anonymised.

7. WHAT ARE YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA?

In accordance with the applicable legislation, you have a number of rights concerning the collection and processing of your personal data:

right of direct access: you have the right to be informed, in a concise, transparent, intelligible and readily available manner, about how we process your Personal Data;

right of interrogation: you also have the right to ask us to confirm that your Personal Data is being processed and, where appropriate, to access your Personal Data;

right of correction: you have the right to ask us to correct your Personal Data that is inaccurate. You also have the right to complete your Personal Data that is incomplete, by providing an additional declaration;

right of deletion: this right may be exercised to the extent that it does not impair the performance of the contract or our compliance with our legal and regulatory obligations;

the right to limit how we process your personal data;

right to modify and/or withdraw, at any time, the consent you gave to the processing of your personal data based solely on your consent;

right to object to the processing of your personal data;

right to portability for your personal data.

You also have the right to define general and/or specific instructions about what should happen to your personal data and how you want your rights to be exercised after your death.

To ensure the information we hold about you is always accurate, we recommend regularly updating your personal data. Personal data protection policy – v. Août 2024 – p.5/7

You can express any requests to exercise your rights about your personal data by contacting us:

by email at data-privacy@axxes.fr; or

by post by writing to Axxès SA, for the attention of the DPO, 15 Rue des Cuirassiers, 69487 Lyon Cedex 03, France.

You can also refuse marketing calls by signing up free of charge to the Bloctel list operated by Opposetel under a public service delegation.

If you are not satisfied, you can complain to the French Data Protection Authority:

Commission Nationale de l’Informatique et des Libertés (CNIL)

3 Place de Fontenoy

TSA 80715

75334 Paris Cedex 07, France

Tel.: +33 (0)1 53 73 22 22 Personal data protection policy – v. Août 2024 – p.6/7

  1. How is my personal data communicated?

Axxès will not process, host or transfer the data collected in or to a country located outside the European Union or recognised as “non-adequate”.

Axxès will take all necessary steps to protect data security and, in particular, to ensure that data is not communicated to unauthorised persons. However, if it becomes aware of an incident affecting the integrity or confidentiality of a user’s data, Axxès must inform the user as soon as possible and explain the corrective action taken.

Within the limits of their respective responsibilities, and for the purposes set out above, the main people who may be given access to the data of the users of axxes.fr are the staff of Axxès.

9. HOW CAN YOU CONTACT OUR DATA PROTECTION OFFICER (DPO)?

You can contact our DPO:

by email at data-privacy@axxes.fr; or

by post by writing to Axxès SA, for the attention of the DPO, 15 Rue des Cuirassiers, 69487 Lyon Cedex 03, France.

10. WHAT IS YOUR COOKIE POLICY?

A “cookie” is a small named data file that can be installed and/or read on your device when you visit the website.

Cookies are used by Axxès to personalise the website contents, analyse website traffic, produce usage statistics and improve your experience of the website. Some information is shared with Axxès partners. Users may accept or refuse the cookies installed by Axxès on the hard drive of their computer/device by modifying their cookie access settings. This means that users refuse to allow the cookies in question to be stored. These cookies can be deleted at any time by users.

In accordance with the recommendations issued by the French Data Protection Authority (CNIL), cookies are not conserved for more than thirteen (13) months from their initial installation on a user’s device, and a user’s consent to the use of these cookies is valid for the same period. The cookies conservation period is not extended with each visit. User consent will therefore need to be renewed at the end of this period.

Types of cookies on the Axxès.fr website

These cookies allow the website to work properly. You can prevent them from being installed and delete them in your browser settings, but this may impair your user experience.

  • Web analytics cookies

Axxès uses the Google Analytics G4 cookie to improve its understanding of user behaviour for the purposes of analysing, improving and optimising the performance of Axxès.fr. Personal data protection policy – v. Août 2024 – p.7/7

  • Third-party cookies to improve website interactivity

The Axxès website uses some services offered by third-party websites, in particular:

  • • Share buttons (YouTube, Vimeo, Instagram, TikTok, LinkedIn, Facebook)
  • • Videos shown on the website (YouTube, Vimeo)

These functions use third-party cookies installed directly by the third-party websites. When you first visit the Axxès website, a banner will inform you that these types of cookies are used and ask you to indicate your cookie choices. They are only installed if you accept them or if you continue browsing the website by viewing another page of the website. You can find out more and change your cookie settings to accept them at any time, on the “Personal Data Protection Policy” page. You can indicate your cookie preferences for the whole website or for each separate service.

Axxès has no control over the process used by social media to collect information about your browsing activity on the website, associated with the personal data they hold. You should read the privacy policies of the relevant social media.

11. WHAT SECURITY MEASURES ARE IN PLACE?

As the data controller, we take all the necessary steps to preserve the security and confidentiality of your data, including preventing damage and access by unauthorised third parties. For this purpose, we apply all the technical and organisational measures that will guarantee an adequate level of security in view of the risks. We also ensure that our subcontractors comply with the rules on personal data protection.

12. WHAT ABOUT CHANGES TO THIS POLICY?

This policy may evolve and changes may therefore be made. In the case of minor changes, the new policy will be published online in the relevant section of the website. In the case of substantial changes, including alterations to the purposes or the exercise of your rights, you will be informed.