1 PRIVACY POLICY – APP DIABLO™ SUPER BIKER IMPORTANT NOTE This is a translation into English for reference purposes only. The original Italian text of this document can be read here. In the event of any discrepancy between the original Italian version and this English translation, the original Italian version shall always prevail. Date of last update of this Privacy Policy: July 21, 2025 Date of publication and entry into force: July 21, 2025 1. LEGAL INFORMATION 1.1 The privacy of your Personal Data is of the utmost importance to us. This privacy policy (the Privacy Policy”) covers and is designed to help you understand how we process information that we collect about you when you interact with us or that you provide to us through the app DIABLO™ SUPER BIKER” (hereinafter the “App”). 1.2 Pirelli Tyre S.p.A., with registered offices at Viale Piero e Alberto Pirelli 25, 20126 Milan, Italy, Fiscal Code, VAT and Milan Monza Brianza Lodi Business Registry Enrolment n. 07211330159 (hereinafter referred to as “Pirelli”, “we”, “us” or “our”, as appropriate) will act as “Controller” of your Personal Data for the purposes detailed in Section 3. 2. COLLECTION OF INFORMATION 2.1 For purposes of providing the services offered by the App, we collect personal data, which under applicable data protection legislation, in particular Regulation EU 679/2016 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (also referred to as the "GDPR"), includes information that can be used to identify you, including: your first and last name, country, email, the photographs that you will upload to the App and more information acquired by the mobile device on which the App has been downloaded and is used (specifically: GPS location data, speed, lean angle, acceleration and lap times in case the route is on a track) (hereinafter as "Personal Data"). 2.2 It is clarified that in the event of access to the App through third-party applications or websites, the App may access certain data provided by the third-party application or website you use to identify you and allow you access to the services offered by the App. Technical information 2.3 When you use the App, we may also collect information that can be used to identify your mobile device or interactions with the App. This information is collected through the use of small text files called "cookies" and / or other similar technologies (hereinafter jointly referred to as "Cookies"). 2.4 For all information on how we use Cookies you can refer to our Cookie Policy. 3. USE OF PERSONAL DATA 3.1 We may use your Personal Data for the following purposes: (i) to allow your registration to the App; (ii) to respond to your requests of assistance; (iii) to provide you with the services offered by the App, including those involving the use of your GPS location data (used to record the routes you have taken, allowing you to view your performance within the App), which are subject to your prior consent, as requested by the mobile device on which the App has been
2 downloaded and is used. After anonymizing your Personal Data, the aforementioned information may be used for legitimate interests of the Data Controller, such as statistical purposes or for the communication of such anonymised data to partners of the Data Controller for their independent statistical purposes. 3.2 Pirelli may also use your Personal Data for marketing purposes, as described under Section 7 below, and subject to your prior consent. 4. SHARING OF PERSONAL DATA 4.1 We may share your Personal Data when authorized by law or as follows: (a) Pirelli Group companies. Your Personal Data may be shared with Pirelli & C. S.p.A. and/or with other Pirelli Group companies incorporated in Europe, to pursue legitimate interests related to the performance of technical and organizational activities functional to the purposes described in Section 3. (b) As permitted or required by law. In certain cases, we may be required to provide Personal Data in response to a valid court order, subpoena, government investigation, or as otherwise required by law. We also reserve the right to report to law enforcement agencies any activities that we, in good faith, believe to be unlawful or in violation of applicable laws. We may release certain Personal Data when we believe that such release is reasonably necessary to protect the rights, property, and safety of others and ourselves, or to detect, prevent, or otherwise address fraud, security, or technical issues. (c) Business transaction. In the event that we intend to sell or transfer ownership or control of any or all of our business, operations or services to a third party, we may need to disclose your Personal Data to a potential buyer both before and after the purchase. We will do so in accordance and in compliance with the data protection laws applicable to you. In any case, in the event the sale goes through, we will require that the receiving party agree that they will be similarly bound by the provisions of this Privacy Policy and that they will only use and disclose your Personal Data as we are similarly entitled under this Privacy Policy. In the event the sale does not go through, we will require the potential purchaser to not use or disclose your Personal Data in any manner whatsoever and to completely erase the same. 5. YOUR PRIVACY RIGHTS 5.1 You have several privacy rights in accordance with the data protection laws applicable to you. According to GDPR provisions, you have the right to access to your data processed by us, correct it, delete it, limit/restrict the processing of your data that can be performed by us, and you have the right to your Personal Data portability and the right to be notified about any possible data breaches of the safety of your Personal Data that may put at risk your rights to confidentiality and personal data protection. In order to exercise your rights, you can contact us at the addresses indicated in the section “HOW CAN YOU CONTACT US” below. You can also use your personal area within the App to directly perform the operations allowed therein. You can also lodge a complaint with the authority competent in your country, in accordance with applicable data protection laws. We may not be able to accommodate every request related to certain information if we believe this would violate any law or other legal requirement, or other data subjects' rights. 6. RETENTION OF PERSONAL DATA 6.1 We will retain your Personal Data as follows: (i) if you have submitted support requests without creating an account, for a period of 1 (one) year from our last communication; (ii) if you have
3 created an account, for a period of 3 (three) years from the date of the collection of such data; (iii) for marketing purposes, for a period of 3 (three) years from the date of collecting your consent, unless you request otherwise. Furthermore, if within the period indicated in paragraphs (ii) and (iii) you take actions on your account or on one of Pirelli's websites or apps (such as, by way of example and not limitation, registering for promotions or events, requesting new services, responding to surveys) that demonstrate your interest in maintaining the account or relationships and contacts with Pirelli related to Pirelli's products and/or services and/or Pirelli group companies, we will retain your Personal Data for an additional 3 (three) years from the date of registering such actions, without, however, sending marketing communications in the absence of your specific consent. Following the data retention periods for the purposes stated above, your Personal Data will be archived and retained where necessary (for example, in relation to products and/or services you have purchased or used, or in the event of your participation in contests), for the period of time required by applicable laws concerning the storage of data and documents for administrative, accounting, tax, and defensive purposes (in accordance with the applicable statute of limitations). 7. We will delete your Personal Data upon your request, if permitted, in accordance with the data protection laws applicable to you. COMMERCIAL ELECTRONIC COMMUNICATIONS 7.1 When you opt-in to receive direct marketing emails or communications, you consent to Pirelli to send you any promotional emails (including newsletters) and other commercial electronic communications concerning products and/or services of Pirelli or of other Pirelli Group Companies. You can always limit the communications that Pirelli sends to you. To refuse future commercial emails, simply click the link labelled “unsubscribe” at the bottom of any email Pirelli sends you. 7.2 Please note that even if you have decided to opt out of receiving future promotional emails, you may still need to be contacted by us for important information about your account, in accordance with applicable data protection laws. 8. WHERE WE STORE YOUR PERSONAL DATA 8.1 Pirelli will store your Personal Data on its IT systems based in the European Union. 9. PRIVACY POLICIES OF THIRD PARTIES 9.1 This Privacy Policy only addresses the use and disclosure of information by Pirelli. We are not responsible for the privacy policies of other websites or application that may be accessible from the App and encourage you to read all applicable terms, conditions and privacy policies provided by all third parties prior to providing them with your information. 10. LIMITATIONS TO MINORS’ PERSONAL DATA 10.1 If you are a minor, please do not provide us any Personal Data about yourself without the provision of adequate consent by the holder of parental responsibility over you. If we learn that we have collected Personal Data from a minor, without the holder of parental responsibility's consent, we will promptly delete that information. If you believe we have collected Personal Data from a minor, please contact us at the addresses indicated in the section “HOW CAN YOU CONTACT US” below.
4 11. SECURITY OF PERSONAL DATA 11.1 We have security protocols in place to protect your Personal Data from unauthorised access, improper use or disclosure, unauthorised modification, and unlawful destruction and accidental loss. We only allow access to our databases when necessary, and then under strict guidelines as to what use may be made of such data. 11.2 It is your responsibility to protect the security of your login information, and we recommend that you use a unique password for our App that is different from the password you may use on any other site or mobile application. 12. CHANGE OF PRIVACY POLICY 12.1 Our Privacy Policy may be subject to changes. The date the Privacy Policy was last revised is identified at the top of the page. 13. HOW TO CONTACT US 13.1 If you have questions or concerns regarding this Privacy Policy, or if you wish to review, edit your Personal Data or request that we delete Personal Data stored in the databases we actively use, please contact: Privacy.Europe@pirelli.com. You may also contact the Data Protection Officer of Pirelli Tyre S.p.A. at the Company's registered office, email: DPO_Ptyre@pirelli.com. ***** For Serbian users of DIABLO™ Super Biker App, contacts of local representative are as follows: Address: Karanovic & Partners o.a.d. Belgrade, Resavska 23, Belgrade, Serbia E-mail: pirelli.local.representative@karanovicpartners.com Tel: +38111-3094 200