Terms of Use

Version: 2.0 - August 2026

Applicable law: French law, GDPR (EU) 2016/679, EU Directives

Compliance: LCEN • French Consumer Code • Directive 2011/83/EU

This English text is a courtesy translation. The French version is the only authoritative version and prevails (see "Authoritative language version" below); French law applies.

Table of contents

Section 1 - IDENTIFICATION, LEGAL FRAMEWORK AND PRELIMINARY RESPONSIBILITIES

IDENTIFICATION OF THE PUBLISHER

In accordance with articles 6(I) and 6(II) of the LCEN (French Act for Confidence in the Digital Economy):

Company name: MIFELIA

Legal form: SASU (single-shareholder simplified joint-stock company)

SIRET number: 10268028700012

Registered office: 17 rue Saint-Jean, 54000 Nancy, France

Email address: contact@truffox.com

Telephone: 03 72 47 25 99

Legal representative / Publication director: MIFELIA

Representative's telephone number: 03 72 47 25 99

The Publisher is subject to all regulations applicable to information society services, in particular the LCEN, the GDPR, the French Consumer Code and Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights.

HOSTING INFRASTRUCTURE

Technical infrastructure: Google Cloud Platform (Firebase)

Server location: European Union

The Publisher ensures that the Application is hosted on infrastructure located within the European Union, guaranteeing compliance with the GDPR provisions on the location of personal data. Data is not transferred outside the EU, except for the third-party services listed in section 3.6 below, for which appropriate safeguards are implemented.

Hosting provider: Google Cloud Division

Hosting terms: https://cloud.google.com/terms/

DATA PROTECTION OFFICER

In accordance with article 37 of the GDPR, the Publisher appoints a data protection officer:

Title: Data Protection Officer (“DPO”)

Capacity: MIFELIA

Email address: dpo@truffox.com

Postal address: 17 rue Saint-Jean, 54000 Nancy, France

The Data Protection Officer is responsible for:

a) Monitoring compliance of personal data processing with the GDPR;

b) Acting as the point of contact with the French data protection authority (Commission Nationale de l'Informatique et des Libertés, “CNIL”);

c) Receiving and handling Users' requests to exercise their rights under articles 15-22 of the GDPR;

d) Ensuring compliance with professional secrecy;

e) Directing data protection requests received by the Publisher to the appropriate person.

Users may send any request relating to their personal data to the Data Protection Officer at the contact details above, within the time limits and under the conditions provided for by the GDPR.

APPLICABLE LAW AND JURISDICTION

These Terms of Use, together with the Privacy Policy and the Legal Notice, are governed entirely by the law of the French Republic, in particular:

- The French Civil Code (Articles 1101 et seq.);

- The French Consumer Code (Articles L. 211-1 et seq.);

- The French Commercial Code;

- Regulation (EU) 2016/679 (GDPR);

- Act no. 2004-575 of 21 June 2004 for Confidence in the Digital Economy (LCEN);

- Directive 2011/83/EU of the European Parliament and of the Council on consumer rights.

Any dispute, litigation or action arising from the application, interpretation or performance of these Terms of Use shall be subject to the subject-matter jurisdiction of the courts within the jurisdiction of the Publisher's registered office.

However, a consumer User residing within the European Union retains the right, under article 4(1) of Council Directive 93/13/EEC of 5 April 1993, to bring proceedings before the courts of their place of residence or domicile.

Before any legal action, the consumer User undertakes to comply with the prior mediation procedure set out in section 1.5 below.

Authoritative language version: These terms are drafted in French. Any translation into another language (in particular English, Spanish, Italian or German) is provided as a courtesy. In the event of any divergence, contradiction or difficulty of interpretation between the French version and a translated version, the French version alone is authoritative and prevails, and French law remains solely applicable in accordance with this section.

CONSUMER MEDIATION AND AMICABLE DISPUTE RESOLUTION

In accordance with article L. 611-1 of the French Consumer Code and articles 14 and 15 of Directive 2013/11/EU of the European Parliament and of the Council of 21 May 2013 on alternative dispute resolution for consumer disputes (“ADR Directive”), every consumer User has the inalienable right to use, free of charge and before any contentious proceedings, an out-of-court dispute resolution mechanism.

Designated consumer mediator: appointment in progress

Full address: to be specified shortly

Email address: to be specified shortly

Website: to be specified shortly

The mediation procedure follows these steps:

a) The consumer User first sends the Publisher a written and detailed request setting out their complaint, using the form available at contact@truffox.com, within two (2) months of the event giving rise to the dispute;

b) The Publisher undertakes to respond to this request within fourteen (14) calendar days;

c) If no amicable resolution is reached within two (2) months of the initial request, the consumer User may refer the matter to the consumer mediator at the contact details above;

d) Mediation is free of charge for the consumer and requires no additional legal fees.

The Publisher agrees to participate in the mediation procedure and to comply with the mediator's recommendations.

Section 2 - RIGHTS AND OBLIGATIONS

PURPOSE AND NATURE OF THE SERVICE

The “Truffox” Application is a community digital platform dedicated to pet owners (mainly dog owners), classified as an “information society service” within the meaning of article 1(1)(b) of Directive 2015/1535/EU of the European Parliament and of the Council of 9 September 2015.

Non-exhaustively, the Application allows:

a) The creation of one or more profiles of animals belonging to the User (name, breed, size, age, temperament, declared vaccination status, photograph);

b) The organisation of walks between Users: creation of an outing with date, place and participation terms (manual or automatic approval of requests);

c) Community discovery and listing of walking “spots” (parks, forests, beaches, etc.), with reviews and ratings left by Users;

d) Viewing and publishing community alerts reporting a localised, time-limited danger (treated area, presence of ticks, dangerous area), which other Users may confirm or invalidate;

e) Internal messaging attached to a given walk, allowing participants to exchange with each other;

f) A community loyalty programme (experience points, badges, monthly ranking) and a referral system between Users.

The Application is provided under a “Consumer-to-Consumer” (C2C) model: walks are organised and carried out directly between Users, without any involvement of the Publisher in how they actually take place and without any obligation of result as to the presence or behaviour of participants and their animals.

LEGAL CAPACITY, MINORS AND ACCESS RESTRICTIONS

2.2.1 Minimum age required

In accordance with the distribution rules of app stores (Apple App Store and Google Play Store), the Application is accessible from the age of 13. The Application has no age-verification mechanism of its own: access control for minors relies on the native tools provided by the app stores, which it is up to parents or legal guardians to activate and configure.

2.2.2 Parental consent and supervision

The creation of an account by a minor aged 13 to 15 requires the prior authorisation of their parents or legal guardians, in accordance with the digital consent threshold set by French law. The Publisher strongly recommends using the native parental control mechanisms provided by the app stores (such as Apple Family Sharing or Google Family Link) to approve downloads and supervise the minor's access.

2.2.3 Adults (18 years and over)

Adult users must have full legal capacity to be bound by these terms. The Publisher reserves the right to suspend or close the account of any user in the event of inappropriate use or use that does not comply with the community rules.

ACCOUNT CREATION AND MANAGEMENT

2.3.1 Creation formalities

To access the full features of the Application, the User must create a personal account by providing the following minimum information:

a) A valid, active email address under their exclusive control (in a format compliant with RFC 5322 standards);

b) A username (name displayed publicly) freely chosen by the User and not infringing the rights of any third party (trademark, copyright, image rights, legal provisions against discrimination);

c) A password of appropriate complexity, providing authentication that is sufficiently robust against unauthorised access;

d) A profile photograph (optional) which, where provided, will be subject to automatic filtering against nudity and other inappropriate content.

The User undertakes to provide accurate, complete, up-to-date, lawful information consistent with reality. The Publisher reserves the right to verify the accuracy of this information by any appropriate means.

2.3.2 Account security and responsibility

The User remains solely responsible for maintaining the absolute confidentiality of their authentication credentials (email address, password) and for the physical security of the device from which they access the Application.

The User assumes full civil and criminal liability for all activities carried out through their account, including activities initiated by a third party who has obtained access to their credentials.

The User undertakes to notify the Publisher immediately at contact@truffox.com in the event of suspected unauthorised access or fraudulent use of their account.

ACCOUNT DELETION AND DATA ANONYMISATION

2.4.1 Right to terminate and delete

The User may terminate their contractual relationship with the Publisher and delete their account at any time and without justification, by submitting a formal request through the Application interface (Settings > Delete account menu, after re-authentication and explicit confirmation) or by sending a written request to contact@truffox.com.

This deletion results in the immediate deletion of the authentication account and of access to the Application. The associated personal data held in the Publisher's databases is deleted within fourteen (14) days of the request, in accordance with articles 17-18 of the GDPR (Right to erasure).

2.4.2 Anonymisation of community content

Content published by the User and shared with the community (reviews of a spot or a walk, community alerts) may be retained after account deletion in anonymised form, stripped of any identifier that could trace it back to its author, in order to preserve the integrity and usefulness of community information (reliability of a spot, history of an alert). This anonymised data does not allow a natural person to be identified and is processed in a manner irreversibly dissociated from any personal identifier, in accordance with GDPR article 5(1)(e).

2.4.3 Inactive accounts

As of the date of these Terms of Use, the Publisher does not apply automated deletion of inactive accounts. Data is retained for the periods set out in section 3.5 (Retention periods) below and may be subject to periodic review in accordance with the data minimisation principle of article 5(1)(e) of the GDPR.

2.4.4 Complete and irrevocable deletion

A User wishing to obtain the total, definitive and irreversible deletion of all of their data, including anonymised and aggregated data, must make an explicit and formal request by registered letter with acknowledgement of receipt addressed to contact@truffox.com, with the following express mention in the subject line:

“REQUEST TO EXERCISE THE RIGHT TO ERASURE - ARTICLE 17 GDPR”.

The Publisher undertakes to process this request within thirty (30) calendar days of receipt of the request, extendable by a further two (2) months in the event of justified complexity in accordance with article 12(3) of the GDPR, and will inform the User of the measures taken.

INTERNAL MESSAGING, MODERATION AND REPORTING

2.5.1 Content rules

The Application allows Users to publish messages (messaging attached to a walk), reviews, descriptions of spots and alerts, as well as photographs (profile, animal, spot). The User undertakes to scrupulously comply with the following provisions:

a) Legality: All content must strictly comply with the applicable legal and regulatory provisions, in particular the French Criminal Code.

b) Prohibitions: All content constituting any of the following is strictly prohibited:

Defamatory, insulting, offensive or degrading statements;

Incitement to discrimination, hatred or violence against a person or group of persons on the basis of protected characteristics (origin, religion, sexual orientation, disability, etc.);

Child sexual abuse material, sexual exploitation of children or minors;

Threats of violence or intimidation;

Harassment, cyberbullying or intimidation;

Fraudulent content, scams or attempted scams;

Unsolicited advertising, spam or direct marketing without authorisation;

Deliberately published false community information (false spot, false danger alert);

Violent or obscene content or content contrary to public order.

2.5.2 Automatic moderation

The Application uses automated systems to moderate published content (text and photographs), designed to detect inappropriate language and inappropriate visual content before publication. These systems operate on a probabilistic basis and do not guarantee exhaustive coverage.

2.5.3 Community moderation

Certain content is moderated directly by the community:

a) Community alerts may be confirmed or invalidated by other Users who have observed the same situation, or its absence, on site;

b) Spots may be reported for invalid or outdated information.

2.5.4 Reporting and handling by the Publisher

Users may report any message, content or behaviour considered inappropriate, unlawful or in breach of these Terms of Use through the reporting functions available in the interface.

Each report must include a brief but precise description of the reason for the report. Vexatious or malicious reports intended to harass a User may result in the suspension or deletion of the reporter's account.

As of the date of these Terms of Use, reports are handled manually by the Publisher on a case-by-case basis; a dedicated moderation interface is under development. Manifestly unlawful content (child sexual abuse material, death threats, incitement to terrorism) is handled with absolute priority. Other violations are handled within a maximum of seven (7) calendar days where the Publisher's resources allow.

2.5.5 Moderation actions and effects

In response to a validated report or in the event of automatic detection of a substantial violation, the Publisher may take the following actions, depending on severity:

a) Warning notified to the User;

b) Removal of the offending content;

c) Temporary suspension of the account;

d) Permanent deletion of the account in the event of repeated or serious violations.

The User will have five (5) days to contest the moderation by writing to contact@truffox.com.

2.5.6 Limitations of liability regarding moderation

The Publisher cannot guarantee the completeness, perfect effectiveness or error-free nature of automated, community or manual moderation. Some infringing content may escape moderation; conversely, some lawful content may be removed by mistake.

The Publisher disclaims all liability for the consequences arising from imperfect moderation or a moderation error.

LIMITATION OF LIABILITY - WALKS AND INTERACTIONS BETWEEN USERS

2.6.1 Matchmaking platform only

The Application is a technical platform connecting pet owners who wish to organise or join walks. The Publisher does not in any way take part in the organisation, supervision or actual conduct of walks between Users.

The Application creates no contractual relationship between the Publisher and Users regarding the performance of the walks themselves; walks are organised and carried out directly between Users according to the arrangements agreed between them, without any involvement of the Publisher.

2.6.2 Exclusion of liability

The Publisher expressly disclaims all liability in the event of any incident, dispute, harm or damage of any kind arising from or relating to:

a) A meeting or a walk between Users and their animals;

b) An incident between animals (fight, bite, injury) or between an animal and a person, occurring during a walk organised through the Application;

c) An accident occurring during a walk (fall, injury, exposure to a hazard of the terrain), whether physical, material or immaterial;

d) The accuracy, timeliness or reliability of community information (condition of a spot, reality of a danger alert, declared vaccination status of a third party's animal);

e) Inappropriate, abusive, discriminatory, harassing or criminal behaviour of one User towards another;

f) Failures to honour commitments, promises or arrangements agreed between Users (time, place, participation in a walk);

g) A User's failure to comply with the regulations applicable to the keeping and movement of animals (Rural Code, municipal orders).

The Publisher assumes no obligation to verify the background of Users, the actual behaviour of their animals, or to carry out any prior check of information published by the community (spots, alerts, reviews).

2.6.3 Tools provided - Limited liability

The Publisher makes the following optional tools available to reduce perceived risks, without being able to guarantee their absolute effectiveness or assume responsibility for them:

a) Rating and review system for walks and spots;

b) Community confirmation or invalidation of danger alerts;

c) Reporting and blocking of another User suspected of inappropriate behaviour;

d) Manual approval of walk participants, at the discretion of its organiser;

e) Documented messaging: exchanges between participants create a record of the arrangements made, useful in the event of a dispute.

Despite the availability of these tools, the User remains solely responsible for assessing the risks and for their decisions regarding meetings with other Users and their animals.

2.6.4 User responsibility

The User retains full responsibility for their decisions and actions, in particular:

a) Assessing the profile and reliability of other participants before a walk;

b) The compatibility and supervision of their own animal in contact with other animals and people;

c) Compliance with safety rules (keeping the animal on a lead in accordance with local regulations, up-to-date vaccinations, cleanliness);

d) Verifying community information by their own means (condition of a spot, reality of an alert) before relying on it;

e) Compliance with the regulations applicable to the keeping and movement of animals.

The Publisher formally recommends to all Users:

To first meet the other participants in a public place and to check the sociability of the animals before a longer walk;

Never to leave an animal unattended with unknown animals or people;

To check community alerts and spots out of caution rather than relying on them blindly;

To immediately report any suspicious or dangerous behaviour, or any manifestly erroneous information.

Section 3 - PROTECTION OF PERSONAL DATA (GDPR)

DATA CONTROLLER AND DPO

In accordance with article 37 of the GDPR, the Publisher of the Application designates the following entities responsible for the processing of personal data:

Main data controller:

Legal entity: MIFELIA

Address: 17 rue Saint-Jean, 54000 Nancy, France

Email address: contact@truffox.com

Telephone: 03 72 47 25 99

Data Protection Officer (DPO):

Capacity: MIFELIA

Email address: dpo@truffox.com

The data controller determines the purposes and means of processing Users' personal data. The DPO monitors compliance of the processing with the GDPR and is the focal point of contact for Users and supervisory authorities (CNIL).

CATEGORIES OF PERSONAL DATA COLLECTED

The Application collects the following categories of personal data:

IDENTIFICATION DATA (Articles 4(1), 5(1)(a) GDPR):

Email address provided at registration

Username chosen by the User

Password (stored in irreversibly hashed form)

Profile photograph (JPG/PNG image provided voluntarily, automatically filtered)

[Optional] Year of birth

DATA RELATING TO THE USER'S ANIMALS:

Name, species, breed, size, age, temperament of the animal

Declared vaccination status

[Optional] Microchip number

Photograph of the animal (automatically filtered)

GEOLOCATION DATA (Article 4(1) GDPR - sensitive by nature):

GPS coordinates of the User's position

Collected during active use of the map (display, search for nearby walks, spots or alerts) and when creating a walk, a spot or an alert

The Application does not carry out continuous or background GPS tracking outside these active uses

Accuracy: up to 5-10 metres (depends on the GPS receiver)

ACTIVITY AND USAGE DATA:

History of walks created, joined and viewed

Spots created and reviews left

Alerts published and confirmations/invalidations made

Connection dates and times (timestamps)

Device type (iOS / Android)

Operating system version

Application version

Ratings and reviews left by or for the User

Messages sent and received as part of a walk (text content)

Experience points, badges, monthly ranking, referral code

TECHNICAL AND CONNECTIVITY DATA (Article 6(1)(f) GDPR - legitimate interest):

Device IP address (IPv4/IPv6 type)

Unique device identifier (UDID, UUID)

Connection type (WiFi, mobile data 3G/4G/5G)

Authentication and access logs

PAYMENT DATA (Not applicable - the Application is entirely free):

No paid feature exists to date. No payment data (banking, in-app billing) is collected, processed or stored by the Publisher.

LEGAL BASES FOR PROCESSING

In accordance with article 6 of the GDPR, each processing of personal data is based on a specific legal basis:

3.3.1 Performance of the contract (Article 6(1)(b) GDPR)

Purpose: Providing the contractual services

Data concerned:

Email address, username, password

Walk, spot, alert and animal profile data

Duration: For the duration of the contract and in accordance with article 5(1)(e) GDPR

3.3.2 Consent (Article 6(1)(a) GDPR)

Purpose: Processing of data beyond contractual obligations

Data concerned:

Geolocation when using the map

Demographic data (year of birth)

Cookies and analytics tools

Formality: Explicit consent obtained via popup or toggle switch

Right of withdrawal: The User may withdraw their consent at any time via contact@truffox.com

3.3.3 Legitimate interest (Article 6(1)(f) GDPR)

Purpose: Security, fraud prevention, service improvement

Data concerned:

Technical data (IP, device identifiers)

Access logs

Interaction history

Balance: The Publisher has carried out a legitimate interest assessment showing that the processing does not exceed Users' reasonable expectations

Right to object: The User may object to this processing via contact@truffox.com

3.3.4 Legal obligation (Article 6(1)(c) GDPR)

Purpose: Legal compliance and requests from authorities

Data concerned: Any data required by law

Examples:

Disclosure of security logs to a judicial authority

Retention of accounting records for tax purposes

Notification to the CNIL in the event of a breach

Duration: According to the statutory retention periods

SPECIFIC PURPOSES OF PROCESSING

Personal data is processed for the following purposes:

a) PROVISION OF THE SERVICE:

Creation and management of the User account and animal profiles

Connecting Users via the platform (walks, spots)

Delivery of messages within a walk's messaging

Delivery of community alerts

Display of ratings and reviews

b) SECURITY AND FRAUD PREVENTION:

Detection of fraudulent use

Prevention of cyberattacks

Moderation of content violating the Terms of Use

Handling of reports

Blocking of suspicious accounts

c) IMPROVEMENT AND OPTIMISATION:

Aggregated (not individual) statistical analyses

A/B tests to optimise the interface

Identification of bugs and malfunctions

d) LEGAL COMPLIANCE:

Compliance with the GDPR and French legal obligations

Response to requests from competent authorities

Notification to the CNIL in the event of a breach

Retention of evidence for potential disputes

e) COMMUNICATION:

Service-related notifications (incoming messages, nearby alerts)

Moderation notifications (suspension, warning)

Policy or terms updates (if accepted)

RETENTION PERIODS

In accordance with article 5(1)(e) of the GDPR (storage limitation), data is retained for the following periods:

PERSONAL IDENTIFIABLE DATA (email address, username, photo):

Active period: For the entire duration of the active account

After account deletion: Deletion within 14 days

WALK, SPOT AND ALERT DATA:

Retention period: Two (2) years from publication

Reason: To allow community history and the resolution of disputes

After 2 years: Automatic deletion or anonymisation

GEOLOCATION DATA:

Duration: Deletion or anonymisation after the walk is closed or the relevant alert expires

PAYMENT DATA (Not applicable - the Application is free):

No payment data is collected, processed or stored by the Publisher.

MESSAGING DATA:

Duration: Retained during the contractual relationship

After account deletion: Retention possible for investigation if a dispute is reported

Without a dispute: Deletion possible within 90 days

AGGREGATED AND ANONYMISED DATA:

Duration: Indefinite retention

Definition: Data with no link to an identified person

Use: Statistics, research, service improvement

DATA TRANSFERS OUTSIDE THE EU

In accordance with article 44 of the GDPR, a data transfer may exceptionally occur to third countries (countries outside the European Union).

3.6.1 Hosting infrastructure

The Application is hosted on Google Cloud Platform (Firebase), whose active data servers are located within the European Union. As a matter of principle, no transfer to third countries is necessary for hosted data.

As a backup or in the event of a security incident, Google may temporarily route data to backup servers located outside the EU (in particular the United States).

3.6.2 Transfers to the United States - Appropriate safeguards

Under article 46 of the GDPR, data transfers to the United States (in particular for the services described in section 3.7 below) benefit from the following appropriate safeguards:

a) Standard Contractual Clauses (SCC): The contracts binding the Publisher to its providers incorporate the SCCs adopted by the European Commission (Commission Decision 2021/914).

b) Additional clauses: Additional technical measures of encryption and anonymisation may be implemented to reduce the risk.

c) Schrems II compliance: The Publisher has conducted a post-Schrems II compliance analysis to verify that the US legal framework (in particular the Cloud Act, FISA) would not undermine the level of protection of the GDPR.

3.6.3 Right to object to transfers outside the EU

Any User concerned about a transfer of their data outside the EU may object to this transfer by writing to the DPO (contact: dpo@truffox.com). The Publisher will examine the request and may propose mitigating measures (storage of data in the EU only).

PROCESSORS AND THIRD-PARTY PROVIDERS

In accordance with article 28 of the GDPR, the Publisher undertakes to process personal data only through duly contracted processors offering appropriate safeguards.

The main processors are:

DATA HOSTING:

Name: Google Cloud Platform (Firebase)

Activity: Database hosting, authentication, file storage, IT infrastructure

Location: European Union

Contract: Signed data processing agreement (Data Processing Agreement)

Data processed: All user data

Purpose: Secure storage and operation of the Application

Safeguards: GDPR compliance, ISO 27001 certifications, SCC

MAPPING AND GEOCODING:

Name: OpenStreetMap Foundation (Nominatim service, reverse geocoding) and CartoDB (base map, distributed via the Fastly CDN)

Activity: Conversion of a GPS position into a readable address; display of the Application's base map

Location: OpenStreetMap Foundation (United Kingdom); Fastly (United States, SCC safeguards)

Data processed: GPS coordinates transmitted during an address search or when the map is displayed

Purpose: Map display and address search

TRANSACTIONAL EMAILS:

Name: Brevo

Activity: Sending of account-related transactional emails (password reset, confirmations)

Location: European Union (France)

Data processed: Email address, content of the transactional email

Purpose: Communication related to the User account

STATISTICAL ANALYSIS:

Name: Google Analytics / Firebase Analytics

Activity: Aggregated analysis of user behaviour

Location: United States (SCC safeguards apply)

Contract: Data Processing Agreement

Data processed: Aggregated user events (no personally identifiable data)

Purpose: Improvement of the Application and of the truffox.com website

Safeguards: Anonymised data, masked IP

ADVERTISING MEASUREMENT (truffox.com website):

Name: Meta Platforms, Inc. (Facebook Pixel)

Activity: Measurement of the effectiveness of advertising campaigns and of site visits

Location: United States (SCC safeguards apply)

Contract: Meta Pixel data terms

Data processed: Browsing events on the site, advertising identifiers

Purpose: Advertising measurement and remarketing

Safeguards: Loaded only after the User's consent via the cookie banner

PUSH NOTIFICATIONS:

Name: Google Cloud Messaging (GCM) / Apple Push Notification service (APNs)

Activity: Delivery of notifications

Location: United States (SCC safeguards apply)

Contract: Standard store contracts

Data processed: Notification identifier, message content

Purpose: Delivery of notifications relating to walks, spots and alerts

PAYMENT (Not applicable):

As the Application is entirely free, no payment provider or billing processor (such as Stripe, Google Play Billing or Apple In-App Purchase) is used.

The Publisher guarantees that each of these processors is bound by a written contract governing the processing of data in accordance with article 28 of the GDPR. These contracts include in particular:

- Confidentiality obligations

- Technical and organisational security measures

- Users' rights

- Assistance in the event of a legal request

- Deletion or return of data at the end of the contract

The User may request the full and up-to-date list of processors via contact@truffox.com.

SECURITY OF PERSONAL DATA

In accordance with article 32 of the GDPR and the requirements of the NIS2 Directive, the Publisher implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental disclosure, alteration and destruction.

TECHNICAL MEASURES:

a) Encryption in transit: Data transmitted between the User's device and the Publisher's servers is encrypted using the TLS 1.2+ protocol (HTTPS).

b) Encryption at rest: Data stored in the database benefits from symmetric or asymmetric encryption depending on sensitivity.

c) Network isolation: Data is isolated in dedicated subnets and environments, inaccessible to the public internet.

d) Access management: Role-based access control (RBAC) limiting access to personnel with a need to know.

e) Security logs: Recording of all accesses and modifications for compliance audit.

ORGANISATIONAL MEASURES:

a) Security policy: Formalised document defining security standards.

b) Staff awareness: Training on security risks and GDPR compliance.

c) Incident management: Escalation and investigation protocol in the event of a suspected security breach.

LIMIT OF LIABILITY REGARDING SECURITY:

Despite the implementation of security measures, no IT security system is entirely infallible or invulnerable. The Publisher does not guarantee absolute security against sophisticated cyberattacks, hacking by a third party, or catastrophic failures.

USER RIGHTS - ARTICLES 15-22 GDPR

In accordance with articles 12-22 of the GDPR, the User has the following rights regarding their personal data. These rights are exercised by sending a written and dated request to the Data Protection Officer (DPO) at the contact details given in section 1.3 above, together with proof of identity.

3.9.1 RIGHT OF ACCESS (Article 15 GDPR)

The User may request confirmation of the processing of their personal data and access to a copy of all such data within thirty (30) calendar days of receipt of the request (extendable by 2 months in the event of justified complexity).

Procedure:

- Request: Email or registered letter to the DPO

- Required content: Identification of the User, clarification of the data requested

- Form of transmission: Electronic copy in a structured format (e.g. CSV)

- Cost: Free for the first request; additional copying costs possible for manifestly unfounded or excessive requests

3.9.2 RIGHT TO RECTIFICATION (Article 16 GDPR)

The User may require the correction of inaccurate, incomplete or outdated data concerning them, without undue delay.

Procedure:

- Request: Via contact@truffox.com or the settings interface (Profile > Edit my data section)

- Processing: Without undue delay, and at most within 30 days

- Consequences: Corrected data will be updated in all systems

3.9.3 RIGHT TO ERASURE (Article 17 GDPR) - “Right to be forgotten”

The User may request the complete erasure of their personal data in the following cases:

a) The data is no longer necessary in relation to the purposes for which it was collected;

b) The User withdraws their consent and no other legal basis justifies the processing;

c) The User objects to the processing and there are no overriding legitimate grounds;

d) The data has been unlawfully collected;

e) Erasure is necessary to comply with a legal obligation.

Processing time: Thirty (30) calendar days (extendable by 2 months).

Exceptions - Right to erasure not applicable:

- If the processing is necessary to comply with a legal obligation (e.g. tax obligation to retain data for 6 years);

- If the processing is necessary for the establishment, exercise or defence of legal claims;

- If the User has been involved in criminal activity and the data constitutes evidence.

3.9.4 RIGHT TO RESTRICTION OF PROCESSING (Article 18 GDPR)

The User may request restriction of processing (temporary suspension) if:

a) The accuracy of the data is contested and the Publisher must verify its accuracy;

b) The processing is unlawful but the User opposes erasure;

c) The data is no longer necessary in relation to the purposes, but the User needs it for the establishment, exercise or defence of legal claims;

d) The User has objected to the processing pending verification of the Publisher's legitimate grounds.

Effect: The data will be retained but processed only with the User's consent or for the purposes of legal defence.

3.9.5 RIGHT TO DATA PORTABILITY (Article 20 GDPR)

The User may receive a copy of their personal data in a structured, commonly used and machine-readable format (e.g. CSV, JSON format), and transmit this data to another controller without hindrance.

Limits of the right:

- Applies only if the processing is based on consent (article 6(1)(a)) or performance of the contract (article 6(1)(b));

- Portability must not affect the rights or freedoms of others;

- The Publisher may refuse if the request is manifestly unfounded or excessive.

3.9.6 RIGHT TO OBJECT (Article 21 GDPR)

The User may object, on grounds relating to their particular situation, to the processing of their personal data carried out on the basis of legitimate interest (article 6(1)(f)), in particular:

- Objection to profiling or predictive analysis;

- Objection to processing for direct marketing purposes;

- Objection to security or fraud prevention processing.

Upon receipt of the objection, the Publisher ceases the processing, unless it demonstrates compelling legitimate grounds that override the interests or rights of the User.

3.9.7 RIGHT NOT TO BE SUBJECT TO AUTOMATED DECISION-MAKING (Article 22 GDPR)

The User has the right not to be subject to a decision based solely on automated processing (in particular profiling) which produces legal effects or similarly significantly affects them.

Exceptions:

- The decision is necessary for entering into or performing a contract;

- The decision is authorised by law;

- The User has given their explicit consent.

In these cases, the Publisher will provide the User with explanations of the logic of the processing and the measures to safeguard their rights.

3.9.8 RIGHT TO LODGE A COMPLAINT (Article 77 GDPR)

The User has the inalienable right to lodge a complaint with the competent supervisory authority (Commission Nationale de l'Informatique et des Libertés - CNIL in France) if the User considers that their rights under the GDPR are not being respected.

CNIL contact details:

Website: https://www.cnil.fr

Address: 3 Place de Fontenoy, 75007 Paris, France

Telephone: +33 1 53 73 22 22

The User may lodge their complaint without prejudice to any other administrative or judicial remedy.

PROCESSING OF MINORS' DATA (ARTICLE 8 GDPR)

In accordance with Article 8 of the GDPR and the digital consent threshold set at 15 years by French law:

- The Application is not intended for children under 13, in accordance with the distribution conditions of app stores; access at that age must be entirely supervised by the legal representative via the family sharing of app stores.

- From 13 to 14 years old, the prior and explicit authorisation of parents or legal guardians is mandatory for the processing of their personal data.

- From the age of 15, the minor may lawfully consent themselves to the processing of their personal data for the use of the Application.

Legal representatives have at any time a right of access, rectification and complete erasure of the minor's personal data by writing to the DPO at dpo@truffox.com.

PERSONAL DATA BREACH - NOTIFICATION TO THE CNIL

3.11.1 Definition and notification threshold

A “personal data breach” is the unauthorised access to, disclosure, destruction or alteration of personal data due to a security failure (hacking, theft, error, etc.).

In accordance with article 33 of the GDPR, the Publisher notifies the CNIL of any substantial breach within seventy-two (72) hours of discovery, unless the breach is unlikely to result in a risk to the rights and freedoms of the natural person.

3.11.2 Risk assessed

The Publisher assesses the risk according to the following criteria:

- Nature and volume of the data compromised

- Number of persons affected

- Identifiability of the persons (personally identifiable or anonymised data?)

- Likelihood and severity of the risk (accidental access vs. intentional theft?)

A risk is qualified as “substantial” if a breach could result in:

- Discrimination

- Identity theft

- Violation of privacy

- Moral or material damage

3.11.3 Notification process

Upon discovery of a substantial breach:

Step 1 (H+0-24h): Technical isolation of the breach, audit of the unauthorised access.

Step 2 (H+24-48h): Internal notification to the DPO.

Step 3 (H+48-72h): Notification to the CNIL via the online form (https://www.cnil.fr), including:

- Description of the breach

- Date and discovery

- Data affected

- Number of persons

- Corrective measures taken

- DPO contact

Step 4 (H+72h+): Notification of affected Users by email or in-app notification, in simple and transparent language.

3.11.4 Content of the notification to Users

The notification to affected Users includes:

- Clear description of the breach

- Personal data compromised

- Likelihood and type of risk

- Corrective measures put in place

- Recommendations (change password, monitor account, etc.)

- DPO contact details for questions

- GDPR rights (right of access, erasure, etc.)

3.11.5 Obligation not to disclose to malicious third parties

The Publisher undertakes NOT to disclose breached data to malicious third parties in exchange for silence (cyber ransom). In the event of a ransom demand, the breach is immediately reported to the competent authorities (police, cybercrime).

Section 4 - LIABILITY AND LIMITATIONS OF LIABILITY

INDEMNIFICATION BY THE USER

In accordance with articles L. 131-1 et seq. of the French Consumer Code and the general principles of French contract law, the User agrees to indemnify, defend and hold harmless the Publisher, its owners, officers, employees, agents, providers and partners from any damage, loss, penalty, fine, cost or expense, including attorneys' fees and legal costs, arising from or directly or indirectly related to:

a) The User's breach of these Terms of Use or of any applicable law;

b) The User's infringement of the rights of a third party (copyright, trademark rights, image rights, right to confidentiality);

c) Content published or transmitted by the User on the Application;

d) Their interactions, communications or meetings with other Users;

e) Unauthorised, fraudulent or unlawful use of the Application;

f) Failure to comply with the recommended safety or good conduct rules;

g) Harm to the rights or freedoms of others arising directly from their actions on the Application.

FORCE MAJEURE - COMPLETE EXEMPTION FROM LIABILITY

The Publisher cannot be held liable for any failure or delay in the performance of its obligations under these Terms of Use resulting from an event constituting force majeure, within the meaning of articles 1218 and 1220 of the French Civil Code.

Events of force majeure include in particular:

a) Natural disasters: earthquakes, floods, storms, seismic events, volcanic eruptions, landslides, extreme weather conditions;

b) Political or military human acts: war, acts of terrorism, insurrection, civil unrest, coup d'état, government embargo;

c) Failure of third-party infrastructure: massive telecommunications service interruptions, internet provider outage, failure of the electricity supplier;

d) Cyberattacks: massive DDoS attacks, sophisticated computer hacking, ransomware affecting the infrastructure, security failure of a third-party provider (Google Cloud, etc.);

e) Epidemics or pandemics: government lockdown, movement restrictions, forced closures of critical facilities;

f) Technical failure: prolonged power outage, server failure beyond the Publisher's control, irreversible data corruption;

g) Accident: disaster affecting the critical premises of the Publisher or its providers.

During the period of force majeure, the Publisher will not be liable for the unavailability of the Application. The period of non-performance may be extended for as long as the event persists, provided that the Publisher takes reasonable measures to minimise its impact and resume the service.

Notification: The Publisher endeavours to notify Users of any prolonged force majeure event.

SERVICES PROVIDED “AS IS” - EXCLUSION OF WARRANTIES

The Application is provided as is (“AS IS”) without any warranty, express or implied, in particular:

a) No warranty as to the accuracy, completeness, reliability or relevance of the content;

b) No warranty as to the uninterrupted availability of the service;

c) No warranty as to the absence of viruses, malware or malicious code;

d) No warranty as to meeting the User's expectations;

e) No warranty as to the absence of errors or failures;

f) No warranty as to compatibility with all devices, operating systems or network configurations;

g) No implied warranty of merchantability or fitness for a particular purpose.

This exclusion of warranties applies even in the event of a defect, error or malfunction notified to the Publisher.

LIMITATION OF LIABILITY - DAMAGE CAPS

As the Application is entirely free, the User has paid no sum to the Publisher for access. Except in cases of mandatory statutory liability, the Publisher's liability is accordingly nil, except in the event of a deliberate breach of the GDPR or the exceptions listed below.

This limitation applies to all types of damages, direct or indirect, including:

a) Loss of revenue or profit;

b) Loss of data;

c) Loss of clientele;

d) Business interruption;

e) Moral damages;

f) Punitive damages.

Exceptions (unlimited liability):

Notwithstanding the above limitations, the Publisher's liability remains full and unlimited in the event of:

- Death or personal injury (which cannot be excluded under article L. 211-5 of the Consumer Code)

- Intentional misconduct or fraud by the Publisher

- Intentional breach of the GDPR

- Breach of consumer law (articles L. 211-1 et seq.)

- Cases where liability must mandatorily be invoked (Article 1217 of the French Civil Code)

Section 5 - FINAL PROVISIONS

LEGAL COMPLIANCE - USER OBLIGATIONS

The User undertakes to use the Application in strict compliance with:

a) All laws, regulations, orders and directives applicable in their jurisdiction;

b) The rights of a third party (intellectual property, image rights, right to privacy, moral rights of authors);

c) These Terms of Use, the Legal Notice and the Privacy Policy;

d) The safety recommendations published by the Publisher.

The User accepts that any breach of this obligation gives rise to their civil, criminal and administrative liability.

SEVERABILITY AND ENTIRE AGREEMENT

5.2.1 Severability

If a provision of these Terms of Use is held to be invalid, unenforceable, unlawful or contrary to public policy by a competent court, that provision shall be severed and annulled, without affecting the validity, enforceability and legal effect of the other provisions.

5.2.2 Entire agreement

These Terms of Use, together with the Privacy Policy and the Legal Notice, constitute the entire and exclusive agreement between the User and the Publisher concerning access to and use of the Application.

They cancel and replace any prior agreement, written or oral, between the parties relating to the same subject matter.

No provision may be modified, deleted, extended, interpreted differently or supplemented except by:

a) A writing signed by both parties (amendment agreement);

b) An official update published by the Publisher on this page with an indication of the modification date and notification to Users.

MODIFICATION OF THE TERMS OF USE

The Publisher reserves the right to modify all or part of these Terms of Use at any time and without prior justification.

Modification procedure:

a) Modifications are published on this page with a clear indication of the update date and the effective date;

b) In the event of a substantial modification, the Publisher will notify Users via in-app notification and/or email within the fourteen (14) days preceding the effective date;

c) Users have a reasonable period (minimum 14 days) to review the modifications;

d) Continued use of the Application after the effective date constitutes acceptance of the modifications;

e) A User who rejects the modifications must terminate their account and stop using the Application before the effective date.

The Publisher undertakes to regularly publish an updated version of the Terms of Use on its website, with a history of modifications.

COOKIES AND TRACKING TOOLS

The mobile Application does not use cookies in the traditional Web sense (HTTP files). However, it stores locally on the User's device:

- Authentication identifiers (JWT token)

- User preferences (language, theme, display settings)

- Data cache to improve performance

No behavioural advertising tracking data is currently collected.

If behavioural advertising tools are activated in the future, prior notification will be sent to Users and the terms will be updated accordingly, with an opt-out or accept/refuse mechanism.

PUBLIC VISIBILITY AND SEARCH ENGINE INDEXING

User profiles, walks, spots and alerts published on the Application are NOT indexable by public search engines (Google, Bing, Yahoo, etc.) and remain accessible only via the Application to other registered Users.

Indexing robots (“crawlers”) are explicitly blocked via the robots.txt file and “noindex” meta tags.

If a User wishes their data to be removed from Internet archives (Internet Archive, search engine caches), they may make a request to the DPO.

CONTACT AND COMPLAINTS

For any question, request for information, exercise of GDPR rights or complaint concerning the Application, the User may contact the Publisher:

By email: contact@truffox.com

By registered letter: 17 rue Saint-Jean, 54000 Nancy, France

By telephone: 03 72 47 25 99

The Publisher undertakes to acknowledge receipt of any request within seven (7) working days and to process the request in accordance with the applicable legal time limits (30 days GDPR, 14 days Consumer Code, etc.).

Complaints: The User may lodge a complaint with:

- The Publisher directly (addresses above)

- The consumer mediator (see section 1.5)

- The CNIL (in the event of a GDPR question)

- The competent courts (in the event of a dispute)

ANALYTICS AND TRACKING TOOLS

Analytics - Firebase Analytics and Google Analytics (truffox.com website)

The Application and the truffox.com website use Firebase Analytics and Google Analytics respectively to collect aggregated data on the use of the service, in particular: user events, pages viewed.

The data collected is limited to the minimum necessary and is not subject to any additional consent request beyond acceptance of these Terms of Use.

Analytics data is processed anonymously or in pseudonymised form and does not allow direct identification of the User. It is used solely for the purposes of improving and optimising the service.

Provider: Google LLC | Compliance: Standard Contractual Clauses (GDPR)

Section 6 - LEGISLATIVE COMPLIANCE AND REGULATION

COMPLIANCE WITH APPLICABLE REGULATIONS

The Application and the Publisher comply with all applicable regulations, in particular:

FRENCH LAW:

- Civil Code (articles 1100 et seq. - contract law)

- Consumer Code (articles L. 211-1 et seq. - consumer protection)

- Commercial Code (articles L. 122-1 et seq. - electronic commerce)

- Rural and Maritime Fishing Code (keeping and movement of pets)

- Act no. 2004-575 of 21 June 2004 for Confidence in the Digital Economy (LCEN)

- Act on Information Technology and Liberties of 6 January 1978, as amended

- Act of 22 July 2020 on the protection of children's privacy

EUROPEAN LAW:

- Regulation (EU) 2016/679 of 27 April 2016 (GDPR)

- Directive 2011/83/EU of 25 October 2011 (consumer rights)

- Directive 2013/11/EU of 21 May 2013 (consumer mediation - ADR)

- Directive 2015/1535/EU of 9 September 2015 (digital services)

- Directive (EU) 2022/2555 of 14 December 2022 (NIS2 - cybersecurity)

REPORTING OBLIGATIONS - CNIL

In accordance with article 30 of the GDPR, the Publisher maintains a record of processing activities (“GDPR Register”) detailing:

- The purposes of each processing operation

- The categories of data

- The categories of recipients

- The retention periods

- The security measures

This register is kept available to the CNIL as proof of compliance.

CNIL notification number: In progress

MODERATION RESPONSIBILITY - LCEN

In accordance with article 4 of the French Act for Confidence in the Digital Economy (LCEN), the Publisher carries out moderation of content published by Users.

Under this article, the Publisher cannot be held liable for unlawful content as long as it has not had actual knowledge of it and acts promptly after receiving notification.

Upon receipt of a notification of unlawful content, the Publisher undertakes to process the request within seven (7) days and to proceed with removal if the content constitutes a manifest criminal offence.

APPENDICES

APPENDIX A - STANDARD CONTRACTUAL CLAUSES (SCC) - SUMMARY

Under article 46(2)(c) of the GDPR, exceptional data transfers outside the EU benefit from the standard contractual clauses (SCC) adopted by the European Commission.

These SCCs guarantee a level of protection equivalent to that of the GDPR, in particular through:

- Confidentiality obligation of the third-party controller

- Restriction of use to authorised purposes only

- Appropriate technical security measures

- Right of access and audit of the Publisher

- Obligation of notification in the event of a breach

- Right of complaint of Users

Applicable European Commission decision: 2021/914/EU of 4 June 2021.

APPENDIX B - ESSENTIAL CONTACTS

DATA CONTROLLER:

MIFELIA

Address: 17 rue Saint-Jean 54000 Nancy, France

Contact: contact@truffox.com

Telephone: 03 72 47 25 99

DATA PROTECTION OFFICER (DPO):

Name / Capacity: MIFELIA

Email: dpo@truffox.com

Address: 17 rue Saint-Jean 54000 Nancy, France

CONSUMER MEDIATOR:

Name: Appointment in progress

Email: To be specified shortly

Address: 17 rue Saint-Jean 54000 Nancy, France

Website: To be specified shortly

CNIL (Supervisory authority - France):

Address: 3 Place de Fontenoy, 75007 Paris, France

Telephone: +33 1 53 73 22 22

Website: https://www.cnil.fr

DOCUMENT UPDATED ON: 27 August 2026

These Terms of Use represent the complete agreement between the Publisher and the User. Any use of the Application after acceptance implies full adherence to them.