Personal Data Protection Policy

The Automobile Club de l'Ouest attaches particular importance to ensuring the confidentiality of the personal data it collects and uses as part of its activities, and more generally to the protection of customer privacy.

This Privacy Policy describes how personal data is collected when Customer’s connect to and use the Automobile Club de l'Ouest websites ("Sites") and mobile applications ("Apps"). The policy also informs how personal data is used and protected by the Automobile Club de l'Ouest, customer rights and how to contact the ACO.

This policy is an important document. We recommend reading it attentively and checking regularly for modifications.

Responsibility for processing personal data

The following is responsibility for processing personal data:

The Automobile Club de l’Ouest, association loi de 1901, SIREN 775 652 316,

24 Heures Circuit

72019 Le Mans Cedex 2 France

Contact our data protection officer at the following address for any questions regarding use of your data of if you wish to send us comments, suggestions or concerns: dpo@lemans.org

Personal Data collected by the ACO

The Automobile Club de l’Ouest only collects data necessary and pertinent received from Customers via sites, apps and services used at the 24 Heures du Mans circuit, in regional agencies and official stores.

In certain cases, Customer’s communicate personal information directly, particularly when you create an account, make a purchase, registers for newsletter or participate in a competition.

You provide the following information:

- identification data: surname, first name, birth date

- contact data: postal and email address, phone number

- data associated with operations conducted on our sites and apps: purchase of tickets products, type of subscription, order history

- payment data (bank account details) and other information associated with transactions

- reviews and comments posted on the sites and apps

- event data: hour of arrival, entrance used, images.

In other cases, the ACO collects data by using cookies to understand how you use our Sites and Apps.

We collect the following personal data automatically and directly from Customers when they use our services:

- the IP address and device ID

- data about the browser or device: name, operating system, preferred language

- authentication data: connection and use logs, IP address, unique login

- browser data: sites or app visited, last pages consulted, ads clicked, products searched, length of visit, products place in your shopping cart, etc.

Children’s data

We encourage parents to raise their children’s awareness about the protection of their privacy and how they communicate on the internet.

We respect pertinent legal provisions and do not authorise children under 16 to register on our site or apps. We request the authorisation from legal guardians when they create a Site or App or for their participation in operations conducted by the Automobile Club de l’Ouest, such as competitions.

How the ACO uses Customer data

The Automobile Club de l’Ouest uses Customer data to:

- provide you with requested products and services

- process and ensure order tracking including product delivery

- communicate with you about the purchase or the event attended by the Customer

- answer Customer questions, solve problems and receive Customer reviews

- register Customer participation in a competition, predictions, surveys

- manage payment for purchases.

The ACO also processes data for reasons other than the strict execution of the contract, subject to prior verification for legitimate reasons. The ACO process data for:

- organising marketing campaigns and sales promotions

- carrying out studies and collecting statistics to improve your experience

- analyse use of products and services to improve our range

- identify and correct bugs in our Sites and App to ensure the function correctly

- ensure your protection against any fraudulent transactions or embezzlement

- guarantee the exercise of personal data rights.

The ACO also processes Customer data, within the limits and in compliance with the provisions of Article L. 332-1 of the French sports code, for the purpose of ensuring the security of sporting events by refusing or cancelling, where applicable, the issue of access tickets to such events or access to persons who have violated or contravene the provisions of the general terms and conditions of sale or regulations relating to the security of such events.

If you agree, the ACO sends marketing information and details about products, services and events organised by the Automobile Club de l'Ouest and its partners.

Access to your personal data

The Automobile Club de l’Ouest may transfer your personal data to:

- service providers who supply a product or service: postal and delivery services for example;

- payment service providers for payment operations and checks;

- third-party IT service providers such as platform providers, hosting services, technical support for software and applications which may contain Customer data, data analysis and emails;

- service providers associated with the organisation of events organised by the Automobile Club de l’Ouest including access and security on the 24 Heures du Mans circuit;

- administrative, judicial and supervisory authorities when required by the law.

However, no Customer data will be given to partners for marketing or commercial purposes without your consent.

The Automobile Club de l'Ouest also ensures that its partners and service providers comply with current regulations.

Duration of personal data storage

Customer personal data will be stored as long as necessary to fulfil the purposes in this policy within legal time limits.

We store Customer personal data when the last connection to the customer account was less than three (3) years ago.

When you buy products or services (ticket office, store etc.) from the Automobile Club de l'Ouest or participate in an ACO event, the ACO may store your personal data for a longer period to comply with legal obligations and applicable limitation periods.

Transfer of Customer personal data outside the EU

Customer personal data may be processed outside the EU. In this case, we take necessary measures with our service providers to ensure data protection in compliance with current regulations.

If the service providers concerned are not party to the Privacy Shield agreement for transfers to the United States of America, or are not located in a country with legislation considered to offer adequate protection, they will then have previously signed the "standard contractual clauses" of the European Commission or will be subject to binding internal rules approved by the personal data protection supervisory bodies.

Personal data security

The ACO implement suitable organisational and technical measures to protect personal data. The ACO works to protect personal data, taking into account the sensitivity of the information and the potential risks incurred by processing and implementation. The ACO uses all means necessary to guarantee the confidentiality, integrity, availability and resilience of Customer data The ACO also ensures that personal data is stored in information systems with suitable security systems, to which access is protected, restricted and recorded.

The ACO enter into strict confidentiality agreements with anyone processing data on their behalf. We also ensure that all members of

ACO staff and any person processing personal data respect the rules for data protection and respect confidentiality.

If Customers believe their personal data is being used inappropriately by third parties, please contact the ACO immediately by email: dpo@lemans.org

Your rights

In compliance with regulations, Customers have the following rights:

· Right of access - to obtain information about the processing of personal data and a copy;

· Right of rectification - to request inaccurate personal data is modified; If you have an account, it is easy to change your data at: account.lemans.org.

· Right to erasure/right to forget - to obtain the erasure or deletion of personal data;

· Right to limitation - to request a limitation on how your data is processed;

· Right to portability - to obtain an electronic copy or transfer personal data from the ACO database to another.

Customers can also send their instructions to ACO for storage, deletion or communication of their personal data in the event of death and designate the person responsible.

These are not absolute rights, but are exercised under the conditions and within the limits of current regulations.

If the Customer has consented to receiving marketing information or our newsletters by email, they can unsubscribe by simply clicking on the unsubscribe link in any ACO email or communication.

You also have the right to deactivate cookies. The internet browser settings are usually set by default to accept cookies. This can easily be changed in the browser settings. The procedure can be found in the browser help function.

If you are the legal guardian of a child under 16 years of age and believe that they have provided the ACO with information without your consent, contact the ACO at the below address to request that the information be deleted and to close their account.

Exercise personal data protection rights

You can contact our Data Protection Officer at any time or exercise your rights by clicking on this link: dpo@lemans.orgor at the following address: Automobile Club de l’Ouest, Circuit des 24 Heures, 72019 Le Mans Cedex 2 France

The request must include a photocopy of ID: national identity card or passport, resident's card, residence card or travel document issued by the French government State or European Union identity card. A reply will be sent by the relevant department within one month of receipt of the request.

In accordance with regulations, it is possible to file a complaint with the CNIL according to the terms and conditions indicated at www.cnil.fr.

Changes to our Personal Data Protection policy

Regulations and practices change. The ACO reserves the right to change the Personal Data Protection Policy to adapt to such changes when required.

As soon as changes are made to the Personal Data Protection Policy, it will be published on the ACOs Sites and Apps for consultation.