Thales Privacy Policy for “Thales Biometric Data Collection Campaign” Mobile Application

The protection of your personal data is a priority for Thales, which ensures that your personal data is processed with complete transparency and security.

When using this Thales Biometric Data Collection Campaign” Mobile Application (the “Application”) you will share your personal data with THALES DIS CZECH REPUBLIC S.R.O., a Czech company registered with the Trade and Companies Register of Prague under number 264 32 293, whose registered office is at 4, Michle, Zeletavská 1448/7, PSC 140 00 PRAHA, Czech Republic (“THALES”).

In this case, Thales acts as data controller, meaning that Thales determines the purpose and manner of processing your personal data.

1. What personal data do we collect and process?

Thales may process the following personal data when you use the Application:

2. What are the purposes for processing your personal data?

Your data may be used for the following purposes:

3. What is the legal basis for the processing of your personal data?

The legal basis for the processing of your personal data is the End-User License Agreement to which you are party since you downloaded the Application and the consent form you signed with one Thales entity related to the Biometric data collection campaign for this purpose.

4. How long do we keep your personal data?

Your personal data will be kept for a period of five (5) years from the date your personal data was collected.

5. Who receives your personal data?

Recipients of all or part of your personal data may include:

When your personal data is transferred by a Thales company established in the European Economic Area (EEA) or the United Kingdom (UK) to a Thales company outside these areas in a country without an adequacy decision, this transfer is based on the Binding Corporate Rules (BCR) adopted by Thales.

Thanks to the Thales BCR, wherever your personal data is processed within the Thales Group, it benefits from the same standard of protection. You can access the Thales BCR here.

When your personal data is transferred by a Thales company established in the EEA to a third-party outside the EEA in a country without adequacy, Thales relies on Standard Contractual Clauses (SCC) adopted by the European Commission. You can obtain a copy of the SCC signed by Thales by making a “Personal data protection” request here.

When your personal data is transferred by a Thales company established in the UK to a third-party outside the UK in a country without adequacy, Thales relies on the International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the SCC issued by the Information Commissioner’s Office.

6. What security measures are in place to protect your data?

Thales implements technical, organizational, and contractual security measures necessary to protect your personal data against accidental or unlawful destruction, loss, alteration, disclosure, or unauthorized access.

7. What are your rights concerning your personal data?

You have the right to:

For any request or complaint, please contact:

You also have the right to lodge a complaint with the competent data protection authority.

8. Update of the Thales EUDIW LSP Wallet Privacy Policy

This notice is updated regularly to take into account technological innovations as well as legislative and regulatory changes.

Date of last revision: October 2025