Terms of service

General Terms and Conditions (GTC)

Juice Technology AG UID CHE-236.291.474

Effective from 24 September 2026

1. Scope

1.1 These General Terms and Conditions (GTC) apply to all business relationships between Juice Technology AG, Kasernenstrasse 2, 8184 Bachenbülach, Switzerland (hereinafter “Juice”), and its customers concerning the sale, rental, delivery and provision of products, software and services (hereinafter the “Contract”).

1.2 These GTC apply irrespective of the type and form in which the Contract is concluded, in particular to contracts concluded via the online shop, at Juice sales premises, orally, by telephone, by email, on the basis of an offer or by other means.

1.3 These GTC apply to consumers and business customers. Consumers are natural persons who enter into a contract predominantly for private purposes. Business customers are natural or legal persons, partnerships with legal capacity and other legal entities of any kind acting within the scope of their commercial or professional activities when entering into the Contract. Where individual provisions apply only to consumers, business customers, resellers or specific groups thereof, for example by region, this is expressly stated.

1.4 Individual agreements, offers, order confirmations, service descriptions and expressly agreed Service Level Agreements (SLA) shall prevail over these GTC in the event of a conflict, provided they have been validly agreed. Clause 2.3 applies additionally to Individual Commercial Terms outside Juice’s applicable standard terms.

1.5 In relation to business customers, conflicting or supplementary general terms and conditions or purchasing terms of the customer shall apply only if Juice has agreed to their application in writing through a person authorised to legally represent Juice. Consent by implied conduct, in particular by accepting or executing an order, delivery, service or payment, is excluded.

2. Offers and Conclusion of Contract

2.1 Presentations of products and services in catalogues, price lists, the online shop or other documents do not generally constitute a binding offer by Juice unless expressly designated as binding.

2.2 Unless a different binding period is stated in the offer, Juice shall remain bound by the offer for 30 days from the date of the offer.

2.3 Individual Commercial Terms outside Juice’s applicable standard terms are binding only if expressly set out in an offer, order confirmation or other written agreement and signed by a person authorised to legally bind Juice. They apply exclusively to the order or period specified therein and do not establish any entitlement to corresponding terms for subsequent orders or contractual relationships.

2.4 By placing an order, the customer submits a binding offer to enter into a Contract. Unless expressly agreed otherwise or a binding offer by Juice has been accepted within the applicable period, the Contract is concluded only when Juice accepts the order by issuing an order confirmation or by executing the order. The order confirmation confirms in particular the agreed scope of performance, terms and delivery dates.

2.5 For orders placed by telephone, email or otherwise outside the online shop, Juice may transmit or make available to the customer electronically the order confirmation and the GTC applicable to the Contract. Where the GTC have not already been validly incorporated, they shall be incorporated no later than with the order confirmation before the acceptance becomes legally binding on the customer.

2.6 Information in brochures, illustrations, videos, drawings, diagrams, online presentations and information concerning dimensions, weights and technical characteristics is provided for descriptive purposes. Technically necessary or required changes after conclusion of the Contract remain reserved, provided they do not materially impair the agreed use and mandatory statutory rights remain unaffected.

2.7 All intellectual property rights of Juice, in particular copyrights, trademark rights, design rights, patents, know-how and rights in software, documentation, drawings, designs, circuit diagrams and other documents, remain with Juice or the respective rights holders. The acquisition of a product, software or service does not transfer any such rights unless expressly agreed otherwise.

2.8 The customer is entitled to use Juice’s intellectual property rights to the extent necessary for the lawful and intended use of the products, software or services acquired by the customer in connection with the relevant purchase. Any use beyond this requires the prior written consent of a person authorised to legally represent Juice. Commercial use of Juice trademarks, logos and other identifiers shall in all cases require the prior written consent of a person authorised to legally represent Juice.

3. Prices and Payment

3.1 The prices agreed at the time the Contract is concluded shall apply in the specified currency. For consumers, taxes and other price components that must be included are shown in accordance with applicable statutory requirements. Clause 3.6 applies additionally to business customers.

3.2 Payments are due in accordance with the payment terms stated in the offer, order confirmation or invoice. Juice is entitled to require advance payment or payment upon ordering. New customers are generally supplied against advance payment. Deviating payment terms or payment terms granted at a later date, in particular 30 days net, require express approval by Juice and do not establish any entitlement to corresponding payment terms for future orders.

3.3 In the event of late payment, the statutory consequences shall apply. In relation to business customers, Juice may declare other outstanding claims arising from the business relationship due and require advance payment or appropriate security for further deliveries. Juice is entitled to set off due monetary claims against the customer against due monetary claims of the customer against Juice, irrespective of the contractual or business relationship from which the respective claims arise. The special provisions on merchandise credits remain reserved.

3.4 Prices for subsequent repeat orders are binding only if expressly agreed. Special services, such as certificates, certificates of origin or customer-specific documentation exceeding the documentation required for legally compliant distribution, may be charged separately.

3.5 In relation to business customers, Juice may adjust agreed prices for longer-term contracts or deliveries if, after conclusion of the Contract, material cost factors beyond Juice’s control, such as raw material, component, energy, transport, customs, levy or currency costs, change materially and a price adjustment is contractually provided for or agreed in the individual case.

3.6 Unless expressly agreed otherwise, prices stated to business customers are exclusive of VAT and exclusive of freight, transport, packaging, insurance, customs duties, taxes, levies and other ancillary costs associated with the delivery or performance. Deviating agreements, in particular agreed Incoterms, remain reserved.

3.7 Any contribution by Juice to advertising, marketing, sales promotion or other measures of the customer, as well as bonus, rebate, discount, listing, portal, EDI, handling, logistics, goods return, employee benefit, partner support or comparable programmes, services, fees or costs, requires a prior express written agreement and confirmation by a person authorised to legally represent Juice. Such arrangements cannot be established by oral agreements, correspondence or actual or implied conduct of Juice employees. Unilateral deductions, set-offs, charges, fees or other reductions of Juice claims are not recognised. The corresponding amounts remain due in full and may be subsequently charged by Juice.

3.8 Merchandise credits, in particular those arising from goodwill, goods returns, bonus, discount, marketing or comparable arrangements, are granted exclusively as credits redeemable against goods. Merchandise credits cannot be redeemed for cash, transferred or otherwise paid out and may not be set off against existing or future monetary claims against Juice. Merchandise credits may only be redeemed against separate deliveries of goods by Juice. For this purpose, the customer may select products from the Juice product range available at the time of redemption. The value of a merchandise credit is determined by the net merchandise value of the relevant products shown in the order confirmation applicable to the underlying transaction and the terms agreed therein. VAT and freight, transport, packaging, insurance, customs, levy and other ancillary costs are not taken into account when determining the credit value. The net prices and terms of the order confirmation underlying the credit transaction shall apply to the valuation of products supplied in settlement.

4. Delivery, Shipping and Title

4.1 Delivery dates and delivery periods are binding only if expressly agreed in writing as binding. Compliance is conditional upon the customer providing required information, approvals, specifications and cooperation in good time. Agreement of a delivery date or delivery period does not constitute a fixed-date transaction. A fixed-date transaction requires an express written agreement.

4.2 Juice shall not be liable for delays or impediments to performance caused by events beyond Juice’s control, including in particular natural events, war, governmental measures, labour disputes, epidemics or pandemics, failures of energy, communications or transport infrastructure, and significant disruptions or failures affecting suppliers or supply chains. Agreed delivery and performance periods shall be extended by the duration of the impediment and a reasonable restart period. If a material impediment lasts longer than 90 days, either party may terminate the part of the Contract affected by the impediment that has not yet been performed. Services already rendered and costs and expenses incurred for the relevant order up to that time shall be paid by the customer.

4.3 Juice is entitled to make partial deliveries and invoice them separately. Partial deliveries are payable in accordance with the agreed payment terms.

4.4 Unless otherwise agreed, packaging and shipping shall be at Juice’s discretion.

4.5 In relation to business customers, place of delivery, allocation of costs and transfer of risk are governed by the agreed Incoterm. If no Incoterm or deviating provision has been agreed, risk passes to the customer when the goods are handed over to the forwarding agent, carrier or other transport service provider. Mandatory statutory provisions on the transfer of risk apply to consumers.

4.6 Juice retains title to the respective goods until they have been paid for in full. Until then, the purchaser’s right of disposal is limited to possession of the goods. The customer shall cooperate with any required registration or other security measure.

4.7 In the event of externally visible transport or packaging damage, the affected delivery must be inspected immediately for damage to the delivered products. Identified transport damage, packaging damage and visible product damage should, where possible, be noted with the transport service provider and must be reported to Juice within 24 hours of receipt. Suitable evidence, in particular photographs of the packaging and affected products and, where available, a damage report issued by the transport service provider, must be submitted within this period both to Juice and to the transport service provider. Any further obligation of business customers to inspect and notify defects is governed by Clause 5.4. If a business customer fails to carry out the inspection, notification or submission of evidence in due time and this makes it more difficult or impossible to determine the cause of the damage or assert claims against the transport service provider, the business customer shall bear the resulting disadvantages.

5. Statutory Warranty and Voluntary Guarantee

5.1 Defects are governed by the applicable statutory warranty provisions unless these GTC validly provide otherwise in relation to business customers.

5.2 Where Juice additionally grants a voluntary guarantee for a product, the content, scope, duration, conditions and exclusions of that guarantee are governed by the guarantee terms applicable to the respective product, in particular the product documentation supplied with the product. A voluntary guarantee does not affect mandatory statutory warranty rights.

5.3 Products must be used exclusively for their intended purpose and in compliance with the safety information and product documentation. Unauthorised interventions, manipulations or modifications to products and use other than for the intended purpose are prohibited. They result in the loss of the customer’s statutory warranty, voluntary guarantee and other defect-related claims and liability claims against Juice. Mandatory statutory liability and product liability provisions remain reserved. For safety reasons, products that have been manipulated, modified or impaired by improper use may no longer be put into operation or continue to be operated until their safe use has been confirmed by Juice or a specialist authorised by Juice in writing.

5.4 Business customers must generally notify visible defects in writing or text form within eight days of receipt and defects that become apparent later within eight days of discovery, to the extent such a notification obligation is permissible under applicable law. Mandatory statutory rights remain unaffected.

6. Assembly and Installation

6.1 Where Juice provides assembly, installation or service work, the customer shall provide the agreed technical and structural conditions in good time and grant the required access. Soiled or biologically contaminated devices or installations shall be cleaned at the customer’s expense where this is necessary to enable performance of the service.

6.2 Where assembly or installation work is performed by third parties, Juice assumes no responsibility for its proper execution. Juice is not liable for errors, damage or malfunctions caused by incorrect, incomplete or non-compliant assembly or installation by third parties.

6.3 Before work begins, the customer shall inform Juice of special safety regulations, technical dependencies and other circumstances material to safe and proper performance.

6.4 Additional expense resulting from missing or inaccurate information, unavailable prerequisites or delays attributable to the customer may be charged additionally in accordance with the agreement and applicable law.

7. Repairs, Service and Support

7.1 Service, support and repair requests must be submitted through the contact or service channels designated by Juice. Products may be sent in only after prior approval by Juice within a service or support case and exclusively to the service centre designated by Juice. All additional costs arising from a shipment that has not been approved or does not comply with Juice’s return instructions, including receipt, triage, redirection, transport, customs, taxes, levies, investigations and handling, may be charged to the sender. Juice may freely dispose of unsolicited products for which the complete documentation required for identification and processing is missing after 60 days from receipt.

7.2 Where a repair or inspection is not covered by statutory warranty rights or a voluntary guarantee, Juice may charge the associated expense after informing the customer in advance. This applies in particular to inspections where no defect covered by statutory warranty or voluntary guarantee is found, to cost estimates that have not been approved, or to shipments sent to a location not designated for that purpose.

7.3 Where the customer accepts these GTC when opening a new service or support case, they apply to the service and support relationship thereby established or specified and to related digital services. Earlier purchase contracts are not thereby amended retroactively.

7.4 The customer shall provide Juice in full with the information, documents, evidence and records requested by Juice and reasonably required for the examination and processing of a service, support, statutory warranty or voluntary guarantee case. Until these are available, Juice is not obliged to continue examining or processing the relevant case.

7.5 Juice may restrict or discontinue the availability of services, spare parts, repairs, support and other services for products whose statutory warranty period has expired, in particular where products have reached the end of their product life cycle or the required spare parts, tools, systems or technical resources are no longer available.

7.6 If, in processing a service or support request, it becomes apparent that the cause lies outside Juice’s area of responsibility or system boundary, in particular in third-party systems, installations, configurations or other circumstances for which Juice is not responsible, Juice is entitled to charge the resulting inspection, diagnostic and processing effort at the applicable rates.

8. Software and Digital Services

8.1 In connection with its products, Juice may provide software, firmware, apps, cloud and backend services, dashboards, interfaces and other digital services. The scope and duration of the digital service owed are determined by the relevant Contract, service description or selected product or service.

8.2 Unless expressly agreed otherwise, Juice does not owe any specific uninterrupted availability of digital services or any specific service level. Juice endeavours to provide reasonable availability and may carry out maintenance, security measures and technically necessary interruptions. Despite appropriate technical and organisational measures, individual data may for technical reasons be lost, incomplete or no longer available. Juice assumes no liability for damage arising from the loss, incompleteness or unavailability of such data. For transactions already settled, the respective settlement is authoritative; permanent availability of the underlying historical data is not guaranteed.

8.3 Availability may in particular be affected by maintenance, security measures, internet or mobile network connections, energy supply, cloud or telecommunications providers, third-party interfaces or events beyond Juice’s control.

8.4 Juice may further develop and modify digital services, in particular to improve functionality, security, compatibility or usability, to adapt to technical developments or changed legal requirements, and to mitigate security risks. In the course of such developments, existing functionality may be modified or discontinued and new functionality may be added. The core services and core functionality of the respective products and services shall be maintained. Mandatory statutory rights remain unaffected. In relation to consumers, changes shall be made only subject to the requirements of the applicable mandatory law.

8.5 To the extent required by law or contract, Juice shall provide necessary updates, including security updates, during the relevant period and inform the customer accordingly.

8.6 The customer is responsible for installing updates provided by Juice, or enabling their installation, within a reasonable period where this is necessary for safe and contract-compliant use and can reasonably be expected of the customer.

8.7 Juice may configure the scope of functionality differently depending on product and variant and may change the allocation of functions to products and product variants for future offerings. Additional functions may be provided for a limited period or on a trial basis and subsequently removed. Such temporary or trial provision does not establish any entitlement to permanent availability.

8.8 Unless otherwise agreed, for the duration of the respective right of use the customer receives a simple, non- exclusive and non-transferable right to use software and digital services provided by Juice as intended in connection with the products and services for which they are intended.

8.9 The customer may not, without authorisation, reproduce or otherwise use, distribute, make publicly available, rent or sublicense software, access data, parameters or release information, in whole or in part, remove proprietary notices, or provide access data to unauthorised third parties. Acts mandatorily permitted by law, in particular mandatory rights relating to examination, interoperability or error correction, remain unaffected.

8.10 Upon the sale or other transfer of a Juice product to a third party, rights of use transfer only to the extent provided for in the respective service description, right of use or applicable law. Existing personal accounts and access credentials of the previous user are not transferable. Where Juice provides a user-change or registration process for this purpose, that process must be used. The previous and new users must be registered separately and clearly assigned to their respective accounts, access authorisations, settlements, and personal and historical data. Personal and historical data of the previous user shall not be made accessible to the new user. The customer must provide the information required for the user change completely and accurately and complete the prescribed user-change process.

8.11 The customer is responsible for settings, configurations and changes made by the customer and by persons commissioned or authorised by the customer to access the systems, as well as for customer-side technical prerequisites and connected systems. These include, for example, network and internet connections, access devices, energy supply, HEMS and other connected systems, as well as the vehicle used. If such settings, changes, prerequisites or connected systems cause malfunctions or additional support effort, Juice is entitled to charge the resulting inspection, diagnostic and processing effort.

9. Processing of Personal Data on Behalf of the Customer

9.1 Where Juice processes personal data on behalf of the customer in connection with cloud, backend, app, support, diagnostic, maintenance or other digital services, the Data Processing Agreement (DPA) in Annex 1 shall apply additionally.

9.2 Personal data shall be processed in accordance with the applicable data protection law, in particular the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation of the European Union (GDPR). The DPA takes account of the requirements of both legal regimes to the extent they apply to the respective processing on behalf of the customer. Where Juice processes personal data for its own purposes and under its own data protection responsibility, such processing is governed by the applicable data protection provisions and the corresponding privacy notices.

10. Online Remote Access, Technical Interventions and Data Processing

10.1 These provisions apply where the customer expressly permits Juice to access systems online in connection with service, support, diagnostics, maintenance, troubleshooting, inspection, restoration or similar services. Online remote access shall take place only with the customer’s express consent in connection with the respective case.

10.2 Online remote access includes access to charging infrastructure and to associated IT, network, communications, control, energy and other systems, components, interfaces and data to the extent required for the agreed purpose.

10.3 Acceptance of these GTC alone does not constitute consent to any specific online remote access. Online remote access shall take place only where the customer has expressly consented to the relevant access. Where such consent has been given, the provisions of this Clause 10 shall apply.

10.4 Within the scope of the authorised access, Juice may, to the extent required for the agreed purpose, view, read, transfer, store and process configurations and data and carry out tests, restarts, configuration changes and software or firmware measures.

10.5 Unless expressly agreed otherwise, Juice does not guarantee any specific result, the correction of a particular fault, or the restoration or maintenance of a particular system state.

10.6 The customer warrants that it is authorised to grant the necessary rights of access and processing and to issue the necessary instructions in respect of all affected systems and data and has obtained any required consents or approvals from third parties. Before performance, the customer shall inform Juice of special security requirements, restrictions and material dependencies on third-party systems.

10.7 Before online remote access, the customer shall make appropriate backups of data, settings and configurations material to it and ensure that these can be restored if necessary.

10.8 The customer acknowledges that online remote access and technical interventions may affect systems, data and their operation even when carried out with due professional care. Such effects may include, in particular, changes to or loss of data, settings or configurations, interruptions of operation, functional changes, incompatibilities, communications or network disruptions, and further restoration or adjustment work.

10.9 Liability of Juice and persons acting in its name or on its behalf for damage in connection with online remote access and associated technical interventions is excluded. This applies in particular to loss of data or configurations, operational, production or usage downtime, loss of profit, third-party claims, and indirect or consequential damage. Mandatory statutory liability provisions remain reserved.

10.10 The customer shall indemnify Juice and persons acting in its name or on its behalf against third-party claims arising because, contrary to Clause 10.6, the customer was not authorised to grant the required rights or failed to obtain required third-party consents or approvals.

10.11 Where Juice processes personal data on behalf of the customer in the course of online remote access, the DPA shall apply additionally. By consenting to online remote access, the customer simultaneously gives Juice the instructions required under the DPA to process the relevant personal data for the purpose of carrying out that access.

11. Business Customers and Resellers

11.1 The provisions of this Clause apply exclusively to business customers.

11.2 Juice shall not be liable to business customers for indirect or consequential damage, such as loss of profit, production, operational or usage downtime, loss of business opportunities, or loss of data or configurations, except where such liability cannot be excluded or limited under mandatory law.

11.3 In relation to business customers, unless expressly agreed otherwise, Juice does not guarantee uninterrupted or error-free operation of software, digital services and backend services, any specific availability, compatibility with third- party systems not expressly approved, or the achievement of any particular economic or technical result.

11.4 The business customer is responsible for appropriate backups of its data, settings and configurations and for appropriate operational precautions against outages, to the extent reasonably required in view of the nature of the services used.

11.5 Confirmed orders from business customers may be cancelled or changed only with Juice’s consent. Juice may make its consent conditional upon reimbursement of costs already incurred and payment of reasonable cancellation compensation. A lump-sum compensation is owed only if specified in the offer, order confirmation or another agreement.

11.6 Voluntary returns of defect-free products by business customers require Juice’s prior consent. Juice may in particular make acceptance of the return conditional upon the products being in as-new condition, with complete accessories and suitable original packaging, and may make a reasonable deduction for inspection, refurbishment, depreciation and administrative costs.

11.7 When ordering, resellers shall inform Juice of the intended country of final use where this is relevant to product approval, labelling, brand, scope of delivery or regulatory requirements. Contrary to express Juice instructions, the reseller may not distribute products under an impermissible brand or in a version not approved for the intended country of final use.

11.8 Where appropriate for efficient performance, technical assistance, service, support, safety, statutory information or digital services, Juice is entitled to communicate directly with the respective end customer, operator or user and to provide services directly to them. Contractual intermediaries, in particular resellers, distributors or other sales partners, need not be included in such communication or service provision. This does not alter the contractual allocation of purchase price, commission or other commercial claims between the parties involved.

11.9 If a customer sells or otherwise provides Juice products to third parties for use or operation, the customer shall, before any cloud, backend, app or other digital services are used, inform the respective purchaser or user of the applicable Juice terms and the DPA and ensure that they are validly accepted.

11.10 The customer shall ensure that Juice is granted online remote access to a purchaser’s or user’s systems only if that purchaser or user has expressly consented to such access. The customer may not grant Juice any rights of access, data processing or technical intervention on behalf of third parties that differ from those provided for in these GTC.

11.11 If the products are subsequently sold or otherwise provided to another party, the obligations under Clauses

11.9 and 11.10 shall be passed on accordingly. Juice may require reasonable evidence that this has been done.

11.12 If a business customer culpably breaches any requirement concerning the country of final use, branding, required consents or the passing on of obligations, and this results in third-party claims against Juice, the business customer shall indemnify Juice against such claims to the extent permitted by law.

12. Consumers

12.1 All mandatory statutory consumer rights apply to consumers. Provisions of these GTC that expressly apply only to business customers do not apply to consumers.

12.2 For contracts with consumers in Germany or Austria, the mandatory statutory provisions concerning goods, goods with digital elements and digital services apply in particular. Statutory update, warranty and information obligations are not restricted by these GTC.

12.3 Consumers in Germany and Austria shall receive separate information on the right of withdrawal or cancellation for contracts for which such a statutory right exists.

12.4 The choice of Swiss law under Clause 14 does not affect, in relation to consumers, those mandatory statutory protections that apply independently of this choice of law under the applicable rules of private international law.

13. Liability

13.1 Juice is liable in accordance with mandatory statutory provisions. Exclusions and limitations of liability in these GTC apply only to the extent permitted by the applicable law.

13.2 Juice is not liable for damage resulting from use other than for the intended purpose, failure to observe safety or product information, unauthorised modifications, unsuitable third-party systems, or failures of cooperation attributable to the customer.

13.3 The special liability provisions of these GTC for business customers under Clause 11 and for online remote access under Clause 10 take precedence over the general liability provisions of this Clause 13.

14. Governing Law and Jurisdiction

14.1 Contractual relationships with Juice are governed by Swiss law, excluding conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods (CISG).

14.2 The exclusive place of jurisdiction for disputes with business customers shall be Juice’s registered office in Bachenbülach, Switzerland. Juice is also entitled to bring proceedings against a business customer at the latter’s registered office.

14.3 Mandatory statutory provisions on jurisdiction apply to consumers.

15. Final Provisions

15.1 Amendments and supplements to individual contracts must comply with the form required by applicable law or the respective agreement. Individual agreements remain reserved.

15.2 Should any provision of these GTC be or become wholly or partly invalid or unenforceable, the remaining provisions shall remain unaffected to the extent permitted by law.

15.3 Juice may amend these GTC for future contracts. For existing contractual relationships, in particular ongoing digital services, amendments apply only if and to the extent contractually agreed and permitted under applicable law. Mandatory information, consent and termination rights remain unaffected.

15.4 The German version of these GTC is authoritative. Translations, in particular into English and French, are provided for convenience.

15.5 Objections based exclusively on language, linguistic complexity or failure to understand matters presented in written language are not recognised by Juice.

ANNEX 1 DATA PROCESSING AGREEMENT (DPA)

PREAMBLE

Juice provides the customer with services relating to products, charging infrastructure, software, cloud and backend systems, apps and other digital services. In the course of these services, Juice may process personal data on behalf of the customer. This Agreement governs the processing and protection of such personal data and applies where Juice acts as a processor for the customer. It applies in particular to cloud, backend, app and fleet services and to support, service, diagnostic, maintenance and online remote access services.

1. SUBJECT MATTER AND DURATION OF PROCESSING

The subject matter of this DPA is the processing of personal data by Juice on behalf of the customer in connection with the products and services agreed between Juice and the customer or used by the customer. Processing shall be carried out in accordance with applicable data protection law, in particular the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation of the European Union (GDPR). The duration of processing on behalf of the customer generally corresponds to the duration of the respective service or contractual relationship within which Juice processes personal data on behalf of the customer. Statutory retention and documentation obligations remain reserved.

2. NATURE AND PURPOSE OF PROCESSING

Juice processes personal data exclusively within the scope of the agreed services and in accordance with the customer’s documented instructions, unless Juice is required by applicable law to process the data beyond those instructions. Processing may in particular serve the operation, provision, administration and billing of products and digital services, fleet management, and the analysis, diagnosis, maintenance, support, troubleshooting, inspection and restoration of products, charging infrastructure, software and associated systems. Depending on the service, processing may in particular include collecting, recording, organising, storing, reading, retrieving, using, transmitting, matching, altering, restoring, restricting and deleting personal data.

3. CATEGORIES OF PERSONAL DATA PROCESSED

Depending on the nature and scope of the service used by the customer, the following categories of personal data may in particular be processed: master, contact, user and identification data; employee, driver and user data; vehicle, driving and location data; charging, energy, billing and transaction data; communications, network and connection data, in particular IP addresses; system, device, configuration, log and diagnostic data; data concerning the use of products, backends, apps and digital services; and other personal data made accessible to Juice in connection with an agreed service or online remote access authorised by the customer. Data subjects may include, in particular, employees, drivers, users, administrators, agents and other persons whose personal data are processed by the customer or through systems operated or used by the customer.

4. CUSTOMER INSTRUCTIONS

Juice generally processes personal data only on the customer’s documented instructions. Commissioning or using an agreed cloud, backend, app or other digital service constitutes an instruction to carry out the data processing necessary and agreed for that service. The customer’s express consent to online remote access constitutes an instruction to carry out the data processing required for that access under the GTC and this DPA. If Juice considers that an instruction infringes applicable data protection law, Juice may suspend its execution pending clarification.

5. CUSTOMER OBLIGATIONS AND RESPONSIBILITY

The customer is responsible for the lawfulness of the collection and processing of personal data provided or made accessible to Juice and for the permissibility of the instructions it issues. The customer warrants that it is authorised to instruct Juice to carry out the relevant data processing and that any required information, consents or other legal bases exist in relation to data subjects and third parties. The customer shall inform Juice of special data protection requirements to the extent relevant to the agreed processing on behalf of the customer.

6. CONFIDENTIALITY AND ACCESS

Juice shall ensure the confidentiality of personal data processed on behalf of the customer and shall ensure that persons who obtain access to such data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality. Access to personal data is restricted to persons who require it to perform their duties. Juice protects personal data and analyses derived from it against unauthorised access and makes them available to third parties only where required for contractual performance, pursuant to permissible sub-processing, or due to statutory obligations.

7. TECHNICAL AND ORGANISATIONAL MEASURES

Juice implements appropriate technical and organisational measures to protect the personal data processed, taking into account the state of the art, the nature and scope of the processing and the associated risks. The applicable technical and organisational measures are described in Annex 1 to the DPA (TOM). Juice is entitled to adapt these measures in line with technical developments, provided the agreed level of protection is not materially reduced overall.

8. SUB-PROCESSORS

Juice is entitled to engage sub-processors to provide the agreed services, provided the requirements of the applicable data protection law are met. Juice shall ensure that sub-processors are subject, with regard to the protection of personal data, to obligations appropriately corresponding to those applicable to Juice under this DPA. Where applicable data protection law requires the customer’s prior specific or general authorisation, such authorisation shall be obtained in accordance with statutory requirements. In the case of general authorisation, Juice shall inform the customer of intended changes concerning the addition or replacement of sub-processors and enable the customer to object on legitimate data protection grounds.

9. ASSISTANCE TO THE CUSTOMER AND PERSONAL DATA BREACHES

Upon becoming aware of a personal data breach, Juice shall inform the customer without undue delay where the breach concerns data processed on behalf of the customer and such information is required by law. Taking into account the nature of the processing and the information available to Juice, Juice shall reasonably assist the customer in fulfilling its data protection obligations, in particular regarding the exercise of data subject rights and, where required, data protection impact assessments and notifications of personal data breaches.

10. RETURN AND DELETION

Upon termination of the respective processing on behalf of the customer, Juice shall delete or return the personal data processed on behalf of the customer in accordance with the customer’s instructions and applicable data protection law, unless statutory retention obligations or other legal grounds prevent deletion. Where data are required to process transactions, settlements, claims or other contractual matters that have not yet been completed, they may continue to be processed until those matters are completed.

11. EVIDENCE AND AUDITS

Juice shall provide the customer with the information reasonably required to demonstrate compliance with the applicable statutory requirements for processing on behalf of the customer. Where required by law, Juice shall permit reasonable inspections or audits by the customer or an independent auditor appointed by the customer and bound by confidentiality. Scope, timing and conduct must be agreed with Juice in advance and shall appropriately take into account Juice’s operational and security interests. Existing certifications, audit reports and other suitable evidence may be used to fulfil this obligation.

12. DATA LOCATION AND INTERNATIONAL TRANSFERS

Personal data are generally processed within Switzerland, the European Union or the European Economic Area. Where personal data are transferred to or made accessible from a country for which no adequate level of data protection is recognised, Juice shall ensure that the safeguards required under the applicable data protection law are in place for the transfer.

13. TERM AND RELATIONSHIP TO THE GTC

This DPA applies for the duration of the respective processing on behalf of the customer. It forms part of the GTC or the respective contractual relationship between Juice and the customer where Juice processes personal data on behalf of the customer. In the event of conflicts between this DPA and other contractual provisions, the provisions of this DPA shall prevail with respect to processing of personal data on behalf of the customer. Jurisdiction and governing law are determined by the corresponding provisions of the GTC or the underlying contractual relationship.

ANNEX 1.1 TECHNICAL & ORGANISATIONAL MEASURES (TOM)

Through the technical and organisational measures described below, Juice ensures that personal data processed on behalf of the customer are protected in accordance with the requirements of applicable data protection law. The measures serve in particular to ensure the confidentiality, integrity, availability and resilience of the systems and services used and the ability to restore the availability of data and systems in a timely manner following an incident. Juice maintains procedures for regularly testing, assessing and evaluating the effectiveness of these measures.

1. PHYSICAL ACCESS CONTROL

Unauthorised physical access to premises and facilities is prevented. Measures include in particular access control systems using RFID and activity logging, mechatronic keys with selective access rights and logging, designated security, IT and facility personnel, and monitoring systems, in particular door alarm systems and video surveillance.

2. SYSTEM ACCESS CONTROL

Unauthorised access to IT systems is prevented. Measures include in particular password procedures with defined security requirements, automatic locking by password and timeout, and the identifiability of system users.

3. DATA ACCESS CONTROL

Activities within IT systems outside the access rights granted in each case are prevented. Measures include in particular differentiated access rights by profiles, roles, transactions and objects, access logs and evaluations, access restrictions, and defined rights to read, modify and delete data.

4. TRANSFER CONTROL

The transmission of personal data during electronic transfer and data transport is controlled. Measures include in particular encryption and tunnelling, especially VPN, logging, and authorised and traceable access.

5. INPUT CONTROL

Traceability of the input, modification and deletion of data is ensured by appropriate logging systems.

6. PROCESSING CONTROL

Personal data are processed in accordance with the agreed instructions. Responsibilities between the customer and Juice are delineated in particular through clear contractual provisions and formalised commissioning and instructions.

7. AVAILABILITY CONTROL

Personal data are protected against accidental destruction or loss. Measures include in particular regular backups, disk mirroring, remote storage, antivirus and firewall systems, and disaster recovery and continuity planning.

8. SEPARATION AND PURPOSE-LIMITATION CONTROL

Data collected for different purposes are processed separately as appropriate. Measures include in particular tenant and usage concepts, corresponding access restrictions, and functional separation of production, testing and other relevant systems.

9. EFFECTIVENESS CONTROL

Juice regularly reviews the effectiveness of the implemented technical and organisational measures. This includes in particular audits and recertifications, IT audits, penetration tests, and regular review and assessment of the security measures used.

10. CERTIFICATIONS AND INFORMATION SECURITY

Juice Technology AG is certified to ISO 27001:2022 in the field of information security and holds TISAX certification. Policies, regular updates, technical security measures and a controlled authorisation system serve to continuously improve the protection of data and systems against internal and external risks.

---