Data Protection Information

1. Introduction

Telio Management GmbH and its affiliated companies (“Telio”, “we”, “us”, or “our”) are committed to protecting your personal data and respecting your privacy.

This Privacy Policy explains how we collect, use, store, and protect personal data when you visit this website and access investor-related information and documentation.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable data protection laws.

2. Controller

The controller responsible for the processing of personal data on this website is:

Telio BidCo Germany GmbH
Gasstraße 18, Haus 3
22761 Hamburg
Germany

For further information, please refer to the legal notice (Imprint) on this website.

3. Data Protection Officer

If you have any questions regarding data protection or the processing of your personal data, you may contact our Data Protection Officer:

Data Protection Officer

Telio BidCo Germany GmbH
Gasstraße 18, Haus 3
22761 Hamburg
Germany
E-Mail: info@tel.io

4. Personal Data We Process

When you visit this website, certain information is automatically collected and processed by our web servers.

This may include:

  • IP address

  • Date and time of access

  • Requested webpage or file

  • Referring website (referrer URL)

  • Browser type and version

  • Operating system

  • Device information

  • Amount of data transferred

  • Access status and server log information

This information is required for the secure operation and delivery of the website.

5. Purpose and Legal Basis of Processing

We process personal data for the following purposes:

  • Providing access to the website and investor information

  • Delivering downloadable documents and materials

  • Ensuring website security and stability

  • Detecting and preventing misuse of the website

  • Maintaining and improving technical functionality

  • Demonstrating acceptance of mandatory legal disclaimers where applicable

The legal basis for processing is Article 6(1)(f) GDPR. Our legitimate interest is the secure and efficient operation of the website and the provision of information to investors and other interested parties.

Where necessary to provide content specifically requested by a user, processing may also be based on Article 6(1)(b) GDPR.

6. Disclaimer Acceptance

Access to certain parts of this website or specific investor documentation may require users to acknowledge and accept a legal disclaimer.

Where such acceptance is required, we may record:

  • Confirmation that the disclaimer was accepted

  • Date and time of acceptance

  • Technical information necessary to demonstrate compliance with legal and regulatory requirements

This processing is based on our legitimate interest under Article 6(1)(f) GDPR and our legal and regulatory obligations relating to the provision of investor information.

7. Investor Documentation

This website provides access to bond-related and investor-related documentation, including but not limited to:

  • Financial reports

  • Presentations

  • Bond documentation

  • Regulatory announcements

  • Other investor materials

Downloading these documents generally does not require the submission of additional personal data beyond the technical information automatically processed during website access.

8. Cookies

This website may use cookies and similar technologies that are necessary for the operation, security, and functionality of the website.

Where legally required, non-essential cookies will only be used with your prior consent.

Further information about the cookies used on this website can be found in our Cookie Policy.

9. Recipients of Personal Data

We may share personal data with carefully selected service providers that support the operation, hosting, maintenance, and security of the website.

Such providers process personal data only on our behalf and in accordance with applicable data protection laws and contractual safeguards.

Personal data may also be disclosed to public authorities or regulatory bodies where required by law.

10. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards will be implemented in accordance with Articles 44 et seq. GDPR.

Such safeguards may include:

  • Adequacy decisions issued by the European Commission

  • Standard Contractual Clauses approved by the European Commission

  • Other legally recognized transfer mechanisms

11. Data Retention

Personal data will only be retained for as long as necessary to fulfil the purposes described in this Privacy Policy or as required by applicable law.

Server log data is generally retained for a limited period and deleted thereafter unless longer retention is required for security, legal, or regulatory purposes.

12. Your Rights

Under the GDPR, you have the following rights:

  • Right of access

  • Right to rectification

  • Right to erasure

  • Right to restriction of processing

  • Right to data portability

  • Right to object to processing

  • Right to withdraw consent at any time where processing is based on consent

  • Right to lodge a complaint with a competent supervisory authority

To exercise any of these rights, please contact us using the details provided above.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or organizational changes.

The latest version will always be available on this website.

Last updated: June 2026.