What is Personal Information?
Personal Information is any information relating to personal or material circumstances that relates to an individual. This may include a name, date of birth, e-mail address, postal address, or telephone number but also online identifiers such as IP addresses or device ID`s.
What is processing?
“Processing” means any operation or set of operations which is performed upon Personal Information, whether or not by automatic means. The term is broad and covers virtually any handling of data.
Who is responsible for data processing?
The responsible party for data processing is Know Your Car (“Know Your Car”, “we”, “us” or “our”). If you have any questions or if you wish to exercise your rights, please contact us using [email protected] or use our Contact Form.
What are the grounds for processing Personal Information?
We only process your Personal Information, if at least one of the following reasons applies:
- for the fulfillment of contractual obligations
- within the framework of our legitimate interests
- based on your consent
Data we collect automatically.
Each time you visit our website, our system automatically records the following data from the visiting device and stores it in a so-called log file: i) Name of the retrieved file, ii) date and time of the visit, iii) amount of data transferred, iv) message about successful retrieval, type of browser and version used, v) IP address (identification of the user’s device), vi) Operating system of the visiting device, vii) Internet service provider of the visiting device, viii) website from which you access our website, and ix) which of our website pages you are accessing. The basis for processing is our legitimate interest.
Content Delivery Network
We use a Content Delivery Network (CDN) to distribute our online content. A CDN is a network of regionally distributed servers of our technical service providers connected via the Internet. When our website is visited, your device`s browser transmits information to these service providers, which is collected in corresponding server log files. Server log files are generally anonymized and then transmitted without any personal reference. Server log files include, in particular, i) details of the browser and operating system used, ii) the previously visited pages (so-called referral URL), iii) the IP address of the device used, iv) the name of the Internet provider, as well as v) the date, time of all page views including the amount of data transmitted. The legal basis for processing is our legitimate interest.
To provide our website, we use the services of Cloudways who processes all data to be processed in connection with the operation of this website on our behalf. This represents a legitimate interest.
Content Management System (CMS)
We also use the Content Management System (CMS) of WordPress (Automattic Inc) to publish and maintain the created and edited content and texts on our website. This means that all content and texts submitted to us is transferred to WordPress. This represents a legitimate interest.
Third-party services and content
We use content or service offers of third-party providers on the basis of our legitimate interests in order to integrate their content and services (“services”).
This always requires that the third-party providers of this content are aware of the IP address of the user, as without the IP address they would not be able to send the content to their browser. The IP address is therefore necessary for the display of this content.
The following provides an overview of third-party providers and their content, together with links to their privacy policies, which contain further information on the processing of data and so-called opt-out measures, if any,
- Analytics: Google Analytics by Google LLC
- Tag Management: Google Tag Manager and Google Site Tag by Google LLC and PixelYourSite by Minimal Work SRL
- Fonts: Google Fonts by Google LLC and Font Awesome by Fonticons Inc,
- Spam protection: reCAPTCHA by Google LLC,
Data we collect directly
In addition to your name, address, and e-mail address, IP address or phone number, if provided, we usually collect the context of your message which may also include certain Personal Information. The Personal Information collected when contacting us is to handle your request and the bases are both your consent and contract.
Insofar as you have given us your separate consent to process your data for marketing and advertising purposes, we are entitled to contact you for these purposes via the communication channels you have given your consent to.
You may give us your consent in a number of ways including by selecting a box on a form where we seek your permission to send you marketing information, or sometimes your consent is implied from your interactions or contractual relationship with us. Where your consent is implied, it is on the basis that you would have a reasonable expectation of receiving a marketing communication based on your interactions or contractual relationship with us.
Direct Marketing generally takes the form of e-mail, SMS but may also include other less traditional or emerging channels. These forms of contact will be managed by us, or by our contracted service providers. Every directly addressed marketing sent or made by us or on our behalf will include a means by which you may unsubscribe or opt out.
For business reasons and in order to be able to recognize market trends, wishes of contractual partners and users, we analyze the data we have on business transactions, contracts, inquiries, etc., whereby the group of persons concerned may include contractual partners, interested parties, customers, visitors, and users of our shop.
The analyses are carried out for the purpose of business evaluations, marketing, and market research (e.g., to determine customer groups with different characteristics). The analyses serve us alone and are not disclosed externally, unless they are anonymous analyses with summarized, i.e., anonymized values. Furthermore, we take the privacy of users into consideration and process the data for analysis purposes as pseudonymously as possible and, if feasible, anonymously (e.g., as summarized data).
If you have consented to receive our newsletter, we will use your email address to send you information about us, our products and promotions, and news. You can revoke your consent to receive the newsletter or to the creation of personalized user profiles at any time with effect for the future. You will find the unsubscribe link at the end of each newsletter. The revocation leads to the deletion of the collected user data.
We are present on social media (currently Facebook, Pinterest, and Twitter) on the basis of our legitimate interest. If you contact or connect with us via social media, we and the relevant social media platform are jointly responsible for the processing of your data and enter into a so-called joint controller agreement. The Personal Information collected when contacting us is to handle your request and the bases are both your consent and our legitimate interest.
When you visit our profiles and interact with us and others
When you visit our social media profiles, we, as the operator of the profile, process your actions and interactions with our profile (e.g., the content of your messages, enquiries, posts or comments that you send to us or leave on our profile or when you like or share our posts) as well as your publicly viewable profile data (e.g., your name and profile picture).
Which Personal Information from your profile is publicly viewable depends on your profile settings, which you can adjust yourself in the settings of your social media account.
Please take care not to transmit or share sensitive data or confidential information (e.g., application documents, bank or payment data) via social media platforms; we recommend that you use a more secure means of transmission (e.g. e-mail).
Processing of your Personal Information by the relevant social media platform
Targeted Interest-Based Advertisements
We also use these anonymous usage statistics to display targeted interest-based advertisements. The display of interest-based advertisements or the highlighting of posts on social media is carried out on the basis of an analysis of the user’s prior usage behavior by the relevant social media platform without us being able to view Personal Information of individual users or merge it with any Personal Information we may process or obtain knowledge of the identity of the users to whom interest-based advertisements are displayed. This data processing is based on our legitimate interests. If you do not wish to participate in our advertising personalization or retargeting/tracking you can object to behavioral advertising at the following websites: Your Online Choices, Digital Advertising Alliance of Canada, Network Advertising Initiative, AdChoices and the European Interactive Digital Advertising Alliance (Europe only).
Who receives my data?
Within Know Your Car, those that need your data to fulfill our contractual and legal obligations will receive access to it. We ensure that access by our employees to your data is only available on a need-to-know basis, restricted to specific individuals, and is logged and audited. We communicate our privacy and security guidelines to our employees and enforce privacy and data protection safeguards strictly.
Outside of Know Your Car, only if this is i) necessary for the performance of our services, ii) you have consented to the disclosure, iii) or if we are legally obliged to do so e.g., by court order or if this is necessary to support criminal or legal investigations or other legal investigations or other legal proceedings; or proceedings at home or abroad or to fulfill our legitimate interests.
How long will my data be stored?
As far as necessary, we process and store your Personal Information for the duration of our business relationship, which also includes, for example, the initiation and execution of a contract. In addition, we are subject to various storage and documentation obligations, which result from the minimum statutory retention periods. The retention and documentation periods specified there are 4 to 10 years.
How do we secure your data?
Our website uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of content or contact requests that you send to us. We have also implemented numerous security measures (“technical and organizational measures”) for example encryption or need to know access, to ensure the most complete protection of Personal Information processed through this website.
Nevertheless, internet-based data transmissions can always have security gaps, so that absolute protection cannot be guaranteed. And databases or data sets that include Personal Information may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, we will notify all affected individuals whose Personal Information may have been compromised as expeditiously as possible after which the breach was discovered.
Is data transferred to a third country?
Your data is not transferred to third countries.
Unless specifically required when using our services and explicit consent is obtained for that service, we do not process sensitive data.
Automated decision-making is the process of making a decision by automated means without any human involvement. Automated decision-making including profiling does not take place.
COPPA (Children Online Privacy Protection Act)
When it comes to the collection of Personal Information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online. We do not specifically market to children under the age of 13 years old.
CAN SPAM Act
The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations. To be in accordance with CAN SPAM, we agree to the following: If at any time you would like to unsubscribe from receiving future emails, you can email us, and we will promptly remove you from ALL correspondence.
Telephone Consumer Protection Act (TCPA)
If we process your Personal Information for the purpose of sending you SMS marketing communications, you may manage your receipt of marketing and non-transactional communications from us by replying or texting ‘STOP’ if you receive our SMS communications. In this respect, the data processing is carried out solely on the basis of our consent in personalized direct advertising per SMS.
Controls For Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (‘DNT’) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, our website does not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this policy.
DO NOT SELL
We do not sell your Personal Information.
Your Rights and Privileges
You can exercise the following rights:
- Right to information
- Right to rectification
- Right to deletion
- Right to data portability
- Right of objection
- Right to withdraw consent
- Right to complain to a supervisory authority
- Right not to be subject to a decision based solely on automated processing.
If you have any questions about the nature of the Personal Information we hold about you, or if you wish to exercise any of your rights, please contact us.
Updating your information
If you believe that the information we hold about you is inaccurate or that we are no longer entitled to use it and want to request its rectification, deletion, or object to its processing, please do so by contacting us.
Withdrawing your consent
You can revoke consents you have given at any time by contacting us. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
In the event that you wish to make a Data Subject Access Request, you may inform us in writing of the same. We will respond to requests regarding access and correction as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days, we will tell you why and when we will be able to respond to your request. If we are unable to provide you with any Personal Information or to make a correction requested by you, we will tell you why.
Changes and Questions
Wednesday, May 10, 2023