Car-In Automotive GmbH operates the website car-in-automotive.de. It is the policy of Car-In Automotive GmbH to respect your privacy regarding any information we may collect while operating our website. For purposes of data protection law, Car-In Automotive GmbH is the data controller and has implemented technical and organizational measures to ensure the protection of personal data processed through this website. Learn about our Cookies Policy.
Our website address is: www.car-in-automotive.de.
We respect your privacy
This privacy notice applies to the use of personal data by Car-In Automotive GmbH. It explains what information we collect, how we use it, who we share it with and how we protect it. It also details the rights available to you in relation to how we hold and use your personal data, how to exercise those rights, and what to do if you require more information or wish to make a complaint.
How we protect your data
We keep our computer systems, files and buildings secure by following legal requirements and appropriate security guidance. We make sure that our staff, and anyone with access to personal data that we are responsible for, is fully trained on how to protect personal data. We ensure that our processes clearly identify the requirements for managing personal data and that they are up to date. We regularly audit our systems and processes to ensure that we remain compliant with these policies and legal obligations.
What data breach procedures we have in place
It is our policy to provide a clear process for handling a personal data breach, should one occur. Where appropriate, Car-In Automotive GmbH will promptly notify you of any unauthorized access to your personal information.
What personal data we collect and why we collect it
We collect your personal data so that we can manage our relationships with you. Activities that we require personal data for include:
- Performance and maintenance of a supply contract
- Provision of products or services
- Improving our existing products and services
- Developing new services
- Responding to requests and providing information
- A range of other activities which we are obliged to undertake, or which we have gained consent to complete
We ensure that the information we collect is appropriate to the purposes for which it is obtained. We do not gather sensitive personal data (e.g. health, genetic, biometric data; racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, and criminal convictions). We expressly request that you do not provide any such sensitive data to us.
Our services are not directed to children under 18. If you learn that a child under 18 has provided us with personal information without consent, please contact us.
By using our website, products, or services, and by submitting any data to us, you warrant that you are eighteen (18) years of age or older.
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
The amount and type of information that we gather depends on the nature of the interaction with us. For example, we ask visitors who sign up at car-in-automotive.de to provide a username and email address. If you are looking for information on our products or services and you use a contact form, we ask you for your Name and email address. Those who engage in transactions with Car-In Automotive GmbH are asked to provide additional information, including as necessary the personal and financial information required to process those transactions. In each case, Car-In Automotive GmbH collects such information only insofar as is necessary or appropriate to fulfil the purpose of the visitor’s interaction with Car-In Automotive GmbH. We do not disclose personally-identifying information other than as described below. And visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from engaging in certain website-related activities.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
Google Analytics is a web analytics service. Web analytics is the collection, gathering, and analysis of data about the behavior of visitors to websites. The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States. Website visitor behaviour is anonymised – full IP address is NOT stored. We have signed the Google DPA and anonymise IP addresses. Data retention at Google is set for 14 months.
PayPal Payment Processing. PayPal is an online payment service provider. Payments are processed via so-called PayPal accounts, which represent virtual private or business accounts. PayPal is also able to process virtual payments through credit cards when a user does not have a PayPal account. A PayPal account is managed via an e-mail address, which is why there are no classic account numbers. PayPal makes it possible to trigger online payments to third parties or to receive payments. PayPal also accepts trustee functions and offers buyer protection services.
The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg. The applicable data protection provisions of PayPal may be retrieved under https://www.paypal.com/us/webapps/mpp/ua/privacy-full.
You can revoke consent for the handling of your personal data at any time from PayPal. A revocation shall not have any effect on personal data which must be processed, used or transmitted in accordance with (contractual) payment processing.
Stripe Payment Processing. Stripe is an online payment service provider. The entity that provides Services in Europe is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin.
Other Parties. Some cookies etc that have been set on our websites are not related to Car-In Automotive GmbH or our partners. When you visit a page with content embedded from, for example, YouTube or Facebook or social media widgets like the Facebook like button, these service providers may use their own cookies etc.
We do not control the use of these cookies etc and cannot access them due to the way that these technologies work, as they can only be accessed by the party who originally set them. You should check the third party websites for more information about these cookies etc.
Who we share your data with
We may share your personal data with, or disclose your personal data to, the following categories of third party:
- Agents or suppliers: these are persons or companies we have contracts with to provide products or services that we use in conducting our business, including managing our relationship with our customers. In many cases, they will be within the European Economic Area (EEA) but in some cases they may be outside of the EEA. We will only share or disclose to these parties the information that they need in order to provide the products or services, and will require those parties to ensure that the information is always adequately protected.
- Professional advisers: we may share or disclose personal data to professional advisers we may engage for any reasonable purpose in connection with our business, including assistance in protecting our rights.
- Other external bodies: in certain circumstances, we may be required by law to disclose personal data to external bodies, such as local authorities, government departments or Police. In these cases, we will only disclose the minimum amount of information required to satisfy our legal obligation. However, once the information is disclosed, we will not be able to control how it is used by those bodies.
How long we retain your data
Information collected by us will be held for as long as it is required to fulfil the purpose it was collected for and to protect our business and our rights. We are required to keep certain types of information for a specific period of time in order to comply with legal requirements. The length of time we keep any part of your personal information will depend on the type of information and the purpose for which it was obtained.
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
Where we send your data
Visitor comments may be checked through an automated spam detection service.
What rights you have over your data
If you have an account on car-in-automotive.de, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
The rights that you have available to you include:
- Gaining access to and copies of your personal data: you are entitled to receive, on request and free of charge, a copy of all your personal data that we hold. There are some limitations to this right. For example, if the data also relates to another person and we do not have that person’s consent, or if the data is subject to legal privilege. Where there is data that we cannot disclose, we will explain this to you.
- Ensuring that your data is accurate: our aim is to ensure that the data we hold about you is correct and up to date. From time to time we may contact you to verify the information that we hold. You may also contact us to correct any errors that you notice.
- Granting or Removing consent: where we require your consent for any processing, for example, to provide you with direct marketing communications, we will clearly explain what the consent is for, and any consequences of giving or refusing consent, and will provide that consent can only be given by way of a positive action by you. We will also ensure that you are able to withdraw any such consent at any time.
- Restricting processing of your data: you have the right to request us to restrict the processing of your personal data in certain circumstances, for example, if there is a dispute over our rights to carry out specific processing activities, or where you do not want us to delete data. We will respond promptly to your request and will provide an explanation if we cannot fully comply.
- Deletion of your data: in certain circumstances, you may have the right to have some or all of your personal data deleted from our records. This is sometimes referred to as the “right to be forgotten”. This may occur if, for example, we retain data which is no longer required by us, or if you withdraw a consent. If you continue to have a relationship with us, we must retain the data we need to manage this relationship. We will respond promptly to your request, and provide reasons if we object to the deletion of any of your personal data.
- Moving your data: where it is possible for us to provide it, you have the right to receive a digital copy of the personal data that you have provided to us.
International Transfers of Data: in certain circumstances, we may transfer your personal information internationally, including outside of the European Economic Area (EEA). Should we do this, we ensure that all transfers are made in accordance with data protection law and that your data it will be given an equivalent level of protection that it has when it is being managed in Germany.
How to make a complaint
If you wish to raise a complaint on how we have handled your personal information, you can contact us directly and we will investigate the matter.
If you are not satisfied with our response or believe we are processing your personal information not in accordance with the law you can complain to the German Data Protection Commissioner’s Office.
Changes to our privacy notice
We will occasionally update this privacy notice. We will post a notice of any material changes on our website prior to implementing the changes, and, where appropriate, notify you using any of the contact details we hold for you for this purpose. We encourage you to periodically review this notice to be informed of how we use your information.
Online Dispute Resolution under Article 14 (1) of the ODR Regulation: The European Commission provides an online dispute resolution platform (OS), which can be found at http://ec.europa.eu/consumers/odr/. In addition, our company does not participate in a consumer dispute resolution process.
What automated decision making and/or profiling we do with user data
We do not use any personal information for automated decision making or profiling; your data is not subject to automated decision making or profiling.
Our contact information
Car-In Automotive GmbH, Daniel-Fahrenheit-Str. 4, Telgte, 48291 Germany
Phone: 02504 / 9 84 99-0 Email: firstname.lastname@example.org Date: 24-05-2018