This document defines Vehicle Smart's processes and procedures for handling personal data and contains the following sections:
References to Vehicle Smart, we, us is synonymous with Vehicle Smart Ltd.
References to you, an individual, an external organisation is synonymous with any user of services provided by Vehicle Smart Ltd (either as an individual or as a business).
This document has been created in order to define the data we hold along with the processes and procedures Vehicle Smart will follow when dealing with personal data provided to us. This is a living document which will continue to be updated as and when required and each change will be recorded in the revision history at the beginning of this document.
The lawful basis for data processing are set out in Article 6 of the GDPR: Lawful Basis For Data Processing
The personal data we can hold for each individual is the following:
If you have used Vehicle Smart services to search for a vehicle then we will hold a copy of your IP address. Our lawful base for processing this data falls under 'Legitimate Interest'. We have a legitimate interest in protecting our IT infrastructure and our data suppliers from abuse e.g. DDOS attacks / hacking attempts.
If you have contacted Vehicle Smart by email then we will hold a copy of your email address. Our lawful base for processing this data falls under 'Legitimate Interest'. We have a legitimate interest in retaining your email address such that we may contact you with regards to a query you may have raised with us and for recording any communications with regards to refunds / purchase restores / product enquiries / beta testing or any other account support you may need.
If you have created an account with Vehicle Smart then we will hold a copy of your email address. Our lawful base for processing this data falls under 'Consent'. By creating an account with Vehicle Smart you are giving us consent to store your email address such that it can be used to identify you when you want use Vehicle Smart services e.g. log in, data back up & data restore.
If you have created an account with Vehicle Smart we will record your account metadata e.g. activities which include account log in, log out, performing a data back up or data restore. Our lawful base for processing this data falls under 'Consent'. By creating an account with Vehicle Smart you are giving us consent to monitor your account activities to ensure the security of all accounts held with Vehicle Smart.
Associated Vehicle Data
If you have performed a back up of your garage data then we will hold a copy of your vehicle data (for each vehicle). Our lawful base for processing this data falls under 'Consent'. By creating an account with Vehicle Smart you are giving us consent to store your vehicle data such that it can be used with Vehicle Smart services e.g. data back up & data restore.
The vehicle data stored includes all of the following data items (** where provided by you):
All data controlled by Vehicle Smart is held within the EU on secure platforms. We use data encryption for all account credentials.
Our priority is to keep your data private and your communications free from spam. We will never share your data without your consent and we do not share any personal data with anyone outside of Vehicle Smart Ltd except in special circumstances (see below).
How we use your personal date is defined by each data type:
We will use your IP address for network activity logging and rate limiting.
We will use your email address to contact you with regards to your account, for communications you have made with us regarding our services and for marketing services you have opted-in for.
We use your account activity for account validation and for monitoring account activity patterns.
Associated Vehicle Data
We store your associated vehicle data on our secure platforms so that you can perform backup and restore functions.
If you contact us with a query which we cannot answer then we may need to forward your query on to one of our data providers. In this instance, we may share your email address or contact number (if you have provided them to us) with a data provider so that they can contact you direct with an answer to your query. We will always seek your consent before passing on your contact details.
We will retain all data for a minimum of 6 years.
If you want to us delete your personal data please email us: firstname.lastname@example.org
You can request to know what data we hold about you. To do this, simply send an email request to: email@example.com with the details you'd like to know. We will aim to respond to all data requests within 28-days.
Please note: we will charge for requests or refuse to honour any requests which are manifestly unfounded or excessive.
We take privacy and data protection very seriously. We have many protections in place already however we will not be immune to every type of malicious attack, hacking attempt or human error.
As a paid member of the Information Commissioners Office (ICO) we are obliged to report data breaches to the ICO and to any individuals where it is likely to result in a risk to the rights and freedoms of those individuals.
If we discover a data breach, we will assess the impact and follow ICO and GDPR guidelines on reporting and investigating data breaches. We will attempt to notify any affected individuals (where possible) and inform them of the impact should we be required to do so.
Vehicle Smart Ltd operates exclusively inside the EU. We do not store, process or control any data outside of the EU and therefore all GDPR regulations regarding international operations are not applicable to Vehicle Smart at this time.