PERSONAL DATA PROTECTION POLICY FOR mobileMAP, mobileCHAT, mobileNET and other CVS MOBILE applications



CVS MOBILE, informacijske rešitve d.d.

Valid from: 1st January 2019

1. INTRODUCTORY INFORMATION

CVS MOBILE, informacijske rešitve d.d., seated at Ulica Gradnikove brigade 11, 1000 Ljubljana, Slovenia (hereinafter referred to as “CVS MOBILE”, “we”, “us”) is a leading provider of innovative telematics and fleet management solutions and services in Central and Eastern Europe and is also the owner of the mobileWEB cloud-based platform, mobileCHAT application, mobileMAP application, mobileNET application and other CVS MOBILE applications.

At CVS MOBILE we respect your right to privacy and take personal data protection extremely seriously, as we would like to provide you with the highest level of protection of the personal data you have trusted us with.

This Personal data protection Policy (hereinafter referred to as “Policy”) is based on relevant legislation on the protection of personal data, in particular the Personal Data Protection Act and the EU General Data Protection Regulation.

This Policy is limited to the processing of personal data associated with the use of the mobileMAP, mobileCHAT, mobileNET and other CVS MOBILE applications. For general Privacy Policy, which covers the use of our mobileWEB cloud-based platform https://mobileweb.cvs-mobile.com/, the information about our services and sending of e-news, click http://docs.cvs-mobile.com/privacy-policy/.

When using our services, you’ll share some information with us. That is why this Policy defines key issues of processing personal data when using our applications, such as who collects your personal data, how your personal data is collected and for which purposes, how the data is protected and with whom it is shared. CVS MOBILE has many different Policies, depending on which of our services you use. General Policy for the users of our mobileWEB platform is available at http://docs.cvs-mobile.com/privacy-policy/. For any other specific services (ex. Use of applications issued by CVS MOBILE) see Policies which are limited to the processing of personal data associated to this specific services.

We tried to write our entire Personal Data Protection Policy as understandable as possible. If you still have any questions concerning personal data, do not hesitate to contact us.

In order to enable you to quickly and efficiently find information you need, we have created an interactive index, designed to provide you with information about a topic that you are interested in in one click:

  • 1. INTRODUCTORY INFORMATION
  • 2. BASIC CONCEPTS
  • 3. WHO COLLECTS AND PROCESSES MY PERSONAL DATA?
  • 4. FOR WHOM IS THIS POLICY INTENDED
  • 5. ON WHAT LEGAL BASIS DO WE COLLECT AND PROCESS YOUR PERSONAL DATA?
  • 6. WHAT TYPES OF PERSONAL DATA DO WE COLLECT?
  • 7. HOW LONG DO WE KEEP YOUR PERSONAL DATA?
  • 8. HOW DO WE PROTECT YOUR PERSONAL DATA?
  • 9. WHO DO WE TRANSMIT YOUR PERSONAL DATA TO?
  • 10. WHAT ARE MY RIGHTS REGARDING PERSONAL DATA PROCESSING?
  • 11. FINAL PROVISIONS

2. BASIC CONCEPTS

Here you can find definitions of basic concepts that we use in our Policy.

Each particular concept defined below has a meaning within this Policy as defined in this section.

Personal data means any information that refers to a specific or identifiable individual (for example, the name, surname, e-mail address, telephone number and identifiers that are specific to the individual's physical, physiological, genetic, economic, mental, cultural or social identity, etc.).

Controller means a legal entity that determines the purposes and means of processing of your personal data.

Processor means a legal or natural person who processes personal data on behalf of the controller.

Processing means collecting, storing, accessing and all other forms of use of personal data.

EEA means the European Economic Area, which identifies all the Member States of the European Union, Iceland, Norway and Liechtenstein.

Application means the mobileMAP application or mobileCHAT application or mobileNET application or any other application issued by CVS MOBILE, which an individual can download to their electronic devices via Google Play or App Store or are installed by CVS Mobile directly to devices.

Client means a legal or natural person who signs a Contract (hereinafter referred to as “Contract”) for the use of the mobileWEB platform that is issued by CVS MOBILE. After an initial registration procedure, the Client receives master credentials to access in the mobileWEB platform. Master access in the mobileWEB platform enables the creation of new mobileWEB users and assign them specific access rights in mobileWEB platform. The client shall enable users to register and use the application.

User means any individual who has received an invitation via e-mail to access mobileWEB platform and has finished the registration procedure. Any User, who has the credentials to access mobileWEB platform, can use those credentials to access and use mobileMAP, mobileCHAT or others CVS MOBILE applications. When using mobileNET application, user does not need credentials to access. The use of mobileNET application is independent from the User and is connected directly to the vehicle.

Entry point is any application function that an individual uses and where personal data is collected. The entry points are further defined in Chapter 5 of this Policy.

Content of Clients means any information, file or data published by clients in mobileWEB database, which is not under the control of CVS MOBILE. In relation to these data the Client designates CVS MOBILE as its personal data processor.

Prior activities of the user mean the activities that an individual performed on the platform https://mobileweb.cvs-mobile.com before using his account in any CVS MOBILE application.

3. WHO COLLECTS AND PROCESSES MY PERSONAL DATA?

Controller of the personal data being processed within the applications (mobileMAP, mobileCHAT, mobileNET and other applications issued by CVS MOBILE) is CVS MOBILE, informacijske rešitve d.d., seated at Ulica Gradnikove brigade 11, 1000 Ljubljana, Slovenija.

As the controller of personal data, CVS MOBILE is responsible for processing and retention of your personal data.

In order to further upgrade the level of personal data protection, CVS MOBILE has appointed an authorized person for the protection of personal data, who ensures that the handling of personal data is at all times consistent with the relevant legislation.

In CVS MOBILE, we appointed the following person as an authorized person for the protection of personal data: Mr. Bojan Jelen. The authorized person for the protection of personal data can be reached through the following e-mail: support@cvs-mobile.com.

If you have any questions regarding the use of this Policy or with regards to the exercise of your rights arising from this Policy, please contact us at to the email defined above.

4. FOR WHOM IS THIS POLICY INTENDED

This Policy applies to Users of applications issued by CVS MOBILE in regard with logging in the applications.

5. ON WHAT LEGAL BASIS DO WE COLLECT AND PROCESS YOUR PERSONAL DATA?

In accordance with the legislation governing the protection of personal data, we may process your personal data on the following legal bases:

  • a) Contract. We process your personal data when such processing is required to complete the contract which the Client has concluded (for example, ensuring the operation of the application);
  • b) Legitimate interest. We process your personal data when CVS MOBILE has a legitimate interest in processing. We will expressly define within this Policy in what events we process the data on a legitimate interest basis.
  • c) The law. When processing is necessary for the fulfillment of legal obligations (e.g. data that we keep for tax liabilities).

Is the provision of personal data mandatory?

The provision of personal data is mandatory in certain cases. In most cases, you provide us with personal data on a voluntary basis. It is obligatory to provide only the personal data that we collect on the basis of the requirements of the legislation.

The provision of personal data that we need to fulfill the Contract is voluntary. However, in the event that you do not provide us with all the personal data that we need to execute the contract we will not be able to provide full services (for example we cannot provide the Service for you if you do not provide us with information on e-mail, we need to create the account).

6. WHAT TYPES OF PERSONAL DATA DO WE COLLECT?

At CVS MOBILE, we process your personal data solely on the basis of clearly stated and legitimate purposes, securely and transparently.

How do we obtain personal data?

We collect your personal data when you provide it to us (for example, using our applications, signing up in to our applications, inquiring by e-mail, telephone or writing to our address or by any other means in which you provide us with your personal data).

Your personal data can also be obtained automatically when you use mobileMAP, mobileCHAT and other CVS MOBILE applications. When automatic collection of data occurs, you shall be properly informed before collecting, or asked for your consent to such a collection of personal data. Also, the consent will explicitly indicate all the categories of personal data we collect.

What categories of personal data do we collect?

We collect your personal data at entry points, which are defined in the list below. Any collection and processing of your personal data takes place only when such processing is necessary to fulfill the specific purpose of the processing. In the list below, in addition to the listed categories of data we collect, you will also find the purpose of the processing for which this data is needed. Your personal data may be processed for one or more purposes. We will also inform you accordingly whether the processing of personal data for a specific entry point is based on legitimate interest.

  • a) Logging-in to application:
    • • To log-in to our applications you use the same username and password you created for logging-in to mobileWEB cloud-based platform. To learn more about registration of the account please see our mobileWEB privacy policy, http://docs.cvs-mobile.com/privacy-policy/. Except the mobileNET application in which you don’t need to sign in, because it is connected directly to the vehicle.
    • • We also offer in-app notifications, each user decide to enable them. You can enable in-app notifications by clicking Allow. You can always deactivate in-app notifications in settings of the applications.
    • • We collect the following data categories: username (e-mail), date and time of logging-in, User operating system.
    • • We collect and process this data for the purpose of enabling logging-in to the application.

In addition to the purposes outlined above, personal data collected at one of the points of entry can also be used for the following purposes:

  • a) Communicating with you to provide quality responses to your inquiries. Communication is carried out on the basis of our legitimate interest to ensure effective communication with our Clients. Communication with the client and/or user is based on the contractual relation with the Client.
  • b) To enforce any legal claims and to settle disputes. Personal data can be disclosed in order to protect our business and to enforce and/or protect our rights. We will disclose your personal data only in the manner and under the conditions required by law.

At CVS MOBILE, we carefully protect the principle of the minimum amount of data provided by law, and therefore our mobileWEB platform, mobileMAP, mobileCHAT and other CVS MOBILE applications are developed in the way to ensure that we collect only data that are appropriate, relevant and limited to what is necessary for the purposes for which they are processed.

CVS MOBILE will only process your data for specified, explicit and legitimate purposes. We undertake not to process your personal data in a manner incompatible with the purposes defined in this Policy.

If there is a need for further processing of personal data, we will inform you in advance and, when necessary, request for consent. You are entitled to revoke at any time any processing of your personal data, based on your consent. You can notify us of the revocation of the consent at any of the contact points defined in Chapter 3 of this Policy.

7. HOW LONG DO WE KEEP YOUR PERSONAL DATA?

We keep your personal data in accordance with the relevant legislation. We will keep your personal data:

  • a) only for as long as it is absolutely necessary to achieve the purposes for which we are processing (for the purposes for which we process personal data, please refer to Chapter 6 of this Policy),
  • b) for a period prescribed by the law (we note here that the deadlines for the retention of personal data may also be defined by other laws, not only in the field of personal data protection, such as for example 10 years for the issued invoices, in accordance with the tax legislation),
  • c) for the period necessary for the fulfillment of Contract, which includes guarantee periods and deadlines during which it is possible to enforce any claims on the basis of a concluded contract.

When the retention period for certain personal data expires, we will delete the personal data or anonymize it so that the reconstruction of personal data will no longer be possible, i.e. it will not be possible to discover to whom the data refers based on the anonymized data.

The retention period for personal data collected when logging into our applications is 10 years.

For any additional information, please contact us at any of the contact details defined in Chapter 2 of this Policy.

8. HOW DO WE PROTECT YOUR PERSONAL DATA?

At CVS MOBILE we protect your personal data against illegal or unauthorized processing and/ or access, and against unintentional loss, destruction or damage. We undertake all measures according to our technological capabilities (including the cost of implementing certain measures) and the impact assessment on your privacy.

To ensure that your personal data is safe, we have undertaken the appropriate technical and organizational measures, in particular:

  • a) ensuring the regular updating and maintenance of the hardware, software and application equipment that we use for the processing of personal data,
  • b) establishing a restriction on access to personal data,
  • c) regular backup,
  • d) encryption of your formulation,
  • e) ensuring the education of employees who process personal data at work,
  • f) careful selection of processors that we trust for the processing of personal data;
  • g) supervising both employees and processors and regular audits,
  • h) establishing protocols for preventing or limiting damage in case of potential security incidents

In the event of a violation of the protection of personal data, we will notify without delay about any such violation the competent supervisory authority (in Slovenia, the Information Commissioner). You can read more about the competent authority on their website https://www.ip-rs.si/.

If there is suspicion of a criminal offense regarding the violation of personal data, CVS MOBILE will also report such violations to the police and the competent state prosecutor's office.

In the event of a violation of data protection that may cause a high risk to the rights and freedoms of individuals, we will inform you of such an event without undue delay.

9. WHO DO WE TRANSMIT YOUR PERSONAL DATA TO?

Your personal data may be, exclusively in order to achieve the purpose for which it was collected, transmitted to, or we may allow access to the data to certain third parties defined below. Such third parties may only process your personal data for the purposes for which the data was collected.

Accordingly, any third party to whom we transmit personal data must comply with the applicable law as well as with the provisions of this Personal Data Protection Policy. With external processors, however, the protection of personal data is further defined by the contract.

Your personal data may be transmitted to:

  • • Our external processors who take care of the needs of CVS MOBILE and the functioning of the applications (e.g. companies that provide programming, software maintenance or marketing services).
  • • When this is required by the law (e.g. tax authorities, courts, etc.).

We may transmit your personal data to third parties (defined above) outside the European Economic Area (EEA), where personal data processing occurs. In any transmission outside the European Economic Area, we will undertake specific additional measures to ensure the security of your personal data.

Such measures consist mainly of agreements with third parties on the establishment of binding rules in the field of personal data protection, verification that an approved certification mechanism which meets our standards for the protection of personal data is in place, and the conclusion of relevant contractual obligations that regulate the protection of personal data.

10. WHAT ARE MY RIGHTS REGARDING PERSONAL DATA PROCESSING?

You have the following rights regarding the personal data processing:

  • a) Access to personal data: You may request information from CVS MOBILE about whether we are processing your personal data, and if we are, you can request access to your personal data and information about the processing (which data is processed and where this data originated from).
  • b) Correction of personal data: you may request from CVS MOBILE to correct or complete your incomplete or inaccurate data being processed.
  • c) Restriction of the personal data processing: you may request from CVS MOBILE a restriction of the processing of your personal data (when, for example, checking accuracy or the completeness of your personal data).
  • d) Deletion of personal data: you may request from CVS MOBILE to delete your personal data (we cannot delete the personal data that we keep on the basis of legal requests or contractual relation).
  • e) Printout of personal data: you may request from CVS MOBILE to provide you with your personal data that you have provided us with in a structured, widely used and machine-readable form.
  • f) Objection to the processing of personal data: You have the right to object to the processing of your personal data when processing is for direct marketing purposes or in the event of transmitting your personal information to third parties for the purposes of direct marketing. You can also object to processing when your data is used for direct marketing purposes using customized or individual offers ("profiling"). You can make an objection in any way defined in Chapter 2 of this Policy.
  • g) The right to data transmission: you have the right to request the printout of personal data that you have provided us with. We will provide you with the information in a structured, widely used and machine-readable form. You are entitled to provide this data to another controller of your choice. Where technically feasible, you may request that your personal data be transmitted directly to another controller.

Contacts for the exercise of the rights:

If you have any questions regarding the use of this Policy or with regards to the exercise of your rights arising from this Policy, please contact us at any of the following contacts:

a) E-mail: support@cvs-mobile.com

You have the right to file a complaint against us with the Information Commissioner, who is the competent authority for the protection of personal data.

The integrity of personal data processed, and regular updating is a priority for CVS MOBILE. Please kindly inform us of any change of your personal data to support@cvs-mobile.com. We will take care of the correction or supplementing your personal data in the shortest possible time.

In case of exercising any of the rights, we may require additional personal data (such as name, surname, e-mail address) for identification purposes. We will only need additional information when the information you provide is not sufficient for reliable identification (for example if we receive unsigned email and we do not have that email in our data base, we will ask for additional information in order to determine if we process your personal data and to execute your request). In this way, we want to prevent your personal data from being transmitted to a third party due to unreliable identification.

11. FINAL PROVISIONS

At CVS MOBILE, we can change this Policy at any time. We shall notify you of the change of the Policy in the mobileMAP, mobileCHAT or any other CVS MOBILE application. We shall consider that you agree with the new version of this Policy if, after the new version enters into force, you continue to use our platform and other applications, or services defined by this Policy.

The current version of this Policy will be available on our website:

http://docs.cvs-mobile.com/privacy-policy/

© 2019 CVS Mobile, Inc.