1. Data Controller
The controller of your personal data is Carvago Polska Sp. z o.o., registered office at Domaniewska 44, 02-672 Warsaw, Poland (NIP: 5223194937, KRS: 0000876219, REGON: 387834691), hereinafter referred to as the “Controller”.
The Controller has not appointed a Data Protection Officer. For data protection inquiries, please contact us at: info@caraudit.pl.
2. Purposes and Legal Bases for Processing
We process your personal data for the following purposes and on the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR): order processing, delivery of vehicle inspection services, order-related communication.
- Legal obligation (Art. 6(1)(c) GDPR): invoicing, fulfilment of tax and accounting obligations.
- Legitimate interest of the controller (Art. 6(1)(f) GDPR): fraud prevention, analytics, service improvement, establishment or defence of legal claims.
- Consent (Art. 6(1)(a) GDPR): marketing communications, analytical cookies.
3. Scope of Data
We process the following categories of personal data:
- Identification and contact data: name, email address, phone number, correspondence address.
- Vehicle data: make, model, VIN number, vehicle location.
- Payment data: transaction data processed by the payment operator GoPay. The Controller does not store full payment card details.
- Technical data: IP address, browser type, device information, cookies.
4. Data Recipients
Your personal data may be shared with the following categories of recipients:
- EAG SE group companies: to the extent necessary for service delivery and internal administration.
- GoPay: payment operator, for processing payment transactions.
- Salesforce: CRM system used for order management and customer relations.
- Google Analytics: analytics tool (only with consent for analytical cookies).
- Inspection technicians and partners: to the extent necessary to carry out the vehicle inspection.
5. Data Transfers Outside the EEA
Some of the above-mentioned entities may process data outside the European Economic Area (EEA):
- Salesforce (USA): data transfer secured by Standard Contractual Clauses (SCCs) approved by the European Commission.
- Google (USA): data transfer secured by Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Data Retention Periods
We retain your data for the following periods:
- Contract-related data: 6 years from the end of the calendar year in which the payment was due (general statute of limitations for claims pursuant to Art. 118 of the Polish Civil Code).
- Marketing data: until consent is withdrawn.
- Analytics data: 26 months.
- Data arising from legal obligations: for the period required by law (e.g. tax documentation: 5 years).
7. Data Subject Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR): the right to obtain information on whether your data is being processed and to obtain a copy.
- Right to rectification (Art. 16 GDPR): the right to correct inaccurate data or supplement incomplete data.
- Right to erasure (Art. 17 GDPR): the right to request deletion of data where there is no basis for further processing.
- Right to restriction of processing (Art. 18 GDPR): the right to request restriction of processing in certain circumstances.
- Right to data portability (Art. 20 GDPR): the right to receive data in a structured format and transfer it to another controller.
- Right to object (Art. 21 GDPR): the right to object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3) GDPR): at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint: you have the right to lodge a complaint with the President of the Office for Personal Data Protection (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
To exercise your rights, please contact us at: info@caraudit.pl.
8. Automated Decision-Making
The Controller does not use automated decision-making, including profiling, as referred to in Art. 22(1) and (4) GDPR, i.e. making decisions that produce legal effects or similarly significantly affect the data subject, based solely on automated processing of personal data.
9. Data Security
The Controller implements appropriate technical and organisational measures to protect processed personal data, in accordance with Art. 32 GDPR. In particular, the Controller applies:
- Data transmission encryption: the website uses the SSL/TLS protocol to encrypt data transmitted between the user’s browser and the server.
- Access control: access to personal data is limited to authorised persons, to the extent necessary for the performance of their duties.
- Regular security reviews: the Controller regularly reviews applied security measures to ensure their adequacy to the current level of risk.
11. Changes to the Privacy Policy
The Controller reserves the right to update this Privacy Policy. Any changes will be published on this page with the date of the last update. We recommend regularly reviewing the privacy policy.