Privacy Policy
Effective as of 23 May 2018
1) General information
Porsche Leasing BG EOOD is a sole limited liability company registered in the Republic of Bulgaria, UIC 131283654, (Porsche Leasing), owner of the domain www.porscheleasing.bg.
Porsche Mobility BG EOOD is a sole limited liability company registered in the Republic of Bulgaria, UIC 203261484 (Porsche Mobility).
Porsche Insurance Broker BG EOOD is a sole limited liability company registered in the Republic of Bulgaria, UIC 175167480 (Porsche Insurance Broker).
Porsche Finance Group Bulgaria includes Porsche Leasing, Porsche Mobility, Porsche Insurance Broker, whose sole owner is Porsche Bank AG, Austria, and the companies operate jointly on the Bulgarian market and provide the full package of services related to operating and financial leasing, insurance brokerage, fleet management, etc., using the website www.porscheleasing.bg.
Data Protection Officer (DPO) is the determined by the companies members of the Porsche Bank Group under the Joint Administrators Agreement and can be found at e-mail gdpr@porscheleasing.bg;
The Joint Administrators Agreement is the agreement entered into between the companies of the Porsche Financial Group Bulgaria on 23 May 2018, having the following main features:
The personal data of the customers of each of the companies in the Porsche Financial Group Bulgaria are processed jointly with the other companies of the group* in order to provide the customer with a quality service for the full package of services related to operating and financial leasing. The affiliation to the Porsche Finance Group Bulgaria often determines the use of the same Processors in order to ensure a high level of security in the processing of personal data.
In strict compliance with all statutory principles of personal data processing and in order to guarantee the rights of data subjects, the companies of the Porsche Financial Group Bulgaria have agreed to:
- The right to information of each data subject shall be exercised by the company with which the data subject first comes into contact;
- To the extent that the data subject's consent is required as a basis for processing personal data, it shall be provided to the company with which the data subject first comes into contact. Once given in this way, it shall be deemed valid and available in respect of the other companies of the Porsche Finance Group Bulgaria, as long as it concerns the types of processing carried out by them. Consents given on the website www.porscheleasing.bg. Consents given on the website are deemed to be given for the processing methods indicated therein
- The DPO for the companies of the Porsche Financial Group Bulgaria as joint administrators can be found at gdpr@porscheleasing.bg. If a data subject submits a request to a specific company of the Porsche Financial Group Bulgaria, the latter shall immediately inform the DPO;
- Each company of the Porsche Financial Group Bulgaria is obliged to provide information on the actions taken on the rights/claims of the data subject on the basis of Articles 15-22 of the General Data Protection Regulation in a timely manner, but not later than 1 month from the request. Where there are factual or technical difficulties in complying with such requests in a timely manner, the time limit for compliance may be extended by a further 2 months, which shall be notified to the data subject within 1 month of receipt of the request;
- Inquiries of data subjects made electronically will be answered electronically unless otherwise requested by the data subject;
- Each of the companies of the Porsche Bulgaria Financial Group is responsible for complying with requests to exercise the rights of data subjects, regardless of which of the companies the specific request is addressed to;
- The companies of the Porsche Financial Group Bulgaria jointly implement policies, organizational and technical measures to ensure the security of personal data, their lawful processing, respect for the rights of data subjects, as well as the engagement of Processors to guarantee the same level of data protection and processing;
- In the event of a breach of the security of processing, the companies of the Porsche Bulgaria Financial Group shall cooperate with each other so that all necessary measures are taken to mitigate the consequences for the security of the data/the rights of the data subjects, as well as to notify (no later than 72 hours after becoming aware of it) the Commission for the Protection of Personal Data pursuant to Article 33 of the General Data Protection Regulation and, if necessary, the data subject under the terms of Article 34 of the same Regulation;
- Notwithstanding the agreements in the Agreement, the data subject may direct his or her claims to any of the companies of the Porsche Bulgaria Financial Group. The latter shall be jointly and severally liable for the exercise of the data subject's rights, irrespective of which specific company is the customer by virtue of the commercial transactions concluded/prepared;
- The Agreement is concluded for an indefinite period, and in the event of termination, each of the companies of the Porsche Financial Group Bulgaria will receive a copy of the documents/records evidencing the joint lawful processing of personal data during its term;
- The law applicable to the Agreement shall be Bulgarian law.
This Privacy Policy applies only to www.porscheleasing.bg, and not to individual landing pages and third-party websites that you may access via referral or other similar means from www.porscheleasing.bg. In these cases, Porsche Finance Group Bulgaria has no control over the processing of data by third parties and cannot guarantee the protection and privacy of your personal data.
2) Security and data protection
Porsche Financial Group Bulgaria has taken the necessary technical and organizational measures to protect your data on www.porscheleasing.bg from any unauthorized acts, including loss and unauthorized access. In order to ensure high security, measures are taken at two stages - at the design stage of individual segments of the website and the services offered, and at the default stage - when you as a user fill in a contact form / register on My Contract or by other similar means. Measures include restricting access to your personal data, strictly following the rules in the internal policy and the Joint Administrators Agreement, appropriate training of those responsible for processing your personal data and compliance with best practices, guidelines and instructions on the protection of personal data from competent supervisory authorities. All measures are subject to regular review and periodic updates. In the event of a personal data breach, we will notify you without undue delay within an appropriate time after becoming aware if the personal data breach is likely to result in a high risk to your rights and freedoms.
In cases where a password and username (My Contract) may be required to allow you to access your account, you are responsible for keeping this password secure and confidential by not disclosing it to third parties and thereby helping to keep your data highly secure. The initial access code is set out in your contract, and for security reasons it is advisable to register immediately with a new unique password and username.
3) Personal data processing activities
Your personal data will only be processed by Porsche Finance Group Bulgaria in accordance with applicable data protection regulations. When you correspond with us by email or complete a feedback form on our website, you confirm that the data you have provided is accurate, correct and up to date. Through the website, Porsche Finance Group Bulgaria collects personal data about you in the following ways:
- Contact form;
- Application for power of attorney for travelling abroad;
- Request a quote for Auto Casco and Third Party Liability;
- My contract;
- Contract Inquiry;
- Cookies
When you visit the website, cookies are attached to your terminal device that allow your actions or preferences to be "remembered" for a certain period of time. For more information, please see our Cookie Use and Management Policy here.
4) Categories of personal data
The following categories of personal data are collected through the website:
Categories/registers of personal data | Objectives | Method of data collection |
---|---|---|
Name and Surname | Identifying the user; contacting the user; providing the requested service/answering your questions; offering new products and services | Contact form; request for a power of attorney for travelling abroad; request for a quote for Car Insurance and Third Party Liability; login to My Contract; contract enquiry |
Phone/Fax, e-mail | Contacting the user; providing a requested service/answering your questions; offering new products and services | Contact form; request for a power of attorney for travelling abroad; request for a quote for Auto Casco and Third Party Liability; login to My Contract; contract enquiry |
Vehicle and owner details (name, phone and age) | Provision of requested service | Application for a power of attorney for travelling abroad; request for a quote for Auto Casco and Third Party Liability |
Data related to website user behavior | Improving services and understanding consumer interests and behavior online; offering new products and services | Cookies |
5) Storage period. Destruction
Personal data shall be kept for the periods necessary to achieve the purposes for which it was collected. We take all necessary technical and organisational measures to destroy data that is no longer necessary, except where there is a legal basis to process it for a longer period of time; where you have made a request to restrict processing, in accordance with your rights detailed below; or in order to be compatible with the original purpose for processing, of which you will be informed in due time.
6) Legality
Personal data is processed on the grounds set out in Article 6 of the General Data Protection Regulation as follows:
In cases where you fill in the Contact Form - we process your personal data on the basis of your consent and in view of your specific request (e.g. information on the models and makes of cars offered, questions relating to the purchase of cars and/or car financing, positive feedback and criticism, etc.).
In the event that you send a Request for a Power of Attorney to drive abroad and a Request for a quote for Car Insurance and Third Party Liability, we will process your data on the basis of taking steps at your request prior to entering into a contract for the purpose of concluding it.
If you use My Contract, we will process your data on the basis of your consent. My Contract is an additional functionality for you to keep track of the main parameters in relation to an already concluded contract and the use of this functionality is exclusively voluntary. Should you choose not to use My Contract, your decision will not affect in any negative way the performance of the contract you have entered into with a company of the Porsche Finance Group Bulgaria.
In the event that you send us the Contract Enquiry Form, the processing is necessary for the performance of a contract to which you are a party.
The processing of data by means of cookies is carried out on the basis of your consent for the purposes of improving the quality of the services we offer on the website, as well as to improve the use of the website.
Only after obtaining your explicit consent, we may use some of the data collected, namely: first name, last name, telephone, email, data collected through cookies to offer you new relevant products and services from the Porsche Finance Group Bulgaria.
7) Providing and withdrawing user consent
With regard to the data that the Porsche Finance Group Bulgaria collects and processes on the basis of your consent, you may withdraw your consent at any time. For this purpose, please contact the DPLP.If consent is withdrawn, the Porsche Finance Group Bulgaria will cease processing the data.
8) Our partners
Porsche Finance Group Bulgaria processes the data with the support of professional partners, namely Porsche Bank AG, Porsche Informatik GmbH, Raiffeisen Informatik GmbH, Raiffeisen Bank International AG, Raiffeisen Service Center GmbH (all based in Austria) and Porsche BG Ltd, UIC 131258238, insurance companies, car lease retrieval companies, lawyers, notaries, couriers, archiving companies, companies offering web-based payment systems, SMS notifications, companies installing and maintaining car security devices, companies registering, filing insurance claims, providing replacement cars, providing roadside assistance, changing tires, fuel cards, providing car parking, customer satisfaction surveys and software developers.
Our partners are carefully selected and ensure that they have taken appropriate legal, technical and organisational measures to ensure that your data is processed in accordance with applicable data protection legislation and to protect your rights and freedoms. Our partners may not use personal data for their own purposes or provide it to third parties without the express instruction of the Porsche Finance Group Bulgaria.9) Requesting consultation with a dealer
In the context of requesting a consultation with a dealer via the website, the data you provide in the form is used by us for the purpose of processing your enquiry. You consent to this data being sent to the respective dealership for this purpose. This consent may be withdrawn at any time without giving reasons by sending a message to us at info@porscheleasing.bg. Withdrawal of consent does not affect the remaining contractual relationship.
10) Disclosure of Third Party Data
Porsche Finance Group Bulgaria will not disclose personal data to Third Parties, except where it is necessary to protect the vital interests of you/another individual or for the purposes of complying with a legal obligation that applies to us as data controllers.Porsche Finance Group Bulgaria does not transfer personal data to any third country or international organization outside the European Union.
11) Your rights
As the subject of data processed by the Porsche Finance Group Bulgaria, you have the following rights:
a. Right to information
In addition to the information set out above, you should note that you are not subject to automated decision making, but we do carry out profiling for the purposes of assessing your ability to pay. Under applicable data privacy law, you have the rights below and we undertake to respond to any request you make within 1 month of receipt of the request and without charge. If there are factual or technical difficulties in fulfilling such requests in a timely manner, the time limit for fulfillment may be extended by an additional 2 months, which shall be notified to the data subject within 1 month of receipt of the request.
b. Right of access
You can ask for confirmation of whether and what personal data is being processed about you, as well as access to this data.
For users who have already concluded a contract, access to the information takes place through My Contract.
For users who do not have a contract, access to the information is done by making a request to the DPOH.
We will provide you with an extract of the personal data that is being processed. We may charge a reasonable fee based on administrative costs for additional extracts. Where you make a request by electronic means, where possible we will provide the information in a commonly used electronic form unless you have requested otherwise.
c. Right of correction
If we process incomplete or incorrect personal data from you, you can request its correction or completion at any time..
d. Right to deletion
You can request the deletion of your personal data in the following cases:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;- you withdraw your consent on which the processing is based and there is no other legal basis for the processing;
- you consider that the personal data have been unlawfully processed.
Please note that there may be other reasons that prevent the immediate erasure of your data, such as statutory retention obligations, pending proceedings, the establishment, exercise or defence of legal claims, etc.
e. Right to restriction of processing
You have the right to request a restriction of processing if:
- you contest the accuracy of the personal data, for a period that allows us to verify the accuracy of the personal data;
- the processing is unlawful, but you do not want the personal data to be erased and instead request a restriction on its use;
- we no longer need the personal data for the purposes of the processing but you require it for the establishment, exercise or defence of legal claims
- you have objected to the processing pending verification whether the Porsche Finance Group Bulgaria's legitimate grounds for processing the data override your interests.
In the event of a requested restriction of processing, we will inform you before the restriction of processing is lifted.
f. Right to data portability
You may request the data you provide in a structured, commonly used and machine-readable format where both conditions are met:
- the processing of the specific data is based on consent or on a contractual basis; and- the processing is carried out by automated means.
g. Right to object
You have the right, at any time and on grounds relating to your particular situation, to object to the processing of your personal data which is based on a legitimate interest or is necessary for the performance of a task carried out in the public interest or the exercise of official authority, in the event that such is granted to the Porsche Finance Group Bulgaria, including profiling based on these grounds.
Where you have consented to the processing of data for direct marketing purposes, you have the right to object to processing of personal data at any time without providing any grounds.
h. Right to file a complaint
If you believe that we have violated applicable data protection law in the processing of your data and have affected your rights as a result, please contact us. Of course, you also have the right to lodge a complaint with the Data Protection Commission.Any requests, as well as further clarifications and information relating to the exercise of your rights, can be requested directly to the Porsche Finance Group Bulgaria by contacting the DPO.
12) Dispute resolution and applicable law
In case of disputes, the applicable law shall be the law of the Republic of Bulgaria and the competent court shall be the relevant court in the city of Sofia.
Any disputes between the Porsche Finance Group Bulgaria and users regarding personal data may be resolved by negotiation between the parties. In the unlikely event of a legal dispute, it should be referred to the Personal Data Protection Commission or directly to the competent court in the city of Sofia.
13) Actualization
The Privacy Policy shall take effect from the date stated at the beginning and may be amended subsequently. The updated Policy will be effective on the day it is posted on the Website. If you visit the website after the Policy has been changed/ read the same while obtaining services from Porsche Financial Group Bulgaria, you will be bound by the new Privacy Policy.For further information, you may also read our Terms of Use or contact DPO.
*Only personal data collected by Porsche Insurance Broker when arranging insurance for non-leased cars is excluded from the scope of the Agreement.