Updated 5 December 2023
Toyota Connected Europe
Privacy Policy
This policy is provided by Toyota Connected Europe Limited (“TCEU”, “we”, or “us”), 2nd Floor, 80 Turnmill St, London EC1M 5QU. TCEU is a Controller of your data in respect of the purposes described in this policy. Our Data Protection Officer can be contacted by sending an email to privacy@toyotaconnected.eu
Many of the services we provide we do so jointly with our partner Toyota Motor Europe NV/SA, whose privacy policy can be found here: toyota-europe.com/legal/data-privacy-policy
PRODUCT SPECIFIC LAYERED PRIVACY NOTICES
TCEU offers many different products and services, which result in different processing activities taking place. To assist you with finding out about how we process your personal data, please access the table in the following link and then select the country you reside in together with the policy that relates to the services we have supplied to you: toyotaconnected.eu/privacy-policy/products
CROSS BORDER PROCESSING & LEAD SUPERVISORY AUTHORITY
TCEU is an international organisation whose Head Office is in London, UK. TCEU also has a presence in Belgium at the following address: Bourgetlaan 60, 1140 Brussel, Belgium. The Belgium authority is the Lead Supervisory Authority for TCEU in processing personal data of non-UK data subjects.
WHAT DOES TCEU DO?
TCEU is a data company. We provide services that relate to the way you move around using vehicles. This could be data that we collect from cars, or data to help you buy, lease, rent, or choose a car, or generally move around; we call this mobility. More generally TCEU contributes to helping people understand their vehicles, how economical they are, the costs of travel, problems with their vehicles and many similar things that will help you, and governments understand the future of mobility.
WHERE DO WE COLLECT YOUR DATA FROM?
We collect data in multiple ways depending on the services we provide you. To help you understand the data processing relating to you, we have layered this Privacy Policy, to allow you to click on the parts that are most relevant to you. The data sources include you directly, your devices, third parties with whom we are Joint Controllers, as well as third parties that share data with us to allow us to provide the services.
WHAT CATEGORIES OF DATA DO WE COLLECT?
Contact Details
Name, address, email address, telephone numbers, any other contact details.
Technical details from use of our websites and or apps
Technical data, such as your IP address, your internet browser, the pages you have visited on this website, information relating to your session and device information (for example hardware model, operating system, version and mobile network information), and any data you voluntarily give us via submitting or entering details within our website or mobile applications, such as submitting mileage from a leased vehicle, or choosing a reservation date for a service. If you choose to participate in any of our user research projects, we will gather data relating to you before and during such participation.
Connected Car Data
Name, address, email address, telephone numbers, any other contact details.
Contact Details
- Telematic data – any data extracted from, or related to the car, rather than the driver, including, but not limited to fuel level, warning lights, IMEI, MSISDN and SIM Card ID.
- Driver behavioural data – data relating to actions initiated by you, the driver. For example, how much fuel you have consumed, how many times you accelerated, when and how you used the brakes, whether you clicked in your seatbelt, as well as events that indicate you may have, or actually have been involved in an accident.
- Geo data – data relating to your location when you drive your car. This is precise points, including the longitude and latitude of your vehicle, including the time.
- Analytics and profiles – including scoring to help you understand how you drive your vehicle.
Leasing/renting/hiring car data
Any data that you enter via our systems/applications in relation to your vehicle, including but not limited to, mileage, booking dates, times and pick up and drop off points, driving licence details, selfies, vehicle type, vehicle registration, lease type, length of lease, payments, credit card information and proof of income.
Preferences
Your choices and preferences about marketing and advertising, including methods such as email, text, phone, post, as well as agreement to cookies and similar technologies. See our Cookie Policy for details about cookies and similar technologies.
User Research Data
- Name
- Demographic details gathered from User Testing Inc. including your age range, gender, household income, employment details and status (including job function, job seniority, company size & industry and location) and device information (including browser, color depth, CPU, free memory & operating system).
- Whilst we do not receive this data directly from User Testing Inc, given that we request participants based on satisfaction of these criteria, we are able to make inferences about what demographic you are in based on this data.
- Opinion and historical usage information relating to our products collected (i) from UserTesting Inc.; (ii) from you; and (iii) during your participation in our user research projects.
- Audio and video recordings of your participation in our user research projects.
- Comments you make publicly available in respect of any Toyota products across social media platforms.
Recruitment data
This is data you provide to us, either by request or voluntarily when you apply for a job with TCEU. See our Recruitment Policy for further details.
WHO DO WE SHARE YOUR DATA WITH?
Your personal data may be transferred between TCEU affiliates throughout the world and, as detailed in the privacy policy specific to the service we provide to you, certain third parties, such as:
- Service providers that provide services on our behalf.
- Legal advisors, auditors and other professional advisors.
- Courts, tribunals, arbitrators or other judicial committees; and
- Local or foreign governments, regulators and law enforcement agencies.
When third parties are given access to your personal data, TCEU will take the required contractual, technical and organisational measures to ensure that your personal data is only processed to the extent necessary.
TCEU also uses service providers to help deliver its services. These providers, known as Processors, can only process your data on our behalf. The main processors that we use are:
- Microsoft Azure – Ireland – Hosting and infrastructure;
- Amazon Web Services – Germany – Hosting and infrastructure;
- Toyota Motor North America, Inc. – North America – Administration and support
- Infosys Limited – India – Business Support;
- Endava (UK) Ltd – United Kingdom – Business Support;
- Toyota Motors Europe NV/SA – Belgium – Administration and support;
- User Testing, Inc. – North America – A customer experience online feedback platform; and
- Any of the Toyota Group companies.
THE PURPOSES, LAWFUL BASIS AND RETENTION
Purpose
Lawful basis
Categories of Data
(some or all of each category mentioned)
Retention Period
Who your data is shared with
Connected Car Services Europe
Performance of a contract
Technical details from use of our websites and/or apps
Connected car data
Contact details
12 months from the date of ingestion for connected car data
6+ years UK, or statutory limitation period for contact details
Toyota Motors Europe NV/SA, with whom we are a Joint Controller
Connected Car Privacy Notice
Analytics – website and mobile app use
Consent
Technical details from use of our websites and/or apps
13 months, or until you withdraw Consent
N/A
Marketing and personalized advertising
Consent
Technical details from use of our websites and/or apps
Contact details
websites and/or apps Contact details 13 months or until you withdraw Consent
Any third parties that we list in our Cookie Policy
User research and product testing
Consent & Legitimate Interests
User Research Data
When relying on Legitimate Interests for comments made across social media platforms, we anonymise the data immediately upon receipt.
12 months or until you withdraw Consent
Data is anonymous and outside of the scope of GDPR
N/A
Complying with applicable laws, rules, regulations, guidance, codes, and industry/ professional rules and regulations
Legal obligation
Any and all of the data categories as and when the circumstances arise
On a case-by-case basis
On a case-by-case basis, and will include police and competent authority court orders
Responding to any questions or queries you may have about TCEU or this website
Legitimate interests
Any data that you provide to us
On a case-by-case basis depending on your reasons for contacting us
On a case-by-case basis depending on your reasons for contacting us
As and if the circumstances arise that we need to process or disclose data for the vital interests of data subject or another natural person, including helping to fight crime
Processing is necessary to protect the vital interests of the data subject or another natural person
Any and all of the data categories as and when the circumstances arise
On a case-by-case basis
On a case-by-case basis, and will include police and competent authorities
As and if the circumstances arise that we need to process or disclose data for the vital interests of data subject or another natural person, including to help fight crime
Performance of a task carried out in the public interest
Any and all of the data categories as and when the circumstances arise
On a case-by-case basis
On a case-by-case basis, and will include police and competent authorities
Ensure the integrity and security of your personal data
Legal obligation
Audit logs: identifier of who accessed the data, when they accessed the data and what records were changed.
Minimum 12 months unless exception requires a longer of shorter period
N/A
WITHDRAWING CONSENT
Where we rely on your consent to process your data, you have a choice about continuing with the processing of your data or withdrawing your consent to stop the processing. To withdraw your consent to cookies and similar technologies, please follow the instructions in our Cookie Policy.
For other processing activities, please send your request to privacy@toyotaconnected.eu.
For other processing activities, please send your request to privacy@toyotaconnected.eu.
ANALYSING YOUR DATA - PROFILING
The analysis we do, can, for example, help inform us about products and services you are most interested in, and generally make conclusions about your preferences and behaviour. This is to help:
- you make choices about what car to buy/lease/rent;
- inform you about your driving patterns, including how economical your car journey was;
- improve our services to you, by helping us research and develop existing and new products;
- facilitate and improve the sale of products and services more effectively and/or efficiently; and
- provide a more personalised online experience for you. This includes making decisions on which products and services, promotions and offers, to send you marketing information about
- We work with User Testing Inc. to recruit participants for our user research testing activities who display certain requested characteristics/attributes. For instance, we may request participants who are aged between 30 to 35, who live in an urban area and who are a Toyota driver. Through this exercise (and when combined with personal data that we gather about user testers during the our user research projects), we will engage in profiling. We undertake profiling to help us develop a broad perspective and understanding of the users of our vehicles for the benefit of our customers.
SECURITY MEASURES
Whilst TCEU takes all reasonable precautions to protect personal data from loss, misuse, alteration or destruction and complies with data protection laws, data transmission over the internet may not be adequately secured by the sender. As a result, TCEU cannot ensure the secure receipt of any information that is sent to TCEU by this medium and any such information is sent at your own risk.
SPECIAL CATEGORY DATA
TCEU does not intentionally process special category sensitive data, such as health, political or religious beliefs, and we do not knowingly attempt to identify, predict, evaluate or in any way process data that would indicate any of the above. Whilst it may be possible to make inferences about any of the above from data collected, TCEU does not make those inferences.
CHILDREN'S DATA
TCEU does not process children’s data.
WHERE IS YOUR DATA PROCESSED?
TCEU may transfer your personal data to countries or territories outside your place of residence, where data protection laws may not offer the same level of protection available in your home country. We will implement appropriate measures to ensure that your personal data remains protected and secure when it is transferred outside of your home country, in accordance with applicable data protection and privacy laws. These measures include data transfer agreements implementing standard data protection clauses. You can find more information about data transfer agreements here.
YOUR RIGHTS WITH RESPECT TO YOUR PERSONAL DATA
You may be entitled to:
- receive confirmation from us as to whether we process your personal data, and, where we do, access a copy of that personal data and certain other information;
- request the rectification of any inaccurate personal data that we hold about you;
- request the erasure of your personal data in certain circumstances;
- request the restriction of our processing of your personal data in certain other circumstances, for example in certain scenarios where we are unable to comply with a request to erase your personal data;
- receive a copy of the personal data that you have provided to us in a structured, machine-readable and commonly used format and/or, where possible, to request we transmit that personal data to another organization;
- object to certain processing of your personal data;
- withdraw your consent to the processing of your personal data (where we are processing your personal data based on your consent); and
- make a complaint about our handling of your personal data to your local data protection supervisory authority (details of local supervisory authorities in each EU Member State can be found here).
If you would like to exercise your rights, please let us know by getting in touch via emailing privacy@toyotaconnected.eu.
You also have a right to make a complaint to the regulator by telephoning 0303 123 1113.
You also have a right to make a complaint to the regulator by telephoning 0303 123 1113.