EUROPCAR APPLICATION PRIVACY POLICY (ECI)

 

 

1. Who processes your personal data collected through this website?

 

Europcar International S.A.S.U. whose registered office is located at 13 Ter Boulevard Berthier

75017 Paris, France (hereinafter referred to as "ECI") is responsible for the processing of your personal data (i.e. any information that would allow to identify you, either directly or indirectly) collected through this application.

 

2.  For what purposes does ECI collect your personal data?

 

ECI processes personal data that you voluntarily provide to ECI through this application for the following purposes:

 

a)      Your registration as ECI member, creation of your account and providing you with a Driver ID. You will be asked to provide the following types of information in order to create your account:

-       Mandatory: first name, last name, date of birth, email address, password, postal address, city, driving license number (issuing country, city & date or expiry date), a picture of Yourself  (solely for identification and theft or fraud detection purposes)

-        Optional: Postal code, phone number.

-        Optional: storing a means of payment in your account (credit card number, date and expiry date)

 

This processing is necessary to identify you and to prepare and facilitate your future booking / rental agreements with ECI.

 

 

b)      Your booking:

i.        to confirm and guarantee your booking;

ii.       to import a booking;

iii.      to modify or cancel your booking; 

iv.   to exchange with you in relation to your booking (e.g. to provide you with information on your booking, to send you reminder notice before your check-in / check-out, to respond to your questions or suggestions);

v .    to enable you to benefit from a negotiated rate and/or a partnership program you have entered into with third parties such as frequent flyer programs

iv.    to manage your invoices if you decide to pay in advance, and handle any arrears;

v.        to manage potential claims

 

This processing is necessary for the management of your booking and the preparation of the rental agreement concluded with an entity of Europcar group or network. 

 

c)    If you decide to pay in advance, your payment for ECI products / services, including if you wish to use your deviceÕs camera to automatically enter your credit card data, and/or to block an amount of the deposit on your credit card (this can also be done if you pay on arrival at the rental counter)

 

This processing is necessary for the performance of the purchase of ECI products / services. For your full information, ECI can only retain your credit card information, subject to your express consent in order to facilitate future payments.

 

d)     The improvement of Europcar products / services on the basis of technical information regarding your device (e.g., operating system, phone brand ...), your rating of our app (collected and displayed on the Apple or Google store) and customer surveys you have completed.

 

This processing, aiming at having a better understanding of ECI members' needs and offering you customized functions to enhance your experience of Europcar products / services, is based on ECI "legitimate interest".

e)            Promotional and marketing activities, namely:

i.            the sending of email and SMS notifications for special promotions / deals and the display of ÒpushÓ notices on your deviceÕs screen;

 

 

 

ii.           the recording of your rental history to suggest you preferred products / services when looking for new booking / rentals;

 

iii.           the recording of your rental history:

- to send you commercial messages,

- to send you special offers; and/or

- to make you benefiting from special advantages;

depending on the volume, amounts, frequency of your orders, duration of your rentals and your activity on our application (e.g., number of visits);

 

iv.            the display of a ÒpushÓ notice about a booking you did not complete or send you a summary about a booking enquiry ;

v.            access to or management of your loyalty program and membership card;

vi.          the organization of promotional contests / sweepstakes;

vii.         the management and update of Europcar customers / prospects database

viii.        the publication of your ratings on Europcar products / services.

 

Direct marketing processing activities (prospection directe), i.e. any commercial message from ECI aiming at promoting Europcar products / services, are subject to your express consent.

By exception, if you are already an ECI existing customer and that the message concerns products / services similar to those you have already purchased, the underlying processing aiming at promoting these products / services will not be based on your consent but on ECI "legitimate interest".

 

f)  The management of fines, in particular:

i.          to transfer to the Agence Nationale de Traitement AutomatisŽ des Infractions the identity of the driver (or potential driver);

ii.         to satisfy fines collection procedure to which ECI may be subject

 

This processing is required by law.

 

g)  The management and update of a watch list of customers presenting certain contractual risks based on:  

i.            payment incidents which have given rise to legal proceedings;

ii.           vehicle accidents or repeated damages caused by Europcar customers

iii.          accidents or damages caused voluntarily by Europcar customer;

iv.         use of Europcar vehicles in breach of the general terms and conditions for rental of vehicles. 

 

h)  If you activate this functionality, the geolocation of your device in order to display the station nearest to you (Òstation finderÓ). This data is only stored on your device.

 

Station finder processing is subject to your express consent provided in the app.

 

For your full information, ECI carries out certain processing of your personal information through "SDKs" collected when you use the app. These processing are described in further detail below.

 

3.      Who are the data recipients of the personal information we collect about you?

3.1 Categories of recipients

 

Your personal data will be disclosed, as necessary / relevant, to:

 

a)  to the authorised personnel of ECI and of entities of the same group, entities of ECI franchise network and agent / sales intermediary appointed by ECI, for the purposes described in this privacy policy;

b)  third party IT service providers for technical purposes in order to help ECI in providing you with access to this application and to Europcar products / services. The main IT service providers are:

                  i.            Cap Gemini, for business applications development and maintenance;

                  ii.           Sopra Steria, for data center maintenance and user support services;

                iii.           Unisys, for hardware implementation and maintenance;

                iv.           SalesForce, for marketing services;

         v.            Google Inc., in particular for hosting services and business applications.

vi. external consultants for various missions in the course of ECI business activities.

 

c)  regarding the information processed for the payment of fines, to the Agence Nationale de Traitement AutomatisŽ des Infractions;

d)   regarding the information processed for the purpose of the management and update of a watch list of customers presenting certain contractual risks to the vehicle rental agencies branch of the Conseil national des professions de l'automobile to the benefit of their members;

e)   marketing agencies for the preparation and conduct of marketing campaigns;

f)             external consultants for various missions in the course of ECI business activities.

 

ECI can also disclose your personal data to the extent required by law and/or by competent authorities.

 

3.2 International transfers

 

As necessary to provide you with ECI services, ECI will, to the extent necessary for the purposes set forth herein, transfer your personal data outside the EU to the abovementioned third parties.

 

Depending on the case, certain recipients may be located in countries which have been recognized by the European Commission as ensuring an adequate level of data protection or in countries which has not been recognized as ensuring such a level of protection. In any case, ECI has put in place appropriate safeguards to protect your personal data, in compliance with the EU regulation no.2016/679.

To find more information regarding the countries where your personal data can be transferred and their level of data protection by ECI, please click here.

To have more information about the transfer of your personal data outside the European union, please refer to the contact information provided at the end of this Policy.

4.  For what period will ECI retain your personal data?

Your personal data are retained for different period, depending on the purposes of the processing :

 

Purpose

Retention period

Your registration as Europcar member, the creation of your account and the provision of your with Europcar ID

Your booking

For the duration of the commercial relationship.

However, information that may evidence a right or a rental agreement, or that must be kept in compliance with a legal requirement, may be subject to an intermediate archiving policy for a period of time that does not exceed the time that is necessary for the purposes for which it is kept, in accordance with applicable legal provisions.

Payment – Payment card information _ Deposit

Upon effective completion of the payment.

However, payment card information (excluding the visual cryptogram):

¤  that may evidence a payment (i.e. card number and date of validity) is subject to an intermediate archiving policy for a period of time of 13 months after the effective payment for a credit card and 15 months for a deferred debit card, to be used only if the transaction is disputed;

¤  can be retained for a longer period, subject to your express consent to facilitate future payments.

In any case, when the payment card is expired, related information will be deleted.

Promotional and marketing activities

For ECI customers, 3 years as from the end of the relationship with ECI.

For prospects – who are not Europcar customers – 3 years as from the collection of your personal information OR as from the last request for information you made.

Operation of ECI live web chat

3 years as from the end of the relationship with ECI.

 

Improvement of ECI services depending on your preferences

3 years as from the end of the relationship with ECI.

Payment of fines

For the time necessary to identify the driver (or the potential driver) liable for the infraction leading to the fine, which cannot exceed 45 days after receipt of the fine. However, relevant information can be kept for a longer period of up to 12 months after receipt of the fine, subject to an intermediate archiving policy.

Requests from Agence Nationale de Traitement AutomatisŽ des infractions including personal information are deleted once these requests have been proceeded by ECI.

The management and update of a blacklist of customers presenting certain contractual risks namely:

i.        payment incidents which have given rise to legal proceedings

ii. vehicle accidents or repeated damages caused by Europcar customers

iii.  accidents or damages caused voluntarily

3 years as from the occurrence of the relevant event

iv.  the use of Europcar vehicles in breach general terms and conditions for rental of vehicles

5 years as from the occurrence of this event

 

For the following SDKs:

Accengage:

-       Accengage is a tool for sending Push Notifications for Mobile Applications. It collects different kind of informations to segment the campaigns :
* personal informations about the user : User email hashed, app used id, android id, etc...
* informations about the navigation : country, timestamp, etc...
* informations about the device used : device type, device model, device language, etcÉ

-       The data Collected by Accenage are not transferred to servers located outside of UE

-       Some data (related to the abandonment of basket for example) are related to the sessions in order to be able to trigger a specific message. And some data are "persistent" and are hosted at Accengage so that they can be used to segment the databases for different campaigns.

-       The data of the database is hosted for 12 months. If a user does not open the app in the last 12 months, the line corresponding to the device will be removed from our database

AppsFlyer:

-        AppsFlyer is a mobile marketing analytics and attribution platform. It allow us to monitor the performance of our different marketing channel for the apps . It collects different kind of informations :
- personal informations about the user : first name, device ID, etc...
- informations about the navigation : country, language, date, etc...
- informations about the device used : device model, OS version etcÉ

-       All data stored is hosted on servers located in the European Union

-       The data collected are linked to a publicity ID (or device identifier) ​​and not to a session, this is due to our attribution model

-       The data collected  are stored for 24 months for aggregate data. The personal data is stored for 3 months

Google Tag Manager (GTM):

-       GTM is a tag management system that allows you to quickly and easily update tracking codes and related code fragments (tags) on mobile apps

-       Google Tag Manager can collect some informations, for instance the using service mode, the tags triggered and how they are triggered.

-       The data collected can be used by Google to improve, maintain, protect and develop the Google service in accordance of the privacy rules. However Google does not share these data with other Google product without the consent of the client

-       Google can keep the data collected up to 180 days

CRASHLYTICS/FABRIC:

-       Crashlytics gives crash reporting, with real-time analytics to understand what is happening in an app. FabricÕs analytics engine provides insights to Europcar, such as growth, retention, and engagement.

-       The data collected are: Installation UUID (retains Installation UUID data for 90 days).

IP Addresses - once received it is geo-coded to a city and displayed on Audience Insights map for 10 seconds. Retained temporarily.

-       Crash traces and their associated identifiers are kept for 90 days.

CARD IO:

-       CardIo is a credit card scanning service that allows with the phone camera to automatically fill the credit card information on Europcar App.

-       Credit card data are not collected by CardIo

 

5.      What rights can you exercise with respect to the processing of your personal data?

At any time, you can view and/or update your personal profile, which includes member registration, driver information and car rental preferences information, through the "My Profile" section, accessible through the main navigation bar of the Europcar app. You will be able to change your password, secret question, update or correct phone number, address, email, and driving licence information and update your car rental and travel preferences including insurance, means of payment and frequent traveler membership.

 

As per EU regulation no.2016/679, you can also benefit from the following rights:

 

a)      right of "access": right to obtain confirmation as to whether or not your personal data are being processed by ECI, and, where that is the case, to access to these personal data and to obtain further information on the characteristics of our processing [1];

b)  right "to rectification": right to obtain the rectification of inaccurate personal data or the right to have incomplete personal data completed, including by means of providing a supplementary statement;

c)  right to "erasure" (or the so-called "right to be forgotten"): right to obtain the deletion of your personal data in certain circumstances[2];

d) right to "restriction": right to obtain restriction of processing under certain circumstances [3]. Should the processing of your personal data be restricted, such data can only be further processed subject to your consent (save for storage purposes) and you will be informed before the restriction of processing is lifted;

e)  right to "object": at any time, a right to object to the processing of your personal data to prevent ECI from continuing to carry out such processing:

                                         i.            where your data are processed for direct marketing purposes;

                       ii.            where your personal data are processed on the basis of ECI's legitimate interest. In that case, your request will be satisfied only if you provide ECI with a description of the particular situation legitimating your request and save if ECI can demonstrate overriding legitimate grounds in light of your particular situation.

f)           right to "withdraw your consent": where the processing of your personal data is based on your consent, a right to withdraw your consent to the processing of your personal data at any time and to prevent ECI from continuing to carry out such processing;

g)  right to "data portability": where the processing of your personal data is based on your consent and carried out by automated means, the right to receive your personal data provided to ECI, in a Excel spreadsheet [4] and to transmit those data to a designated third party.

h)  right of a "deceased person" (for France): right to define guidelines regarding the processing of your personal information after your death.

 

If you wish to exercise any of these rights, please contact the entities as set out below in section 6.

 

To protect your privacy and security, we will take reasonable steps to verify your identity before granting access or making corrections.

As per article 77 of the EU regulation no. 2016/679, you can lodge a complaint about the processing of your personal data with the body regulating data protection in your country[5] if you consider that the processing of your personal data infringes the said EU regulation no. 2016/679.

 

6.   Who to contact when you have a query regarding the processing of your personal data?

 

Depending on the purpose of your query, you will find below:

 

a)  To exercise your rights (access, rectification, erasure, restriction, etc.): you can use the online form available here and contact

 

      Australia: customerrelations@europcar.com.au

      Austria: datenschutz@europcar.at

      Belgium: Customer.servicesBelgium@europcar.com

      Canada: privacy@discountcar.com

      China: (+86) 1010-5678 or pr@izuche.com

      Denmark: dk_customerservice@europcar.dk

      Egypt: customer.service@europcar-egypt.com

      Europcar International: ecicustomerservice@europcar.com

      Finland: varaukset@europcar.fi

      France: espace.relationclient@europcar.com

      Germany: datenschutz@europcar.com

      Ireland: res@europcar.ie

      Italy: customerserviceitaly@europcar.com

      Luxemburg: lu_customerservice@europcar.lu

      Japan: please complete the form available on https://rental.timescar.jp/view/inquiry/english/general/input.jsp 

      New Zealand: customerrelations@europcar.com.au

      Poland: ado@europcar.pl

      Portugal: apoio.clientes@europcar.com

      Russia: customerservice@europcar.ru

      Spain: lopd.es@europcar.com

      Sweden: kundsupport@europcar.se

      Switzerland: CustomerService@europcar.ch

      Turkey:  TR_Customerservice@europcar.com.tr

      UAE : AE_Customerservice@europcar-uae.com

      UK: customerservicesuk@europcar.com

      USA: personaldata@advantage.com

 

b)  For general query regarding the processing of personal data carried out by Europcar:

      Australia: privacyinformation-australia@europcar.com

      Austria: datenschutz@europcar.at

      Belgium: privacyinformation-belgium@europcar.com

      Canada: privacy@discountcar.com

      China: (+86) 1010-5678 or pr@izuche.com

      Denmark: privacyinformation-denmark@europcar.com

      Egypt: customer.service@europcar-egypt.com

      Europcar International: eis-dpo@europcar.com

      Finland: varaukset@europcar.fi

      France: privacyinformation-france@europcar.com

      Germany: privacyinformation-germany@europcar.com

      Ireland: privacyinformation-ireland@europcar.com

      Italy: privacyinformation-italy@europcar.com

      Luxemburg: privacyinformation-luxemburg@europcar.com

      Japan: please complete the form available on https://rental.timescar.jp/view/inquiry/english/general/input.jsp 

      New Zealand: privacyinformation-newzealand@europcar.com

      Poland: ado@europcar.pl

      Portugal: privacyinformation-portugal@europcar.com

      Russia: customerservice@europcar.ru

      Spain: privacyinformation-spain@europcar.com

      Sweden: kundsupport@europcar.se

      Switzerland: CustomerService@europcar.ch

      Turkey: TR_Customerservice@europcar.com.tr

      UAE: AE_Customerservice@europcar-uae.com

      UK: privacyinformation-uk@europcar.com

      USA: personaldata@advantage.com

 

 

If you have questions regarding this app, please contact: ecicustomerservice@europcar.com 

 

7.      How does ECI protect your personal data?

 

ECI is committed to protecting the information it collects through this application.

In particular, ECI uses appropriate physical, technical and organizational security measures to prevent unauthorized or unlawful processing, accidental loss of or destruction of or damage to your personal data.

ECI's systems are configured with data encryption, or scrambling technologies, and industry-standard firewalls. When you send personal information to a ECI application over the Internet, your data is protected by "Transport Layer Security" (TLS) technology to ensure safe transmission.

Any credit card transaction you make through ECI applications is done through our Secure Server Technology. This technology notably:

 

a)      assures your browser that your data is being sent to the correct computer server, and that the server is secure;

b)      encodes the data, so that it cannot be read by anyone other than the secure server;

c)      checks the data being transferred to ensure it has not been altered.

 

8.      What rules apply to the processing of your personal data when clicking on links placed on ECI application directing to ECI partner's websites or other websites?

 

You may find various links to ECI's partners websites or other third party websites (e.g. for travel services) on this application. ECI would like to draw your attention to the fact that this privacy policy does not apply to the processing of your personal data carried out by our partners or other third parties when visiting their respective websites and that ECI is not responsible for these kind of processing. We encourage you to review the privacy policies of ECI's partners and other third parties to further understand the rules applicable to the processing of your personal data carried out by the same.

 

9.      Changes to this Privacy Policy

 

This privacy policy was published on May 25th, 2018. In case of changes to this privacy policy implemented by ECI, such changes will be identified by ECI on this webpage.

When a change materially impacts a processing carried out on the basis of your consent, ECI will contact you to obtain a new consent.

 

 


[1] Regarding the purposes of the processing, the categories of personal data concerned, the categories of recipients, whether these data are transferred to third countries and appropriate safeguards put in place (if any), the storage period, the existence of any automated decision-making based on these data, the right to lodge a complaint with the relevant data protection authority, the existence of other data subjects' rights (rectification, erasure, restriction).

[2] Where (i) data are no longer necessary in relation to the purposes for which they are processed, (ii) you withdraw your consent and there is no other legal ground for the processing, (iii) you object to the processing of your personal data and there are no overriding legitimate grounds, (iv) it is demonstrated that your personal data have been unlawfully processed, to comply with a legal obligation.

[3] If (i) you contest the accuracy of the personal data, (ii) it is demonstrated that the processing is unlawful and you oppose to the erasure of the personal data but you would like to request the restriction of its use instead, (iii) ECI no longer needs the personal data for the purposes of the processing but these are required by you for the establishment, exercise or defence of legal claims.

[4] Or any other commonly used and machine-readable format.

[5] The country where you have your habitual residence, place of work or place of the alleged infringement.