TERMS & CONDITIONS
We, Lotus Cars Limited, take your privacy seriously and are committed to protecting it.
This privacy policy sets out details about our processing of the personal data which we collect from the Lotus Emira, or that you provide to us, as part of:
- Accessing your vehicle’s “Navigation Features”, consisting of:
- Traffic
- Weather
- Parking search
- Point of interest search
- Providing you with emergency call support and breakdown support (“e-call” and “b-call”, together the “emergency functions”), including customer surveys
- Using the onboard computer (the “IHU”) features
- Using voice controls,
together the “Features”.
This policy applies in addition to our End User Licence Agreement (which we call the “EULA” in this policy) which governs the use of the Features. This privacy policy and EULA cover Features used in your vehicle in both the United Kingdom (“UK”) and the European Union (“EU”).
The information which we refer to in this policy, is not linked to you personally, but to the vehicle and in turn to the account of the owner of the vehicle who has registered his/her details with us.
The owner will therefore be able to view such personal data, as well as exercise subject access rights in respect of this personal data – as the data does not differentiate between different drivers or passengers of the vehicle, as it is vehicle and owner linked only. By using the Features you are confirming that you understand and agree to any data which you generate being used and linked to the vehicle and owner in this way.
There is also information which is stored and visible in the in-vehicle display regarding the Features (including journey information and searches). Any user of the vehicle is able to view this information and delete it using the in-vehicle display controls.
Information which we may collect from you
We may collect, use, store and transfer different kinds of personal data about you which includes:
– Saved Preferences: your preferred settings, names and saved locations.
– Inputted Information: any information which you enter into the in-vehicle display, including areas of interest and search requests entered by you.
– Location Data: the vehicle’s co-ordinates (using Global Navigation Satellite Systems), direction of travel and speed – this information is automatically transmitted to us when you use the Navigation Features which depend upon your location (such as journey planning, points of interest searches or parking searches). We will also collect your location when you use the e-call and b-call functions, to provide you with assistance. Your co-ordinates and direction of travel are automatically transmitted when the e-call function is used.
– Vehicle IP address: this is the identifier linked to the vehicle session, to transmit data to and from the vehicle for the Navigation Features. The Vehicle IP address changes each time you use the vehicle, or there is a re-connection to the mobile network for data transmission from the vehicle.
– Voice data: this is sent offboard to provide voice control functionality, where required.
– Car details: we will collect your vehicle identification number when you use the e-call and b-call functions and licence plate when you use the b-call function, to provide you with assistance. We also collect certain technical data (such as vehicle type, fuel type), when the e-call feature is activated.
– Contact details: we will collect your contact details, such as your name, phone number and email address, when you use the b-call function, to provide you with assistance.
– Key personal details: We will collect your nationality and gender, when you use the b-call function, to ensure that we can provide you with suitable assistance.
– Call recordings and survey responses: We collect this information when you use some of the emergency functions.
Our third party service provider, HERE Global B.V. based in the Netherlands (which we refer to in this policy as “HERE Global”) provides the software and data functionality for the Navigation
Features. When you are using the Navigation Features, we are the controller of the personal data which is being processed and HERE Global is the processor.
When you use the Navigation Features certain information is sent to HERE Global to provide the features. HERE Global would also like to use the information for product improvement purposes.
When they do this they are a controller of the data and have set out information relating to this in their own privacy notice which can be found below.
How we will use your personal data
Purpose | Lawful basis |
To process your personal data to provide the Features (other than e-call and customer surveys). | In relation to the owner of the vehicle, we rely upon the performance of our contract with you, to provide the car’s functionality. In relation to other users of the vehicle, we rely upon our legitimate interest provide a value added service relating to driver and passenger convenience. |
To process your data to provide the e-call function. | We rely upon our legal obligation to provide an e-call function, to process the personal data of both the owner and other users of the vehicle. |
To process your data to run surveys relating to our b-call services | We rely upon our legitimate interest in improving the services we offer to users of our vehicles to send an initial text to individuals who request breakdown support via the vehicle and in running the survey. |
In certain circumstances we may process your personal data, especially where provided via the emergency functions, if it is necessary to protect the vital interests of a natural person (and you are incapable of providing consent).
We may also rely on our legitimate interests in providing you with a service you would expect from a Lotus to process your data to provide additional services.
Disclosure of your personal data
We disclose your personal data to our third party service providers (such as HERE Global, as well as our mobile network data transmission service providers, hosting providers and emergency and breakdown service providers) to allow provision of the Features. It will also, in the event the e-call function is used, disclose your personal data to the appropriate emergency services.
Lotus will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.
The disclosure of your information may involve transferring your data outside the UK or EU, where are service providers and their sub-processors are located outside the UK or EU. Whenever we transfer your personal data out of the UK or EU we will only transfer your personal data to countries where they have an adequacy regulation finding under the data protection laws, or where we have entered into standard contractual clauses with the service provider, or the service provider can confirm that it has binding corporate rules, to provide adequate safeguards for international personal data transfers.
With regard to the personal data which is being processed in the European Economic Area, an Adequacy Regulation applies.
Where we store
The data that we collect from you will mainly be stored in the United Kingdom and European Economic Area. In certain cases out third party suppliers may, subject to appropriate security measures, as noted above, store your personal data in other third countries.
How long we keep your personal data
We will only retain your personal data:
- Where it is stored in the vehicle IHU, until such time as you decide to delete the information, using the in-vehicle display;
- Where it is sent from the vehicle to HERE Global in order to fulfil a Navigation Features request, the detail of the request is retained for 30 days, while the vehicle’s IP address is retained for a period not exceeding one year, with most information being securely deleted earlier than this; and
- Where it is otherwise transmitted from the vehicle no longer than 7 years (reflecting the usual statutory limitation period, plus one year).
Your legal rights
As we mentioned earlier on in this policy, all personal data is linked to the vehicle and its owner’s account. Therefore, the rights referred to here are those available to the owner, as we will not be linking the personal data in any identifiable way to any other occupant of the vehicle.
Therefore, you, as the owner of the vehicle, have the right to:
- Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it. You will not usually have to pay a fee to access your personal data (however, any repetitive, excessive or unfounded access request may be subject to a reasonable fee to meet our administration costs in providing you with details of the information we hold about you; alternatively, we could refuse to comply with your request in such circumstances).
- Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data which we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
- Request erasure of your personal data. This enables you to ask us to delete or remove personal data in certain circumstances. With regard to personal data stored on the IHU, you can delete this using the in-vehicle display controls.
- Object to processing of your personal data on grounds relating to your particular situation where we are relying on a legitimate interest (or those of a third party). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:- If you want us to establish the data’s accuracy.
- Where our use of the data is unlawful but you do not want us to erase it.
- Where you need us to hold the data even if we no longer require it, as you need it to establish, exercise or defend legal claims.
- You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to processing in an automated manner of personal data which you provided to us, on the basis of consent or where we used the personal data to perform a contract with you.
- Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you, as mentioned in this policy.
To exercise any of the rights above (to the extent that you cannot do so using the in-vehicle display), please contact us using the Contact details listed below.
Changes to our privacy policy
This privacy policy may be amended from time to time.
Contact us
Questions, comments and requests regarding this privacy policy should be addressed to our data protection officer at: legal@lotuscars.com
Data Protection Officer, Legal and Compliance Department, Lotus Cars Limited, Potash Lane, Hethel, Norwich, Norfolk NR14 8EZ UK.
If you are not happy, or have a complaint about the way in which we use your personal data, we hope that you will contact us at the above address. If you are not satisfied (or in the alternative), you may also make a complaint to the supervisory authorities:
- European Data Protection Supervisor which is the supervisory authority who regulates personal data in the EU – details of their contact details are available from their website: edps.europa.eu.
EU Representative
Our representative in the European Union is DüssData Solutions & Protection GmbH.
You may contact our representative at:
DüssData Solutions & Protection GmbH
Carl-Maria-Spett-Straße 30
40595 Düsseldorf, Germany
+49 173 1677947
Your Privacy while using HERE APIs
HERE’s Privacy Policy explains how your personal data is processed in context of HERE products and services. The following policy supplement provides additional details regarding your use of an application provided by a party other than HERE which has integrated services from HERE that provides location-based functionalities in context of the application.
Additional information applicable to users in specific countries may be found by visiting HERE’s Privacy Policy above and selecting the applicable location in the drop down at the top right of the page.
What is HERE’s involvement?
HERE makes available certain application programming interfaces, or “APIs” as well as software development kits, or “SDKs”, which consist of interfaces or libraries of computer code that developers can integrate into their applications. The HERE APIs and SDKs enable developers to better use HERE services, or to add location-aware features into their applications. This supplement addresses data processing activities that occur in context of these location-aware features. Information which is sent to HERE as a necessary part of providing the HERE services is addressed in the general HERE Privacy Policy.
What information does HERE collect?
Search keywords and other contextual location- or request-related information
If the application you are using makes use of HERE-provided APIs, the data processing involves collection of request attributes in relation to the area of interest or type of request. For example, if you are interested in weather information, traffic conditions, or parking availability information in a particular area, that location or area is provided to HERE to provide the corresponding weather, traffic or parking availability information back to you. If you search for a particular place, the search keyword is provided to HERE, along with the location information provided by you as the search area of interest to be able to return appropriate place information corresponding to your search back to you.
How we use the information HERE has collected?
Providing the products and services
Information sent to HERE through use of its APIs and SDKs is used to provide you with HERE’s products and services, to process your request, or as otherwise may be necessary to provide the location services offered to you through your auto manufacturer and to ensure the functionality and security of HERE’s products and services.
Improvement of products and services
HERE uses the collected information to improve and enrich its APIs, SDKs, maps and location services. The collected information helps HERE to focus improvement efforts to things that are most relevant to its consumers and to avoid error situations in the future. For these purposes, HERE may combine information collected by the APIs or SDKs with other data it may have. Even when combined with other information, HERE does not use this data to identify you personally or even attempt to discover your identity.
How does HERE collect the information?
The APIs only collect information in context of a particular request and only as necessary to respond to the particular request. The HERE APIs themselves do not actively collect any information from any vehicle or device you are using.
What is HERE’s information sharing practices?
HERE not share the information collected by the API or SDK related data collection with independent third parties, unless otherwise explained in our privacy policies. However, information collected related to a particular third-party feature may be shared with the provider of that application or feature in aggregated non-identifiable form.
What safeguards are in place?
The HERE APIs do not collect or process any user or device identity information. Each request is processed independently to be able to respond to the request. The services do not conduct any profiling activities unless specifically designed for a personalized use. You will be notified separately if personalization context applies. The APIs use secured protocols to request the information from HERE’s servers. When the request is sent, it is logged to a log file, which is retained for approximately 30 days for the aforementioned improvement purposes. Because HERE operates its services on a global basis, data submitted in a request may be processed outside the country in which it was submitted. Where requests are transferred outside of the European Economic Area, HERE has put in place safeguards such as the Standard Contractual Clauses and other appropriate technical and organizational measures to ensure that personal data is appropriately protected.
What is HERE’s legal basis for processing your personal data?
In connection with providing you the HERE products and services, including the HERE API services, HERE processes your personal data pursuant to the services agreement with your auto manufacturer. For these processing activities, your auto manufacturer acts as the controller for your data. Please review your auto manufacturer’s privacy notice for further information about how they may process your data and your associated rights.
HERE may also process information submitted to its API services for its legitimate business interests, such as ensuring the security of its services and systems and internal product maintenance and improvement. In connection with HERE’s internal product maintenance and improvement activities, HERE does not process your personal data in a way which identifies or profiles you individually, but rather to create aggregated and anonymized insights as part of HERE’s mapping activities. Additional information regarding HERE’s legitimate business interests and your associated rights may be found in HERE’s Privacy Policy.
How long does HERE retain Personal Data?
HERE endeavours to only collect personal data that are necessary for the purposes for which they are collected, and to retain such data for no longer than is necessary for such purposes. Where collected, the records of your activity within the application are typically maintained only for a short period before being anonymized. As mentioned above, the log file containing the API request information used for internal product maintenance and improvement purposes is maintained for approximately 30 days, after which the requests are anonymized. Where provided to HERE by your auto manufacturer, information such as IP addresses used in connection with certain audit, accounting, and security aspects of providing our API services may be retained for a period of up to a year.
What are your rights?
As explained in more detail in HERE’s privacy policy, you have the right to know what personal data HERE holds about you, and to access it. You have a right to have incomplete, incorrect, unnecessary, or outdated personal data deleted or updated. You have the right to request that your personal data be erased, and to obtain a copy of your data in a machine-readable format. You have the right to object to or restrict processing in certain circumstances, such as where you believe the data is inaccurate or the processing activity is unlawful. Additional rights may be available in your jurisdiction. You should review the HERE privacy policy applicable to you for further information about your privacy rights.
Who is the controller of your Personal Data?
For providing you the HERE products and services, including the API services, your auto manufacturer is the controller of your personal data. Please see your auto manufacturer’s privacy notice for additional information. In connection with ensuring the security of our services and systems and our internal product maintenance and improvement, HERE Global B.V. of Kennedyplein 222 -226, 5611 ZT Eindhoven, Netherlands is the controller of your personal data.
Other information
You may contact HERE or our Data Protection Officer (as identified in our privacy policy linked above) through the following contact details:
HERE Global B.V
c/o Privacy
Kennedyplein 222-226
5611 ZT Eindhoven
Netherlands
Email: privacy@here.com