Privacy Policy

Introduction

This Privacy Policy (“Policy”) explains how your information is collected, used, and disclosed by Umoto Limited (“Umoto”/”we”/”us”/ “our”) in connection with the use of our Umoto app (“App”). This Policy applies where we are acting as a Data Controller, where we determine the purposes and means of the processing of the personal data in accordance with the requirements of the General Data Protection Regulation (“GDPR“). Processing activities that are not covered by this Policy may be supplemented by further data protection declarations that must be observed separately.

This Policy not only applies to individual users but also extends to companies that use our services. We are fully committed to ensuring GDPR compliance as we deliver our services to client companies. As the data controller, we prioritize the protection of our clients’ personal data, adhering to GDPR principles and legal requirements while maintaining complete transparency.

As the data controller, we prioritize the protection of our clients’ personal data, adhering to GDPR principles and legal requirements while maintaining complete transparency.

Safeguarding your privacy is our top priority, and Umoto is dedicated to following current laws and best practices.

The GDPR describes how companies must collect, handle, process, and store personal information. To comply with the law, personal information must be collected and used fairly, stored safely, and not disclosed unlawfully. GDPR is underpinned by the following key principles of data protection:

  • Processed lawfully, fairly, and in a transparent manner.
  • Collected for specified and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
  • Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
  • Accurate and kept up to date. Every reasonable step will be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased, or rectified without delay.
  • Kept for no longer than is necessary for the purposes for which the personal data is processed.
  • Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
  • Not transferred to other countries, unless that country or territory also ensures an adequate level of protection.

 

We take these responsibilities seriously and this Privacy Policy describes our approach to data protection.

This Privacy Policy helps to protect us from data security risks, including:

  • Breaches of confidentiality. For instance, information being given out inappropriately.
  • Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
  • Reputational damage. For instance, the company could suffer reputational loss if unauthorized users successfully gained access to sensitive data.
  • Any other risks related to the collection, storage, or processing of your data.

Who this privacy policy applies to

This Policy relates to the users of the mobile application Umoto App. Processing of your data is required in order for you to be able to use the application, and so that we can offer improvements to our services. It applies to all data that the company holds relating to identifiable individuals. The categories of personal data that are being processed are separately stated for each processing activity further below in this Privacy Policy.

We do not routinely collect or process sensitive data about you. However, where this is the case, we will ensure we take appropriate precautions to protect your data and inform you accordingly.

Age Limitation

Our App is not intended to be used by persons under the age of 16. Should you become aware that your child has downloaded the App without your consent and has revealed their personal data, please inform us.

Should we become aware that person under the age of 16 has registered, we will undertake measures for deletion of all the personal data together with the user profile.

Processing of data, purpose, and legal basis

We process your personal data in accordance with the provisions of the GDPR to ensure the use of the mobile application functionalities and deliver continuous upgrades to its performance. The key purpose for processing your data within the Umoto platform is to provide you with a seamless and efficient automotive service experience. Our primary features are designed to enhance your interaction with vehicle maintenance, ensuring convenience and proactive management.

  • Effortless Service Booking: Say goodbye to phone calls and waiting lines. Book your vehicle services with just a few taps.
  • Real-Time Reminders: Umoto will tell you when your insurance, service, MOT and road tax are due.
  • Garage at Your Fingertips: Explore and connect with a wide range of trusted garages. View ratings, services offered, book appointments and message them directly through the App.
  • Vehicle Health Tracking: Keep track of your vehicle’s health and service history. Receive diagnostic updates and personalised maintenance tips.

 

The legal basis of all our processing activities is based on Art. 6 (1) GDPR, more specifically your personal data are being processed based on the contract (Terms of Use) and your consent for the use of our App. You will receive further information in the context of the presentation of the individual processing activities.

By processing your data, we aim to enhance your overall experience with vehicle maintenance, providing a user-friendly platform that simplifies service bookings, keeps you informed, connects you with reliable garages, and ensures your vehicle stays in optimal condition. Rest assured, your data is handled responsibly to deliver a personalized and efficient service tailored to your automotive needs.

Contact information

You may reach out to us, the Data Controller responsible for your personal data, through the following contact information:

Umoto Limited
Unit 22 Bolney Grange Business Park Stairbridge Lane, Bolney, Haywards Heath, West Sussex, England, RH17 5PB

https://umoto.com
[email protected]

Processing activities and categories of personal data

We will only use your personal data for the purposes for which we collected it and as you would reasonably expect your data to be processed and only where there is a lawful basis for such processing, as follows:

User profile and provision of the App

Nature and purpose of data processing:
In order to use the App, it is necessary to create a user profile. The following personal data is collected and stored as part of the user profile:

Name and surname, email address, phone number, vehicle registration number.

In addition, when providing our App by connecting to our servers, a UserID and system logs are processed.

Legal basis:
The processing is carried out pursuant to Art. 6 (1) lit. b GDPR meaning that the processing is necessary for the performance of the provisions of the Terms of Use of the App to which You and Us are parties  and on the basis of your consent.

Recipient:
Recipients of the data are technical service providers. As so-called order processors, the service providers are obliged to process the data only within the scope of our instructions and on the basis of an order processing contract in accordance with Art. 28 GDPR.

Retention period:
The data is kept as long as the user profile exists and/or the user account is active. For more details refer to the section Storage duration of this Privacy Policy.

Garages and navigation

Nature and purpose of the processing:
The processing involves facilitating users to explore and connect with a diverse array of trusted garages through the Umoto platform. This includes providing users with the ability to view ratings, assess the services offered by these garages, and seamlessly book appointments. Furthermore, users can directly communicate with the selected garages by sending messages through the App. The primary purpose is to empower users in efficiently identifying, engaging with, and scheduling services from reputable garages, thereby enhancing their overall automotive service experience.

For the creation of a list of nearby garages, the geo-coordinates of the place of the vehicle is proccessed.

Legal basis:
The processing is carried out pursuant to Art. 6 (1) lit. b GDPR meaning that the processing is necessary for the performance of the provisions of the Terms of Use of the App to which You and Us are parties  or in order to take steps at the request of the data subject prior to entering into a contract on the basis of the terms of use for the App services that apply between you and us and on the basis of your consent.

Recipient:
Recipients of the data are technical service providers. As so-called order processors, the service providers are obliged to process the data only within the scope of our instructions and on the basis of an order processing contract in accordance with Art. 28 GDPR.

In addition, geo-coordinates are transmitted to the map service selected by you. The processing of the map service is carried out by the map service as the responsible party on its own legal basis.

Retention period:
The data will be kept as long as the user profile exists and/or the user account is active. For more details refer to the section Storage duration of this Privacy Policy.

Payment function

Nature and purpose of the processing:
As part of our service, the payment process for charging your vehicle can be carried out. During the payment process, we process your name as well as data about your charge (information about the services, date, time, amount) and payment method, e.g. credit card number, expiration date, and security number. Your data is encrypted using a token before it is transmitted to our payment service providers.

Legal basis:
The processing is carried out pursuant to Art. 6 (1) lit. b GDPR meaning that the processing is necessary for the performance of the provisions of the Terms of Use of the App to which You and Us are parties  or in order to take steps at the request of the data subject prior to entering into a contract on the basis of the terms of use for the App services that apply between you and us..

Recipient:
The recipient of the data is a service provider. As a so-called order processor, the service provider is obliged to process the data only within the scope of our instructions and on the basis of an order processing contract in accordance with Art. 28 GDPR.

Retention period:
The data will be kept for as long as it is necessary for the payment process and must be kept in accordance with the applicable tax laws.

Personalized recommendations and updates

Nature and purpose of the processing:
The processing involves monitoring and maintaining a record of the health and service history of users’ vehicles within the Umoto platform. This includes providing users with real-time diagnostic updates and personalized maintenance tips. The primary purpose is to empower users with comprehensive insights into their vehicle’s condition, ensuring proactive management of maintenance needs. By offering personalized recommendations and updates, the platform aims to enhance the user’s ability to make informed decisions, optimize vehicle performance, and contribute to an overall improved vehicle ownership experience.

Legal basis:
The processing for the above purposes is based on your consent.

Recipient:
The recipient of the data is a service provider. As a so-called order processor, the service provider is obliged to process the data only within the scope of our instructions and on the basis of an order processing contract in accordance with Art. 28 GDPR.

Retention period:
The data processing will take place until you withdraw  your consent.

Recipients of the data

We use various service providers for the provision of our offers. These service providers act only according to our instructions and are contractually obligated to comply with the provisions of Art. 28 GDPR.

Storage duration

We will take all reasonable steps to ensure that your personal data is processed only for the period required by the purpose of processing in each case. If the storage period is not specified for any type of data, that personal data will be deleted as soon as the purpose or legal basis for storage ceases to apply. Personal data will not be deleted if storage is required by law (e.g. § 257 HGB, 147 AO). Furthermore, we may store your personal data until the expiry of the statutory limitation periods, provided that this is necessary for the assertion, exercise, or defense of legal claims. Additional details about the storage of personal data can be found in our Retention Policy.

Data subject rights and supervisory authority

In relation to the information that you provide to us, we are legally responsible for how that information is handled. We will comply with the GDPR in the way we use and share your personal data. Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

Right to information

You can at any time request to be informed about what personal data is being processed and the purpose for such processing.

Right to access

You can request Umoto to provide you with access to your personal data that is being processed. This request allows you to see or view your own personal data, as well as to request copies of the personal data.

Right to rectification

You can ask for an update of your personal data in case you believe that your personal data is not up to date or accurate.

Right to withdraw consent

You have the right to withdraw your previously given consent for processing of your personal data for a specific purpose. The request requires Umoto to stop the processing of the personal data that was based on the consent provided earlier. The data subject can withdraw the consent in the same manner that was given, or by submitting a request at [email protected]

Right to object

You have the right to object to the processing of your personal data at any time. This effectively means that you can stop or prevent us from using your data.

Right to restriction of processing

You have the right to ask for restriction of processing of your personal data by us as a data controller. Where processing of your data is restricted, it can be stored by Umoto, but most other processing actions, such as deletion, rectification etc. will require your permission.

Right to object to automated processing

We do not undertake activities that imply automated personal data processing. If a need for this type of processing appears in future, we will provide you with the ability to object to a decision based on automated processing.

Right to be forgotten

Also known as the right to erasure, provides you with the ability to ask for the deletion of your data. We respect your right but also note that this is not an absolute right and depends on the legal basis of the processing and retention period in line with other applicable laws.

Right for data portability

We provide you with the ability to ask for transfer of your personal data. As part of such a request, you may ask for your personal data to be provided back to you or transferred to another controller. When doing so, the personal data must be provided or transferred in a machine-readable electronic format.

To exercise your rights, you can contact us by email at [email protected]

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We aim to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.

You may at any time pursuant to Art. 77 GDPR in conjunction with. § 19 BDSG file a complaint with a supervisory authority, e.g. with the competent supervisory authority of the federal state in which you live or with the authority responsible for us.

Security

We have put in place appropriate security measures to safeguard your personal data, preventing inadvertent loss, unauthorized access, alteration, or disclosure. Additionally, access to your personal information is restricted to employees, contractors, and third parties with a legitimate business need. They will process your data solely based on our instructions and are bound by confidentiality obligations.

In compliance with GDPR, we commit to promptly report any actual or potential data breaches to the relevant authorities within 24 hours and to notify affected individuals within 72 hours. Should you have any questions or concerns regarding the usage of your data, please reach out to us.

Our application may include links to third-party websites, plug-ins, and applications. Clicking on such links or enabling connections may result in third parties collecting or sharing data about you. We do not have control over these third-party websites and disclaim responsibility for their privacy statements. We encourage you to review the privacy notices of each website you visit upon leaving our application.

Google Services/ Apple Services

The App can be downloaded and installed free of charge via the Apple App Store or the Google Play Store. For more details regarding the use of their services please refer to the following documentation:

Changes to the privacy policy

We reserve the right to adjust this privacy policy at any time. The current version of the Privacy Policy applies.