Our privacy policy

Welcome to these data protection terms and conditions of OÜ Ideal Auto (hereinafter Ideal Auto or us). We want you to feel secure when you interact with us in the course of a customer relationship or other co-operation and to understand how we use your personal data (hereinafter also referred to as data or details).

We have the right to unilaterally amend these data protection terms and conditions in the event of changes to legislation governing the protection of personal data or to our own data processing. We will notify you of any amendments 1 month before they come into force on our website. The latest version of these data protection terms and conditions is always available on our website www.idealauto.ee

Definitions

To help you to better understand our data protection terms and conditions, we will explain the main definitions related to data protection as follows.

The GDPR means the European Union’s General Data Protection Regulation (EU) 2016/679, the implementation of which started on 25 May 2018 and is applicable in all EU Member States.

Personal data means any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly on the basis of their name, personal identification code, place of location information or network identifier, or on the basis of one or more physical, physiological, genetic, mental, economic, cultural or social identities.

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller means the person who decides why and how personal data are processed.

Processor means a person, public authority, agency or other body that processes personal data on behalf of the controller.

These data protection terms and conditions apply if:

  • you use Ideal Auto’s services as a private individual or as a business customer;
  • you are a representative or contact person of our business customer, supplier or other partner;
  • you are our partner;
  • you subscribe to our newsletter or you have expressed a wish to receive our offers, by e-mail or SMS;
  • you simply submit a request for information via our online environment or by e-mail. Controller

1. Controller

OÜ Ideal Auto
Registry code: 14103554
Address: Peterburi tee 47c, Tallinn 11415, Estonia
E-mail: info@idealautoauto.ee

2. What type of personal data do we collect and from what sources?

If you use our services as a private individual, you will provide us with your details yourself by contacting us by e-mail, calling us or through the contact form on the website.

  • Identifying information – given name and surname, personal identification code/date of birth, identity document number
  • Contact details – phone number, e-mail address
  • CCTV recordings – Ideal Auto’s service rooms and the tunnel car wash are equipped with CCTV cameras to protect people, property and automated services.
  • Vehicle details – details of the vehicle for which you have ordered services from us: registration number, VIN code (in case of sale), make, model, mileage (in case of sale)
  • Service details – data that provides an overview of your activities in relation to your use of our services, i.e. the goods and services you purchase, as well as any breaches by you and any contracts you enter into with us
  • Debt data – data on the customer’s debts, including assignment of receivables.

If you contact us and interact with us as a representative or contact person of a business customer or other partner (i.e. a legal entity), or if you are a partner of ours, you will provide us with the following personal data in the course of such interaction: given name and surname, job title, e-mail address, mobile and/or landline number.

We assume that such information is for professional and business communications and does not include private contact information.

If you use our services as a representative of a business customer, we may also receive your data from your employer. In this case, we will assume that your employer has a legal basis (your consent, the need to perform the contract, legitimate interest, etc.) for transferring your data to us and has informed you of such transfer.

If you visit Ideal Auto’s dealerships where we use CCTV cameras for security purposes, please be aware that you may end up in the recordings (for more information on the use of CCTV cameras, see section 7 below).

3. For what purposes and on what legal basis do we process your data?

We process your personal data for different purposes. Regardless of the purpose of processing, there must be a legal basis for the use of the data for each purpose. In assessing our processing of your data, we have determined that our processing of your personal data is carried out on the following four legal bases.

  • Processing of data necessary for the performance of a contract

We process data on this legal basis when it is necessary for the performance of a contract concluded with you or for taking steps at your request prior to entering into a contract with you.

  • Processing of data necessary for Ideal Auto to comply with its legal obligations

In certain cases, we have a legal obligation to process your data in a certain way (e.g. retaining source documents for accounting). In this case, neither we nor you have any influence over data processing.

  • Processing of personal data based on the legitimate interests of Ideal Auto

Legitimate interest means that we do not need to process your data directly for the performance of a contract and we do not have a legal obligation to do so, but we still need to process the data. For example, to develop our products and services – by profiling; to make the right business decisions – by collecting statistical data, etc.

As we are not obliged by law or by mutual contract to process data on the basis of legitimate interest and since we do not ask for your consent, you have the right under the GDPR to ask us for clarification of our processing on this basis and to object to it if you consider that the processing of your data on the basis of legitimate interest infringes on your rights.

  • Processing of personal data based on your consent

In certain cases, where the processing of your data is a matter of your choice (e.g. sending direct marketing messages and offers by SMS and/or e-mail), we will ask for your consent. If the processing is based on your consent, please be aware that you always have the right to withdraw your consent by e-mailing info@idealautoauto.ee. If your consent was given for direct marketing, you can withdraw your consent by using the “unsubscribe” link at the end of each marketing message. If you withdraw your consent, we will stop processing your personal data for the purpose for which you gave your consent. Withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of consent prior to its withdrawal.

In the table below, we set out the main purposes and legal bases for the use of data.

Purpose of processing

Data categories

Legal basis

Pre-contractual relations (e.g. responding to enquiries from customers; preparing contracts, holding negotiations)

Identifying information, contact details

For performance of contracts

Performance of contracts, provision of services ordered by customers

Identifying information, contact details,
details of vehicle

For performance of contracts

Vehicle number recognition in the automatic tunnel car wash

Details of vehicle (reg. number)

Legitimate interest; for performance of contracts

Identification of the customer

Identifying information

For performance of contracts

General marketing, product development (segmentation)

Service details

Legitimate interest

Maintaining and developing customer relations (entry into contracts, receiving/executing orders, providing information on contract performance)

Identifying information, service details, contact details, details of vehicle

For performance of contracts

Accounting (including retaining source documents for accounting)

Identifying information, service details

Statutory obligation

Debt management, including assignment of receivables

Identifying information, contact details,
debt details

Legitimate interest

Settlements (invoicing, submitting invoiced and collecting payments)

Identifying information, contact details

For performance of contracts

Management of circumstances and events affecting the provision of services to the customer (notification, handling of complaints)

Identifying information, service details, contact details

For performance of contracts

Responding to requests for information from public and state authorities

Identifying information, service details, contact details, details of vehicle

Statutory obligation

Direct marketing (offers and newsletter from Ideal Auto)

Identifying information, contact details

Agreement

Data exchange between companies in the same group as Ideal

Identifying information, contact details

Legitimate interest

Protection of our property, employees and customers – use of CCTV cameras in Ideal Auto’s service rooms and the tunnel car wash

CCTV recordings

Legitimate interest

Disclosure of personal data to our service providers on a need-to-know basis

Identifying information, service details, contact details, details of vehicle

Legitimate interest

When dealing with you as a representative of a business customer or other partner (i.e. a legal entity), we will use your personal data to enter into and perform contracts between Ideal Auto and the legal entity that employs you and to enable any concurrent communication. In this case, processing is based on the legitimate interest of Ideal Auto.

Legitimate interest means that we do not process your data for the performance of a contract entered into with you (the contract is entered into with a legal entity) and we have no statutory obligation to process the data, but we still need to process the data to facilitate communication between legal entities.

In connection with your work or area of responsibility, we may sometimes send you direct marketing offers and communications, for example, if your employing company is a customer of ours or if you have previously ordered our services as a representative of your company. Such direct marketing activities are also carried out on the basis of Ideal Auto’s legitimate interest. If you receive such direct marketing messages from us, you always have the right to opt-out by clicking the opt-out link at the bottom of the message or by sending us an e-mail requesting to opt-out.

4. To whom do we disclose your data?

We will disclose your personal data to third parties to the extent necessary to achieve the purposes for which we process your personal data or if we are required to do so by law.

  • Other companies in the same group as Ideal (all located in the European Union): where it is necessary for management decisions and the development of the group’s business, for the use of common data systems or for similar purposes.
  • Service providers: where it is necessary to provide the service to us (e.g. IT systems and equipment maintenance service provider, organisation of promotions and direct marketing).
  • Public authorities and government institutions (e.g. the Estonian Police and Border Guard Board, the Estonian Data Protection Inspectorate): where we are required to do so by law or where sharing the data is necessary to protect our rights;
  • Professional advisers: auditors, lawyers, accountants and other persons providing advisory and consultation services;
  • Third parties in connection with corporate transactions: from time to time, we may share your information with third parties in connection with a corporate transaction, such as the sale of a company or part of a company to another company. Also in the context of establishing a joint venture, merger or other reorganisation of a company.

We do not hold your personal data outside the European Economic Area and we do not transfer data outside the European Economic Area.

5. How long do we retain your data?

We will retain your personal data for as long as required by applicable law or necessary to achieve the purposes of processing as described in these data protection terms and conditions. Below are some examples of data retention periods:

Retention period:

Examples

3 months (after which the recordings are overwritten)

CCTV recordings

12 months

Data on persons who have asked for an offer or made other inquiries but with whom no contract has been entered into

3 years (after expiry or termination of the contract)       

Customer contract data and service details to protect us against potential claims or to make a claim to protect us and our rights

7 years (after expiry or termination of the contract)       

Original accounting documents (e.g. customer membership agreement and invoices)

Until you withdraw your consent

Processing of contact data for direct marketing purposes

Up to 10 years

Details of debts for which a recovery procedure has been initiated

If you would like to find out more about how we retain your personal data, please send an inquiry to the e-mail address provided in section 1 of these data protection terms and conditions.

6. Your rights regarding your data

Right of access – you have the right to know what data we collect about you, the purposes for which we process it, to whom we disclose it, for how long we retain it, and your rights regarding restriction of processing, rectification, erasure and processing of data. To respond to your request, we first need to identify you in order to avoid sharing your data with unauthorised persons. We have the right to respond to your request within 30 days.

Right to rectification – you have the right to request the rectification of personal data concerning you if it is incorrect or incomplete.

Right to erasure – in certain cases, you have the right to request that we erase your personal data, in particular if the processing of your data is based on your consent and you withdraw it.

Right to restriction of processing – in certain cases, you have the right to prohibit or restrict the processing of your personal data for a certain period of time (e.g. if you have objected to the processing).

Right to object – you have the right to object to the processing of data where such processing is based on the legitimate interest of Ideal Auto. If you object, Ideal Auto will stop processing your personal data unless we can demonstrate that there is a compelling legitimate reason for the processing which overrides your interests, rights and freedoms as a data subject or if data is processed with the purpose of establishment, exercise or defence of legal claims;

Right to data portability – where the processing of your personal data is based on your consent or on a contract entered into with us and the data is processed by automated means, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format. You also have the right to request Ideal Auto to transfer the data directly to another service provider if this is technically feasible (i.e. if the other service provider is able to receive the data in the format in which it is transferred).

If you would like to exercise any of the above rights, please contact us at the e-mail address provided in section 1 of these data protection terms and conditions.

7. Use of CCTV cameras

Ideal Auto uses CCTV in its dealerships to protect customers and employees, as well as their and our own property, and to provide an automated service in the tunnel car wash.

Our service rooms and the automatic car wash are equipped with CCTV cameras based on a security concept prepared by our consulting security company. For example, your cars are also covered by the CCTV surveillance area when you use our automatic car wash. This means that customers and partners in these areas may be caught on CCTV recordings.

Below is a brief overview of the basic CCTV terms and conditions: the following are the basic CCTV terms and conditions:

  • legal basis for the use of CCTV cameras – legitimate interest
  • short description of the CCTV surveillance system – a fixed video surveillance system based on IP cameras, stored on a server on a local network, no audio recording
  • to whom may the recordings be disclosed – the recordings are not disclosed to third parties
  • who has access to the surveillance system and the recordings – only Ideal Auto employees who need access to recordings to perform their work duties have access to the recordings
  • how long are the recordings retained – recordings are retained for 1 month, after which the video system will automatically start overwriting them
  • surveillance time – 24/7
  • type of surveillance – recording
  • what steps are taken to protect the data collected by the surveillance system – the recordings are kept securely on a hard disk and only the aforementioned persons can access the recordings
  • how to access the data we have collected about you – to access the data we have collected about you, please contact us at the e-mail address provided in section 1 of these data protection terms and conditions. When accessing the data, you should bear in mind that we only keep the recordings for 1 month and that to protect the rights and interests of others on the recording, we need to make them unidentifiable, so we cannot give access immediately.

8. Right to lodge a complaint with the Estonian Data Protection Inspectorate and the courts

If you would like further information regarding your personal data or the exercise of your rights, please contact us at the e-mail address provided in section 1 of these data protection terms and conditions.

However, if you find that the processing of your personal data violates the requirements of the General Data Protection Regulation, you have the right to turn to the Estonian Data Protection Inspectorate or the courts to protect your rights and interests.