Data Protection

General information

The data controller within the meaning of the EU General Data Protection Regulation (GDPR) is:


smart Europe GmbH
Esslinger Str. 7, 70771 Leinfelden-Echterdingen, Germany
E-Mail eu.dataprotection@future.smart.com


The body, which alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses or similar) is the natural or legal person of smart Europe GmbH.

Data protection officer required by law

A responsible data protection officer has been designated for our company:


Katja Green

DEKRA Assurance Services GmbH

Handwerkstraße 15, 70565 Stuttgart

E-Mail: eu.dataprotection@future.smart.com

1. Hosting and Content Delivery Networks (CDN)

This web application is hosted by smart Europe GmbH, Esslinger Str. 7, 70771 Leinfelden-Echterdingen, Germany and our service providers (hoster). The personal data, collected on this web applications, is stored on the servers of the hosters in the EU (currently Frankfurt, Germany). This may include IP addresses, contact requests, meta and communication data, contract data, contact data, names, website accesses and other data generated via a website. The hosters are used for the purpose of contract fulfillment vis-à-vis our potential and existing customers (Art. 6 para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR). Our hoster will only process your data to the extent necessary to fulfill the respective service obligations and follow our instructions regarding this data.

To ensure data protection-compliant processing, we have concluded an order processing contract according to Art. 28 GDPR with our hoster.

2. Privacy Policy

We are pleased about your visit to our web applications and your interest in our offers. The protection of your personal data is an important concern for us. In this privacy policy, we explain how we collect your personal data, what we do with it, for what purposes and on what legal basis this is done, and what rights and claims are associated with it for you.


The privacy policy for the use of our web applications does not apply to your activities on websites of social networks or other providers that are accessible via links on our web applications. Please check the websites of these providers for their privacy policies.

3. Collection and processing of your personal data

  1. When you visit our web applications, we store certain information about the browser and operating system you use, the date and time of your visit, the access status (e.g., whether you were able to access a web application or received an error message), the use of functions of the web application, the search terms you may have entered, the frequency which you access individual contents, the name of accessed files, the amount of data transferred, the website from which you accessed our web application, and the website you visit from our web applications, whether by clicking on links provided by us or by entering a domain directly in the input field of the same tab (or window) of your browser, in which you have opened our web application. We also store your IP address and the name of your Internet service provider for a period of seven days for security reasons, in particular to prevent and detect attacks on our applications or fraud attempts.
  2. We only store other personal data if you provide us such data, e.g. in the context of a registration, a contact form, a chat, a survey, a price offer or for the execution of a contract, and also in these cases only to the extent that we are permitted to do so on the basis of a consent granted by you When requesting a price quote, initiating a contract or for contract processing, Art. 6 (1) lit b GDPR is the legal basis for the processing.

4. Purposes of use of personal data

  1. We use the collected personal data when you visit our web applications to operate them as conveniently as possible for you and to protect our IT systems from attacks and other illegal activities.
  2. If you provide us further personal data, e.g. in the context of a registration, a chat, a contact form, a survey, or a lottery we will use this data for the before mentioned purposes.
  3. For the execution of a contract as well as for customer administration reasons and – if necessary – for the execution and settlement of any business transactions, we use the data in each case only to the extent necessary for this purpose.
  4. In addition, we use personal data insofar as we are legally obligated to do so (e.g. storage for the fulfillment of commercial or tax law retention obligations, release in accordance with official or court orders, e.g. to a law enforcement agency).
  5. Below we list the legal basis and purposes for the processing of personal data:
    1. Purpose: Provision of the website for the general public and for the purpose of contacting our customers and interested parties
      Legal Basis: Contract fulfillment or balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in providing an Internet presence, including for non-registered users, in order to provide general information about our company.
    2. Purpose: Collection of statistical information about the use of the website (so-called web analysis)
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in receiving information about the use of the website, in particular to improve our offer.
    3. Purpose: Detection of malfunctions and ensuring system security, including detection and tracking of unauthorized access attempts and accesses to our web servers
      Legal Basis: Fulfillment of our legal obligations in the area of data security as well as balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in eliminating disruptions, ensuring system security and detecting and tracking unauthorized access or access attempts.
    4. Purpose: Protecting and defending our rights
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in asserting and defending our rights.
    5. Purpose: Processing of your inquiries, concerns and feedback
      Legal Basis: Contract fulfillment or balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in processing and considering your comments and feedback.
    6. Purpose: Random evaluation of the processing of customer concerns for quality assurance
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests:We have a legitimate interest in the random evaluation of the processing of customer concerns for quality assurance.
    7. Purpose: Data consolidation as part of customer care by smart Europe GmbH
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in a current and consolidated data profile as part of customer service by smart Europe GmbH. Consolidation serves to minimize data and ensures that our customers' data is up-to-date and correct.
    8. Purpose: Provision of the functionalities to our customers and interested parties as well as the public
    9. Purpose: Sending of product information, newsletters, advertising and market research
      Legal Basis:Contract fulfillment or consent
    10. Purpose: Determination of faults and guarantee of product safety including detection and tracking of unauthorized access attempts and access to our products by customers
      Legal Basis: Compliance with legal obligations in the area of product liability, balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in ensuring product safety and the detection and tracking of unauthorized access or access attempts.
    11. Purpose: Customer care
      Legal Basis: Contract fulfillment
    12. Purpose: Review of social media channels for customer care purposes
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in checking our social media channels with regard to complaints or queries from our customers and making them aware of our customer care channels.
    13. Purpose: Random evaluation of the processing of customer concerns for quality assurance
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in the random evaluation of the processing of customer concerns for quality assurance.
    14. Purpose: Handling of possible remuneration and / or bonus programs
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in fulfilling our legal obligations towards the partner.
    15. Purpose: Handling of legal disputes
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: Assertion, exercise or defense of legal claims of smart Europe GmbH.
    16. Purpose: General customer analysis, statistical evaluations for corporate management, cost recording and controlling using the VIN
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests:
      • Analysis of sales and order data by model sales channel, order status
      • Analysis of requested variants and equipment
      • Reporting on business parameters, if necessary using the VIN
    17. Purpose: Fraud and money laundering prevention
      Legal Basis: Compliance with legal obligations, balancing of interests
    18. Purpose: Prevent, combat and investigate the financing of terrorism and offences endangering assets, comparisons with European and international Anti-terrorist lists
      Legal Basis: Compliance with legal obligations, balancing of interests
    19. Purpose: Fulfillment of official requirements (e.g. recall campaigns by the Federal Motor Transport Authority)
      Legal Basis: Compliance with legal obligations, balancing of interests
      Legitimate interest when balancing interests: Fulfillment of legal and regulatory requirements
    20. Purpose: Fulfillment of tax control and reporting obligations, archiving of data
      Legal Basis: Compliance with legal obligations, balancing of interests
      Legitimate interest when balancing interests: Fulfillment of legal and regulatory requirements
    21. Purpose: Disclosure in the context of regulatory / judicial measures for the purpose of gathering evidence, prosecuting and enforcing claims under civil law
      Legal Basis: Compliance with legal obligations, balancing of interests
      Legitimate interest when balancing interests: Fulfillment of legal and regulatory requirements
    22. Purpose: Internal auditing and investigations
      Legal Basis: Legal obligation
    23. Purpose: Field measures
      Legal Basis: Field measures Compliance with legal obligations
      Legitimate interest when balancing interests: With a query based on the vehicle identification number you have entered, you can retrieve field measures and recalls for the vehicle. The data you have entered will not be saved.
    24. Purpose: Compliance checks (e.g. compliance checks, documentation of compliance inquiries and compliance with compliance requirements)
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: Review of compliance with legal provisions, internal company guidelines, rules and standards of smart Europe GmbH, employees, business partners and other authorized third parties.
    25. Purpose: Provision of the service (smart Europe GmbH online advice)
      Legal Basis: Contract fulfillment
    26. Purpose: Collection of statistical information from the website
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in receiving information about usage, in particular to improve our offer.
    27. Purpose: Provision of a contact option to process your concerns or inquiries
      Legal Basis: Contract fulfillment
    28. Purpose: Customer and prospect support
      Legal Basis: Consent
    29. Purpose: Customer survey (including satisfaction survey)
      Legal Basis: Consent
    30. Purpose: Creation of customized information
      Legal Basis: Consent
    31. Purpose: Creation of a customer profile as a basis for advertising and market research
      Legal Basis: Balancing of interests
      Legitimate interest when balancing interests: We have a legitimate interest in a consolidated customer profile, provided that the subsequent use for advertising and market research is in accordance with data protection and competition law requirements

5. Transfer of personal data to third parties

  1. Our web applications may also contain third-party offers. If you click on such an offer, we will transfer data to the respective provider to the extent necessary (e.g., information, that you found this offer on our website and, if applicable, further information that you have already provided for this purpose on our websites).
  2. We also use qualified service providers (e.g. IT service providers, marketing agencies) to operate, optimize and secure our web applications. We only pass on personal data to them insofar as this is necessary for the provision and use of the web applications and their functionalities, for the pursuit of legitimate interests, for the fulfillment of legal obligations or insofar as you have consented to this (see section 6).

6. Server-Log-Files

The providers of the pages automatically collect and store information in so-called server log files, which your browser automatically transmits to us. These are:


  • IP address (Internet protocol address) of the terminal device from which the online offer is accessed;
  • Internet address of the website from which the online offer was accessed (so-called origin or referrer URL);
  • Name of the service provider through whom the online offer is accessed;
  • Name of the files or information accessed;
  • Date and time as well as duration of the retrieval;
  • Amount of data transferred;
  • Device (PC, mobile, other), operating system and information on the Internet browser used, including installed add-ons (e.g. for the Flash Player);
  • http status code (eg "request successful" or "requested file not found").

This data is not merged with other data sources.


The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website for this purpose, the server log files must be collected.

7. Technical and organizational security measures

We use technical and organizational security measures to protect the data we manage against manipulation, loss, destruction and against access by unauthorized persons. We continuously improve our security measures in line with technological developments and possibilities.

8. SSL resp. TLS encryption

Our web applications use SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests, etc. that you send to us as the operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

9. Legal basis of data processing

  1. If you have given us your consent for the processing of your personal data, this will be the legal basis for the processing (Art. 6 para. 1 letter a GDPR)
  2. For the processing of personal data for the purpose of initiating or fulfilling a contract with you, Art. 6 para. 1 letter b GDPR is the legal basis.
  3. Insofar as the processing of your personal data is necessary for the fulfillment of our legal obligations (e.g. for the retention of data), we are authorized to do so pursuant to Art. 6 para. 1 lit. c GDPR.
  4. In addition, we process personal data for the purposes of safeguarding our legitimate interests as well as the legitimate interests of third parties pursuant to Art. 6 (1) (f) GDPR.
  5. Maintaining the functionality of our IT systems, the (direct) marketing of our own and third-party products and services (unless this is done with your consent) and the legally required documentation of business contacts are such legitimate interests. We take into account in particular the type of personal data, the purpose of processing, the circumstances of processing and your interest in the confidentiality of your personal data as part of the respective necessary balancing of interests.

10. Right to restrict the processing of personal data

You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time. The right to restriction of processing exists in the following cases:

  • If you dispute the correctness of your personal data stored by us, we usually need time to verify this. For the duration of the review, you are entitled to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is being done unlawfully, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but require it for the exercise, defense or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of the deletion.
  • If you have raised an objection pursuant to Art. 21 (1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If the processing of your personal data has been restricted, these data - apart from their storage - may only be processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or a authorized member state of Europe.

11. Deletion of your personal data

We delete your IP address and the name of your Internet service provider, which we store for security reasons, after seven days.


Otherwise, we delete your personal data as soon as the purpose for which we collected and processed the data no longer applies. Beyond this point in time, storage only takes place insofar as this is required in accordance with the laws, regulations or other legal provisions to which we are subject, in the EU or in accordance with legal provisions in third countries, if an appropriate level of data protection is provided there in each case.


Insofar as deletion is not possible in individual cases, the relevant personal data will be marked with the aim of restricting its future processing.

12. Rights of the data subject

As a data subject, you have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), data erasure/deletion (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).

  1. Right to information, correction, restriction, transfer, blocking, deletion: You have the right to free information about your stored personal data, the origin of the data, their recipients and the purpose of the data processing and a right to correction, restriction, transfer, blocking and deletion of this data at any time within the framework of the applicable legal provisions.
  2. Revocation of consent to data processing:
    If you have consented to the processing of your personal data by us, then you have the right to cancel your consent at any time. The legality of the processing of your personal data until a revocation is not affected by the revocation. Likewise, further processing of this data on the basis of another legal basis, such as for the fulfillment of legal obligations (see section "Legal bases of processing"), remains unaffected.
  3. Right of protest (Art. 21 GDPR):

    You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) GDPR (data processing in the public interest) or Article 6(1)(f) GDPR (data processing on the basis of a balance of interests).

    If you object, we will only continue to process your personal data insofar as we can demonstrate compelling legitimate grounds for doing so that override your interests, rights and freedoms, or insofar as the processing serves the assertion, exercise or defense of legal claims.

    If we process your personal data for the purpose of direct marketing to protect legitimate interests on the basis of a balance of interests, you also have the right to object to this at any time without stating reasons.

  4. We ask you to send your claims or explanations to the following contact address, if possible: eu.dataprotection@future.smart.com.
  5. Right to lodge a complaint with the competent supervisory authority:

    If you believe that the processing of your personal data violates legal requirements, you have the right to lodge a complaint with a competent data protection supervisory authority (Art. 77 GDPR).

    The responsible data protection supervisory authority is: State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg

    Dr. Stefan Brink

    Address: Lautenschlagerstraße 20, D- 70173 Stuttgart

    Postal address: Postfach 10 29 32, 70025 Stuttgart

    Telephone: +49 711/61 55 41-0

    Email: poststelle@lfdi.bwl.de

    https://www.baden-wuerttemberg.datenschutz.de/online-beschwerde/


13. Newsletter

If you subscribe to a newsletter, offered on our website, the data provided during the newsletter registration will only be used for shipping of the newsletter, as far as you do not agree to a further use. You can unsubscribe at any time using the unsubscribe option provided in the newsletter.

  1. The data you provide for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe proactive from the mailinglist. Your data will be deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data that has been stored by us for other purposes remains unaffected by this.
  2. After you have unsubscribed from the newsletter distribution list, your e-mail address will be stored by us or the newsletter service provider in a blacklist, if necessary, in order to prevent future mailings.

The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both – your and our interest – in complying with the legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 (1) f GDPR).

14. Data transmission to recipients outside the European Economic Area

  1. When using service providers (see section 1.) and passing on data to third parties based on your consent (see section 5.), personal data may be provided to recipients in countries outside the European Union ("EU"), Iceland, Lichtenstein, Norway (= European Economic Area), USA and India are transferred and processed there.
  2. In the following countries, from the EU's point of view, there is an adequate level of personal data protection (so-called "adequacy"), in compliance with EU standards: Andorra, Argentina, Canada (limited), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, Uruguay. We agree with recipients in other countries on the use of EU standard contractual clauses or binding corporate rules to create an "adequate level of protection" according to legal requirements. For more information, please contact us: eu.dataprotection@future.smart.com.

Miscellaneous

The area of data protection is subject to frequent changes that make it necessary to adapt our data protection declaration. Please check our website at regular intervals to keep track of the changes. Our data protection officer is available to answer your questions:

Email: eu.dataprotection@future.smart.com.

Status: August 2021