Privacy Policy

for contact with Porsche Middle East & Africa FZE via the Porsche Contact Centre

We, Porsche Middle East & Africa FZE (hereafter "we" or " [PME]") appreciate your interest in our products and services and in our company and products. Your privacy is extremely important to us. We therefore take the protection of your personal details very seriously and treat them in strictest confidence. Your personal data is processed only within the scope of the legal provisions of the EU's data protection law, in particular the General Data Protection Regulation (hereafter "GDPR"). In this privacy policy we provide you with information about the processing of your personal data and your rights as a data subject in the context of the steps taken to process your request as part of contact. For information on other products and services offered by other companies within the Porsche Group, please refer to the respective privacy policy for these services or companies.

If we include a link to this privacy policy from external social media activity, the following conditions apply only if the data processing operations as part of such social media activity are actually within our area of responsibility and more specific and therefore higher ranking data protection information is not provided within the scope of such social media activity.

1. Controller and data protection officer for data processing; contact

Controller for data processing in accordance with the data protection legislation is:
Porsche Middle East and Africa FZE
Plot-29-911, Dubai Silicon Oasis
Dubai, United Arab Emirates
P.O. Box 341356
Telephone (+971) 4 3569 911
Facsimile (+971) 4 3569 997
Service License No. 25
www.porsche.com

Please do not hesitate to contact us if you have questions or suggestions relating to data protection.
You can contact our data protection officer at the following address:
Porsche Middle East and Africa FZE
Plot-29-911, Dubai Silicon Oasis
Dubai, United Arab Emirates
P.O. Box 341356
Telephone (+971) 4 3569 911
Facsimile (+971) 4 3569 997
Service License No. 25
www.porsche.com

2. Subject matter of data protection

The subject matter of data protection is the protection of personal data. This is all information that relates to an identified or identifiable natural person (known in legislation as the data subject). This covers, for example, information such as name, postal address, e-mail address or telephone number as well as information that necessarily originates within the context of contact when processing your respective request, such as complaints, data quality related enquiries, enquiries about the Porsche Sales Organisation or Porsche Marketing campaigns.

3. Type, scope, purposes of and legal basis for automated data processing

The use of personal data during a form of making contact regarding the related enquiry is partially permissible without registration. Even when you use the website without registering however, personal data can be processed.

An overview of the type, scope, purposes of and legal basis for automated data processing within the context of using personal data during a form of making contact is further described below. of personal data during a form of making contact Information on processing personal data when using individual services and functions is set out in number 5 below.

4. Individual services and functionalities

We shall process personal data insofar as this is necessary for the preparation and implementation of the agreement. The purposes depend on the specific contract and, in particular, encompass
• Processing of inquiries from prospective and actual customers in relation to products and complaints of PME
• Technical support for customers and dealers, in particular by providing the service hotline for you to contact us by phone.

Data is processed on the basis of Article 6 (1) (b) GDPR. You must provide the personal data necessary for the preparation and implementation of the contact to process your respective request. We cannot process your enquiry or accommodate your request without this data.

4.1 Compliance with legal obligations or processing of personal data in the public interest

We also process your personal data to comply with legal obligations to which we are subject. The obligations may arise, for example, from commercial, tax, telecommunications, money laundering, financial or criminal law. The purposes of processing arise from the respective statutory obligation; the processing generally serves the purpose of complying with state obligations with regard to monitoring and duty of disclosure.

Data is processed on the basis of Article 6 (1) (c) or (e) GDPR. If we collect data on the basis of a legal obligation or in the public interest, you need to specify the personal data that is needed to fulfil the legal obligation. We cannot process your enquiry or comply with these obligations if this information is not provided.

5. Safeguarding of legitimate interests

We process your personal data for the purposes of safeguarding our legitimate interests. In addition to the interests specified in the description of the individual services and functions under Sections 3 and 5, data processing processes take place within the framework of contact to process your request or after registration, in particular against the background of the following interests:

  1. Further development of products, services and care offers as well as other measures for controlling business cases and processes;
  2. Improvement of product quality, rectification of faults and malfunctions by analysing vehicle data and customer feedback;
  3. Processing data on a central prospect and customer service platform as well as upstream and downstream systems for customer loyalty and sales purposes;
  4. Processing warranty and goodwill cases as well as non-contractual prospect and customer inquiries and concerns;
  5. Risk control and coordination of recall campaigns;
  6. Ensuring lawful actions, prevention of and protection against legal violations (in particular criminal offences), assertion of and defence against legal claims;
  7. Guaranteeing the availability, operation and safety of technical systems as well as technical data management.

In this respect, the relevant data is processed on the basis of Article 6 (1) (f) GDPR.

6. Consent

If you grant us consent for specific data processing processes, this is always deemed to be for a specific purpose; the purposes are set out in the content of the actual declaration of consent. Data is processed in this case on the basis of Article 6 (1) (a) GDPR. We cannot accommodate the request covered by the consent if you do not provide your consent. You can withdraw your consent at any time. This will not affect the lawfulness of processing based on consent given before its withdrawal.

7. Recipients of personal data

Internal recipients: Within PME the only people who have access are those who need it for the purposes referred to above in each case.

External recipients: We only forward your personal data to external recipients outside PME if this is necessary for administering or processing your request, if another legal authorisation exists or if we have your consent to forward the data.

External recipients can be:

a) Processors
Group companies in Porsche AG or external service providers that we use to provide services, for example for provision of the infrastructure and operation of the Contact Centre as well as maintenance of this offering on behalf of Porsche AG. We carefully select and regularly inspect these processors to make sure that the security and confidentiality of your personal data are safeguarded. The service providers may use the data only for the purposes we have specified.
The Porsche Contact Centre is operated on our behalf by:
Sitel GmbH, Münsterstraße 100, 40476 Düsseldorf

b) Public bodies
Authorities and public institutions, such as tax authorities, public prosecutors or the courts, to which we (must) transfer personal data for legally binding reasons or to safeguard legitimate interests. The data is transferred on the basis of Art. 6 Para. 1 (c) and/or (f) GDPR or Art. 26 Para. 1 (2) German Data Protection Act (Bundesdatenschutzgesetz; BDSG).

c) Private bodies
Porsche dealers and service companies, cooperation partners, service providers or persons to whom the data is transferred on the basis of consent, to execute a contract with you or to safeguard legitimate interests, for example, Porsche Centres and Porsche Service Centres, financing banks, providers of other services or transport service providers. The data is transferred on the basis of Article 6 (1) (a), (b) and/or (f) GDPR.

8. Data processing in third countries

If data transfer takes place to bodies, the headquarters of which or the data processing location of which is not in a member state of the European Union or in another state that is a signatory to the Agreement on the European Economic Area, we ensure, before transfer, that apart from in statutorily permitted exceptional cases, the recipient either has an appropriate level of data protection, e.g. through an adequacy decision of the European Commission, through suitable guarantees such as a self certification by the recipient for the EU-US Privacy Shield or the agreement of EU standard contractual clauses between the European Union and the recipient, or that you grant your consent to the data transfer.

You can obtain from us an overview of the recipients in third countries and a copy of the specifically agreed regulations for ensuring an appropriate level of data protection. To this end, please use the information under Section 1.

9. Sources and data categories for data gathered from third parties

We process not only personal data received directly from you. We obtain some personal data from third parties, provided we have a legal basis to do so. The following is an overview of the relevant sources and data categories when collecting data from third parties:

• We receive watchlist data from third parties to comply with legal obligations to prevent criminal offences and to safeguard the public interest. This data is then processed on the basis of Art. 6 Para. 1 (c) or (e) GDPR.

10. Automated decision-making and profiling

We do not use automated decision-making processes according to Article 22 GDPR to prepare, establish and forge business relationships. Profiling is only performed within the framework of the processing purposes described in this document to protect our justified interests.

11. Duration of storage, deletion

Unless otherwise stipulated in the description of the individual services and functions, the following applies:

We store your personal data only for the length of time necessary to fulfil the intended purposes, or – in the case of consent – until you withdraw your consent. If you withdraw your consent to process your personal data, we will delete it unless relevant legal provisions stipulate that it can be processed further. We will also delete your personal data if we are obliged to do so for other legal reasons.

In line with these general principles, we will usually delete your personal data immediately
- after the legal basis ceases to apply and provided that no other legal basis applies (e.g. commercial law and tax law retention periods). If the latter is the case, we delete the data once the other legal basis ceases to apply.
- if we no longer need the data for the purposes of preparing and executing a contract or legitimate interests and no other legal basis applies (e.g. commercial law and tax law retention periods). If the latter is the case, we delete the data once the other legal basis ceases to apply.
- if the purpose of collecting the data no longer applies and no other legal basis applies (e.g. commercial law and tax law retention periods). If the latter is the case, we delete the data once the other legal basis ceases to apply.

12. Rights of data subjects

As the data subject affected by the data processing, you have several rights. Specifically,

Right of access: You have the right to obtain information from us about the data that we have stored about you.

Right of rectification and erasure: You have the right to demand that we rectify incorrect data and – provided the legal requirements are met – that we delete your data.

Restriction of processing: You have the right – provided the legal requirements are met – to demand that we restrict the processing of your data.

Data portability: If you have provided us with data on the basis of a contract or consent, you have the right, in accordance with the legal requirements, to obtain the data you have provided in a structured, standard and machine-readable format or you can demand that we transfer this data to another responsible person.

Objection to the processing of data on the legal basis of "legitimate interest": You have the right to object at any time, on grounds relating to your particular situation, to our processing of your data, provided this objection is based on the legal basis of "legitimate interest". If you exercise your right to object, we will cease the processing of your data unless we can – pursuant to the legal requirements – prove compelling legitimate reasons for further processing, which override your rights.

Withdrawal of consent: If you have given us consent to process your data, you can withdraw this consent at any time with effect for the future. The lawfulness of the processing of your data remains unaffected up until withdrawal of consent.

Right to lodge a complaint with a supervisory authority: You can also submit a complaint to the competent supervisory authority if you believe that processing your data is in breach of the legislation. To do so, you can apply to the data protection authority that is responsible for your town/city or country or the data protection authority that is responsible for us.

Contacting us: Please do not hesitate to contact us free of charge if you have any questions regarding the processing of your personal data, your rights as a data subject and any consent that you may have given. To exercise all of these above-mentioned rights, please contact https://www.porsche.com/privacy-contact or by post at the address specified above in Section 1. In doing so, please ensure that it is possible for us to identify you uniquely.

13. Links to third-party offerings

Services delivered by other providers that may be referred to within the scope of contact to process your particular request have been and are structured and provided by third parties. Third-party services can be:
- Support service providers of Porsche Sales & Marketplace GmbH
- Support service providers of Porsche Deutschland GmbH
- Support service providers of Porsche Lifestyle GmbH & Co. KG
- Other service providers

We do not have any influence over the structure, content, or role of these third-party services. We explicitly distance ourselves from all content in all third-party offerings. Please contact the providers of these third-party offerings as required for the relevant information.

14. Version

The latest version of this privacy policy applies. Date 16.07.2020.