Privacy Policy We, Dr. Ing. h.c. F. Porsche AG, Porsche Asia Pacific Pte Ltd and Porsche Services Singapore Pte. Ltd. (hereinafter referred to as "we", "our", "us" or "Porsche"), appreciate your interest in our online content and services. We take the protection of your personal data very seriously. Your personal data will be processed in accordance with the statutory provisions of the applicable data protection law.

Porsche’s importers and dealers in Porsche’s distribution network are, unless stated otherwise, independent businesses and not part of the Porsche Group. Such importers/dealers utilise Porsche’s websites as a platform to share their information with you (e.g. available stocks, vehicle options and price, etc.). There may also be links or functions provided by third-party provider (more details in “Integrated third-party services” and “Links to third-party services“ sections below). This Privacy Policy describes how we process your personal data and about your rights in connection with your personal data processed by us, on-line or off-line. For information on the processing of personal data in other areas, please refer to the respective specific privacy policies.

If we refer to this Privacy Policy from external websites or social media profiles, the following explanations apply only insofar as the processing takes place in our area of responsibility and insofar as no more specific and therefore prior information on data protection is provided in the context of such websites or social media profiles.

1. Contact details; Data protection officer
We are dedicated to answering any queries or feedback you may have on our brand, products and services at info@porsche-ap.com.

If you have any questions or suggestions regarding data protection, please feel free to contact our data protection officer at:

Attn: Data Protection Officer of Porsche Asia Pacific Pte Ltd
20 McCallum Street,
#12-01, Singapore 069046
Email: compliance@porsche-ap.com

Attn: Data Protection Officer of Porsche Asia Pacific Pte Ltd
20 McCallum Street,
#12-01, Singapore 069046
Email: compliance@porsche-ap.com

2. Personal data that may be collected
Depending on the specific event, instance and purpose of data collection, personal data collected by us may include information for identification and verification (e.g. name, gender, date of birth, nationality, answers to security questions, driving license), contact details (e.g. postal address, email address, telephone number), financial information (e.g. income, expenses, credit history), payment information, credit card information, employment information (e.g. curriculum vitae, occupation, position held, salary), vehicle information (e.g. chassis number, vehicle identification information, service history, vehicle-related telematics), opinion (e.g. review, survey), preference (e.g. interests, marketing preferences), location, information recorded (e.g. image and sound) when you enter zones at our premises monitored by CCTV, information recorded when you call or interact with our customer assistance/interaction (e.g. via phone, emails or online chatting platform), and information collected via cookies and comparable technologies (more details in “Cookies and comparable technologies“ section below).

Even if you use our websites and social media without registration or actively providing your information to us, personal data may still be collected and processed, such as information that may be generated when you use our websites, in particular information about the beginning, end and extent of use as well as the transmission of the IP address of the device you use to connect to the Internet, the geographical location of your device, the browser you are using, the type of device you are using (tablet, mobile, desktop), the URL you came from and the websites you access.

We may collect additional personal data which you provide arising out of or in connection with your requests/queries to us or your activities with us, for example, your purchase of products or services, material posted by you on our websites or social media, your participation in events, meetings, promotional activities, social media offerings, use of mobile or other IT applications.

We may also receive your personal data from other sources, such as our importers/dealers (Porsche Centres), financial services partners, business partners, service providers, credit reference agencies, fraud prevention agencies, event agencies and other third parties authorised by you to share your information.

If you are under the age of 18 or the applicable age permitted by the data protection law in your country to provide a valid consent on the collection and processing of your personal data, please do not provide your personal data to us.

3. Purposes of personal data processing
The purposes of processing your personal data are notified to you at the time your personal data is collected, consented by you, or deemed consented by you pursuant to the applicable data protection law. We use your personal data to carry out activities arising out of or in connection with such purposes, which may also include:

Performance of a contract and pre-contractual measures Compliance with our legal obligations in accordance with applicable laws and regulations Safeguarding of national interests Necessary processing for any investigation or legal proceedings Identifying you and any accounts you hold with us Security vetting and measures Managing your queries, request, feedback or complaint Fulfilment of your request of rendering goods or services, including billing and administrative processes Research, statistical analysis and behavioural preferences Prevention and detection of fraud and criminal activities Credit scoring and credit checking Marketing purposes Customer profiling and analysis of purchasing, browsing and personal preferences Customisation of our websites and contents to your particular preferences Improving the content and security of our websites Monitoring purpose in accordance with our legitimate interests (e.g. security, quality assurance, training, audit, compliance with laws and regulations, etc.) Development of new products and services Improvement of our products and services Notifying you of any changes to our websites, products, services or any other change which may affect you

3.1 Performance of a contract and pre-contractual measures


We process your personal data if this is necessary for the performance of a contract to which you are a party or for the implementation of pre-contractual measures taken in response to your request. In particular, these are the following functions:

Registration process and creation of a user profile


Registration is not possible without the mandatory data. The mandatory data required for the registration and creation of a user profile are marked with an "*" in the respective input field. When creating a user profile, you have the option of voluntarily providing additional information, such as company contact data, profession, date of birth, etc. Please note that these details are not required for registration and that you alone decide whether you wish to provide us with these details. If you do not provide us with this information, we may not be able to fully comply with your wishes when using this function. The data you provide will be used by us to create your user profile and to identify you later on each login. Depending on the function for which you are registering, further data, e.g. a vehicle configuration selected by you, may be collected and then linked to your profile data. When using the functions described in detail below, further personal data may also be collected and processed (e.g. payment data when placing orders) and, if necessary, transmitted to third parties (e.g. Porsche Centres) in order to provide you with these functions.

Magazine orders and subscriptions


To order a magazine or subscription, e.g. Christophorus magazine, the mandatory data required for the orders or subscriptions are marked with an "*" in the respective input field. In the case of a credit card payment, the card number, validity date of the card, holder name and card verification number are also collected. On a voluntary basis, you can also provide additional information; however, this information is not required for the execution of the order. The personal data you provide in the context of the order will be used by us for the execution and processing of orders placed and payment transactions.

Live chat


In certain areas, we offer contact and advice via live chat. With the help of the live chat, you can communicate with one of our consultants via text messages. When you access and use the live chat, your browser automatically transmits the following data at the beginning of use for technical reasons, which we store separately from other data that you may transmit to us: date and time of access, duration of the visit to our online offer, type of browser including version, operating system used, amount of data sent, type of event, IP address (shortened/altered). If you also provide us with additional personal data via the live chat, this is done on a voluntary basis.

Marketing materials orders


In certain areas, we offer marketing materials such as stickers etc. that you can order. In order to send out the materials, we collect the data as required to deliver these materials to you. The personal data you provide in the context of the order will be used by us for the execution and processing of orders placed. If you also provide us with additional personal data in context of the order, this is done on a voluntary basis.

Saving a configuration as a “Pass” in the Wallet app


Once you have configured your desired Porsche model in the Car Configurator, you can use a QR code or link to save the selected configuration as a Pass in the Wallet app of your end device (available on Apple's iOS and Android). A Porsche code is stored in the Pass, which can be used to display your configuration directly in the Car Configurator or to communicate it to your Porsche Centre. No registration or login with a user profile is required to use this function. The process can be repeated for further configurations. In the settings on the back of the Pass, you can decide whether the Pass should be updated if necessary and whether push notifications relating to the Pass can be sent to you. Such push notifications will generally contain information about updates and news related to your saved configuration. Per configuration, a separate Pass will be offered for you to save. Please note that the required Wallet app is not offered by Porsche AG and may need to be installed separately. The Pass is saved within the functionalities of iOS or Android via a device-related ID. It is generally not possible for us to determine your identity via the Pass. For statistical purposes, we record how often Passes with certain configurations are saved and deleted. We process your personal data in order to provide you with the desired functions. You can revoke your consent at any time with effect for the future by selecting the corresponding unsubscribe link on the back of the Pass. We record how often Passes with certain configurations are saved and deleted, and we align the sending of other Porsche offers with your configuration in order to safeguard our interests in the further development of products and services as well as in customer segmentation, e.g. by calculation and evaluation of affinities, preferences and customer potential.

3.2 Compliance with legal obligations


We process your personal data to comply with legal obligations to which we are subject. These obligations may arise, for example, from commercial, tax, anti-money laundering, anti-corruption, fraud prevention, financial or criminal law.

3.3 Safeguarding of legitimate interests


We also process your personal data to pursue the legitimate interests of ourselves or third parties, unless your rights, which require the protection of your personal data, outweigh these interests. The processing to safeguard legitimate interests is carried out for the following purposes or to safeguard the following interests:

 

Further development of products, services and support offers as well as other measures to control business transactions and processes Improvement of product quality, elimination of errors and malfunctions, among other things by means of analysis of vehicle data and customer feedback Processing of data in a central prospective customer and customer care platform as well as upstream and downstream systems for customer retention and sales purposes Needs analysis and customer segmentation, e.g. calculation and evaluation of affinities, preferences and customer potential Handling of non-contractual inquiries and concerns Risk management and coordination of recall actions Ensuring legally compliant actions, prevention of and protection against legal violations (especially criminal offences), assertion of and defence against legal claims, internal and external compliance measures Ensuring availability, operation and security of technical systems as well as technical data management Answering and evaluation of contact requests and feedback

When you use our websites, data relating to your end device and your use of the online offer are processed and stored in a so-called log file. This concerns in particular technical data such as date and time of access, duration of the visit, type of terminal device, operating system used, functions used, amount of data sent, IP address and referrer URL. We process this data to ensure technical operation and to determine and eliminate faults. In doing so, we pursue the interest of permanently ensuring technical operability. We do not use this data for the purpose of drawing conclusions about your person.

When we send emails for customer and prospect management, we may use commercially available technologies such as tracking pixels or click-through links. This enables us to analyse which or how many emails are delivered and/or rejected and/or opened. The latter is done in particular using tracking pixels. It will not be possible to fully measure the opening rate of our emails using tracking pixels if you have deactivated the display of images in your email program. In this case, the email will not be displayed completely. However, we are still able to track whether an email has been opened if you click on text or graphic links in the email. By using click-through links, we can analyse which links in our emails are clicked and derive what interest there is in certain topics. When you click on the corresponding link, you are guided through our separate analysis server before the target page is called up. Based on the results of the analysis, we can make emails more relevant, send them in a more targeted manner or stop them from being sent. If you do not want such data to be collected and tracked, do not click on text or graphic links in emails.

As part of the further development of products, services and support offerings, you may be selected from time to time to participate in a survey when visiting our websites or participating in our activities on-line or off-line. Participation is voluntary. We do not use the data collected in the surveys for the purpose of drawing conclusions about you or your identity. Data directly related to your identity will only be processed if you provide it on a voluntary basis as part of the survey.

3.4 Consent


We process your personal data on the basis of corresponding consent. If you give your consent, it is always for a specific purpose; the purposes of processing are determined by the content of your declaration of consent. You may revoke any consent you have given at any time by writing to the contact details under Section 1.

If you have given your consent, the companies listed in the declaration of consent can use the data on this basis, e.g. for individual customer and prospective customer support and contact you for these purposes via the communication channels you have requested. Your data will be used in this context to offer you an inspiring brand and customer care experience with Porsche and to make communication and interaction with you as personal and relevant as possible. Which of your data is actually used for individual customer and prospective customer support depends in particular on which data has been collected on the basis of orders and consultations (e.g. when buying or servicing Porsche products) and which data you have provided (e.g. your personal interests) at the respective contact points (e.g. at the Porsche Centre).

We send out newsletters after respective registration, i.e. with your consent. If the content of the newsletter is specifically described in the context of a registration, these are decisive for the scope of the consent. Furthermore, our newsletters contain information about our products, offers, promotions and our company. The entity named in the registration process is responsible for processing your data. The registration is carried out by means of the so-called double opt-in procedure, i.e. after your registration you will receive an email asking you to confirm your registration in order to prevent the misuse of your email address. The registrations for the newsletter are logged by us in order to be able to prove the registration process and the consent contained therein in accordance with the legal requirements. You can revoke your consent to receive our newsletter at any time, e.g. by unsubscribing from the newsletter. You will find an unsubscribe link to exercise this right at the end of each newsletter.

4. Access authorisations in the end device
To the extent functions of our websites require the granting of authorisation to access your end device (e.g. access to location data or photos), the granting of these authorisations is voluntary. However, if you wish to use the corresponding functions, you must grant the appropriate authorisations, otherwise you will not be able to use these functions. The permissions remain active as long as you have not reset them in your device by deactivating the respective setting.

5. Cookies and comparable technologies
We use cookies and comparable technologies in connection with our websites which serve to communicate with your end device and exchange stored information (hereinafter collectively referred to as "Cookies"). These Cookies are primarily used to make the functions of our websites usable. General examples in which the use of Cookies is technically required in this sense are the storage of a language selection, login data or a shopping or watch list. Accordingly, technically required Cookies may be used by us to enable the processing described in Section 3 and to ensure the proper and secure operation of our websites. The data processing is then necessary to implement the functions you have selected or to protect our legitimate interest in the functionality of our websites.

Insofar as we would also use Cookies in order to analyse the use of our websites and to be able to target it to your interests and, if necessary, to provide you with interest-based content and advertisements, this is done exclusively on the basis of your voluntary consent. You will then have the opportunity to make the appropriate settings within the websites via Cookie Policy. You may revoke any consent you have given at any time with effect for the future. Further information on Cookies and their function in detail as well as on setting and revocation options can be found directly in the corresponding areas of Cookie Policy. Please note that we only make available the consent management in the context of our websites if, in addition to the above-mentioned technically required Cookies, consent based Cookies are to be used.

If you do not wish to use Cookies in general, you can also prevent their storage by adjusting the settings of your end device accordingly. Stored Cookies can be deleted at any time in the system settings of your end device. Please note that blocking certain types of Cookies can lead to impaired function of our websites.

6. Integrated third-party services
Insofar as we integrate services of other providers within the scope of our websites in order to provide you with certain content or functions (e.g. playing videos or route planning) and we process personal data in the process, the data processing is necessary to implement the functions you have selected or to protect our legitimate interest in an optimal range of functions of our websites. Insofar as Cookies may be used within the scope of these third-party services, the statements under “Cookies and comparable technologies” section apply. Please also refer to the privacy policy of the respective third-party providers with regard to the third-party services.

Services of other providers which we integrate or to which we refer are provided by the respective third parties. We have no influence on the content and function of the third-party services and are generally not responsible for the processing of your personal data by their providers, unless the third-party services are completely designed on our behalf and then integrated by us on our own responsibility. Insofar as Cookies are to be set on the basis of your consent, you will receive further information on the responsibility for setting these Cookies and any associated third-party services in the corresponding area of their cookie policies.

Unless otherwise stated, profiles on social media are generally only included in our websites as a link to the corresponding third-party services. After clicking on the integrated text/image link, you will be redirected to the offer of the respective social media provider. After the redirection, personal data may be collected directly by the third-party provider. If you are logged into your user account of the respective social media provider, the provider may be able to assign the collected information of the specific visit to your personal user account. If you interact via a "share" button of the respective social media provider, this information can be stored in the personal user account and published if necessary. If you want to prevent the collected information from being assigned directly to your user account, you must log out before clicking the included text/image link.

7. Sources and categories of data in case of third party collection
We also process personal data that we receive from third parties or from publicly accessible sources. Below you will find an overview of the corresponding sources and the categories of data obtained from these sources.

 

Group Companies, Porsche Centres and service companies: information on the products you use and on your interests Cooperation partners and service providers: creditworthiness data from credit agencies

8. Recipients of personal data
Within our company, only those persons who need your personal data for the respective purposes mentioned have access to it. Your personal data will only be passed on to external recipients if we have legal permission to do so or have your consent. Below you will find an overview of the corresponding recipients:

 

Commissioned processors: Porsche Group companies or external service providers, for example in the areas of technical infrastructure, performance and maintenance as well as payment processing, which are carefully selected and reviewed. The processors may only use the data in accordance with our instructions. Public bodies: Authorities and state institutions, such as tax authorities, public prosecutors' offices or courts, to which we (must) transfer personal data, e.g. to fulfil legal obligations or to protect legitimate interests. Private bodies: Porsche Group companies, Porsche Centres and service companies, cooperation partners, (non-processor) service providers or commissioned persons such as Porsche Centres and service companies, financing banks, credit agencies or transport service providers.

9. Data processing in third countries
To the extent permissible by applicable data protection law, the information you provide to us may be transferred out of your local country in order to enable processing in accordance with the purposes stated in the Privacy Policy. These countries include the places where Porsche Group companies have business operations. If a data transfer takes place to entities whose registered office or place of data processing is not located in a member state of the European Union, another state party to the Agreement on the European Economic Area or a country that may not have adequate protections in place regarding your personal data, we will ensure prior to the transfer that either the data transfer is covered by a statutory permit, that guarantees for an adequate level of data protection with regard to the data transfer are in place (e.g. through the agreement of contractual warranties, officially recognized regulations or binding internal data protection regulations at the recipient), or that you have given your consent to the data transfer.

10. Protection of personal data
We use technical and organisational measures to safeguard your personal data, including without limitation:

 

Technology such as encryption, firewall and penetration test to prevent unauthorised access to your personal data Secured servers to protect the storage of your personal data Appropriate rights and access control to ensure that access to your personal data is on a need-to-know basis for permitted purposes Confidentiality obligations imposed on our employees Adequate data privacy policies and procedures

11. Storage duration; erasure of data
We store your personal data, if there is legal permission to do so, only as long as necessary to achieve the intended purposes or as long as you have not revoked your consent. In the event of a request to withdraw your consents, we will stop processing your personal data in accordance with your wishes. We will also delete your personal data if we are obliged to do so for other legal reasons. Applying these general principles, we will usually delete your personal data immediately:

 

after the legal permission has ceased to apply and provided that no other legal basis or legitimate business purpose (e.g. commercial and tax law retention periods) intervenes. If the latter applies, we will delete the data after the other legal basis has ceased to apply if your personal data is no longer required for the purposes we pursue and no other legal basis or legitimate business purpose (e.g. commercial and tax law retention periods) intervenes. If the latter is the case, we will delete the data after the other legal basis has ceased to apply.

12. Your Rights
Right to access: You have the right to receive information about your personal data stored by us, unless the applicable data protection law provides an exclusion to this right. Where permitted by applicable data protection law, we may charge a reasonable administrative fee for costs incurred before we fulfil your right to access. The fee chargeable will be notified to you when you submit your request to us.

Right to correction: You can demand that we correct incorrect data free of charge, unless the applicable data protection law provides an exclusion to this right.

Right to withdrawal of consent: If you have given us your consent to process your personal data, you can revoke it at any time with effect for the future. The legality of the processing of your data until revocation remains unaffected. If your withdrawal of consent is not to direct marketing in general but to direct marketing to a particular channel (e.g. email or phone), please specify the channel to which you are objecting.

Right to lodge a complaint with a supervisory authority: You can also lodge a complaint with the competent supervisory authority if you believe that the processing of your data violates applicable law. You can contact the supervisory authority responsible for your place of residence or your country or the supervisory authority responsible for us.

If you have any question regarding the processing of your personal data, or if you would like to exercise your above-mentioned rights, please contact us via mail or email to the contact details provided under Section 1. Please make sure that we can definitely identify you. If you revoke your consent, you can alternatively choose the contact method that you used when you gave your consent.

13. Links to third-party services
The websites and services of other providers to which our websites links are designed and provided by third parties. We have no influence on the design, content and function of these third-party services. We dissociate ourselves expressly from all content of all linked services from third parties. Please note that the services of third parties linked on our websites may install their own cookies on your end device or collect personal data. We have no influence on this. In this respect, please refer to the providers of these linked third-party services. The services of third parties generally also include those of other Porsche Group companies and Porsche Centres which are linked on our websites or which are otherwise integrated into our websites, such as in particular:

My Porsche Porsche Classic Parts Explorer Porsche Tequipment / TEQ Finder Porsche Service tyre approvals (only available in selected countries)

The respective providers and data controller can be identified via the respective imprint and the privacy policy of the individual third-party services.

The latest version of this Privacy Policy applies. This version dates from 01.11.2021.