III. WHEN YOU USE VEHICLE-BASED DIGITAL SERVICES
Depending on your vehicle model and the functions and services you actually choose, we collect and use your relevant personal information to provide you with more diversified vehicle-based Digital Services. All collected information is generally stored and processed within EU and EEA with the exception of technical data required for Vehicle Performance Analysis and Error identification, which can be transferred outside EU and EEA for third level support. No personal identifiable information will be shared outside EU and EEA.
Please Note: In the process of providing the following vehicle-based Digital Services, we may collect your vehicle information, such as: vehicle charging information, parking brake status, cruising range, alarm status, maintenance status, seat belt status, collision status, vehicle travel time, energy consumption. Please note that the vehicle information alone cannot identify you and does not constitute your personal information. We will treat your vehicle information as your personal information only when it is used in combination with your other information and can identify you. We will process and protect your vehicle information in accordance with this Privacy Statement. The hardware, software of the network system and the data in the system are protected from damage, alteration or leakage due to accidental or malicious reasons, and the system operates continuously and reliably and normally, and the network service is not interrupted.
Some of the following functions and services in the use of the vehicle are provided to you by smart and the third-party service providers that smart connects you to. Except as expressly stated otherwise in this Clause and the applicable user clauses, this Clause does not apply to third-party service providers who independently provide products or services to you. We recommend that you carefully read the privacy clauses or personal information processing rules of third-party service providers before using these services to understand how they will process and protect your personal information, and how you can exercise your relevant rights.
You can activate and deactivate individual services and functions in the privacy settings of your vehicle's DHU, except functions that are necessary for legal, safety and security reasons. You can also control certain services and functions via the Hello smart App. For more information, you can also consult the User Manual, which you can access in your vehicle.
1. Authentication and registration of vehicle SIM card
The vehicle-based Digital Services provided by smart or third parties require a mobile network connection.
When you activate and use the vehicle-based Digital Services, your data will be forwarded to our service provider VODAFONE ENTERPRISE GERMANY GMBH, Ferdinand-Braun-Platz 1 40549 Düsseldorf, Germany who collects your name, address, VIN and engine number on behalf of smart to be able to provide you with our SIM Service, Connectivity Service as well as our E-Call Service. Legal basis for the processing of your data is contract fulfillment pursuant to Article 6 (1) b GDPR.
If your vehicle is equipped with a wireless network connection, data can be exchanged between the vehicle and other equipment. The wireless network connection can be enabled through the transmission and reception unit of the vehicle or by connecting a mobile terminal equipment, such as a smart phone.
2. Vehicle Remote Functions
With the Hello smart App you are able to access and control certain vehicle functions remotely via your smartphone.
You have the Following Remote functions via the Hello smart App:
- You can lock and unlock the door & boot of your vehicle remotely
Collected data: Vehicle identification number (VIN), vehicle information: door status, door lock status, usage mode and car mode; - You can use the App to find the vehicle by flashing light or sounding the horn
Collected data: Vehicle identification number (VIN), Vehicle information: vehicle speed, car location, vehicle direction, usage mode and car mode; - You can use climate control to manage the temperature in the vehicle, including seat heating and steering wheel heating
Collected data: Vehicle identification number (VIN), climate status: seat heating status, seat ventilation status, in-vehicle setting temperature, high voltage status, usage mode and car mode; - You can remotely start and stop charging the vehicle battery
Collected data: Vehicle identification number (VIN), state of charge, charge remaining time, high voltage status, charging current, charging voltage, charging start time, usage mode and car mode; - You can access and display status information of the vehicle via the app remotely
Collected data: Vehicle identification number (VIN), Vehicle status data (such as mileage, battery voltage, door and flap status/position/lock status, the window status/ warning/ position/, vehicle alarm status, sunroof open status, engine status, key status), average consumption and tyre pressure.
Legal basis for the data processing is contract fulfillment pursuant to Article 6 (1) lit. b GDPR.
To provide Vehicle Remote Functions, we use a third party provider for Telematic Service as a data processor.
Digital Services via the Digital Head Unit (DHU)
2.1. Online Navigation
With this function we enable Route calculation, Map updates, showing charging stations, Parking places and Online traffic information. You can only use the navigation map related functions if you activate this function in the privacy settings on the DHU.
Collected data: Favorites (including name, address, vehicle location (latitude and longitude), phone, etc.), destination name, vehicle location (latitude and longitude), point-of-interest (“POI”) address, POI phone, record of consent.
Legal basis for the data processing is contract fulfillment according to Art. 6 para. 1 lit. b) GDPR.
To provide Online navigation services, we use a third party provider for Telematic Service as a data processor.
2.2. App Store
You can download, or delete third party applications via the App Store. The App Store is provided by our third-party service provider Faurecia Clarion Electronics Europe, R. Soeiro Pereira Gomes Lote 1 3-Dto, 1600-196 Lisboa as a data processor. The respective app providers are responsible for data processing in connection with the installation and use of the apps.
Data collected for the provision of the App Store: User ID, application download record.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
2.3. Voice Control
You can use voice control to activate vehicle functions through the voice assistant. You only need to say your command, and the system will help you complete the operation. In order to activate the voice assistant function you need to ensure that the voice assistant is activated in your vehicle privacy settings on the central display. After this function is turned on, native applications such as multimedia/navigation/voice assistant can be operated by voice command. Some functions such as multimedia/navigation can be operated by voice command without activating the voice assistant with a voice wake-up command.
Collected data: Voice input, Device ID, vehicle location (longitude and latitude), coordinates, phone book contact information.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
To provide voice control functions, we use a third party cloud provider (Cerence B.V., CBS-weg 11, 6412 EX Heerlen, The Netherlands) as a data processor.
2.4. User Profile
You can create your individual user profile and store your preferred settings (seat position, door mirrors and, if applicable, head up display). Your profile is connected with your smart ID. When you log in to the vehicle, your profile settings as well as further information you have provided in your smart account (e.g. username)will be loaded.
Collected data: Vehicle identification number (VIN), user ID, username, account type, ergonomic settings (e.g. seat adjustment, door mirrors and, if applicable, head up display).
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR. Please note that after deactivating this function, you will not be able to use several vehicle connectivity functions, such as remote control and monitoring of the vehicle by mobile phone (smart Hello App) and the use of digital keys.
To provide the personalized profile functions, we use a third party provider for Telematic Service as a data processor.
2.5. Weather
If you activate the weather function, this interface shows you the weather information based on your location and region.
Collected data: Vehicle information number (VIN), vehicle location (latitude and longitude), operator, model, device ID.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
To provide you with location-based weather information, we use a third party provider for Telematic Service as a data processor.
2.6. Energy Management
The energy management function allows the user to set charging schedules and to select the time at which the vehicle's battery will be charged at a charging location. In addition, the user can choose whether the vehicle should be air-conditioned and the battery warmed up at the desired departure time.
Collected data: Travel time, charging time, air conditioning preheating, battery pretemperature, user ID, energy consumption, electricity consumption.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
To provide you with energy management services, we use a third party provider for Telematic Service as a data processor.
2.7. Online Music
Using the Online music function allows you to display the QR code of third-party application multimedia services (including Spotify, TuneIn). You scan the QR code to log in or you enter the username and password in the third-party multimedia service interface. It connects you to the third-party application multimedia service installed on the vehicle. You can activate or deactivate the online music function via the privacy settings. The respective providers are responsible for the processing of data in connection with the use of third party multimedia services.
Collected data: Record of consent or disapproval; information on the music collection (last song played, picture, Media ID, search records) will only be stored locally.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
To provide you with the online music function, we use a third party provider for Telematic Service as a data processor.
2.8. 112 E-Call
The "EU Emergency Call" is an emergency assistance system regulated by the European Union and required by law. When you are in an emergency situation while driving, including but not limited to physical discomfort, encountering a safety threat, a safety accident, or an emergency response of the vehicle (such as airbag deployment), and you manually use/activate the function or the function is automatically triggered (such as when a vehicle airbag deploys), the E-Call system transfers data to the emergency call center of the emergency call system. An "EU emergency call" is made uniformly via the European emergency number 112.
Collected data: Emergency call trigger mode (automatic/manual), call trigger time, TCAM SIM number (vehicle built-in SIM number), vehicle information number (VIN), Vehicle type (passenger car or light-duty commercial vehicle), Vehicle energy/power type (gasoline/ diesel/CNG/LPG/electricity/hydrogen), Vehicle location, Driving direction, Vehicle speed, Number of persons in the vehicle, Battery status, Door status, Vehicle collision status (collision location, collision type, collision acceleration, airbag status, anti-theft system status, etc.).
The recipients of the data processed by the in-vehicle E-Call system are the relevant public safety answering points designated by the relevant public safety authorities in their country (such as local police, hospitals, rescue agencies and your emergency contact for emergency rescue services) to first receive and process emergency calls to the European emergency number 112.
The data contained in the system memory is not available outside the system before the in-vehicle system is triggered. The in-vehicle E-Call system is untraceable and is not subject to any continuous tracking under normal operating conditions. The data in the internal memory of the in vehicle E-Call system can be automatically and continuously deleted. The vehicle position data is continuously overwritten in the system's internal memory in order to always maintain the latest vehicle location data required for the normal operation of the system. Activity data logs in the in-vehicle E-Call system are kept no longer than the time required to process an emergency call.
Legal basis for the data processing is our legal obligation pursuant to Art. 6 para. 1 lit. c) GDPR, specifically our legal obligation pursuant to Regulation (EU) 2015/758.
2.9. Private E-Call
Instead of the 112 e-call, you can activate a Private E-call in the DHU settings. If you have selected the Private E-Call, the emergency call as well as the relevant data is not directed to the public safety answering points, but to a private provider (ARC Europe SA, Av. des Olympiades 2, 1140 Evere, Belgium) as a data processor.
Collected data: Vehicle information number (VIN), number of passengers, vehicle type, vehicle direction, car location, vehicle speed, usage mode and car mode. The provider of the Private E-Call may also collect additional information in order to provide you with further services.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
To provide you with the Private E-Call function, we use a third party provider for Telematic Service as a data processor.
2.10.Roadside Assistance (B-Call)
The B-Call allows the user to contact a private roadside assistance provider in the event of a breakdown. Roadside assistance is provided by ARC Europe SA, Av. Des Olympiades 2, 1140 Evere, Belgium (“ARC”), as a data processor. If the user triggers the B-Call, all relevant data about the vehicle's condition as well as the vehicle location are transmitted to ARC and a voice connection is established.
Collected data: Vehicle information number (VIN), vehicle location, license plate number, mobile phone number, mobile phone location, emergency contact name, emergency contact phone number, fault information (including fault code and fault light information). The provider of the B-Call may also collect additional information in order to provide you with further services.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
To provide you with the B-Call function, we use a third party provider for Telematic Service as a data processor.
2.11.Stolen Vehicle Call (S-Call)
The purpose of the Stolen Vehicle Call is conducting stolen vehicle tracking service. Stolen Vehicle Call is provided by ARC Europe SA, Av. Des Olympiades 2, 1140 Evere, Belgium (“ARC”), as a data processor.
For this service, the following data is processed: Data provided by local authority, Vehicle location, Leasing description, if applicable, Main user, Caller/Driver Description, (such as but not limited to): Email/smart ID, First Name, Last Name, Gender/Salutation, Company, Phone Number, Language.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
2.12.Remote Vehicle Diagnostics
smart vehicles are equipped with a real time remote safety monitoring system, which is used to collect and save various system data of the vehicle to facilitate remote vehicle diagnostics, trouble detection, pre-warning for maintenance, fault and quality analysis as well as safety monitoring for your vehicle.
Collected data: Vehicle information number (VIN), vehicle trouble codes originating from various vehicle components, position and motion data (such as time, position, speed, direction, pedal), vehicle maintenance data (due date of next service), vehicle status information (including VIN and time stamp) of various components’ control units including but not limited to battery, e-motor, ADAS, air condition, chassis, environment information (temperature, air pollution), e-motor, high voltage battery and alarm information, vehicle location data (longitude and latitude data), door and flap status/position/lock status and other functions as well as in specific cases log data of various components’ control units.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.
To provide you with real time remote safety monitoring, we use a third party provider for Telematic Service as a data processor.
2.13."Over-the-Air"-Software Updates (OTA)
The vehicle software (infotainment system, ECU firmware) can be updated via “over-the-air”-updates in order to obtain new functions, to provide system updates or to correct bugs and errors.
Collected data: Vehicle identification number (VIN), vehicle hardware and software version, software package, vehicle and software configuration information, operating system, date and time of software upgrade.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR. To provide you with OTA-Updates, we use a third party provider for Telematic Service as a data processor.
For customer support: In the unlikely event that OTA installation is aborted, the B-CALL can be triggered, Location and movement data (possible): Geo data, Vehicle status: before/after upgrade failure.
For continuous improvement of the OTA service: Vehicle configuration, Software configuration, e.g. release notes, date published.
In the unlikely event of an aborted the OTA where a roadside assistance is initiated, the following data is shared with the third-party support service: Vehicle Identification Number (VIN), Location and movement data: Geo data.
2.14.Online Services
This function requires the collection of your vehicle networking data and enables all functions which need access to the Internet.
This switch is disabled by default. With this function enabled you will be able to access vehicle related functions on the "Hello smart" App, including remote functions and digital key.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR. Please note that after deactivating this function, you will not be able to use several vehicle connectivity functions, such as remote control and monitoring of the vehicle by mobile phone (“Hello smart” App) and the use of digital keys.
2.15.Anti-theft system
The anti-theft system prevents others from illegally starting your vehicle. If the antitheft system is enabled, the vehicle status will be continuously monitored. The alarm will be triggered when the door/liftgate is not opened legally. If the remote anti-theft system is activated, a message that the vehicle cannot be started will pop up on the central display.
Collected data: Vehicle information, such as door open status, door lock status, windows open status, and trunk open status.
The vehicle is also equipped with a tracking system, which can track and locate the vehicle and remotely activate the antitheft system to prevent the vehicle from being started.
Collected data: Vehicle information number (VIN), event time, contact name, contact phone number, vehicle location before and after the event, vehicle information (model, color, language setting) for activating the stolen vehicle location service. When you activate the stolen vehicle location service, the vehicle will continuously upload the above information to our call center to provide the police or the user with vehicle location information to help locate the vehicle.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR. To provide you Anti-theft services, we use a third party provider for Telematic Service as a data processor.
2.16.Driver Drowsiness and Attention Warning (DDAW)
The "Driver Drowsiness and Attention Warning" system assesses the driver's alertness and warns the driver if necessary. DDAW function captures the movement of the driver’s face including facial characteristics, such as eyelid opening and closing, length of eye closure, blinking frequency, etc. The data collected by DDAW is limited to the processing of the aforementioned monitoring of facial movements and remains in the vehicle and is not stored or transmitted.
Legal basis for the data processing is our legal obligation pursuant to Art. 6 para. 1 lit. c) GDPR specifically the Regulation (EU) 2019/2144.
2.17.Valet Mode
Before handing over your vehicle to another person, you can turn on the Valet Mode for privacy protection. The Valet Mode can be activated either through tapping the user icon on the top right corner on the central display or by opening the drop-down menu and selecting the Valet Mode in the smart modes tab. To activate the Valet Mode, you will be asked to enter a password on the central display. This password must also be used to deactivate the Valet Mode. If you activate the Valet Mode in your vehicle, the system will log out your profile ID. Certain functions such as Bluetooth, voice assistant and multimedia functions will be switched off leaving only the basic driving functions active.
Collected data: Vehicle identification number (VIN), driving status of the vehicle, the Valet Mode password and the network data required for the remote control of the mobile phone.
Legal basis for the data processing is contract fulfillment pursuant to Art. 6 para. 1 lit. b) GDPR.