Data Privacy Policy

Purpose

Your privacy is important to us and to Société Générale Group to which ALD SA belongs. We have implemented strong principles in that respect, especially in regards of the General Data Protection Regulation (the “GDPR”).

ALD SA Data Privacy Policy aims to explain how we collect, store, use and disclose your personal information whenever you use our products and services, our websites or interact with ALD S.A.

As a data controller, we are responsible for collecting and processing your personal data in a lawful manner. The purpose of this Data Privacy Policy is to inform you about which personal data we may collect about you, the reasons why we use and in some cases share this data, for how long we keep it, what are your rights in this regard and the way to exercise them.

This Data Privacy Policy also aims to spell out the conditions that govern how we protect your information.

1. Which personal data do we collect about you?

We collect and use your personal data to the extent necessary for our business activities and to maintain high standards of personalized products and services. We may collect the following types of personal information: Identification and Contact information, such as your name, last name, city, telephone/mobile number or email address; Professional information, such as your job title or professional address (e.g. postal address and e-mail address, phone number); Financial/Credit information, such as your Credit Acceptance Date or contract information (e.g. credit card number, bank account details, payment data); Private details: such as your gender, date of birth, nationality, language(s), or personal preferences (habits, favorite car, etc.); Data relating to the vehicle leasing contract (e.g. client identification number, contract number, vehicle identification number). Driver data, such as the number/copy of the driver's license, or the employee code driver; We never ask for personal data related to your racial or ethnic origins, political opinions, religious or philosophical beliefs, trade union membership, genetic data or data concerning your sex orientation, unless it is required through a legal obligation. The data we use about you may either be directly provided by you (e.g., if you create an account on one of our sites or make a purchase), or indirectly (e.g., when using tracking tools like browser cookies), or be obtained indirectly from the following sources:

2. What activities and people are concerned by data collection?

This Policy applies to all sources of data collected and processed by ALD Automotive globally in the context of various Group activities such as corporate car leasing, private car lease, sales locations, third-party sources, use of our websites or mobile applications, and all offline processing activities.

We may collect and process your personal information if you are among the following categories: drivers of leased cars, business-to-business customers’ contact, partners, dealers, geographical partners, prospects, fleet managers, shareholders, managers, etc.

3. Why and how do we use your personal information?

ALD S.A. uses your personal information to offer you better services. Therefore, ALD S.A. may use your personal information in the following cases:

(a) **When necessary to comply with legal and regulatory obligations ** We use your personal data to comply with various legal and regulatory obligations, which may include (non- exhaustive list):

(b) **When necessary for contractual purposes ** We use your personal data to enter into and perform contracts, including to:

(c) With your informed knowledge and/or consent ​ In some cases, we must require your consent to process your data for:

4. With whom do we share your personal information with?

We understand that you do not want us to provide your personal information directly to third parties for their own marketing purposes without your consent. However, we occasionally need to use partners or processors to provide you with the requested services and a better experience, for the purposes described above. We therefore limit our sharing of your personal information on a need-to-know basis as follows:

5. How do we ensure the security and integrity of your personal information?

We protect your data through technical and organizational security measures (including education and training of relevant personnel) against accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access, and against all other unlawful forms of processing.

Only those teams and employees who need to know your information within our company can access it. We make sure to implement administration rights and policies within our company, and we take all measures to ensure that employees, advisers and service providers keep your files confidential.

6. How is your personal information transferred?

In case of data transfers originating from the European Economic Area, where the European Commission has recognized a non-EEA as providing an adequate level of data protection, your personal data may be transferred on this basis.

For transfers to non-EEA whose level of protection has not been recognized by the European Commission, we will implement one of the following safeguards to ensure the protection of your personal data:

To obtain a copy of these safeguards or details on where they are available, you can send a request as set out below (see 8. What are your rights and how can you exercise them ?).

7. How long do we keep your personal information?

We retain your personal information only as long as you enjoy a business relationship with ALD Automotive, or the term applicable under local law since our last contact, or as required to comply with ALD Automotive’s legal obligations.

In case of litigation, we may keep your personal information until the end of such legal action, including any potential periods for appeal. We will then either delete or archive it according to the law in force. In any event, your personal information will not be kept in a form that allows you to be identified for any longer than necessary by ALD Automotive for achieving the purposes for which it was collected or processed, or according to the relevant laws in force.

8. What are your rights and how can you exercise them?

To exercise the rights set out in the following section at any time, please send us a letter or an email the following address ALD SA, 1-3 rue Eugène et Armand Peugeot, 92500 Rueil Malmaison, France or contact ALD Automotive’s Data Protection Officer through dpo.ald@aldautomotive.com, and we will handle your request. In accordance with applicable regulations, you have the following rights: To Access: You can obtain information relating to the processing of your personal data, and a copy of such personal data. If you make such a request, we will provide you with all the information on the purposes of the processing, categories of data processed, categories of recipients, data retention term, your rights to rectify, delete or restrict the data accessed if applicable. To Rectify: where you consider that your personal data are inaccurate or incomplete, you can require that such personal data be modified accordingly To Erase: you can require the deletion of your personal data, to the extent permitted by the law To Object: you can object to the processing of your personal data, on grounds relating to your particular situation. You have the right to object to the processing of your personal data for direct marketing puposes, which includes profiling related to such type of marketing. To Withdraw your consent: where you have given your consent for the processing of your personal data, you have the right to withdraw your consent at any time. To Data Portability: Where legally applicable, you have the right to have the personal data you have provided to us be returned to you in an intelligible format.
If you wish to exercise the rights listed above you will also find the contact for each ALD entity in their respective data privacy policy:

Country + URL

In accordance with applicable regulations, in addition to your rights above, you are also entitled to lodge a complaint with the competent supervisory authority.

9. Cookies and other Tracking Tools

In order to provide you with a better experience, when you visit our website or use our mobile applications, we collect certain information by automated means, using technologies such as cookies, pixel tags, browser analysis tools, server logs and web beacons (e.g. Google Analytics).

If you use our web sites, we may collect information about the browser you are using, and your browsing behavior.

Such information aims notably to store your preferences and parameters to save you time, (such as languages preferences), enable log in, fight against fraud, and analyse the performance of our website and services.

If you use our mobile app, we may collect your GPS location, subject to your consent when required. We might also look at how often you use the app and where you downloaded it.

10. What happens when we change this Data Privacy Policy?

Our Data Privacy Policy may change from time to time to reflect changes in the way we processing your personal information. However, these changes will remain fully compliant with applicable law. We encourage you to periodically review this page for the latest information on our privacy practices. We will notify you of any material changes as required by law. We may modify this Privacy Policy periodically to be compliant with any new regulations, so please review it regularly.