PRIVACY POLICY
CAROO, the online car sharing application, Caroo App, and the Website, respects the privacy of individuals and takes the protection of their personal data very seriously. Therefore, we inform you that, for the best and most complete service through our CAROO App, the processing of your personal data is carried out according to the terms and principles of the General Data Protection Regulation 2016/679 (GDPR) and in accordance with national, community, and international laws on the protection of individuals from the processing of personal data, as currently in force.
This Privacy Policy provides information regarding the collection, storage, processing, and use of your personal data, as well as how your personal data is used, disclosed, and protected, the choices you have regarding your personal data, and how you can contact us. For any questions regarding this Privacy Policy or any issues related to the processing of your data and the exercise of your rights, you can contact us at the email address info@caroo.gr.
The private capital company named “CAROO MOBILITY SERVICES PRIVATE CAPITAL COMPANY” (with G.E.MI number 169167801000 and VAT number 802061598), headquartered at Melissou 20, 11635 Athens, Attica, contact phone number 6988236013, contact email address info@caroo.gr, which fully owns the online car sharing application Caroo App, and the website (www.caroo.gr), acting as Data Controller, collects, stores, uses, and generally processes your personal data.
By registering on the Application, using it and the provided services, and providing your personal information, you unreservedly accept, consent, approve, and agree with the Terms of Use – Conditions and the terms set out in this Privacy Policy. If you do not accept and do not consent to the Terms of Use – Conditions and the terms set out in this Privacy Policy, please do not proceed with registration in the Application and do not use it and the provided services.
1. Definitions
For the purposes of this Privacy Policy:
- Account: An account means a unique account created for you to access our Application/Services or parts of it.
- Application: The term Application refers to Caroo, the software provided by the Company.
- Company: The term Company (encountered in this document either as “Company,” “We,” or “Our”) refers to the private capital company named “CAROO MOBILITY SERVICES PRIVATE CAPITAL COMPANY,” headquartered in Greece, Athens, Aristotelous 11-15.
- Country: Country refers to Greece.
- Device: Device means any device that can access the Application/Service, such as a computer, a mobile phone, or a digital tablet.
- Personal Data: Personal Data, as referred to below, is any information that relates to an identified or identifiable person.
- Service: The term Service refers to the Application.
- Service Provider: A Service Provider is any natural or legal person who processes data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, provide the Service on behalf of the Company, perform services related to the Service, or help the Company analyze how the Service is used.
- Usage Data: Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- “You” or “User”: “You” or “User” means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
2. What are personal data?
The term “personal data” refers to information of individuals, such as name, driving license details, ID or passport details, postal address, email address, contact phone number, etc., which identify or can identify your identity, hereinafter “Personal Data or Data.”
3. What is the Processing of Personal Data?
Any act or series of acts performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
4. What Data do we collect?
We ensure to collect only the Data that is absolutely necessary to serve the purpose for which it was provided and are used exclusively for the purposes for which they have been collected. In the context of the provided services, we will use your contact details to keep you informed about matters concerning the rental and use of the car you have chosen through the Application. We collect Data during your visit, registration, and use of the Caroo App and only if you have consented to this, consent which is presumed by the visit, registration, and use of the Application, by filling in the corresponding fields and sending the corresponding documents.
These Data include:
- Identity Data, such as name, surname, patronymic, date of birth, driving license, VAT number, ID number, Passport.
- Copies of documents provided to prove your age or identity and your ability to drive (driving license).
- Contact Data, such as postal address, email address (e-mail), phone number.
- Address or phone number verification details.
- Identification details, such as username, IP address.
- Billing and payment details: Payment information, credit/debit card number for charging the provided services.
- Data related to the Services: We collect information about transactions related to your use of the Application, including the date and time of use of the Application and provided services, the distance traveled, the amount charged, and the payment method.
- Location and image information: During the use of the Application, to provide its features, we collect, with your consent, information about your location and images from the camera and/or the photo library of your Device, concerning exclusively the car you have rented through the Application.
Specifically, location information is collected when the Application is open and remains in the background, even when not in use, to fulfill the purpose of the Application and operate its main part, such as identifying and suggesting to the User the nearest cars.
Additionally, location information is collected when the Application is open and in use, exclusively to provide the functions of our Service, to fulfill the purpose of the Application and our contract, i.e., for the rental of a car through the Application. The collection of location information, in this case, is activated by unlocking the car and deactivated by locking it.
The collection of location information and images from the camera or/and the photo library of your Device, exclusively concerning the car you have rented through the Application, is carried out only to provide functions of our Service, to fulfill the purpose of the Application and our contract, i.e., for the rental of a car through the Application. These information are uploaded through the Application to a server of the Company. The location information is used, as mentioned above, to fulfill the main purpose and function of the Application, which is car rental, to identify and suggest to the User the nearest cars, the exact points of the car on the map, and for directions. The collection of images from the camera or/and the photo library of your Device, exclusively concerning the car you have rented through the Application, is used for unlocking and locking the car and for taking pictures of the car. These aforementioned information are necessary for the correct and unobstructed operation of the Application.
You can enable or disable access to these information at any time through your Device’s settings.
- Technical Data: To offer the best possible Application experience, we collect technical information about your internet connection, information from your device regarding your use of the Application, such as browser type, device type, browser language, IP address, mobile network provider, etc.
- Information collected from the use of cookies in your browser.
5. How we use your Data:
The processing of your Data is conducted either by specially authorized personnel of our Company or through IT systems and electronic devices by our Company and, exceptionally, by third parties, who are contractually bound to our Company for the confidentiality and protection of your Data and process it exclusively for the purposes for which it has been provided to us.
Outlined below is how your data is used and why:
- For the use of the Application and the provided services, namely the car rental: The Company processes your Data to operate the main part of the Application and fulfill its contractual relationship with you, which is car rental through the Caroo App, to comply with legal obligations, to counteract, raise or exercise legal claims.
- To comply with applicable legislation: The Company processes your Data to be able to respond to legal obligations, particularly related to tax and insurance legislation or vehicle insurance coverage derived from an active insurance contract.
- To create a user account: The Company processes your Data to provide account functionalities and facilitate, for example, the provision of services, namely car rental through the Application.
- For communication: The Company uses your Data to respond to your requests/inquiries submitted, for example, through mail or contact form. The information you share with us allows us to manage your requests and respond to you in the best possible way. We can also keep a record of your requests/inquiries to us to better respond to any future communication. We do this based on our contractual obligations to you, our legal obligations, and our legitimate interests to provide you with the best possible service and improve our services based on your personal experience.
- For the operation, improvement, and maintenance of the Application and provided services: Development and improvement of systems for the services we provide you. We do this based on our legitimate business interests.
- To comply with our obligations deriving from the law: To comply with our contractual or legal obligations to exchange data with law enforcement. For example, based on a court order for exchanging data with judicial services.
- To send you communications required by law or necessary to inform you about changes in the provided services.
6. For what purpose we process your Data:
We collect your Data for the purposes of the Application and the provided services, including:
- Assessing your request for registration in the Application and use of the provided services.
- Concluding the rental agreement for the car you selected through the Application.
- Sending you information about the provided services (e.g., booking confirmation of a car).
- Managing any debts you may have towards the Company.
- Complying with obligations imposed by the applicable legislation, such as labor, tax, and insurance laws.
- Improving the provided services and your experience from using the Application.
- Improving and optimizing the Caroo App.
- Operating the main part of the Application and fulfilling its main purpose and our contract, i.e., car rental through the Application.
7. How we use Cookies:
Cookies help make the use of the Application and our Website easier and more pleasant. Cookies are information files that your browser automatically stores on your device’s hard drive when you visit our Application or Website. For example, we use cookies to recognize you as a registered user without needing to log in again each time.
Most of the cookies we use are deleted from your computer or mobile device at the end of the browser session. For example, we use session cookies to record your language preferences and facilitate your browsing when continuing your internet session across multiple pages.
Additionally, we use temporary or permanent cookies that remain stored on your computer or mobile device after the end of the browser session. In each new visit, your favorite data and settings will be automatically recognized. They serve to make the use of our Application more user-friendly, efficient, and secure. Additionally, they allow you to receive selected information based on your interests.
Most web browsers accept cookies automatically. However, you can configure your browser to not store cookies on your computer or mobile device or to always receive a warning when a new cookie arrives. You can find more information about this in your browser’s settings options. Disabling cookies may result in limiting your browsing and the use of our Application or Website.
8. How we use log data:
When you use websites or mobile applications, web servers log personal usage data (called “log files”). Log files provide information about your IP address, the Application or website you last visited, the browser used, the date, the time, and the requested file. We evaluate these personal usage data to identify trends, collect statistics to improve the functionality of the Application, or better tailor our services to the needs of its users.
9. What is the legal basis for processing your Data by the Company:
The processing of your Data is carried out according to:
- The terms of our contractual relationship.
- Your consent, where required.
- The Company’s legal obligations (e.g., tax, labor, insurance legislation, etc.).
- The Company’s legitimate interest.
10. Who are the recipients of your Data:
CAROO guarantees that it will not transfer, disclose, grant, etc., your Data to third parties (other than those mentioned in this document) for any purpose or use unless required by applicable law or demanded by public/judicial authorities/agencies.
Access to your Data is granted to the absolutely necessary personnel of the Company, which is bound by confidentiality, and our cooperating businesses, which process your Data as Joint Controllers or Processors on behalf of us and according to our instructions.
Indicatively, recipients of your Data include:
- Car rental companies cooperating with our Company.
- Insurance companies that insure the cars.
- Companies providing roadside assistance.
- Certified public accounting firms auditing the Company’s financial statements.
- Third-party service providers, natural or legal persons employed by the Company to facilitate the Service, provide the Service on behalf of the Company, perform services related to the Service, or assist the Company in analyzing how the Service is used, and process personal data on behalf of the Company, for example (indicatively), for processing credit cards and payments. When we use third-party service providers, we enter into agreements that obligate them to implement appropriate technical and organizational measures to protect your personal data.
- Other third parties, to the extent necessary for the following purposes: (i) compliance with a government request, court order, or applicable law, (ii) preventing illegal uses of the Application or violations of our Terms of Use and policies, (iii) our protection against third-party claims, and (iv) assisting in preventing or investigating cases of fraud.
- Other third parties when you have given your consent.
Your Data will not be used for any other purpose without your prior notification and consent. The sale of data to third parties is explicitly excluded.
11. How do we ensure that Processors respect your Data:
The Processors processing your data on our behalf have agreed and contractually committed to the Company:
- To maintain confidentiality.
- Not to send your Data to third parties without the Company’s permission.
- To take appropriate security measures.
- To comply with the legal framework for personal data protection, especially Regulation 679/2016/EU (otherwise GDPR).
12. When do we delete your Data:
We retain your Data for as long as necessary or appropriate to ensure compliance with applicable laws and our legal obligations (tax, labor, and insurance legislation) and for as long as necessary to fulfill the purposes set out in this Privacy Policy.
Generally, this means that we will retain your personal data for as long as you have a User account in our Company’s Application unless a longer retention period is required by applicable law. At the end of the retention period, your data will be fully deleted or anonymized, for example, by aggregating with other data, so that it can be used in an unidentifiable way for statistical analysis and business planning.
13. Is your Data secure:
CAROO is committed to safeguarding your Data. Recognizing the importance of the security of your Personal Data, we have taken all appropriate organizational and technical measures that are continuously improved, based on technological advancements, solely for the purpose of security and protection of your Data from any form of accidental or unlawful processing.
However, you should be aware that the transmission of information via the Internet and other electronic means of communication involves certain security risks, and we cannot provide any guarantee regarding the security of information transmitted through these channels.
We take appropriate technical measures, taking into account the latest technology, the scope, circumstances, and objectives of data processing, as well as the severity of risks to rights and freedoms, and organizational measures to ensure a level of protection adapted to the risk.
We also take very seriously our internal data protection. Our employees and authorized service providers are bound by confidentiality and compliance with legal data protection regulations. Access to personal data is provided only to the extent necessary.
14. What are your rights:
You have the right to access your personal Data. This means you have the right to be informed by us if we are processing your Data. If we are processing your Data, you can request information about the purpose of processing, the type of your Data we hold, to whom we disclose it, how long we store it, whether automated decision-making is involved, and about your other rights, such as correction, deletion of Data, restriction of processing, and submission of complaints to the Data Protection Authority.
You have the right to correct inaccurate personal Data. If you find an error in your Data, you can submit a request to us to correct it (e.g., correction of name or address change).
You have the right to erasure/right to be forgotten. You can ask us to delete your Data if it is no longer necessary for the aforementioned processing purposes or you wish to withdraw your consent where it is the only legal basis.
You have the right to data portability. You can ask us to receive your Data in a readable format or ask us to transfer it to another controller.
You have the right to restrict processing. You can ask us to restrict the processing of your Data for as long as your objections to processing are being examined.
You have the right to object and withdraw consent to the processing of your Data. You can object to the processing of your Data, and we will stop processing it unless there are compelling and legitimate reasons that override your right. If you have declared your consent to the collection, processing, and use of your personal data, you can withdraw your consent at any time with future effect.
15. How can you exercise your rights:
To exercise your rights, you can submit a relevant request by sending it to the email address info@caroo.gr, and we will ensure to examine it and respond to you within one (1) month of receiving it.
16. When do we respond to your Requests:
We respond to your requests free of charge without delay, and in any case, within one (1) month from when we receive your request.
17. Where can you address the progress of your Requests:
For information on the progress of your request, you can contact the email address info@caroo.gr.
18. What is the applicable law during the processing of your Data by us:
Applicable law is Greek law, as shaped in accordance with the General Data Protection Regulation 2016/679/EU, and generally the applicable national and European legislative and regulatory framework for personal data protection.
Competent courts for any disputes arising related to your Data are the competent courts of Athens.
19. Where can you file a complaint if we violate the applicable law on the protection of your Personal Data:
You have the right to file a complaint with the Data Protection Authority (postal address Kifisias 1-3, P.C. 115 23, Athens, phone number 210.6475600, email address contact@dpa.gr), if you believe that the processing of your Personal Data violates the applicable national and regulatory legal framework for personal data protection.
20. How will you be informed about any modifications to this Policy:
We update this Policy whenever necessary. If there are significant changes to the Policy or the way we use your Personal Data, we will publish the updated Policy in the Caroo App or our Website (www.caroo.gr) or notify you in any appropriate way.
We encourage you to periodically read this Policy to know how your Data is protected.