This privacy policy explains which personal data are processed in connection with the website, the TOST app and the functions offered, for which purposes this takes place, and which rights data subjects have. Personal data are processed only where legally permitted or where consent has been given. The specific processing operations, legal bases, recipients and storage periods are described below.
1. Definitions
This privacy policy is based on the terms used by the European legislator when adopting the General Data Protection Regulation (GDPR). This privacy policy is intended to be easy to read and understand for the public as well as for customers and business partners. To ensure this, the terms used are explained below.
The following terms are used in this privacy policy:
a) Personal data
Personal data means any information relating to an identified or identifiable natural person, referred to below as the data subject. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more special characteristics expressing the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
b) Data subject
A data subject is any identified or identifiable natural person whose personal data are processed by the controller.
c) Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing means marking stored personal data with the aim of limiting their future processing.
e) Profiling
Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
f) Pseudonymisation
Pseudonymisation means processing personal data so that the data can no longer be attributed to a specific person without additional information, provided that the additional information is kept separately and protected by appropriate technical and organisational measures.
g) Controller
The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
h) Processor
A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
i) Recipient
A recipient is a natural or legal person, public authority, agency or other body to whom the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients.
j) Third party
A third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct responsibility of the controller or processor, are authorised to process personal data.
k) Consent
Consent is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of personal data relating to them.
2. Name and address of the controller
The controller within the meaning of the GDPR and other applicable data protection laws is:
Christian Hillebrand
Kornblumenweg 7
61184 Karben
Telephone: +49 (0) 6039 93 44 816
Email: contact [at]
tesla-order-status-tracker [dot] de
3. Collection of general data and information
When the website is accessed by a person or an automated system, general data and information may be collected and stored in the server log files. This may include browser type and version, operating system, referring website, pages accessed, date and time of access, IP address, internet service provider and other data used to protect the information technology systems against attacks.
These data are used to deliver the website correctly, optimise its content, ensure the long-term operation and security of the systems and provide information to law-enforcement authorities where required after a cyberattack. The data are evaluated statistically for these purposes and stored separately from personal data provided by a user. The legal basis is Article 6(1)(f) GDPR.
4. Routine erasure and restriction
Personal data are stored only for as long as necessary to achieve the purpose of processing or as required by applicable law. When the purpose no longer applies or a statutory retention period expires, the data are routinely restricted or erased in accordance with the applicable legal requirements.
5. Rights of the data subject
-
a) Right to confirmation
Every data subject has the right granted by the European legislator to obtain confirmation from the controller as to whether personal data concerning them are being processed. If a data subject wishes to exercise this right, they may contact an employee of the controller at any time.
-
b) Right of access
Every data subject affected by the processing of personal data has the right granted by the European legislator to obtain free information from the controller at any time about the personal data stored concerning them and a copy of that information. The data subject is also entitled to information about:
- the purposes of the processing;
- the categories of personal data processed;
- the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- where possible, the envisaged period for which the personal data will be stored or, where not possible, the criteria used to determine that period;
- the existence of a right to rectification or erasure of personal data concerning them or to restriction of processing by the controller or a right to object to that processing;
- the existence of a right to lodge a complaint with a supervisory authority;
- where the personal data are not collected from the data subject: any available information as to their source;
- the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved and the envisaged consequences of such processing for the data subject.
The data subject also has the right to obtain information as to whether personal data have been transferred to a third country or an international organisation. If this is the case, the data subject has the right to obtain information about the appropriate safeguards relating to the transfer.
If a data subject wishes to exercise this right of access, they may contact an employee of the controller at any time.
-
c) Right to rectification
Every data subject has the right granted by the European legislator to obtain the immediate rectification of inaccurate personal data concerning them. The data subject also has the right, taking into account the purposes of the processing, to have incomplete personal data completed, including by means of a supplementary statement.
If a data subject wishes to exercise this right to rectification, they may contact an employee of the controller at any time.
-
d) Right to erasure (right to be forgotten)
Every data subject has the right granted by the European legislator to obtain from the controller the erasure of personal data concerning them without undue delay where one of the following grounds applies and where the processing is not necessary:
- The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
- The data subject withdraws consent on which the processing is based pursuant to Article 6(1)(a) or Article 9(2)(a) GDPR, and there is no other legal ground for the processing.
- The data subject objects to the processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects pursuant to Article 21(2) GDPR.
- The personal data have been unlawfully processed.
- The personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject.
- The personal data have been collected in relation to the offer of information society services referred to in Article 8(1) GDPR.
If one of these grounds applies and a data subject wishes to request the erasure of personal data stored by us, they may contact an employee of the controller at any time. We will arrange for the erasure request to be complied with without undue delay.
Where personal data have been made public by us and we are obliged to erase them pursuant to Article 17(1) GDPR, we shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers processing the published personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data, unless the processing is necessary. We will arrange the necessary measures in the individual case.
-
e) Right to restriction of processing
Every data subject has the right granted by the European legislator to obtain from the controller restriction of processing where one of the following applies:
- The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data.
- The processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead.
- The controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims.
- The data subject has objected to processing pursuant to Article 21(1) GDPR pending the verification whether the legitimate grounds of the controller override those of the data subject.
If one of these conditions applies and a data subject wishes to request restriction of personal data stored by us, they may contact an employee of the controller at any time. We will arrange for the restriction of processing.
-
f) Right to data portability
Every data subject has the right granted by the European legislator to receive the personal data concerning them which they have provided to a controller in a structured, commonly used and machine-readable format. They also have the right to transmit those data to another controller without hindrance from the controller to which the personal data were provided, where the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR and the processing is carried out by automated means, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
When exercising the right to data portability pursuant to Article 20(1) GDPR, the data subject also has the right to have the personal data transmitted directly from one controller to another, where technically feasible and where this does not adversely affect the rights and freedoms of others.
To exercise the right to data portability, the data subject may contact the controller at any time.
-
g) Right to object
Every data subject has the right granted by the European legislator to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them which is based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.
We will no longer process the personal data in the event of an objection unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to processing of personal data concerning them for such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If the data subject objects to processing for direct marketing purposes, we will no longer process the personal data for those purposes.
The data subject also has the right, on grounds relating to their particular situation, to object to processing of personal data concerning them for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
To exercise the right to object, the data subject may contact the controller directly. In connection with the use of information society services, the data subject is also free to exercise their right to object by automated means using technical specifications, notwithstanding Directive 2002/58/EC.
-
h) Automated individual decision-making, including profiling
Every data subject has the right granted by the European legislator not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision (1) is necessary for entering into, or performance of, a contract between the data subject and the controller, (2) is authorised by Union or Member State law to which the controller is subject and that law lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, or (3) is based on the data subject's explicit consent.
Where the decision (1) is necessary for entering into, or performance of, a contract or (2) is based on explicit consent, we shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, including at least the right to obtain human intervention, to express their point of view and to contest the decision.
If a data subject wishes to exercise rights relating to automated decisions, they may contact an employee of the controller at any time.
-
i) Right to withdraw consent under data protection law
Every data subject has the right granted by the European legislator to withdraw consent to the processing of personal data at any time.
If a data subject wishes to exercise the right to withdraw consent, they may contact an employee of the controller at any time.
6. Legal bases for processing
Processing based on consent relies on Article 6(1)(a) GDPR. Processing necessary to perform a contract or take steps at the request of the data subject before entering into a contract relies on Article 6(1)(b) GDPR. Processing necessary to comply with a legal obligation relies on Article 6(1)(c) GDPR. Processing necessary to protect vital interests may rely on Article 6(1)(d) GDPR. Processing necessary for a legitimate interest relies on Article 6(1)(f) GDPR, unless the interests or fundamental rights and freedoms of the data subject override that interest.
7. Legitimate interests
Where processing is based on Article 6(1)(f) GDPR, the legitimate interests are the secure operation of the website and TOST services, protection against misuse and the performance of the business activity.
8. Storage period
Personal data are stored for the period required for the relevant purpose or by applicable statutory retention obligations. Once the purpose and any retention obligation have ended, the data are erased unless they are still required for contract performance or the establishment of a contractual relationship.
9. Requirement to provide personal data
The provision of personal data may be required by law or contract, or may be necessary to enter into a contract. Whether data must be provided and the consequences of not providing them depend on the relevant processing operation and will be explained where applicable. Data that are technically necessary to use a function cannot be omitted if that function is to be used.
10. Automated decision-making
As a responsible company, we do not use automated decision-making or profiling.
This privacy policy was created using the privacy-policy generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, which conducts data protection audits, in cooperation with the law firm WILDE BEUGER SOLMECKE.
TOST app and TOST servers: specific processing
11. Local processing and Tesla retrieval
The TOST app retrieves data from the user's Tesla account at the user's request and generally processes the resulting order, vehicle, task and history data locally on the user's device. The TOST app does not transmit this content to the TOST servers. Tesla is responsible for authentication and retrieval from the Tesla account; Tesla's own privacy information also applies.
12. Combined technical request
The TOST app combines several technically necessary functions in a single request to the TOST servers. These functions include checking for updates, news and notices, updating option codes and checking whether a fetch is permitted. Depending on the request, the selected modules and the technical information required for the relevant update are transmitted.
13. Option codes
To update locally stored option codes, the TOST app transmits the time of the last successful update to the TOST servers. This means that only new or changed entries need to be loaded.
14. Updates
The TOST app transmits its version, the selected update channel and the platform so that suitable updates and security-related updates for the operating system in use can be provided.
15. Fetch authorisation and internal usage statistics
For the technical check whether a fetch is permitted, a pseudonymous identifier, a random request identifier and a timestamp are processed. These data are used for authorisation and protection against misuse. The resulting usage data are used for internal, highly aggregated usage statistics.
16. Optional telemetry
Only with explicit consent does the TOST app transmit additional usage data to the TOST servers. These data include pseudonymised order identifiers, vehicle models, language and country, app version, update channel and usage parameters used during retrieval. They are used for error analysis, quality improvements and prioritising functions that are actually used. Consent may be withdrawn at any time in the app's settings.
17. Recipients, logging and storage period
The TOST servers are operated at Hetzner. Only app-related and operationally necessary information is transmitted to the TOST servers. Tesla-related order and vehicle data remain on the user's device. The transmitted information may include module selection, version and update status, platform, news status, the option-code update time and the pseudonymous identifier used for the fetch check. The transmitted identifiers are pseudonymised and additionally protected on the servers. Standard technical connection data such as IP address, time, user agent and error logs may arise during operation. Pseudonymous fetch data are stored for no more than six months after the last relevant activity. The user-related data are then erased. Non-personal aggregate values may remain for internal statistics.
Update checks are additionally aggregated without user identifiers by UTC day, app version, update channel and platform for internal compatibility and update planning. These statistics are not assigned to individual users.
18. Rocket.Chat
The TOST app offers an optional chat function based on Rocket.Chat. The chat is operated on TOST servers. The live-chat widget embedded on the website and the chat function in the TOST app use the same chat service. If you use the chat, the account data required for registration and sign-in, as well as your chat posts, messages and contact data, are processed. These data are used only to provide and operate the chat function. They are not transmitted to external chat providers. Connection data such as IP address, time and user agent may also be processed for technical communication. The functions offered in the chat and the statutory data-subject rights apply to the content and deletion of your chat account.