We work tirelessly to bring our users products and services that are meant to be beautifully designed, intuitive and truly useful. In doing so, we collect information from or about our users without which our products and services would be flawed or non-existent at all.
“Bahub Business Analysis Systems, Lda.” (hereinafter referred to as Bahub) is the controller of personal data processing, which we gather when you are accessing or using Drivit or any other Bahub product or service.Our contact details are as follows:
Address: Bahub Business Analysis Systems, Lda. (Bahub), Avenida António Augusto de Aguiar 24, 2.º Esquerdo, 1050-016 Lisboa
The easiest way to reach our data protection officer is by sending an email to firstname.lastname@example.org or writing us at the address above.
Drivit is enabled by our apps, which can be complemented by the information we collect using: i) a hardware device which plugs into your vehicle (the “OBD adapter”), if you buy one, install it into your car and connect it to one of the Drivit apps, ii) our website. When using Drivit, you provide us with and we collect the following types of personal data:
a. Personally identifiable information
b. Facebook and Google login information
c. Information from your vehicle’s onboard computer
d. Information from your smartphone, including location information
e. Information about the characteristics of your vehicle;
f. Information from our website.
Through your registration process and/or through your account settings, we collect personally identifiable information such as your name/surname and/or e-mail address. We may also collect your car license plate number or vehicle identification number to improve your experience when you use our services, particularly your registering process by automatically providing all the technical specifications of your car. You may also choose to identify some of your common location places (e.g. home, work), which enables us to simplify the display of your common addresses and to give you a summary of relevant information for specific groups of trips (e.g. total monthly cost of the home to work trips).
We may communicate with you through the means you’ve provided, e.g. email, with the main purpose of offering the best customer service and support, and also to keep you updated with important changes and updates to the service. Nevertheless, if at any time you decide that you do not want to receive communications from us, please indicate your preference by unsubscribing from such messages through the “Unsubscribe” link at the bottom of such e-mails. We may also send you alerts through your mobile device if your settings on your mobile device operating system permit such alerts. If you do not wish to receive alerts from us, you have the option to disable them in your settings on your mobile device.
We may give you the option for registering for or logging into the Drivit mobile apps through an external authentication provider (the “Authentication provider”) such as Facebook or Google, using their account login systems. For registering with us using the available Authentication provider in Drivit apps, you will first be redirected to the respective authenticator page where you will be prompted to i) insert your account details, if you are not already logged into the Authentication provider; ii) verify and approve the permissions you may give us by logging with this provider in our apps or services. This link will allow us to view some of the data that you have provided to specific Authentication provider (e.g. account id, name/surname, email address, profile picture) and will be used in accordance to Article 6(1.)(f) of the GDPR. You can revoke these permissions at any time in your Authentication provider account settings by removing our permissions.
To enable some of our Services, e.g. real-time display of vehicle data, we may collect and store information from the vehicle into which you plug a compatible OBD adapter. Examples of the type of information we collect from the vehicle’s onboard computer and sensors include: fuel consumption data, which we present along with the logged trips; and diagnostic trouble codes, which help explain why the vehicle’s check engine light came on.
Examples of the type of information we collect from your smartphone include: location and acceleration data from your smartphone sensors. We use your phone location information to provide you with more information regarding your logged trips. Nevertheless, the collection of this data is solely at your discretion and you can enable or disable location services when you use the App at any time, through your mobile device settings. We could also have access to other identifiable information like your IP address, your smartphone identification code, and the operating system identification code, which we use for bug identification and fixing, security purposes, systems improvements, continuous maintenance and service resilience.
The specification of your vehicle includes details such as the brand, model and manufacturing year of your car. This information is obtained through our app/website, and it may be complemented using third-party services. We collect this information with the main purpose of improving your experience with Drivit and enable the continuous development of additional features.
When you visit our website, we use a common technology called “cookies” to automatically collect information about your use and the equipment that you use to access our site. Cookies are pieces of information that websites send to your computer or other Internet-connected devices to uniquely identify your browser or to store information or settings on your device. Cookies may also be placed by third-party analytics services that we use, such as Google Analytics.
You can choose to opt-out of this by using the “Do Not Track” feature of your browser. Please note, however, that without cookies you may not be able to use all of the features of our site or other websites and online services.
The purposes of processing your data include: i) create your user account; ii) show you your log of trips and present how several key indicators have been evolving over different perspectives (e.g. time, type of trip, trip origin/destination); iii) complement your car’s dashboard by providing real time information of several of your car’s sensors; iv) allow you to do an initial diagnosis of potential problems that your car might have registered; v) search for fuel stations and corresponding fuel prices for a given location area; vi) improve the operation of Drivit and/or develop additional meaningful features and services for your use.
In principle, we process and store each type of personal data solely during the period for which it is necessary for the purposes defined above and to comply with our contractual obligation to you, or if it is necessary for lawful or quality assurance processes. Notwithstanding, apart from i) special statutory provisions; ii) your account registration information (e.g. name, car, email) when your account is still active; we’ve introduced a default personal data retention period of 5 years so that your data isn’t held longer than is necessary.
Bahub employees have supervised access to your information so that we can provide Services to you and help you if you contact us for support. Regarding third parties, rest assured that we do not share your Personal Data with them without your explicit permission, except in the situations provided below:
To provide you with an enhanced user experience, you may choose to share your information with third parties through our App. In these circumstances, we will not share your Personal Data without your explicit permission, usually in the form of a web page, email or app screen where you authorize such sharing of information.
The implementation and provision of certain services may need the transfer of personal data abroad. However, in these cases, legal provisions will be observed, namely provisions assuring that the same level (or higher) of protection of your personal data is followed by the external service providers in these countries.
We certify that our external service providers process your information in a strictly confidential manner and following scrupulously the applicable law and data protection regulations, including the GDPR.
We do not, and never intend to, sell any of your personal data to any third-party.
As a user of Drivit, and under the applicable laws, you have a series of rights that allow you to decide and control at any time what personal data we collect and how we use it. These rights can be exercised at any time and for free, unless they are used in an abusive or unreasonable manner (e.g. multiple right exercise requests when a right has already been exercised before and no material changes have happened since). To exercise your rights, you can do it using the functionalities provided in our account settings or, when not possible, through contacting us via the email email@example.com. In order for us to identify you properly, you should facilitate a copy of an identification document and explicitly state the right you wish to exercise.
In particular, you have the following rights:
a. Right to access – you can request that we confirm if we are or not using your personal data; if we are indeed using them, we will also indicate which personal data we have about you, to which purposes we are using them, the entities to whom we are sharing them, the period for which your data will be stored, if we are using them for profiling or automatic decision making, among others.
b. Right to rectification – You can ask us to change some of your personal data for them to be accurate and up-to-date. In fact, we strongly advise keeping your personal data updated. Shall you have any issues updating your data, do not hesitate to contact us and we will promptly update it.
c. Right to erasure (“right to be forgotten”) – This right will automatically be exercised if the personal data in question is no longer needed for the purpose that we stated that we collected it for, or in the case when you explicitly ask us for your personal data to be deleted.
d. Right to restrict processing – You can request a temporary restriction on the usage of your personal data (you should be advised that, meanwhile, we may not be able to provide you our services in full) i) if you consider your data is inaccurate, and until it is verified or update, ii) if your personal data is no longer used for the intent it has collected for, but you wish to keep it to sustain any complaints and or defend yourself, iii) if you oppose the use of your personal data for a specific purpose and we evaluate the matter.
e. Right to data portability – You can ask us to deliver you, or to a specified authority, whenever technically possible and reasonable, a structured file of common use with a readable content by means of the use of a safe and secure IT system. The file will include personal data like trips/location data, personally identifiable information that we have collected in the scope of our service.
f. Right to complain – If you believe that any of your rights are not being fully met it is of our greatest interest to correct this situation without undue and to report it to the competent authorities, for that purpose you can contact us at firstname.lastname@example.org. It is also your right to lodge a complaint to the competent supervisory authority.
g. Right to object – You can oppose the processing of your personal data for any of the purposes defined in clause 2 or if you do not agree with any of the points in clause 4.
We have taken appropriate technical and organizational measures to guarantee data security, in particular, to protect your personal data against access by third parties, as well as accidental or intentional modification, loss or destruction. Such measures are reviewed periodically and adapted in line with the state of the art. The transfer of your personal data from your terminal equipment (e.g. smartphone) to us is always encrypted.
Your account is protected by a password for your privacy and security. If you access your account via a third-party site or service, you may have additional or different sign-on protections via that third-party site or service. You must prevent unauthorized access to your account and Personal Information by selecting and protecting your password and/or other sign-on mechanisms appropriately and limiting access to your computer or device. In case you connect Drivit to your car, we make use of a compatible OBD adapter of your choice. This flexibility means that you can choose the most suitable adapter based on your needs (e.g. price, connection protocol, standby’s current consumption). Nonetheless, as the choice of a security compliant device is out of our reach, we cannot guarantee the security of the connection between the vehicle ECU and the smartphone via the OBD adapter. Therefore, we deeply encourage you to choose a device which offers a secure, password protected connection with your smartphone.
Last Updated: 24-05-2018