PREAMBLE
Effective Date: 01.06.2024
SEAL GROUP UAB (“we,” “us,” “our”) operates the Auto-rent.lt platform, facilitating vehicle rentals between renters and car hosts. We are committed to protecting the privacy of all users. This Privacy Policy explains how we collect, use, share, and protect your personal data.
1. Introduction
This Privacy Policy (hereinafter referred to as the “Policy”) outlines the manner in which Auto-rent.lt processes personal data, ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. The protection and privacy of our users are of utmost importance to us, and we aim to handle your personal data responsibly, transparently, and securely.
This Policy applies to all data subjects interacting with Auto-rent.lt, including:
- Customers and potential customers using our rental services.
- Legal representatives, employees, and authorized persons of our clients or partners.
- Other users accessing or utilizing Auto-rent.lt services, including website visitors and mobile application users.
- Suppliers, business partners, and their employees involved in cooperation with Auto-rent.lt.
- Any other individuals whose personal data is processed in relation to our services.
By using our services, you acknowledge that your personal data will be collected and processed as described in this Policy.
2. Data Processing Principles
Auto-rent.lt is committed to the following GDPR principles:
- Lawfulness, fairness, and transparency – We process data in a legal, fair, and transparent manner.
- Purpose limitation – Data is collected for specified, explicit, and legitimate purposes.
- Data minimization – Only relevant and necessary data is processed.
- Accuracy – We ensure data accuracy and update it when required.
- Storage limitation – Data is stored for no longer than necessary.
- Integrity and confidentiality – Appropriate security measures protect personal data.
3. What Personal Data Do We Collect?
Auto-rent.lt collects different categories of personal data, depending on the type of service you use and the role you have in the platform. Below is an extensive breakdown:
Auto-rent.lt collects and processes personal data from a variety of sources to provide services efficiently and securely. These sources include but are not limited to:
- Direct Data Collection from Users: Personal data is collected when users register on the platform, create an account, book a vehicle, make payments, or communicate with our support teams.
- Automated Data Collection via IoT and GPS Tracking: Our vehicles are equipped with tracking devices and telematics systems that collect real-time location, trip details, driving behavior, and vehicle status.
- Public Registers and Databases: We retrieve driving license information, vehicle registration data, and compliance records from public authorities such as national transportation agencies.
- Law Enforcement and Governmental Authorities: We may receive and process personal data from police departments, municipal traffic authorities, and other government institutions regarding traffic violations, unpaid fines, or accidents.
- Insurance Companies and Legal Entities: Data related to vehicle damage, accident reports, and liability claims may be acquired from insurance providers and legal service providers.
- Financial Institutions and Payment Processors: Payment verification, fraud detection, and chargeback handling may involve data received from financial institutions, credit card providers, and payment gateways.
- Debt Collection Agencies and Credit Rating Companies: If users fail to meet financial obligations, relevant personal data may be shared with debt collection agencies and credit assessment companies.
- Marketing and Advertising Partners: Auto-rent.lt may collaborate with third-party platforms such as Google, Facebook, and marketing agencies to optimize user experience and provide targeted promotions.
- Business Clients (Employer-Based Rentals): In cases where employees use vehicles under a company account, the employer may provide and access trip data and usage statistics.
- User Interactions via Social Media and Customer Support: Information shared by users via social media platforms, chat systems, or emails is processed for communication, dispute resolution, and service improvement.
Identity Verification
Auto-rent.lt employs multiple identity verification methods to ensure security, prevent fraud, and comply with legal regulations. These methods include:
- Standard Document Verification: Users provide a scanned copy of their driver’s license, which is verified through our partner Sum Sub.
- Facial Recognition and Biometric Comparison: In high-risk rentals, users may be required to undergo biometric verification to confirm their identity.
- Continuous Monitoring: Periodic verification checks may be conducted if suspicious activity is detected, such as multiple failed login attempts or unauthorized account sharing.
Automated Decision-Making:
Auto-rent.lt utilizes advanced automated decision-making systems to enhance security, optimize vehicle distribution, and enforce rental policies. Key processes include:
Fraud Prevention Systems: Algorithms detect unusual activities such as multiple payment method changes, rapid location shifts, or excessive account resets.
- Driving Behavior Analysis: IoT sensors monitor acceleration, braking intensity, and speed to assess risk levels and apply appropriate penalties if necessary.
- Vehicle Misuse Detection: Our system flags improper use cases, such as off-road driving, excessive mileage, or unauthorized vehicle relocation.
- Account Suspension and Restrictions: Users engaging in repeated violations may be automatically flagged for suspension.
- Credit Scoring for Payment Plans: Automated evaluations determine user eligibility for deferred payment options.
- Geofencing Enforcement: Unauthorized entry into restricted zones triggers automated notifications and potential fines.
- AI-Based Pricing Optimization: Vehicle demand and availability analytics are used to adjust rental pricing dynamically.
- Violation Reporting System: If authorities report incidents involving our vehicles, our automated systems flag the user’s account for review.
- Customer Risk Assessment: Data analytics categorize users into different risk tiers based on rental history and behavioral patterns.
- Custom Recommendations and Offers: Personalization algorithms suggest discounts or preferred vehicles based on past rentals.
Users have the right to contest automated decisions by requesting manual review through our customer support channels.
GPS and Vehicle Tracking Policy
The Auto-rent.lt fleet is equipped with advanced GPS tracking and telematics systems to ensure operational security and service efficiency. Data collected through GPS includes:
- Real-Time Vehicle Location: Necessary for rental tracking, theft prevention, and customer support.
- Trip History and Navigation Details: Start and end points, route taken, and estimated travel time.
- Speed Monitoring: Helps enforce legal speed limits and prevent reckless driving.
- Accident Detection and Incident Response: Sensors detect sudden impacts, hard braking, and abnormal movements.
- Parking Compliance Verification: Ensures that vehicles are returned to designated zones.
- Unauthorized Usage Alerts: Notifies users if a vehicle is used beyond contractual terms.
- Insurance and Liability Purposes: Provides data for claims processing and dispute resolution.
- Fleet Management Optimization: Enhances vehicle allocation and maintenance scheduling.
- Geofencing for Restricted Areas: Prevents entry into prohibited regions (e.g., toll roads, private properties).
- Security Investigations: Assists law enforcement in theft or fraud-related cases.
3.1 Data We Collect from Renters
- Personal Identification Data: Name, phone number, email address.
- Payment Information: Credit/debit card details, payment transaction records.
- Driver’s License Data: Hosted by our partner Sum Sub; we access it for verification purposes and in case of accidents or disputes.
- Trip and IoT Data:
- Real-time and historical location data during rental periods.
- Trip details including start and end locations.
- Vehicle telematics data collected through IoT devices, including driving behavior, fuel levels, mileage, speed, and braking habits.
- Login Information: User credentials, account activity, IP address, and device details.
- Website and App Usage: Visit frequency, browsing activity, cookies, and analytics tracking data.
3.2 Data We Collect from Car Hosts
- Personal Identification Data: Name, phone number, email address.
- Vehicle Information: Registration number, insurance details, technical specifications.
- Financial Information: Bank account details for processing rental payouts.
- Rental History: Records of completed rentals, earnings, and customer feedback.
- Limited Trip Data: Hosts receive access to the vehicle’s live location during active rentals and receive a detailed report after the rental is completed.
4. How Do We Use Your Data?
We process personal data only when necessary and for legitimate purposes. Below are the key reasons we collect and use your data:
4.1 For Renters:
- Identity and eligibility verification to confirm that you are legally permitted to rent and drive a vehicle.
- Processing payments and preventing fraud or unauthorized transactions.
- Providing customer support, handling inquiries, and troubleshooting issues.
- Tracking vehicle locations during active rental periods to enhance security and operational efficiency.
- Generating reports for vehicle incidents, insurance claims, and legal compliance.
- Direct Marketing: With your consent, we may send personalized promotions and offers.
4.2 For Car Hosts:
- Managing vehicle rentals, facilitating transactions, and handling payouts.
- Ensuring compliance with safety regulations and operational standards.
- Providing post-rental ride reports, which exclude sensitive renter information unless required by legal authorities.
- Enhancing host security, ensuring vehicles are returned to designated areas, and preventing misuse.
5. Data Sharing and Third Parties
We do not sell personal data. However, we may share data in the following cases:
- With Sum Sub: For driver’s license verification and security screening.
- With Car Hosts: Limited access to the vehicle’s live location and post-rental report.
- With Law Enforcement and Authorities: In case of disputes, fraudulent activities, or when required by law.
- With Payment Processors: To facilitate secure transactions.
- With Insurance Providers: To handle claims and coverage-related processes.
- With Marketing & Analytics Providers: For service improvement, personalization, and advertisements.
6. Data Retention and Security
6.1 How Long Do We Keep Your Data?
We store personal data only as long as necessary for its intended purpose:
- Rental records: Retained for 5 years after last use.
- Payment transaction data: Stored for 10 years for financial auditing and tax compliance.
- Driver’s license data: Stored by Sum Sub, accessed only when needed.
- Vehicle tracking and IoT data: Stored for 2 years for security and operational analysis.
- Rental Records: Stored for five years after the last transaction.
- Payment Transactions: Retained for ten years in compliance with tax laws.
- Driver License Data: Hosted by Sum Sub, with Auto-rent.lt accessing it only when necessary.
- GPS Tracking Logs: Stored for up to twelve months, unless required for disputes.
- Blacklist Entries: Serious violations may result in a ten-year retention period.
- Call and Support Logs: Kept for six months for quality control.
- Email and Chat Correspondence: Retained for two years.
- Video Surveillance Data: If applicable, footage is stored for 30 days in premium vehicles.
- Traffic Violations and Fines: Data related to fines remains on file for up to five years.
- Insurance and Legal Claims: Documents related to disputes are kept as long as legally necessary.
6.2 How Do We Secure Your Data?
We implement strict security measures to protect your personal information:
- Encryption: All sensitive data is encrypted during transmission and storage.
- Access Control: Only authorized personnel can access critical information.
- Anonymization: Where possible, data is anonymized to prevent unauthorized identification.
- Regular Audits: We conduct periodic security audits to ensure compliance with GDPR and industry standards.
7. Your Rights as a Data Subject
You have the right to:
- Access your data through your Auto-rent.lt account.
- Request data deletion if your data is no longer required.
- Modify or correct your data at any time.
- Object to data processing under certain conditions.
- Withdraw consent for marketing or optional data collection.
- File a complaint with the Lithuanian Data Protection Authority.
Requests can be sent to [email protected] or [email protected]
8. Changes to This Policy
We may update this Privacy Policy periodically. Users will be notified of major changes via email or in-app notifications.
For any questions or concerns regarding this Policy, you can contact us at [email protected]
SEAL GROUP UAB
Girulių g. 10-201, LT-12112 Vilnius