Data protection provisions
We, d.h
1. Controller and data protection officer
The controller responsible for the app and the controller within the meaning of data protection law is
Rennbahn Allee 1
5412 Puch/Salzburg
Austria
Managing Director: Stefan Krings
Tel.: +43 662 88921-0
Email: shop@carrera-revell.com
Data Protection Officer:
krupna LEGAL
Email: datenschutz@carrera-toys.com
2. Data processing and purpose
Depending on the specific use of the app, personal data is processed for the purposes listed below. Unless otherwise stated, the legal basis for data processing is Art. 6 para. 1 sentence 1 lit. b GDPR.
2.1 Downloading the app
When the app is downloaded, the necessary information is transmitted to the respective app store, d.hin particular user name, email address and customer number of your account, time of download, payment information and individual device codes. We have no influence on this data collection and are not responsible for it. We process the data provided to the extent necessary to download the app to your device. We do not store this data beyond this.
2.2. Device and connection data
When your device establishes a connection with our server, your device and connection data are processed. This includes the IP address, date and time of the request, device identification number (UDID and comparable device numbers) and other device information (operating system and version, manufacturer and model, IMEI, IMSI, mobile phone number, MAC address). The connection data is not used to draw conclusions about the person of the user or merged with data from other data sources, but is used to identify your device, improve the app and rectify errors. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. After the respective session or use of the app, the data is anonymized by shortening the IP address at domain level.
2.3 First-time registration
To use the app, you must first register. For the initial registration, you must enter your e-mail address, your user name and a password (user name and password hereinafter: "login data"), accept the GTC and then receive a confirmation link by e-mail. As soon as you click on the link in the e-mail, the registration process is complete. A password must be at least 8 characters long and preferably always consist of a combination of upper and lower case letters, numbers and special characters. Trivial words such as "ABC" or keyboard sequences (z.B. "qwert" or "asdfgh"), all kinds of names (z.B. of friends, colleagues, family members, pets), names of cities and buildings, comic characters, car brands, license plates, terms, dates of birth, telephone numbers, common abbreviations, etc. are problematic.
The login data must be kept strictly secret. For your own protection, it is forbidden to reuse previously used passwords.
In addition, your IP address and the time of registration are stored by us as part of the initial registration process. This is necessary to ensure the security of our information technology systems. The legal basis for the processing of your data in this case is Art. 6 para. 1 sentence 1 lit. f GDPR.
Details that are mandatory for the use of the app are marked as mandatory information. Failure to provide this information will mean that you will not be able to complete the registration and use the app.
2.4 Login data - regular login
In order to be able to log in to the app in the future after successful initial registration (section 2.3), it is regularly necessary to enter your login data. Your login data is transmitted to the server in encrypted form and cannot be viewed by third parties. You do not have to re-enter your login details every time you use the app. Instead, your login data is temporarily stored on the end device by using a refresh token. However, to prevent unauthorized use of the app by third parties, we recommend that you log out after use and re-enter your login data each time you use the app.
2.5. Use of the app and how it works
The following functions are available to you in particular when using the app:
Creating drivers, vehicles and routes
Listing races (in particular time and routes)
Performance measurement
Within the app, you have the option of z.B. Name drivers individually. It is not necessary to use real names to use the app.
For the connection between the app and the vehicle, the app requires your approval/authorization for the Bluetooth function of your end device. You will be asked accordingly in the app.
The legal basis for data processing - insofar as you are asked for approval/authorization - is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. You are not obliged to give your consent. However, if you do not give your consent, you will not be able to use the full functionality of the app. You can revoke your consent for the future at any time in the settings of your end device or allow it again.
The other processing of your data is based on Art. 6 para. 1 sentence 1 lit. f GDPR.
2.6. Release/authorization for the location function
For full functionality, the app requires your release/authorization for the location function of your end device. The so-called Location Access Service is required for a data-based Bluetooth connection. The legal basis for data processing is then your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. You are not obliged to give your consent. However, if you do not give your consent, you will not be able to use the full functionality of the app. You can revoke your consent for the future at any time in the settings of your end device or allow it again.
2.7 Crash reports/error messages
If you agree to the transmission of a crash report after a system crash of the app or another technical error, the corresponding information will be transmitted anonymously to the developers of the app for the purpose of evaluation.
3. links to other websites
The app may contain links to social networks (Facebook or Meta, YouTube). These websites are operated by third parties. If you follow the links, information may be transmitted to these third parties. For the purpose and scope of data collection by the third-party websites and the further processing and use of your data there, as well as your rights in this regard and setting options for protecting your privacy, please refer to the respective data protection notices of the operators.
4. Recipients/categories of recipients of your data
We only pass on your personal data to third parties or other recipients if this is necessary for the provision of services, if you have consented, if there is a legal obligation or if the transfer of data is permitted on another legal basis. Where necessary, we have concluded data processing agreements with the recipients of your data in accordance with Art. 28 GDPR. In accordance with this requirement, we use, for example, the hosting services of Amazon Web Services Inc, EMEA SARL 38 avenue John F. Kennedy, L-1855, Luxembourg with a data center in Frankfurt am Main.
We only disclose your data to government agencies within the scope of legal obligations or on the basis of an official order or court decision.
Furthermore, your personal data will or may be transferred to the following recipients or categories of recipients in accordance with the aforementioned provisions:
companies within the
Trade partners, distribution partners etc.
Employees and freelancers
Service providers (z.B. IT service providers)
company buyers/prospective buyers and/or investors
possibly authorities or other government agencies.
5. Data transfer to countries outside the EU
As a rule, we do not transfer your data to recipients outside the EU. However, if it is necessary for our purposes, we will only transfer your data if it is ensured that the recipient of the data guarantees an adequate level of data protection and no other interests worthy of protection speak against the data transfer.
6. Duration of storage of personal data/criteria for determining the duration
Your personal data will be stored by
7. Security measures to protect your personal data
We protect your data against unauthorized access, loss or destruction through technical and organizational measures. Our security measures are continuously improved in line with technological developments. In this context, however, it is important that you maintain active update management to keep the software on your devices up to date. If you z.B. use outdated versions of iOS or Android, some security measures in connection with the app may not be guaranteed.
8. Your rights
Within the framework of the legal requirements, you have a fundamental right to
confirmation as to whether personal data concerning you is being processed by
information about this data and the circumstances of the processing,
rectification, if this data is incorrect,
deletion if there is no justification for the processing and no obligation to retain it (any longer),
restriction of processing in special cases determined by law,
objection in the case of data processing on the basis of Art. 6 para. 1 lit. f GDPR and
transmission of your personal data - insofar as you have provided it - to you or to a third party in a structured, commonly used and machine-readable format.
If the processing of your personal data is based on your consent, you have the right to withdraw your consent at any time, with the consequence that the processing of your personal data will become inadmissible for the future. However, this does not affect the lawfulness of the processing carried out on the basis of the consent until revocation. Please note the settings on your device.
Please send your specific request in writing or by email, clearly identifying yourself, to:
Rennbahn Allee 1
5412 Puch/Salzburg
Austria
Email:datenschutz@carrera-toys.com
Finally, we would like to draw your attention to your right to lodge a complaint with the supervisory authority (Austrian Data Protection Authority, Wickenburggasse 8, 1080 Vienna,dsb@dsb.gv.at)
9. No automated individual decision-making
We do not use your personal data for automated individual decision-making.
10. Changes to the data protection provisions
New legal requirements, business decisions or technical developments may make it necessary to change our data protection provisions. The data protection provisions will then be adapted accordingly. You will always find the current version in the app.
Weitere Sprachen:
