Data protection regulations
In the following we, i.e. Carrera Toys GmbH (hereinafter: "Carrera or we"), inform you about the type, scope and purpose of collecting and using your personal data as part of the Carrera Hybrid app (hereinafter: "App"). Personal data is all information that relates to an identified or identifiable natural person. This includes in particular your name, address and email address.
1. For the processing responsible and data protection officer
The person responsible for the app and the person responsible in the sense of data protection law is
Carrera Toys GmbH
Rennbahn Allee 1
5412 Puch / Salzburg
Austria
Managing Director: Stefan Krings
Tel.: +43 662 88921-0
Email: shop@carrera-revell.com
Data protection officer:
Krupna legal
Email: datenschutz@carrera-toys.com
2. Data processing and purpose
Depending on the specific use of the app, personal data is processed for the following purposes. Unless otherwise stated, the legal basis for data processing is Art. 6 Para. 1 S. 1 lit. b GDPR.
2.1. Download of the app
When downloading the app, the necessary information is transmitted to the respective app store, i.e. in particular username, email address and customer number of your account, time of download, payment information and individual device code. We have no influence on this data collection and are not responsible for this. We process this data provided to the extent that is necessary to download the app to your device. This data does not take place by us by us.
2.2. Device and connection data
If your device establishes a connection to our server, your device and connection data will be processed. These are the IP address, date and time of the request, device adjustment number (UDID and comparable device numbers) as well as other device information (operating system and version, manufacturer and model, IMEI, IMSI, mobile phone number, MAC address). The connection data is not used to draw conclusions about the person of the user or merged with data from other data sources, but serve to identify your device, to improve the app and to remedy the error. The legal basis is Art. 6 Para. 1 S. 1 lit. f GDPR. After the respective session or use of the app, the data is anonymized by reducing the IP address at the domain level.
2.3. First registration
To use the app, you must first register. For the removal, you have to enter your email address, your username and password (username and password below: "login data"), accept the terms and conditions and then receive a confirmation link by email. As soon as you click on the link in the email, the registration process is complete. A password must be at least 8 characters long and, preferably, always consist of a combination of upper and lower case letters, numbers and special characters. Trivial words such as "ABC" or keyboard episodes (e.g. "Qwert" or "AsdfGH"), all types of names (e.g. from friends, colleagues, family members, pets), names of cities and buildings, comic signs, car brands, license plates, terms, birth data, telephone numbers, common abbreviations, etc.
The login data can be kept strictly secret. For your own protection, it is prohibited to use passwords that have already been used.
In addition, your IP address and the time of registration are saved by us as part of the removal. This is necessary to ensure the safety of our information technology systems. In this case, the legal basis for the processing of your data is Art. 6 Para. 1 S. 1 lit. f GDPR.
Information that is absolutely necessary for the use of the app are identified as mandatory information. The non -provision of this information means that you cannot complete the registration and not use the app.
2.4. Registration data - regular registration
In order to be able to register in the app in the future after the successful collection (Section 2.3), it is regularly necessary to enter your login data. Your login data will be encrypted to the server and cannot be viewed by third parties. You do not have to re-enter your login data for every use of the app. Instead, your registration data is temporarily stored on the end device by using a refresh token. However, in order to prevent unauthorized use of the app by third parties, we recommend that you log off after use and to re-enter your login data with every use of the app.
2.5. Use of the app and functionality
As part of the use of the app, the following functions are particularly available:
Creation of drivers, vehicles and routes
List of the races (especially time and routes)
Performance measurement
Within the app you have the option of e.g. naming drivers individually. It is not necessary to use real names for using the app.
For the connection between the app and the vehicle, the app needs its approval/justification for the Bluetooth function of your end device. To do this, you will be queried accordingly in the app.
The legal basis for data processing is - insofar as you are asked for approval/authorization - your consent in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR. You are not obliged to give your consent. However, if you do not give your consent, you cannot use the functioning of the app fully. You can revoke your consent in the settings of your end device at any time for the future.
The other processing of your data is based on Art. 6 Para. 1 S. 1 lit. f GDPR.
2.6. Release/authorization to locate
For the full functionality, the app requires its approval/authorization for the location function of your end device. The so-called location access service is required for a data-based Bluetooth connection. The legal basis for data processing is then your consent in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR. You are not obliged to give your consent. However, if you do not give your consent, you cannot use the functioning of the app fully. You can revoke your consent in the settings of your end device at any time for the future.
2.7. Crash reports/error message
If you agree to the transmission of a crash report after a system crash of the app or another technical error, the corresponding information will be transmitted anonymously to the developers of the app for the purpose of evaluation.
3. Links to other websites
The app may contain links to social networks (Facebook or Meta, YouTube). These websites are operated by third parties. If you follow the links, information may be transmitted to these third parties. The purpose and scope of the data collection by the websites of third parties as well as the further processing and use of your data there, as well as your rights and setting options for protecting your privacy, please refer to the respective data protection information of the operators.
4. Recipient / category of recipients of your data
We will only pass on your personal data to third parties or other recipients if this is necessary for the provision of services, have consented you, there is a legal obligation or the transfer of data is permitted on the basis of a different legal basis. If necessary, we have concluded agreements on order processing in accordance with Art. 28 GDPR with the receivers of your data. According to this requirement, for example, we use the hosting services from Amazon Web Services Inc., EMEA Sarl 38 Avenue John F. Kennedy, L-1855, Luxembourg with a data center in Frankfurt am Main.
We only pass on your data to government agencies within the framework of legal obligations or on the basis of an official order or judicial decision.
In addition, your personal data will be transmitted to the following receipt to the following receivables or categories of recipients or can be transmitted:
Companies within the Carrera group of companies in their current or future form (a group of companies consists of a prevailing company and the company dependent on it, see Art. 4 No. 19 GDPR).
Trade partners, sales partners etc.
Employees and freelancers
Service provider (e.g. IT service provider)
Corporate buyer /prospective and /or investors
If necessary, authorities or other government agencies.
5. Data transmission to countries outside the EU
As a rule, we do not transmit your data to recipients outside the EU. However, if it is necessary for our purposes, we will only transmit your data if it is ensured that the recipient of the data guarantees an appropriate level of data protection and does not speak any other interests worthy of protection against data transmission.
6. Duration of the storage of personal data / criteria for determining the duration
Your personal data is saved by Carrera as long as it is necessary for the aforementioned purposes of processing, in the event of an objection, there are no compelling legitimate grounds for Carrera or if there is no other legal basis for data processing in the event of a revocation. In certain cases, e.g. if there is a statutory retention obligation, your personal data will not be deleted directly, but is initially blocked.
7. Security measures to protect your personal data
We protect your data from unauthorized access, loss or destruction through technical and organizational measures. Our security measures are continuously improved according to the technological development. In this context, however, it is important that you operate active update management in order to keep the software up to date on your devices. For example, if you use outdated versions of iOS or Android, some security measures in connection with the app may not be guaranteed.
8. Your rights
As part of the legal requirements, you are generally entitled to Carrera
Confirmation as to whether you are processed by Carrera,
Information about this data and the circumstances of the processing,
Correction, insofar as this data is incorrect,
Deletion if there is no justification and no obligation to store it (anymore),
Restriction of processing in special legally determined cases,
Objection in the case of data processing based on Art. 6 Para. 1 lit. f GDPR and
Transmission of your personal data - as far as you have provided it - to you or a third party in a structured, common and machine -readable format.
Insofar as the processing of your personal data is based on your consent, you have the right to revoke your consent at any time, with the result that the processing of your personal data for the future will become inadmissible. However, this does not affect the legality of the processing due to the consent until the revocation. Please note the settings on your end device.
Please send your specific request in writing or by email with the clear identification option of your person to the:
Carrera Toys GmbH
Rennbahn Allee 1
5412 Puch / Salzburg
Austria
Email: datenschutz@carrera-toys.com
Finally, we would like to inform you of your right to complain to the supervisory authority (Austrian data protection authority, Wickenburggasse 8, 1080 Vienna, dsb@dsb.gv.at).
9. No automated individual decision
We do not use your personal data for automated individual decisions.
10. Change of data protection regulations
New legal requirements, business decisions or technical developments may require changes to our data protection regulations. The data protection regulations are then adjusted accordingly. You can always find the current version in the app.