Politique de confidentialité
Version : « décembre 2024 »
Protection générale des données
Chez Shiftmove, nous attachons une grande importance à la protection de votre vie privée et nous nous engageons à protéger vos données personnelles et à vous informer précisément comment et à quelles fins vos données sont traitées. Ces informations s'appliquent aux contextes de traitement suivants :
A. Site Web : Informations sur toutes les opérations de traitement des données effectuées dans le cadre du fonctionnement ou de l'utilisation de nos sites Web.
B. Utilisation d'applications logicielles : Informations sur le traitement des données dans nos applications logicielles, à la fois au format Web et mobile.
C. Contact avec les clients professionnels: Comment nous traitons et protégeons les données dans le cadre de nos relations commerciales, de nos communications et de nos partenariats.
D. Candidats : Informations sur le traitement des données dans le cadre de votre processus de candidature chez Shiftmove.
Veuillez utiliser les menus déroulants ci-dessous pour accéder aux informations qui vous concernent.
A. Site Web d'information sur la protection des données :
I. Responsable du traitement des données
Le responsable du traitement conformément à l'article 4, paragraphe 7, du RGPD est :
Shiftmove GmbH
Warschauer Straße 57#
10243 Berlin
Adresse électronique : contact@shiftmove.com
Tél. : +49 30 555 79 852
Si vous avez des questions ou des préoccupations concernant le traitement de vos données personnelles ou l'exercice de vos droits, vous pouvez nous contacter en utilisant les coordonnées fournies ici.
II. Responsable de la protection des données
Vous pouvez contacter notre responsable de la protection des données à l'adresse privacy@shiftmove.com ou par courrier à l'adresse ci-dessus avec la mention « Délégué à la protection des données ».
III. Accès à notre site Web
Lorsque vous visitez notre site Web, nous traitons des données personnelles afin de garantir le bon fonctionnement, le fonctionnement et la sécurité de notre site Web. Les données suivantes peuvent être traitées (fichiers journaux) :
- Système d'exploitation et adresse IP actuelle (dernier octet abrégé) de l'appareil avec lequel vous visitez notre site Web
- Navigateur (type, version et paramètres de langue)
- la quantité de données récupérées
- Date et heure de l'accès à l'URL du site Web visité précédemment (référent)
- l'URL de la (sous) page que vous consultez sur le site
- le fournisseur de services Internet du système d'accès
La collecte de fichiers journaux est techniquement nécessaire pour vous présenter notre site Web et pour garantir la stabilité et la sécurité du site Web. C'est également notre intérêt légitime dans le traitement des données. La base juridique est l'article 6, paragraphe 1, phrase 1, lettre f du RGPD. Ce site Web est hébergé par le prestataire de services AMAZON WEB SERVICES, EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg, avec lequel nous avons conclu un accord de traitement des données. Vos données sont traitées dans un centre de données européen et rendues anonymes 24 heures après leur collecte.
IV. Contacter
Vous pouvez utiliser le formulaire fourni ou les informations de contact disponibles pour nous envoyer des demandes de vente et d'assistance et pour nous contacter sur d'autres sujets. Lorsque vous nous contactez via l'un de nos formulaires Web, les données marquées comme champs obligatoires doivent être fournies. Lorsque vous nous contactez, nous pouvons traiter vos nom et prénom, votre adresse e-mail, votre société, votre numéro de téléphone et d'autres informations relatives à votre demande. Les informations obligatoires, sans lesquelles il n'est pas possible de vous contacter, sont signalées par un astérisque. Les données sont traitées sur la base de l'article 6, paragraphe 1, phrase 1, lettre b du RGPD dans le cadre de l'initiation ou de la mise en œuvre de mesures précontractuelles ou du contrat conclu avec vous ou sur la base de notre intérêt légitime à traiter et à répondre à votre autre demande conformément à l'article 6, paragraphe 1, phrase 1, lettre f du RGPD. D'autres informations ne sont pas obligatoires pour établir un contact et sont donc fournies volontairement sur la base de votre consentement conformément à l'article 6, paragraphe 1, phrase 1, lit. a du RGPD. Vos données personnelles seront supprimées - sous réserve des délais de conservation légaux - dès que la finalité du stockage ne s'applique plus, c'est-à-dire que votre demande a été entièrement traitée et qu'aucune autre communication avec vous n'est requise ou demandée par vous.
Demandes de vente sont gérés via notre système interne de gestion des relations clients. Nous travaillons en collaboration avec le prestataire de services salesforce.com Germany GmbH (« Salesforce »), Erika-Mann-Straße 31-37, 80636 Munich, Allemagne. Vos données sont traitées exclusivement dans des centres de données européens. Toutefois, dans le cas de demandes d'assistance, les données peuvent également être transférées par Salesforce aux États-Unis (pays tiers). Nous avons donc conclu un contrat de traitement des commandes avec Salesforce en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Salesforce est certifiée conformément au cadre de confidentialité des données entre l'UE et les États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles.
Demandes d'assistance sont gérés et traités via notre outil de support client interne Zendesk. Nous travaillons avec Zendesk Inc (« Zendesk »), 181 S. Fremont St., San Francisco, CA 94105, États-Unis. Nous avons conclu un contrat de traitement des commandes avec Zendesk en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Zendesk est certifié conformément au cadre de confidentialité des données entre l'UE et les États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles.
V. Logiciels de publicité et d'analyse
1. Centré sur l'utilisateur
Nous utilisons la plateforme de gestion des consentements Usercentrics comme outil de gestion des consentements dans le cadre de l'intégration des activités de marketing et d'analyse sur notre site Web. La plateforme de gestion des consentements collecte des fichiers journaux et des données de consentement à l'aide de JavaScript. Ce JavaScript permet d'informer les utilisateurs de leur consentement à certaines balises sur notre site Web et d'obtenir, de gérer et de documenter ce consentement. Nous traitons les données suivantes : les données relatives aux consentements que vous avez donnés, les données de l'appareil telles que votre adresse IP abrégée et les données de l'agent utilisateur (type de navigateur, type d'appareil, système d'exploitation, données de version du logiciel). La base légale du traitement est notre intérêt légitime à obtenir un consentement correct et conforme à la loi sur notre site Web conformément à l'article 6, paragraphe 1, point c du RGPD, § 25 TDDDG. Le but du traitement des données est d'analyser et de gérer les consentements accordés afin de respecter notre obligation de gérer les consentements conformément au RGPD. L'utilisation d'Usercentrics a pour but de fournir des preuves des consentements accordés et non accordés et de leur gestion. Vos données sont généralement conservées pendant un an et supprimées sous réserve des délais de conservation légaux. Le fournisseur est Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Allemagne. Vos données sont traitées exclusivement sur des serveurs européens. Nous avons conclu un accord de traitement des commandes avec Usercentrics.
2. Plausible
Nous utilisons le service d'analyse Web Plausible Analytics (« Plausible ») pour optimiser en permanence notre site Web, à la fois techniquement et en termes de contenu. Plausible adopte une approche particulièrement respectueuse de la protection des données pour analyser votre visite. À cette fin, Plausible enregistre uniquement les informations transmises à notre serveur Web par votre navigateur lorsque vous accédez au site Web : date et heure de votre visite, titre et URL des pages visitées, liens entrants, pays dans lequel vous vous trouvez et agent utilisateur de votre logiciel de navigation. Plausible n'utilise ni ne stocke de « cookies » sur votre appareil final. Toutes les données personnelles (par exemple votre adresse IP) sont stockées de manière totalement anonyme sous la forme d'un hachage. De plus, Plausible ne permet que l'analyse agrégée des statistiques des visiteurs. Nous ne pouvons pas suivre votre comportement spécifique sur notre site Web de manière individuelle. De cette manière, nous pouvons analyser votre visite sans stocker de données personnelles sous une forme qui pourrait être lue par nous, Plausible ou par des tiers. La base juridique du traitement est notre intérêt légitime à améliorer et à développer notre site Web conformément à l'article 6, paragraphe 1, point f) du RGPD. Vos données personnelles seront supprimées ou rendues anonymes immédiatement après leur collecte. Vous trouverez de plus amples informations sur la protection des données chez Plausible à l'adresse https://plausible.io/data-policy.Plausible est un produit de Plausible Insights OÜ, Västriku tn 2, 50403, Tartu, Estonie. Nous avons conclu un accord de traitement des commandes avec Plausible.
3. Gestionnaire de balises Google
Nous utilisons le service Google Tag Manager fourni par Google of Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Irlande. Google Tag Manager nous permet d'intégrer des scripts et des plug-ins à notre site Web plus rapidement et de manière plus conviviale. Nous avons conclu un contrat de traitement des commandes avec Google. Google Tag Manager est un service auxiliaire qui traite lui-même les données personnelles uniquement à des fins techniquement nécessaires. Le Google Tag Manager assure le chargement d'autres composants, qui peuvent à leur tour collecter des données. Le Google Tag Manager n'accède pas à ces données. La base légale est votre consentement volontaire conformément à l'article 6, paragraphe 1, point a du RGPD. Vous pouvez révoquer votre consentement à tout moment via notre gestion des consentements avec effet pour l'avenir. Les données sont généralement traitées dans l'UE. Cependant, étant donné qu'un transfert de données vers Google aux États-Unis (pays tiers) ne peut être totalement exclu, nous avons conclu un contrat de traitement des commandes avec Google en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Google est certifié conformément au cadre de confidentialité des données entre l'UE et les États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles.
4. Google Analytics
Notre site Web utilise Google Analytics, un service d'analyse Web fourni par Google, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irlande. Le cookie utilisé à cette fin nous permet d'analyser l'utilisation de notre site Web. Google utilise ces informations en notre nom pour analyser l'utilisation de notre site Web, pour compiler des rapports sur l'activité du site Web et pour nous fournir d'autres services liés à l'activité du site Web et à l'utilisation d'Internet. Les informations générées par le cookie peuvent également être transmises à un serveur de Google LLC aux États-Unis et y être stockées. Sur notre site Web, Google Analytics a donc été étendu par le code « anonymizeIP » afin de garantir une collecte anonyme des adresses IP (ce que l'on appelle le masquage IP). Cela signifie que l'adresse IP de l'utilisateur est d'abord tronquée par Google dans les États membres de l'Union européenne ou dans d'autres États signataires de l'Accord sur l'Espace économique européen. Ce n'est que dans des cas exceptionnels que l'adresse IP complète sera transmise à un serveur de Google aux États-Unis (pays tiers) et y sera tronquée. L'adresse IP transmise par le navigateur utilisé dans le cadre de Google Analytics n'est pas fusionnée avec d'autres données de Google. Nous avons conclu un contrat de traitement des commandes avec Google en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Google est certifié conformément au cadre de confidentialité des données UE-États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles. La base juridique de l'utilisation de Google Analytics est votre consentement conformément à l'article 25 (1) phrase 1 TDDDG, article 6 (1) phrase 1 lit. a RGPD, que vous pouvez donner via la bannière des cookies et également révoquer à tout moment sans donner de raisons avec effet pour l'avenir dans la gestion des cookies. Les données personnelles traitées par Google Analytics sont stockées pendant 14 mois, puis supprimées automatiquement.
5 Microsoft Clarity
Nous utilisons le service Microsoft Clarity sur notre site Web pour analyser statistiquement l'utilisation de notre site Web. Le fournisseur est Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Irlande. Clarity propose des fonctions telles que des cartes thermiques, des rediffusions de session et des rapports sur l'utilisation du site Web pour nous aider à mieux comprendre le comportement des utilisateurs et à optimiser notre site Web. Microsoft Clarity utilise des cookies, qui nous permettent d'analyser l'utilisation de notre site Web, ainsi qu'un code de suivi, qui est exécuté lorsque ce service est appelé. Les informations collectées, telles que l'adresse IP, la localisation, l'heure ou la fréquence des visites sur notre site Web, sont transmises à Microsoft et y sont stockées. Les données sont utilisées pour créer des statistiques d'utilisation anonymes. Nous utilisons Microsoft Clarity avec la fonction dite d'anonymisation. Cette fonction permet à Microsoft de tronquer l'adresse IP au sein de l'UE ou de l'EEE. La base juridique de l'utilisation de Microsoft Clarity est votre consentement conformément au § 25, paragraphe 1, phrase 1, du TDDDG, à l'article 6, paragraphe 1, phrase 1, point a du RGPD, que vous pouvez donner via la bannière des cookies et également révoquer à tout moment sans donner de raisons avec effet pour l'avenir dans la gestion des cookies.Les données sont généralement traitées dans l'UE. Cependant, étant donné qu'un transfert de données vers Microsoft Inc. aux États-Unis (pays tiers) ne peut être totalement exclu, nous avons conclu un contrat de traitement des commandes avec Microsoft en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Microsoft est certifié conformément au cadre de confidentialité des données UE-États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles.
VI. Période de stockage
Sauf indication contraire dans les descriptions des différentes activités de traitement, nous traitons généralement vos données aussi longtemps que nécessaire pour atteindre l'objectif du traitement. Nous supprimons vos données conformément aux délais de conservation légaux (conservation jusqu'à 10 ans, le cas échéant) dès que la finalité du traitement ne s'applique plus ou que cela est exigé par la loi, par exemple lorsque vous retirez votre consentement.
VII. Transferts internationaux de données
Vos données ne seront transférées à des destinataires situés dans des pays extérieurs à l'Union européenne ou à l'Espace économique européen que dans la mesure où les exigences légales garantissent un niveau adéquat de protection des données conformément aux articles 45 et suivants. Le RGPD est respecté. Un transfert n'aura lieu que s'il existe une décision d'adéquation de la Commission européenne pour le pays tiers en question, si un niveau adéquat de protection des données peut être garanti entre l'importateur et l'exportateur de données par le biais de clauses contractuelles types de la Commission européenne et de mesures de sécurité supplémentaires correspondantes, ou s'il existe d'autres exigences légalement reconnues pour le transfert international de données vers des pays tiers. Si une activité de traitement implique un transfert, un accès ou même une possibilité potentielle de divulgation, les destinataires et les garanties pertinentes pour le transfert sont spécifiquement nommés.
VIII. Vos droits
Vous avez le droit de demander la confirmation que nous traitons les données personnelles vous concernant. Si tel est le cas, nous serons heureux de vous fournir des informations sur ces données personnelles et sur les informations énumérées à l'article 15 du RGPD. En outre, vous avez le droit de rectification (article 16 du RGPD), le droit de restreindre le traitement (article 18 du RGPD), le droit à l'effacement (article 17 du RGPD), le droit à la portabilité des données (article 20 du RGPD) et le droit de vous opposer au traitement (article 21 du RGPD) conformément aux exigences légales respectives. Si le traitement est basé sur votre consentement, vous avez le droit de révoquer ce consentement à tout moment (article 7, paragraphe 3 du RGPD) ; la légalité du traitement effectué sur la base du consentement jusqu'à la révocation n'en est pas affectée. Pour exercer vos droits en tant que personne concernée, veuillez contacter privacy@shiftmove.com .Vous avez également le droit de déposer une plainte auprès d'une autorité de surveillance compétente à tout moment si vous estimez que le traitement de vos données personnelles enfreint les règles de protection des données (article 77 du RGPD).
B. Informations sur la protection des données Produits SaaS :
I. Person responsible for data processing
The controller pursuant to Art. 4 (7) GDPR for the processing operations described here:
Shiftmove GmbH
Warschauer Straße 57
10243 Berlin
e-mail: contact@shiftmove.com
Phone: +49 30 555 79 852
In addition, Shiftmove regularly acts as a processor within the meaning of Art. 28 GDPR when providing its products to companies. Information on the data processed in this context is shown separately in this section.If you have any questions or concerns about the processing of your personal data to the extent described here and to exercise your rights, you can contact us using the contact information provided here.
II. Data Protection Officer
You can contact our data protection officer atprivacy@shiftmove.com or by post at the above address with the addition "Data Protection Officer".
III. Avrios
The Avrios fleet management software is only sold to business customers as a processor. You will find information on the processing of data on behalf of the Avrios SaaS application below under 2. processing as a processor. However, Shiftmove also processes data on its own responsibility. Information on this can be found under 1. processing as controller.
1. Processing operations as controller
1.1 Connection data
When you use our products, we process personal data in order to guarantee the smooth, functional and secure operation of our website. The following data may be processed (so-called log files): Operating system and current IP address (last octet shortened) of the end device with which you visit our websiteBrowser (type, version and language setting)the amount of data retrievedDate and time of accessURL of the previously visited website (referrer)URL of the (sub)page that you call up on the websiteInternet service provider of the accessing system The purpose of the processing is to ensure the stable and secure operation of our products. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. This website is hosted by the service provider AMAZON WEB SERVICES, EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg, with whom we have concluded a data processing agreement. Your data is processed in a European data centre and anonymised 24 hours after collection.
1.2 Usercentrics consent management
We use the Usercentrics Consent Management Platform as a consent management tool as part of the integration of marketing and analysis activities within our products. The Consent Management Platform collects log file and consent data using JavaScript. This JavaScript enables users to use their consent to determine which services and data processing take place within our products, to inform them and to obtain, manage and document the corresponding consents. We process the following data: Data on the consents you have givenDevice data such as your truncated IP address and user agent data (browser type, device type, operating system, software version data).The purpose of data processing is to analyse and manage the consents granted in order to comply with our obligation to manage consents in accordance with the GDPR. The use of Usercentrics serves the purpose of providing evidence of granted and non-granted consents and their management.The legal basis for the processing is our legitimate interest in the proper and legally compliant obtaining of consent on our website in accordance with Art. 6 para. 1 lit. c GDPR, § 25 TDDDG.Your data will generally be stored for one year and deleted subject to statutory retention periods. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany. Your data is processed exclusively on European servers. We have concluded an order processing agreement with Usercentrics.
1.3 Planhat
We use the customer relationship management system Planhat to process data to analyse user interactions with our application and user satisfaction with our platform. Planhat uses cookies to collect data for this purpose and stores it on your end device. We process the following data: User identification data (e.g. e-mail addresses, user IDs)Device and browser information (e.g. IP addresses, browser type, operating system),Behavioural and interaction data (e.g. pages visited, clicks, navigation paths)Session data (e.g. session duration, data traffic sources) In addition, pseudonymised and aggregated results on user-friendliness and satisfaction with our application are processed as part of so-called Net Promoter Score ("NPS") surveys.The purpose of the processing is to create aggregated metrics and analyses on the use of our platform and engagement with our application. The data collected is assigned to the customer listed with us within Planthats. The legal basis for the processing is your voluntarily granted consent via our consent management in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. You can revoke your consent to this at any time and with effect for the future via the consent management within the application. The raw data collected is processed for as long as the consent for processing the data exists. The raw personal data will be deleted after 36 months at the latest. However, aggregated analyses and anonymised reports may continue to be stored.For the provision of Planhat we work with Planthat A/B ("Planhat") Malmskillnadsgatan 13, 111 57 Stockholm, Sweden. Your data is processed exclusively on European servers. We have concluded an order processing agreement with Planhat
1.4 Datadog
With the help of the Datadog tool, our developers can collect additional data on the use of our platform for faster troubleshooting and identification of bugs. Datadog uses cookies to collect data for this purpose and stores it on your end device. The following data is processed: User identification data (pseudonymised session ID) Device and browser information (e.g. IP addresses, browser type and version, device type, operating system details)Behavioural and interaction data (e.g. mouse movements, clicks, keystrokes, scrolling behaviour, page visits)Session and performance data (e.g. session duration, timestamps, page load times, network requests and responses)Error and diagnostic data (e.g. JavaScript errors, crash reports, console logs, details on loading resources)Pseudonymised session recordingsThe purpose of the processing is to monitor the performance and stability of our web applications and to analyse user interactions. The aim is to identify errors, improve user-friendliness and diagnose technical problems by collecting session and behavioural data and performance metrics. When using the Session Recording Feeder, no data about your entries within the application is transmitted to Shiftmove. The data is pseudonymised directly on your end device.The legal basis for the processing is your voluntarily granted consent via our consent management in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. You can revoke your consent to this at any time and with effect for the future via the consent management within the application. Session recordings are stored for up to 30 days and then automatically deleted. The raw data collected is processed for as long as the consent for processing the data exists. The raw personal data is deleted after 36 months at the latest. However, aggregated analyses and anonymised reports may continue to be stored.For the provision of Datadog, we work with Datadog, Inc. 620 8th Ave Fl 45New York, NY 10018, USA. Data processing generally takes place on servers within the European Union. In the event that a transfer or access to the data, for example in the case of a support enquiry, cannot be ruled out, the following guarantees ensure an appropriate level of data protection in accordance with legal requirements. Datadog is certified under the EU-US Data Privacy Framework and the adequacy decision of the EU Commission therefore applies to transfers of personal data. We have concluded an order processing agreement with Datadog using the necessary standard data protection clauses and have established an appropriate level of data protection through additional security measures.
1.4 Segment
We use the Segment service to verify and monitor usage licences. We collect the following data for this purpose:Identification data such as e-mail address, User ID, Customer numberPseudonyms, such as session IDs or other device-specific identifiersTechnical data such as IP address, browser type and version, device type (e.g. smartphone, desktop), operating system and version, Interaction and usage data such as page views, interactions with functions such as adding vehicles or drivers with respective time stampsThe purpose of the processing is to ensure that customers comply with the agreement of the corresponding service contract and to start automated processes for contract adjustment in the event of under- or over-utilisation of our platform.The legal basis for processing is our legitimate interest in the contractual provision of our services and monitoring the use of our software in accordance with our terms and conditions.We work together with Twilio, 101 Spear St FL 5 San Francisco, CA 94105, USA, to provide Segment. Data processing generally takes place on servers within the European Union. In the event that transmission or access to the data, for example in the case of a support enquiry, cannot be ruled out, the following guarantees ensure an appropriate level of data protection in accordance with legal requirements. Twilio is certified under the EU-US Data Privacy Framework and the adequacy decision of the EU Commission therefore applies to transfers of personal data. We have concluded an order processing contract with Datadog using the necessary standard data protection clauses and have established an appropriate level of data protection through additional security measures.
1.5 Bugsnag
Bugsnag is an error monitoring tool that identifies and analyses software errors (so-called bugs) in applications in order to improve stability and performance. It is used by developers to fix problems faster and ensure higher software quality.The following technical data is processed:IP addresses Device informationOperating systemBrowser typeSession details (website accessed, date and time of page views)Log files and information on user interactions that led to an error The purpose of processing is to detect software errors, analyse their causes and improve the stability of the application. In addition, performance problems are identified and usage patterns are analysed to ensure the user-friendliness of the software. Bugsnag thus contributes to the continuous improvement of the software and customer satisfaction.The legal basis for the processing of the data is Art. 6 para. 1 lit. f GDPR (legitimate interest), as error monitoring represents a legitimate interest of the controller in order to ensure a stable and functional application. If Bugsnag is used in connection with contractual obligations, the processing is also based on Art. 6 para. 1 lit. b GDPR.The data is stored for as long as is necessary to analyse and rectify errors and then deleted or anonymised, depending on the contractual agreement with Smartbear Software, Inc.
1.6 Contact
You can use the form provided or the available contact information to send us sales and support enquiries and to contact us on other topics. When contacting us via one of our web forms, the data marked as mandatory fields must be provided. We regularly process the following data when you contact us:First names and surnamesE-mail addressThe companyTelephone numberMessage content and further information about your requestConnection and device dataprocess. The mandatory information, without which contact is not possible, is marked with an asterisk. The data is processed on the basis of Art. 6 para. 1 sentence 1 lit. b GDPR in the context of the initiation or implementation of pre-contractual measures or the contract with you or on the basis of our legitimate interest in processing and responding to your other concerns in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. Further information is not mandatory for establishing contact and is therefore provided voluntarily on the basis of your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR. Your personal data will be deleted - subject to statutory retention periods - as soon as the purpose of storage no longer applies, i.e. your request has been fully processed and no further communication with you is required or requested by you.
Sales enquiries are managed via our internal customer relations management system. We work together with the service provider salesforce.com Germany GmbH ("Salesfroce"), Erika-Mann-Straße 31-37, 80636 Munich, Germany. Your data is processed exclusively in European data centres. However, in the case of support requests, data may also be transferred by Salesforce to the USA (third country). We have therefore concluded an order processing contract with Salesforce using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Salesforce is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
Support requests are managed and processed via our internal customer support tool Zendesk. We work with Zendesk Inc ("Zendesk"), 181 S. Fremont St., San Francisco, CA 94105, USA. Your data is processed exclusively in European data centres. However, in the case of support requests, data may also be transferred by Zendesk to the USA (third country). We have concluded an order processing contract with Zendesk using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Zendesk is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
Live chat within the application allows you to contact our employees directly via the chat window provided for questions. We work with Intercom Inc ("Intercom") 55 2nd Street, Suite 400, San Francisco, CA 94105, USA, to provide the chat function. The legal basis for the use of the live chat feature is your voluntarily given consent. The legal basis for the processing is your voluntarily granted consent via our consent management in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Art. 25 para. 1 TDDD. § 25 para. 1 TDDDG. You can revoke your consent to this at any time and with effect for the future via the consent management within the application. Your data is processed exclusively in European data centres. However, in the case of support requests, data may also be transferred by Intercom to the USA (third country). We have therefore concluded an order processing contract with Intercom using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Intercom is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
1.7 Market research and surveys
As part of the use of our applications, we conduct quantitative and qualitative surveys and interviews from time to time. Your personal data is processed as part of these interviews. This includes Name, e-mail address, IP address, communication data and content, survey responses, video and audio recordingsThe processing serves the purpose of measuring the satisfaction of our customers and further developing our products. The legal basis for the processing of the data is your voluntarily granted consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time with effect for the future. As part of the surveys, you can also voluntarily consent to the recording of interviews. The data will be stored for as long as is necessary for the processing purpose or until you withdraw your consent. Recordings of interviews are stored for up to 3 years and then deleted if you do not withdraw your consent beforehand.To optimise appointment bookings, we use the Calendly tool provided by Calendly LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA. We have concluded an order processing contract with Calendly using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Calendly is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
2. Processing within the scope as a Processor
Shifftmove provides the Avrios product as a processor. A processor is anyone who processes data for external purposes in accordance with the instructions of the controller. The data controllers responsible for the use of the Avrios application under data protection law are our customers. They determine the purposes and legal bases of processing and are also responsible for fulfilling requests from data subjects. In the following, we would like to provide you with the information that can be determined with certainty about the processing from the position as processor.
2.1 Categories of data processed:
The following categories of personal data are processed as part of the provision and use of our software:
- Tasks and comments
- Fine notice information (addressee, amount, photos)
- Vehicle information (CO2 emissions, damage reports, licence plate number, chassis number, mileage)
- Photos (driving licence photos and portrait photos)
- Driving licence informationContact information (telephone number, fax number, mobile phone number, e-mail address)
- Communication histories (notifications, e-mail histories with suppliers, service providers, insurance companies, etc.)
- Personal master data (first name, surname, password, address, gender, date and place of birth, language, nationality, residence authorisation, marital status, information on relatives, date of entry and date of departure of employees, information collected in self-administered fields by customers)
- Company management data (internal ID, cost centre, organisation, department, location, sector and sub-sector, reporting structure)
- Information on salary planning (fringe benefits relating to company cars),
- service specifications and associated information (entitlement to company car and class of company car)
- Fuel card information (provider, costs, date, product)
- Accident prevention regulation test results
- Device data and IT usage data.
2.2 Purposes of data processing:
Below you will find a list of the purposes of processing, insofar as they are determined by Shiftmove. Please note that the ultimate purposes of use are determined by the controller under data protection law:
Provision of the Application: Shiftmove will regularly process the following data as part of the provision of the Application: Personal master data, communication data, device data and IT usage data.
Driving licence check: Shiftmove processes the following data to carry out the driving licence check: Personnel master data, communication data, photos (driving licence photos and portrait photos), driving licence information, device data and IT usage data. Drivers can be informed by email or text message when their driving licence is due to be checked. Driving licences are checked by digital visual inspection. All transmitted photos of the driving licence are deleted by the checking user immediately after the driving licence check has been completed. Only the information required for proof of the check is retained. For further information, please contact your responsible colleague at Shiftmove.
Fine management: Shiftmove processes the following data for the management of fines by the Avrios product: Personnel master data, communication data, fine notice information, device data and IT usage data. Customers can upload, document and delete fines themselves in the product.
UVV checks: Shiftmove processes the following data in order to provide training on accident prevention regulations ("UVV"): Personnel master data, communication data, UVV test results, device data and IT usage data. Drivers can be informed of upcoming driving licence checks by email or text message. Fleet managers and authorised users can only see whether a test has been completed and whether it has been passed or failed. Individual results for questions can only be viewed by the drivers.
Task management: Shiftmove regularly processes the following data as part of mapping internal task management: Tasks and comments, personnel master data, communication data, device data and IT usage data. Please note that the task management forms are free text fields. It is therefore up to the user to control which data is processed within this function.
Fuel card management: Shiftmove processes the following data to provide the function for managing fuel cards and their costs: Personnel master data, communication data, fuel card information, device data and IT usage data. The information is loaded into the application with a delay and, due to the lack of information on the place of payment and use, does not allow the behaviour of drivers to be monitored.
Automated collection of vehicle data (High Mobility): Via Avrios, you can use the automated integration of vehicle data via our provider High Mobility. In this case, the mileage and other vehicle information is automatically synchronised in the Avrios system.
Support: As part of the provision of the service, we regularly process support requests from our users. The following data is processed in this context: Personal master data, communication data, communication histories.
2.3 Recipients of the data processing:
Shiftmove selects its processors with the utmost care and only uses processors that offer sufficient security guarantees.The recipients of the data processing in the context of the provision of the Avrios application as a processor are listed conclusively on the following page: https://www.avrios.com/legal/sub-processors.
2.4 Use of cookies
In the following, we will inform you about the type and purpose of information that we store on your device to provide our software application:
Cookies: Name (storage period): Description
Fusionauth.sso (12 months): Stores the information necessary to process single sign-on opti
Cache for correct display of the language in the login process.
Fusionauth.locale (session duration): Cache for correct display of the language in the login process.
Cache for correct display and storage of the session time in the login process.
Fusionauth.timezone (session duration): Cache for correct display and storage of the session time in the login process.
Fusionauth.remember-device (12 months): Stores the check of the device as a trusted device for login.
Federated.csrf (session duration): This cookie is used to protect against cross-site request forgery (CSRF) attacks during federated logins. CSRF attacks aim to trick users into performing unintended actions on a website they are currently logged in to.
app.at (Access Token) (12 months): Stores the user's access credentials for authentication to the server. Required for the correct assignment of rights within the Avrios system.
app.idt (ID Token) (12 months): ID token containing the necessary user information to display and identify the user on the client side.
app.at_exp (Access Token Expiration) (1 hour): Stores the duration until the automated expiration of the user session.
app.rt (Refresh Token) (12 months): This is a refresh token. It is used to obtain new access tokens without the user having to log in again.
Local Storage:
pagingLimits: Saves the selected display limits within the application.
Session.active: Saves the verification status of the session.
Account.secure: Stores user and company information to optimize loading times.
ucData: Saves the settings from the cookie banner.
ucString: Saves a unique ID to recognize the settings in the cookie banner.
upgradeBanner: Saves the display of a notice banner in the event of a license violation.
2.5 Storage period
Shiftmove will store the data that is processed as part of order processing for as long as our customers instruct it to do so. This instruction exists for the duration of the contractual relationship between Shiftmove and its customers. Shiftmove shall delete the processed data no later than 30 days after termination of the contract or at the instruction of the controller.
2.6 Security of processing
Shiftmove attaches great importance to the security of the personal data entrusted to it. In accordance with data protection regulations, Shiftmove undertakes to take all necessary precautions to ensure the security of personal data and in particular to protect it against accidental or unlawful destruction, accidental loss, corruption, dissemination or unauthorised access and against any other form of unlawful processing or disclosure to unauthorised persons. A comprehensive list of all technical and organisational measures taken can be found in Appendix 2 of our Data Processing Agreement. On request, our team will also provide you with our IT security white paper, which describes in detail all the IT security measures taken.
2.7 Exercising rights as a data subject
The fulfilment and protection of data subject rights in accordance with Section 3 of the GDPR is generally the duty of the controller, i.e. the customers of Shiftmove. If you are a user or driver within the Avrios application, please contact the company that purchased your Avrios instance to exercise your data subject rights. You have the right to request confirmation as to whether personal data concerning you is being processed by us. If this is the case, we will be happy to provide you with information about this personal data and the information listed in Art. 15 GDPR. In addition, you have the right to rectification (Art. 16 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to erasure (Art. 17 GDPR), the right to data portability (Art. 20 GDPR) and the right to object to processing (Art. 21 GDPR) under the respective legal requirements. If the processing is based on your consent, you have the right to revoke this consent at any time (Art. 7 para. 3 GDPR); the legality of the processing carried out on the basis of the consent until revocation remains unaffected. Shift Move supports its customers in the fulfilment of requests to exercise data subject rights in accordance with the agreements in our Data Processing Agreement. Please get in touch with your responsible contact person at Shiftmove.
IV. Vimcar (Fleet) logbook
The Vimcar logbook is available as an app and web software and, in conjunction with the Vimcar hardware (OBD connector or box), enables journeys to be recorded and subsequently categorised and the trip data to be filed and stored in accordance with tax law. The Vimcar logbook is generally only sold to business customers as a processor. In some cases, however, customers may be directly affected by the Vimcar logbook. In these cases, Shiftmove is considered the controller and you will find the information relevant to you below under 1. Under 2. information, on the other hand, you will find information on processing in the context of order processing for the Vimcar logbook.
1. Processing operations as controller
1.1 Connection data
When you use our products, we process personal data in order to guarantee the smooth, functional and secure operation of our website and app. The following data may be processed (so-called log files): Operating system and current IP address (last octet shortened) of the end device with which you visit our website, browser (type, version and language setting), the amount of data retrieved, date and time of access, the URL of the previously visited website (referrer), the URL of the (sub)page that you access on the website, the Internet service provider of the accessing system The purpose of the processing is to ensure the stable and secure operation of our products. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. This website is hosted by the service provider AMAZON WEB SERVICES, EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg, with whom we have concluded a data processing agreement. Your data is processed in a European data centre and anonymised 24 hours after collection.
1.2 Provision of the application
If Shiftmove is not the processor for the provision of the logbook, we also process your personal data for the provision of our product. We process the following data for this purpose - please note that not all data is relevant for the version or product variant you are using: First name, surnameE-mail address, telephone number, mobile phone numberLogbook dataPosition data during the tourStart and end point of toursKilometres drivenCategorisation of private and business tripsContact and address dataVIN (Vehicle Identification Number)Technical vehicle data (e.g. repair status), photos of vehicles (optional when using claims management)Device data and IT usage dataThe vehicle data is transmitted to Shiftmove in encrypted form via the OBD connector (or similar) provided, processed on our systems and prepared for display in the application. The legal basis for the processing is the fulfilment of the contract for the provision of our product in accordance with your order pursuant to Art. 6 para. 1 lit. b GDPR. We process your data for as long as the contractual relationship with you exists and delete it immediately after the end of the contract, subject to statutory retention periods. We transfer your personal data to various recipients for the provision of the Vimcar logbook. You can find a list of all recipients and the corresponding processing activities here.
1.3 Usercentrics consent management
We use the Usercentrics Consent Management Platform as a consent management tool as part of the integration of marketing and analysis activities within our products. The Consent Management Platform collects log file and consent data using JavaScript. This JavaScript enables users to use their consent to determine which services and data processing take place within our products, to inform them and to obtain, manage and document the corresponding consents. We process the following data: Data relating to your consent, device data such as your abbreviated IP address and user agent data (browser type, device type, operating system, software version data).The purpose of data processing is to analyse and manage the consents granted in order to comply with our obligation to manage consents in accordance with the GDPR. The use of Usercentrics serves the purpose of providing evidence of granted and non-granted consents and their management.The legal basis for the processing is our legitimate interest in the proper and legally compliant obtaining of consent on our website in accordance with Art. 6 para. 1 lit. c GDPR, § 25 TDDDG.Your data will generally be stored for one year and deleted subject to statutory retention periods. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany. Your data is processed exclusively on European servers. We have concluded an order processing agreement with Usercentrics.
1.4 Datadog
With the help of the Datadog tool, our developers can collect additional data on the use of our platform for faster troubleshooting and identification of bugs. Datadog uses cookies to collect data for this purpose and stores it on your end device. The following data is processed: User identification data (pseudonymised session ID), device and browser information (e.g. IP addresses, browser type and version, device type, operating system details), behavioural and interaction data (e.g. mouse movements, clicks, keystrokes, scrolling behaviour, page visits), session and performance data (e.g. session duration, timestamps, page load times, network requests and responses), error and diagnostic data (e.g. JavaScript errors, crash reports, console logs, details of page load times, network requests and responses). session duration, timestamps, page load times, network requests and responses), error and diagnostic data (e.g. JavaScript errors, crash reports, console logs, resource loading details), geolocation data (e.g. approximate location derived from IP address)The purpose of the processing is to monitor the performance and stability of our web applications and to analyse user interactions. The aim is to identify errors, improve user-friendliness and diagnose technical problems by collecting session and behavioural data and performance metrics. When using the Session Recording Feeder, no data about your entries within the application is transmitted to Shiftmove. The data is pseudonymised directly on your end device.The legal basis for the processing is your voluntarily granted consent via our consent management in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. You can revoke your consent to this at any time and with effect for the future via the consent management within the application. Session recordings are stored for up to 30 days and then automatically deleted. The raw data collected is processed for as long as the consent for processing the data exists. The raw personal data is deleted after 36 months at the latest. However, aggregated analyses and anonymised reports may continue to be stored.For the provision of Datadog, we work with Datadog, Inc. 620 8th Ave Fl 45New York, NY 10018, USA. Data processing generally takes place on servers within the European Union. In the event that a transfer or access to the data, for example in the case of a support enquiry, cannot be ruled out, the following guarantees ensure an appropriate level of data protection in accordance with legal requirements. Datadog is certified under the EU-US Data Privacy Framework and the adequacy decision of the EU Commission therefore applies to transfers of personal data. We have concluded an order processing contract with Datadog using the necessary standard data protection clauses and have established an appropriate level of data protection through additional security measures.
1.5 Segment
We use the Segment service to verify and monitor usage licences. We collect the following data for this purpose:Identification data such as email address, user ID, customer number, pseudonyms such as session IDs or other device-specific identifiers, technical data such as IP address, browser type and version, device type (e.g. smartphone, desktop), operating system and version, interaction and behavioural data such as page views, interactions with functions such as adding vehicles or drivers with respective time stampsThe purpose of the processing is to ensure that customers comply with the agreement of the corresponding service contract and to start automated processes for contract adjustment in the event of under- or over-utilisation of our platform.The legal basis for processing is our legitimate interest in the contractual provision of our services and monitoring the use of our software in accordance with our terms and conditions.We work together with Twilio, 101 Spear St FL 5 San Francisco, CA 94105, USA, to provide Segment. Data processing generally takes place on servers within the European Union. In the event that transmission or access to the data, for example in the case of a support enquiry, cannot be ruled out, the following guarantees ensure an appropriate level of data protection in accordance with legal requirements. Twilio is certified under the EU-US Data Privacy Framework and the adequacy decision of the EU Commission therefore applies to transfers of personal data. We have concluded an order processing contract with Datadog using the necessary standard data protection clauses and have established an appropriate level of data protection through additional security measures.
1.6 Contact You can use the form provided or the available contact information to send us sales and support enquiries and to contact us on other topics. When contacting us via one of our web forms, the data marked as mandatory fields must be provided. When you contact us, we may process your first and last name, email address, company, telephone number and other information relating to your enquiry. The mandatory information, without which it is not possible to contact you, is marked with an asterisk. The data is processed on the basis of Art. 6 para. 1 sentence 1 lit. b GDPR in the context of the initiation or implementation of pre-contractual measures or the contract with you or on the basis of our legitimate interest in processing and responding to your other request in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. Further information is not mandatory for establishing contact and is therefore provided voluntarily on the basis of your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR. Your personal data will be deleted - subject to statutory retention periods - as soon as the purpose of storage no longer applies, i.e. your request has been fully processed and no further communication with you is required or requested by you.
Sales enquiries are managed via our internal customer relations management system. We work together with the service provider salesforce.com Germany GmbH ("Salesfroce"), Erika-Mann-Straße 31-37, 80636 Munich, Germany. Your data is processed exclusively in European data centres. However, in the case of support requests, data may also be transferred by Salesforce to the USA (third country). We have therefore concluded an order processing contract with Salesforce using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Salesforce is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
Support requests are managed and processed via our internal customer support tool Zendesk. We work with Zendesk Inc ("Zendesk"), 181 S. Fremont St., San Francisco, CA 94105, USA. We have concluded an order processing contract with Zendesk using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Zendesk is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
Live chat within the application allows you to contact our employees directly via the chat window provided for questions. We work with Intercom Inc ("Intercom") 55 2nd Street, Suite 400, San Francisco, CA 94105, USA, to provide the chat function. The legal basis for the use of the live chat feature is your voluntarily given consent. The legal basis for the processing is your voluntarily granted consent via our consent management in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Art. 25 para. 1 TDDD. § 25 para. 1 TDDDG. You can revoke your consent to this at any time and with effect for the future via the consent management within the application. Your data is processed exclusively in European data centres. However, in the case of support requests, data may also be transferred by Intercom to the USA (third country). We have therefore concluded an order processing contract with Intercom using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Intercom is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
1.7 Market research and surveys
As part of the use of our applications, we conduct quantitative and qualitative surveys and interviews from time to time. Your personal data is processed as part of these interviews. This includes Name, e-mail address, IP address, communication data and content, survey responses, video and audio recordingsThe processing serves the purpose of measuring the satisfaction of our customers and further developing our products. In the context of contacting you for this purpose, we process your data based on our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR for the application of existing customers or based on your voluntarily given consent. You can object to being contacted for this purpose at any time and via any communication channel. The legal basis for conducting the surveys is your voluntarily granted consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time with effect for the future. As part of the surveys, you can also voluntarily consent to the recording of interviews. The data will be stored for as long as is necessary for the purpose of processing or until you withdraw your consent. Recordings of interviews are stored for up to 3 years and then deleted if you do not withdraw your consent beforehand.To optimise appointment bookings, we use the Calendly tool provided by Calendly LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA. We have concluded an order processing contract with Calendly using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Calendly is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
2. Processing within the scope as a Processor
In principle, Shifftmove provides the Vimcar (Fleet) logbook as a processor. A processor is anyone who processes data for external purposes in accordance with the instructions of the controller. The data controllers responsible for the use of the Vimcar (Fleet) logbook under data protection law are our customers. They determine the purposes and legal bases of processing and are also responsible for fulfilling requests from data subjects. In the following, we would like to provide you with the information that can be determined with certainty about the processing from the position as processor.
2.1 Categories of data processed:
The following categories of personal data are processed as part of the provision and use of our software:
- First name, surname
- E-mail address,
- telephone number,
- mobile phone number
- Logbook data
- Tour data during the tour
- Start and end point of tours
Kilometres driven
- Categorisation of private and business trips
- Contact and address data
- VIN (Vehicle Identification Number)
- Test parameters for carrying out the automated driving licence check (optional when using the driving licence check)
- Technical vehicle data (e.g. repair status), photos of vehicles (optional when using claims management)
- Device data and IT usage data
2.2 Purposes of data processing:
Below you will find a list of the purposes of processing insofar as they are determined by Shiftmove. Please note that the ultimate purposes of use are determined by the data controller:
Provision of the Application: Shiftmove will regularly process the following data as part of the provision of the Application: Personal master data, communication data, device data and IT usage data. The information is stored for as long as Shiftmove provides the product to the customer and the user accounts are not deleted or their deletion is not requested by the customer.
Route documentation logbook for vehicles: Various vehicle-related data is processed to create the logbook: GPS location data (approx. 20 second interval) with time and date information, voltage data to the OBD connector (or box), vehicle identification number (VIN), classification as business or private journey.
Contact and address management: You can create and manage contacts and addresses within the Vimcar (Fleet) logbook to enable faster allocation within the logbook. The contact's name, address and company are processed for this purpose.
Driving licence check: Shiftmove processes the following data to carry out the driving licence check: Personnel master data, communication data, driving licence information, device data and IT usage data. Drivers can be informed by email about the upcoming driving licence check. Driving licences are checked by our service provider LapID. Only the information required to verify the check is stored.
Support: As part of the provision of the service, we regularly process support requests from our users. The following data is processed in this context: Personal master data, communication data, communication histories.
2.3 Recipients of the data processing:
Shiftmove selects its processors with the utmost care and only uses processors that offer sufficient security guarantees.The recipients of the data processing in the context of the provision of the Vimcar (Fleet) logbook as a processor are listed conclusively on the following page: https://www.vimcar.de/legal/datenschutz/subunternehmer.
2.4 Storage period
Shiftmove will store the data processed as part of the order processing for as long as our customer instructs us to do so. aThis instruction exists for the duration of the contractual relationship between Shiftmove and its customers. Shiftmove deletes the processed data no later than 30 days after termination of the contract or on the instruction of the controller. Please note that logbook data and all the raw data required for this are stored for up to 15 years in accordance with currently applicable statutory retention requirements.
2.5 Security of processing
Shiftmove attaches great importance to the security of the personal data entrusted to it. In accordance with data protection regulations, Shiftmove undertakes to take all necessary precautions to ensure the security of personal data and in particular to protect it against accidental or unlawful destruction, accidental loss, corruption, dissemination or unauthorised access and against any other form of unlawful processing or disclosure to unauthorised persons. A comprehensive list of all technical and organisational measures taken can be found in Appendix 2 of our Data Processing Agreement. On request, our team will also provide you with our IT security white paper, which describes in detail all the IT security measures taken.
2.6 Exercising your rights as a data subject
The fulfilment and protection of data subject rights in accordance with Section 3 of the GDPR is fundamentally the duty of the controller, i.e. the customers of Shiftmove. If you are a user or driver within the Avrios application, please contact the company that purchased your Avrios instance to exercise your data subject rights. You have the right to request confirmation as to whether personal data concerning you is being processed by us. If this is the case, we will be happy to provide you with information about this personal data and the information listed in Art. 15 GDPR. In addition, you have the right to rectification (Art. 16 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to erasure (Art. 17 GDPR), the right to data portability (Art. 20 GDPR) and the right to object to processing (Art. 21 GDPR) under the respective legal requirements. If the processing is based on your consent, you have the right to revoke this consent at any time (Art. 7 para. 3 GDPR); the legality of the processing carried out on the basis of the consent until revocation remains unaffected. Shiftnove supports its customers in the fulfilment of requests to exercise data subject rights in accordance with the agreements in our Data Processing Agreement. Please get in touch with your responsible contact person at Shiftmove.
V. Vimcar Fleet Geo
Vimcar Fleet and Fleet Geo is an application for managing vehicle fleets and live GPS tracking of vehicles via a provided box that is connected to the vehicle. When providing Vimcar Fleet Geo, Shiftmove processes data as an independent controller to improve our products. You will find the relevant information on this under 1. Vimcar Fleet Geo is only sold to business customers as a processor. Under 2. information you will therefore find information on the processing of personal data in the context of order processing for the provision of Vimcar Fleet Geo
1. Processing operations as controller
1.1 Connection data
When you use our products, we process personal data in order to guarantee the smooth, functional and secure operation of our website and app. The following data may be processed (so-called log files): Operating system and current IP address (last octet shortened) of the end device with which you visit our website, browser (type, version and language setting), the amount of data retrieved, date and time of access, the URL of the previously visited website (referrer), the URL of the (sub)page that you access on the website, the Internet service provider of the accessing system The purpose of the processing is to ensure the stable and secure operation of our products. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. This website is hosted by the service provider AMAZON WEB SERVICES, EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg, with whom we have concluded a data processing agreement. Your data is processed in a European data centre and anonymised 24 hours after collection.
1.2 Usercentrics consent management
We use the Usercentrics Consent Management Platform as a consent management tool as part of the integration of marketing and analysis activities within our products. The Consent Management Platform collects log file and consent data using JavaScript. This JavaScript enables users to use their consent to determine which services and data processing take place within our products, to inform them and to obtain, manage and document corresponding consents. We process the following data: Data relating to your consent, device data such as your abbreviated IP address and user agent data (browser type, device type, operating system, software version data).The purpose of data processing is to analyse and manage the consents granted in order to comply with our obligation to manage consents in accordance with the GDPR. The use of Usercentrics serves the purpose of providing evidence of granted and non-granted consents and their management.The legal basis for the processing is our legitimate interest in the proper and legally compliant obtaining of consent on our website in accordance with Art. 6 para. 1 lit. c GDPR, § 25 TDDDG.Your data will generally be stored for one year and deleted subject to statutory retention periods. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany. Your data is processed exclusively on European servers. We have concluded an order processing agreement with Usercentrics.
1.3 Datadog
With the help of the Datadog tool, our developers can collect additional data on the use of our platform for faster troubleshooting and identification of bugs. Datadog uses cookies to collect data for this purpose and stores it on your end device. The following data is processed: User identification data (pseudonymised session ID), device and browser information (e.g. IP addresses, browser type and version, device type, operating system details), behavioural and interaction data (e.g. mouse movements, clicks, keystrokes, scrolling behaviour, page visits), session and performance data (e.g. session duration, timestamps, page load times, network requests and responses), error and diagnostic data (e.g. JavaScript errors, crash reports, console logs, details of page load times, network requests and responses). session duration, timestamps, page load times, network requests and responses), error and diagnostic data (e.g. JavaScript errors, crash reports, console logs, resource loading details), geolocation data (e.g. approximate location derived from IP address)The purpose of the processing is to monitor the performance and stability of our web applications and to analyse user interactions. The aim is to identify errors, improve user-friendliness and diagnose technical problems by collecting session and behavioural data and performance metrics. When using the Session Recording Feeder, no data about your entries within the application is transmitted to Shiftmove. The data is pseudonymised directly on your end device.The legal basis for the processing is your voluntarily granted consent via our consent management in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. You can revoke your consent to this at any time and with effect for the future via the consent management within the application. Session recordings are stored for up to 30 days and then automatically deleted. The raw data collected is processed for as long as the consent for processing the data exists. The raw personal data is deleted after 36 months at the latest. However, aggregated analyses and anonymised reports may continue to be stored.For the provision of Datadog, we work with Datadog, Inc. 620 8th Ave Fl 45New York, NY 10018, USA. Data processing generally takes place on servers within the European Union. In the event that a transfer or access to the data, for example in the case of a support enquiry, cannot be ruled out, the following guarantees ensure an appropriate level of data protection in accordance with legal requirements. Datadog is certified under the EU-US Data Privacy Framework and the adequacy decision of the EU Commission therefore applies to transfers of personal data. We have concluded an order processing contract with Datadog using the necessary standard data protection clauses and have established an appropriate level of data protection through additional security measures.
1.4 Segment
We use the Segment service to verify and monitor usage licences. We collect the following data for this purpose:Identification data such as email address, user ID, customer number, pseudonyms such as session IDs or other device-specific identifiers, technical data such as IP address, browser type and version, device type (e.g. smartphone, desktop), operating system and version, interaction and behavioural data such as page views, interactions with functions such as adding vehicles or drivers with respective time stampsThe purpose of the processing is to ensure that customers comply with the agreement of the corresponding service contract and to start automated processes for contract adjustment in the event of under- or over-utilisation of our platform.The legal basis for processing is our legitimate interest in the contractual provision of our services and monitoring the use of our software in accordance with our terms and conditions.We work together with Twilio, 101 Spear St FL 5 San Francisco, CA 94105, USA, to provide Segment. Data processing generally takes place on servers within the European Union. In the event that transmission or access to the data, for example in the case of a support request, cannot be ruled out, the following guarantees ensure an appropriate level of data protection in accordance with legal requirements. Twilio is certified under the EU-US Data Privacy Framework and the adequacy decision of the EU Commission therefore applies to transfers of personal data. We have concluded an order processing contract with Datadog using the necessary standard data protection clauses and have established an appropriate level of data protection through additional security measures.
1.5 Contact
You can use the form provided or the available contact information to send us sales and support enquiries and to contact us on other topics. When contacting us via one of our web forms, the data marked as mandatory fields must be provided. When you contact us, we may process your first and last name, email address, company, telephone number and other information relating to your enquiry. The mandatory information, without which it is not possible to contact you, is marked with an asterisk. The data is processed on the basis of Art. 6 para. 1 sentence 1 lit. b GDPR in the context of the initiation or implementation of pre-contractual measures or the contract with you or on the basis of our legitimate interest in processing and responding to your other request in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. Further information is not mandatory for establishing contact and is therefore provided voluntarily on the basis of your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR. Your personal data will be deleted - subject to statutory retention periods - as soon as the purpose of storage no longer applies, i.e. your request has been fully processed and no further communication with you is required or requested by you.
Sales enquiries are managed via our internal customer relations management system. We work together with the service provider salesforce.com Germany GmbH ("Salesfroce"), Erika-Mann-Straße 31-37, 80636 Munich, Germany. Your data is processed exclusively in European data centres. However, in the case of support requests, data may also be transferred by Salesforce to the USA (third country). We have therefore concluded an order processing contract with Salesforce using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Salesforce is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
Support requests are managed and processed via our internal customer support tool Zendesk. We work with Zendesk Inc ("Zendesk"), 181 S. Fremont St., San Francisco, CA 94105, USA. We have concluded an order processing contract with Zendesk using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Zendesk is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
Live chat within the application allows you to contact our employees directly via the chat window provided for questions. We work with Intercom Inc ("Intercom") 55 2nd Street, Suite 400, San Francisco, CA 94105, USA, to provide the chat function. The legal basis for the use of the live chat feature is your voluntarily given consent. The legal basis for the processing is your voluntarily granted consent via our consent management in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Art. 25 para. 1 TDDD. § 25 para. 1 TDDDG. You can revoke your consent to this at any time and with effect for the future via the consent management within the application. Your data is processed exclusively in European data centres. However, in the case of support requests, data may also be transferred by Intercom to the USA (third country). We have therefore concluded an order processing contract with Intercom using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Intercom is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
1.6 Market research and surveys
As part of the use of our applications, we conduct quantitative and qualitative surveys and interviews from time to time. Your personal data is processed as part of these interviews. This includes Name, e-mail address, IP address, communication data and content, survey responses, video and audio recordingsThe processing serves the purpose of measuring the satisfaction of our customers and further developing our products. In the context of contacting you for this purpose, we process your data based on our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR for the application of existing customers or based on your voluntarily given consent. You can object to being contacted for this purpose at any time and via any communication channel. The legal basis for conducting the surveys is your voluntarily granted consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time with effect for the future. As part of the surveys, you can also voluntarily consent to the recording of interviews. The data will be stored for as long as is necessary for the processing purpose or until you withdraw your consent. Recordings of interviews are stored for up to 3 years and then deleted if you do not withdraw your consent beforehand.To optimise appointment bookings, we use the Calendly tool provided by Calendly LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA. We have concluded an order processing contract with Calendly using the EU standard contractual clauses. The EU standard contractual clauses are available on the website of the European Commission. In addition, Calendly is certified in accordance with the EU-US Data Privacy Framework. The adequacy decision of the European Commission therefore applies to transfers of personal data.
2. Processing within the scope as a Processor
Shifftmove provides Vimcar Fleet Geo as a processor. A processor is anyone who processes data for external purposes in accordance with the instructions of the controller. The data controllers responsible for the use of Vimcar Fleet Geo under data protection law are our customers. They determine the purposes and legal bases of processing and are also responsible for fulfilling requests from data subjects. In the following, we would like to provide you with the information that can be determined with certainty about the processing from the position as processor.
2.1 Categories of data processed:
The following categories of personal data are processed as part of the provision and use of our software:
- First name, surname
- E-mail address,
- telephone number,
- mobile phone number
- Logbook data
- Tour data during the tour
- Live localisation and tour documentation
- Vehicle information (VIN (Vehicle Identification Number), licence plate number, model, year of manufacture)
- Test parameters for carrying out the automated driving licence check (optional when using the driving licence check)
- Technical vehicle data (e.g. repair status), photos of vehicles (optional when using claims management)
- Fuel card information (provider, costs, date, product)
- Vehicle bookings (date, vehicle, duration, driver)
- Device data and IT usage data
2.2 Purposes of data processing:
Below you will find a list of the purposes of processing insofar as they are determined by Shiftmove. Please note that the ultimate purposes of use are determined by the controller under data protection law:
Provision of the Application: Shiftmove will regularly process the following data as part of the provision of the Application: Personal master data, communication data, device data and IT usage data. The information is stored for as long as Shiftmove provides the product to the customer and the user accounts are not deleted or their deletion is not requested by the customer.
Live GPS route documentation of vehicles: Various vehicle-related data is processed for the live GPS route documentation: GPS location data (approx. 20 second interval) with time and date, voltage data to the OBD connector (or box), vehicle identification number (VIN). Depending on the settings within the system, customers can automatically delete the recorded route documentation and GPS data at regular intervals.
Task management: Shiftmove regularly processes the following data as part of mapping internal task management: Tasks and comments, personnel master data, communication data, device data and IT usage data. Please note that the task management forms are free text fields. It is therefore up to the user to control which data is processed within this function.
Warning messages: You can set up alerts for vehicles within the applications. Alerts notify the fleet manager if a vehicle leaves or stays in a previously defined area. The alerts can also be defined for specific periods and days. GPS location data, vehicle data, areas and warning periods are processed for this purpose.
Fuel card management: Shiftmove processes the following data to provide the function for managing fuel cards and their costs: Personnel master data, communication data, fuel card information, device data and IT usage data. The information is loaded into the application with a delay and, due to the lack of information on the place of payment and use, does not allow the behaviour of drivers to be monitored.
Driving licence check: Shiftmove processes the following data to carry out the driving licence check: Personnel master data, communication data, driving licence information, device data and IT usage data. Drivers can be informed by email about the upcoming driving licence check. Driving licences are checked by our service provider LapID. Only the information required to verify the check is stored.
Support: As part of the provision of the service, we regularly process support requests from our users. The following data is processed in this context: Personal master data, communication data, communication histories.
2.3 Recipients of the data processing:
Shiftmove selects its processors with the utmost care and only uses processors that offer sufficient security guarantees.The recipients of the data processing in the context of the provision of Vimcar Fleet Geo as a processor are listed conclusively on the following page: https://www.vimcar.de/legal/datenschutz/subunternehmer.
2.4 Storage period
Shiftmove will store the data that is processed as part of order processing for as long as our customers instruct it to do so. This instruction exists for the duration of the contractual relationship between Shiftmove and its customers. Shiftmove shall delete the processed data no later than 30 days after termination of the contract or at the instruction of the controller. During the introduction of Fleet Geo, customers can specify the storage duration of the route documentation. This specifies after how many months the route documentation should be automatically deleted. The setting can be changed at any time by your contact person at Vimcar.
2.5 Security of processing
Shiftmove attaches great importance to the security of the personal data entrusted to it. In accordance with data protection regulations, Shiftmove undertakes to take all necessary precautions to ensure the security of personal data and in particular to protect it against accidental or unlawful destruction, accidental loss, corruption, dissemination or unauthorised access and against any other form of unlawful processing or disclosure to unauthorised persons. A comprehensive list of all technical and organisational measures taken can be found in Appendix 2 of our Data Processing Agreement. On request, our team will also provide you with our IT security white paper, which describes in detail all the IT security measures taken.
2.6 Exercising rights as a data subject
The fulfilment and protection of data subject rights in accordance with Section 3 of the GDPR is fundamentally the duty of the controller, i.e. the customers of Shiftmove. If you are a user or driver within the Avrios application, please contact the company that purchased your Avrios instance to exercise your data subject rights. You have the right to request confirmation as to whether personal data concerning you is being processed by us. If this is the case, we will be happy to provide you with information about this personal data and the information listed in Art. 15 GDPR. In addition, you have the right to rectification (Art. 16 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to erasure (Art. 17 GDPR), the right to data portability (Art. 20 GDPR) and the right to object to processing (Art. 21 GDPR) under the respective legal requirements. If the processing is based on your consent, you have the right to revoke this consent at any time (Art. 7 para. 3 GDPR); the legality of the processing carried out on the basis of the consent until revocation remains unaffected. Shift Move supports its customers in the fulfilment of requests to exercise data subject rights in accordance with the agreements in our Data Processing Agreement. Please get in touch with your responsible contact person at Shiftmove.
VI. AI Usage in our Products
Shiftmove holds itself accountable and is dedicated to a reasonable and secure usage of AI empowered tools and providers. Shiftmove has established a dedicated AI usage policy and with that only allows a restricted usage of AI reliant tools for the development and provisioning of our products. AI related tools used for the development of the product have no access to any customer personal data. No AI related functionality provided by Shiftmove to customers will establish an automated decision in the sense of Art. 22 GDPR.
Avrios Fines and Invoices Readout Automation
The Avrios fleet management system provides the option to manage fines and invoices within the product and automatically generate necessary document templates for further correspondence from the original invoice and fine files.We deploy an optic character recognition system (OCR) based on machine learning and provided by AWS to extract written text from the provided invoices and fines .pdf files. The files are locally processed on our AWS infrastructure where the OCR system is hosted. The OCR output is then reorganized via a locally trained LLM to extract relevant information, such as licence plate, invoice and billing related information, issuing authority, case number, violation and contact information. Users can then generate response templates using the extracted information from pdf. files, e.g. to forward a violation payment to a specific driver. The live customer data processed by this process is never used to train the AI and is not accessible or in any form retrievable by other Avrios customers. Crucially, it is our strict policy that any user-uploaded PDF documents are not used as training data for the LLM and are retained for a limited time to provide the requested service. Also no data is shared outside of our AWS infrastructure or with other third parties.Our automations around invoices and fines are provided under the relevant package of Avrios and with that are subject to the data processing agreement between Shiftmove and clients.
VII. Storage period
Unless otherwise stated in the descriptions of the individual processing activities, we generally process your data for as long as is necessary to fulfil the purpose of the processing. We delete your data in compliance with the statutory retention periods (retention for up to 10 years where applicable) as soon as the purpose of the processing no longer applies or this is required by law, such as when you withdraw your consent.
VIII. International data transfers
Shiftmove only processes your data on servers within the European Union or the European Economic Area. If Shiftmove processes data outside the European Union, this is explicitly stated in this privacy policy. When transferring your personal data outside the European Union or the European Economic Area, Shiftmove has taken all necessary measures to ensure compliance with legal and regulatory requirements in connection with your personal data. This includes ensuring that there is a lawful basis for the data transfer and that appropriate safeguards are in place to ensure a high level of protection for your data. In addition, we implement measures to ensure the protection of your personal data in accordance with the applicable data protection regulations.Where we transfer your personal data outside the UK, EEA or Switzerland, we will ensure, to the extent required by relevant data protection laws, that at least one of the following safeguards is applied: (1) the transfer is to countries or organisations deemed adequate under data protection law by the European Commission, the UK Government or the Swiss authorities; or (2) we use contractual arrangements approved by those bodies, such as "Standard Contractual Clauses" (SCCs). For more information about the specific mechanisms we use to transfer your personal data, please contact us.
IX. Your rightsYou have the right to request confirmation as to whether personal data concerning you is being processed by us. If this is the case, we will be happy to provide you with information about this personal data and the information listed in Art. 15 GDPR. In addition, you have the right to rectification (Art. 16 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to erasure (Art. 17 GDPR), the right to data portability (Art. 20 GDPR) and the right to object to processing (Art. 21 GDPR) under the respective legal requirements. If the processing is based on your consent, you have the right to revoke this consent at any time (Art. 7 para. 3 GDPR); the legality of the processing carried out on the basis of the consent until revocation remains unaffected. To exercise your rights as a data subject, please contactprivacy@shiftmove.com .You also have the right to lodge a complaint with a competent supervisory authority at any time if you believe that the processing of your personal data violates data protection regulations (Art. 77 GDPR).
C. Informations sur la protection des données pour les clients professionnels :
Les informations suivantes montrent comment nous traitons vos données personnelles lorsque vous nous contactez pour la vente de nos produits ou lorsque nous travaillons avec des prestataires de services externes.
I. Responsable du traitement des données
Le responsable du traitement conformément à l'article 4, paragraphe 7, du RGPD est :
Shiftmove GmbH
Warschauer Straße 57
10243 Berlin
Adresse électronique : contact@shiftmove.com
Tél. : +49 30 555 79 852
Si vous avez des questions ou des préoccupations concernant le traitement de vos données personnelles ou l'exercice de vos droits, vous pouvez nous contacter en utilisant les coordonnées fournies ici.
II. Responsable de la protection des données
Vous pouvez contacter notre responsable de la protection des données à l'adresseprivacy@shiftmove.com ou par courrier à l'adresse ci-dessus avec la mention « Délégué à la protection des données ».
III. Contacter
Vous pouvez utiliser le formulaire fourni ou les informations de contact disponibles pour nous envoyer des demandes de vente et d'assistance et pour nous contacter sur d'autres sujets. Lorsque vous nous contactez via l'un de nos formulaires Web, les données marquées comme champs obligatoires doivent être fournies. Lorsque vous nous contactez, nous pouvons traiter vos nom et prénom, votre adresse e-mail, votre société, votre numéro de téléphone et d'autres informations relatives à votre demande. Les informations obligatoires, sans lesquelles il n'est pas possible de vous contacter, sont signalées par un astérisque. Les données sont traitées sur la base de l'article 6, paragraphe 1, phrase 1, lettre b du RGPD dans le cadre de l'initiation ou de la mise en œuvre de mesures précontractuelles ou du contrat conclu avec vous ou sur la base de notre intérêt légitime à traiter et à répondre à votre autre demande conformément à l'article 6, paragraphe 1, phrase 1, lettre f du RGPD. D'autres informations ne sont pas obligatoires pour établir un contact et sont donc fournies volontairement sur la base de votre consentement conformément à l'article 6, paragraphe 1, phrase 1, lit. a du RGPD. Vos données personnelles seront supprimées - sous réserve des délais de conservation légaux - dès que la finalité du stockage ne s'applique plus, c'est-à-dire que votre demande a été entièrement traitée et qu'aucune autre communication avec vous n'est requise ou demandée par vous.
Demandes de vente sont gérés via notre système interne de gestion des relations clients. Nous travaillons en collaboration avec le prestataire de services salesforce.com Germany GmbH (« Salesforce »), Erika-Mann-Straße 31-37, 80636 Munich, Allemagne. Vos données sont traitées exclusivement dans des centres de données européens. Toutefois, dans le cas de demandes d'assistance, les données peuvent également être transférées par Salesforce aux États-Unis (pays tiers). Nous avons donc conclu un contrat de traitement des commandes avec Salesforce en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Salesforce est certifiée conformément au cadre de confidentialité des données UE-États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles.
Demandes d'assistance sont gérés et traités via notre outil de support client interne Zendesk. Nous travaillons avec Zendesk Inc (« Zendesk »), 181 S. Fremont St., San Francisco, CA 94105, États-Unis. Nous avons conclu un contrat de traitement des commandes avec Zendesk en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Zendesk est certifié conformément au cadre de confidentialité des données entre l'UE et les États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles.
IV. Contact publicitaire
Nous traitons les données des parties intéressées à des fins de contact publicitaire (e-mail, téléphone, courrier). À cette fin, nous traitons les informations suivantes : NomCoordonnées professionnelles (e-mail, téléphone) Position et entrepriseInformations sur la taille de la flotteAutres données relatives à l'entreprise (adresse, taille, domaine d'activité) Dans le cadre de cette approche, nous traitons vos données sur la base de notre intérêt légitime conformément à l'article 6, paragraphe 1, lit. f du RGPD pour la demande de clients existants ou de clients avec un consentement présumé. Vous pouvez vous opposer à ce que l'on vous contacte à cette fin à tout moment et via n'importe quel canal de communication. Vous avez également la possibilité de consentir à un contact publicitaire sur la base de votre consentement volontaire. La base légale est alors votre consentement conformément à l'article 6, paragraphe 1, point a du RGPD. Vous pouvez révoquer votre consentement à tout moment avec effet pour l'avenir en utilisant le lien de désinscription figurant dans la communication électronique que vous avez reçue ou en nous contactant aux informations fournies ci-dessus. Les données seront conservées aussi longtemps que nécessaire aux fins du traitement, ou jusqu'à ce que vous retiriez votre consentement ou que vous vous opposiez au traitement. Si vous demandez à ne plus être contacté par Shiftmove à des fins publicitaires, nous conserverons vos données dans une liste noire pour tous les contacts publicitaires pendant une durée maximale de 3 ans, puis supprimerons vos informations. Nous gérons les données des prospects et des clients via notre système de gestion des relations clients. Nous travaillons en collaboration avec le prestataire de services salesforce.com Germany GmbH (« Salesforce »), Erika-Mann-Straße 31-37, 80636 Munich, Allemagne. Vos données sont traitées exclusivement dans des centres de données européens. Toutefois, dans le cas de demandes d'assistance, les données peuvent également être transférées par Salesforce aux États-Unis (pays tiers). Nous avons donc conclu un contrat de traitement des commandes avec Salesforce en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Salesforce est certifiée conformément au cadre de confidentialité des données entre l'UE et les États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles. Pour les contacts publicitaires par e-mail, nous travaillons avec les fournisseurs Braze, Inc. (« Braze ») 63 Madison Building 28 East 28th Street, Floor 12, New York, NY 10016, États-Unis et Planhat A/B (« Planhat ») Malmskillnadsgatan 13, 111 57 Stockholm, Suède. Nous avons conclu un accord de traitement des commandes avec Braze en utilisant les clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Braze est certifié conformément au cadre de confidentialité des données UE-États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles. Planhat traite les données exclusivement sur des serveurs européens. Nous avons conclu un contrat de traitement des commandes avec Planhat
V. Webinaires
Lorsque vous participez à des webinaires et à des événements en ligne ou que vous accédez à des webinaires à la demande, nous traitons également votre nom, votre adresse e-mail, votre entreprise, votre numéro de téléphone, votre adresse IP et d'autres données techniquement requises, ainsi que tout contenu audio, vidéo et texte que vous envoyez, votre numéro de téléphone et votre photo de profil. La fourniture de ces informations est nécessaire pour participer aux webinaires. La base légale du traitement est votre consentement volontaire conformément à l'article 6, paragraphe 1, point a du RGPD. Nous conservons vos données aussi longtemps que nécessaire à la réalisation de l'événement correspondant et les supprimons, sous réserve des obligations légales de conservation pertinentes, dès que le traitement n'est plus nécessaire. Nous travaillons avec le logiciel de visioconférence Google Meet, fourni par Google Ireland Limited Gordon House, Barrow Street Dublin 4, Irlande, pour l'organisation de webinaires et d'événements en ligne. Les données sont généralement traitées dans l'UE. Cependant, comme un transfert de données vers Microsoft Inc. aux États-Unis (pays tiers) ne peut être totalement exclu, un contrat de traitement des commandes a été conclu avec Google sur la base des clauses contractuelles types de l'UE. Les clauses contractuelles types de l'UE sont disponibles sur le site web de la Commission européenne. En outre, Microsoft Inc. est certifiée conformément au cadre de confidentialité des données UE-États-Unis. La décision d'adéquation de la Commission européenne s'applique donc aux transferts de données personnelles.
VI Durée de conservation
Sauf indication contraire dans les descriptions des différentes activités de traitement, nous traitons généralement vos données aussi longtemps que nécessaire pour atteindre l'objectif du traitement. Nous supprimons vos données conformément aux délais de conservation légaux (conservation jusqu'à 10 ans, le cas échéant) dès que la finalité du traitement ne s'applique plus ou que cela est exigé par la loi, par exemple lorsque vous retirez votre consentement.
VII. Transferts internationaux de données
Shiftmove traite vos données uniquement sur des serveurs situés au sein de l'Union européenne ou de l'Espace économique européen. Si Shiftmove traite des données en dehors de l'Union européenne, cela est explicitement indiqué dans cette politique de confidentialité. Lors du transfert de vos données personnelles en dehors de l'Union européenne ou de l'Espace économique européen, Shiftmove a pris toutes les mesures nécessaires pour garantir le respect des exigences légales et réglementaires relatives à vos données personnelles. Cela implique de s'assurer qu'il existe une base légale pour le transfert de données et que des garanties appropriées sont en place pour garantir un niveau élevé de protection de vos données. En outre, nous mettons en œuvre des mesures pour garantir la protection de vos données personnelles conformément aux réglementations applicables en matière de protection des données. Lorsque nous transférons vos données personnelles en dehors du Royaume-Uni, de l'EEE ou de la Suisse, nous veillerons, dans la mesure requise par les lois pertinentes sur la protection des données, à appliquer au moins l'une des garanties suivantes : (1) le transfert est effectué vers des pays ou des organisations jugés adéquats en vertu de la législation sur la protection des données par la Commission européenne, le gouvernement britannique ou les autorités suisses ; ou (2)) nous utilisons des arrangements contractuels approuvés par ces des organismes, tels que les « clauses contractuelles types » (SCC). Pour plus d'informations sur les mécanismes spécifiques que nous utilisons pour transférer vos données personnelles, veuillez nous contacter.
VIII. Vos droits
Vous avez le droit de demander la confirmation que nous traitons les données personnelles vous concernant. Si tel est le cas, nous serons heureux de vous fournir des informations sur ces données personnelles et sur les informations énumérées à l'article 15 du RGPD. En outre, vous avez le droit de rectification (article 16 du RGPD), le droit de restreindre le traitement (article 18 du RGPD), le droit à l'effacement (article 17 du RGPD), le droit à la portabilité des données (article 20 du RGPD) et le droit de vous opposer au traitement (article 21 du RGPD) conformément aux exigences légales respectives. Si le traitement est basé sur votre consentement, vous avez le droit de révoquer ce consentement à tout moment (article 7, paragraphe 3 du RGPD) ; la légalité du traitement effectué sur la base du consentement jusqu'à la révocation n'en est pas affectée. Pour exercer vos droits en tant que personne concernée, veuillez contacter privacy@shiftmove.com .Vous avez également le droit de déposer une plainte auprès d'une autorité de surveillance compétente à tout moment si vous estimez que le traitement de vos données personnelles enfreint les règles de protection des données (article 77 du RGPD).
D. Informations relatives à la protection des données Candidats :
Nous sommes heureux que vous vous intéressiez à nous et que vous postuliez ou ayez postulé pour un poste chez Shiftmove ou ses sociétés affiliées. Nous aimerions vous fournir les informations suivantes sur le traitement de vos données personnelles dans le cadre de votre candidature. I. Contrôleur et responsable de la protection des données : Le responsable du traitement de vos données est
Shiftmove GmbH
Warschauer Strasse 57
10243 Berlin
courriel : kontakt@shiftmove.com
Numéro de téléphone : +49 30 555 79 852
Shiftmove a également désigné un responsable de la protection des données. Vous pouvez le joindre à l'adresse suivante :.privacy@shiftmove.com
II. Procédure de candidature
1. Finalité du traitement et catégories de données
Pour traiter votre candidature, nous traitons les données que vous nous avez envoyées dans le cadre de votre candidature afin de vérifier votre adéquation au poste (ou à tout autre poste vacant dans nos entreprises) et de mener à bien le processus de candidature. Ces données incluent régulièrement
Coordonnées : Nom, adresse, numéro de téléphone, adresse e-mail.
Documents de candidature: CV, lettre de motivation, certificats, références.
Date et lieu de naissance
Photo de candidature (facultatif)
Données sur la formation et les qualifications : diplômes de fin d'études, études, formation, formation continue
Expérience professionnelle : informations sur les anciens employeurs, les postes et les domaines d'activité
Compétences linguistiques: Compétences en langues étrangères et leur niveau
Connaissances et compétences spéciales : Compétences informatiques, certifications, connaissances spécialisées.
Profils sociaux : Liens vers des profils professionnels tels que LinkedIn ou Xing.
Autres informations : Intérêts, loisirs, bénévolat, adhésions.
2. Base légale du traitement
La base légale du traitement de vos données est l'établissement d'un contrat de travail avec vous conformément à l'article 6, paragraphe 1, lit. b du RGPD. Si les données sont nécessaires à des fins de poursuites judiciaires une fois la procédure de candidature terminée, le traitement des données peut être effectué sur la base des exigences de l'article 6 du RGPD, en particulier pour sauvegarder des intérêts légitimes conformément à l'article 6, paragraphe 1, point f) du RGPD. Notre intérêt réside alors dans l'affirmation ou la défense de droits légaux, par exemple en vertu de la Loi générale sur l'égalité de traitement (AGG). Si vous avez consenti à ce que vos données soient stockées davantage dans notre pool de candidats, la base légale pour le stockage de vos données est votre consentement volontaire conformément à l'article 6, paragraphe 1, point a du RGPD. Vous pouvez révoquer votre consentement à tout moment avec effet pour l'avenir. Pour ce faire, il vous suffit de nous contacter en utilisant les options de contact répertoriées ci-dessus.
3. Bénéficiaires
3.1 Prestataire de services
Pour gérer nos applications, nous utilisons le logiciel Lever, fourni par Lever, Inc. 1125 Mission Street, San Franciscio, CA 94103, États-Unis. Nous avons conclu un accord de traitement des commandes avec le fournisseur de services. Lorsque vous utilisez Lever, vos données peuvent être transférées aux États-Unis. Nous avons donc conclu des clauses contractuelles types avec Lever. Le levier est également soumis à la décision d'adéquation de la Commission européenne en vertu de la Cadre de confidentialité des données entre l'UE et les États-Unis.Pour mener des entretiens en ligne, nous utilisons également le logiciel de visioconférence Google Meet, fourni par Google Ireland Limited Gordon House, Barrow Street Dublin 4, Irlande. Nous avons conclu un accord de traitement des commandes avec le fournisseur de services.
3.2 Sociétés du groupe
Les données de votre candidature seront examinées par le service des ressources humaines après réception de votre candidature. Les candidatures appropriées seront ensuite transmises en interne aux chefs de département responsables du poste vacant concerné. Les prochaines étapes sont ensuite convenues. Au sein de l'entreprise, seules les personnes qui en ont besoin pour le bon déroulement de notre processus de candidature ont accès à vos données. Dans ce contexte, vos données de candidature peuvent être transférées aux employés des sociétés de notre groupe.Vimcar GmbH, Warschauer Strasse 57, 10243 Berlin, AllemagneAvrios International AG, Weststrasse 50, 8003 Zurich, SuisseAvrios POLAND Sp. z o.o., QUICKWORK - 5th floor, UL. FABRYCZNA 6, 53-609 WROCŁAW, PologneAvrios Germany GmbH, Warschauer Straße 57, 10243 Berlin, AllemagneAvrios Italy S.r.l., Via Bernardino Telesio 2, CAP 20145, Milan, ItalieLa transmission a lieu dans la mesure nécessaire à la mise en œuvre de la procédure de candidature.
4. Durée de stockage
Les données des candidats seront supprimées au bout de 6 mois en cas de rejet. À la suite du processus de candidature, vous pourriez recevoir une invitation à rejoindre notre vivier de candidats. Cela nous permet de prendre en compte vos postes vacants dans le cadre de notre processus de sélection de candidats à l'avenir. Si vous y consentez, nous conserverons les données de votre candidature pendant deux ans. Si vous avez été accepté pour un poste dans le cadre du processus de candidature, les données du système de données des candidats seront transférées vers notre système d'information du personnel.
III. Enquêtes auprès des candidats
1. Finalité du traitement et catégories de données
Pour améliorer notre processus de candidature, nous envoyons des enquêtes de satisfaction au début, pendant et après votre candidature. Les résultats de l'enquête sont toujours agrégés et pseudonymisés. Toutefois, si les commentaires concernent des problèmes spécifiques, nous pourrons peut-être établir un lien vers votre personne. Nous traitons les catégories de données suivantes dans le cadre des enquêtes auprès des candidats :
Coordonnées : Nom, adresse e-mail.
Feedback : Commentaires et textes de feedback
Données techniques : Adresse IP
2. Base légale du traitement
La base légale du traitement de vos données est notre intérêt légitime à améliorer notre processus de candidature conformément à l'article 6, paragraphe 1, point f du RGPD.
3. Bénéficiaires
Nous travaillons en collaboration avec Starred B.V., Singel 542, 1017 AZ, Amsterdam, Pays-Bas, pour mener nos enquêtes de candidature. Nous avons conclu un accord de traitement des commandes avec le fournisseur de services.
4. durée de stockage
Les données de l'enquête sont pseudonymisées et agrégées immédiatement après leur collecte. Les réponses individuelles aux questions de feedback sont supprimées au bout de 6 mois.
IV. Vos droits
Vous disposez des droits suivants concernant vos données personnelles et conformément aux exigences légales : le droit à l'information conformément à l'article 15 du RGPD Le droit de rectification conformément à l'article 16 du RGPD Le droit à l'effacement conformément à l'article 17 du RGPD Le droit à la limitation du traitement conformément à l'article 18 du RGPD Le droit de notification conformément à l'article 19 du RGPD le droit à la portabilité des données conformément à l'article 20 du RGPD Le droit de s'opposer conformément à l'article 21 du RGPD. En outre, vous avez le droit de déposer une plainte avec une donnée autorité de contrôle de la protection conformément à l'article 77 du RGPD si vous pensez que vos données personnelles sont traitées illégalement. Le droit de déposer une plainte est sans préjudice de tout autre recours administratif ou judiciaire. Si le traitement des données est basé sur votre consentement, vous avez le droit, en vertu de l'article 7 du RGPD, de retirer votre consentement à l'utilisation de vos données personnelles à tout moment. Veuillez noter que la révocation ne prend effet que pour l'avenir. Cela n'affecte pas le traitement qui a eu lieu avant le retrait du consentement. Si vous souhaitez retirer votre consentement, veuillez utiliser les coordonnées fournies ci-dessus.