Privacy Policy
Hereby we inform You that that, following an internal reorganisation aimed at centralising the processing of personal data of our brand customers and prospective customers, as of 30/06/2023, all Customer Relationship Management (CRM) activities carried out on behalf of the brands referred to above, will all be managed by the company Stellantis Europe S.p.A., with registered office in C.so G. Agnelli 200, 10135 - Turin, Italy (Stellantis Europe). From that date Stellantis Europe, will be the Data Controller of personal data we process about you for CRM purposes according to the Privacy Policy published to our brand websites and Apps
This Privacy Policy is drafted pursuant Article 13 of the EU Regulation 679/2016 (hereinafter “GDPR”) and provide you some examples of how we process Personal Data, and Definitions referring to more detailed explanations (at the end this Privacy Policy) for the capitalized terms herein. For any clarifications regarding this Privacy Policy or how your data are processed, please send your request to: dataprotectionofficer@stellantis.com
You may find further details on the reason why we process your Personal Data in “Why we collect and process your Data” section below.
a) Data provided by you
You can also choose to provide us with Information about your location if, for example, you want to search for Our Network in the area of your interest (e.g. Turin) using Our Website and Application.
If you provide us with the data of third parties, you will be held responsible for having shared such information. You must be legally authorized to share it (i.e., authorized by the third party to share their information, or for any other legitimate reason). You must fully indemnify us against any complaints, claims or demands for compensation of damages which may arise from the processing of third-party Personal Data in violation of applicable data protection law.
b) Data collected by the Browser, Device, and the Application
Some of this information is collected using Cookies and Other Tracking Technologies that are on your Browser or Device. This helps us for instance to avoid malfunctioning during the provision of the Services and allows us to provide you with Content that may be useful to you. More information on cookies can be found in our Cookie Policy.
c) Data inferred by your activity
In other cases, if you contact us by email, mail, telephone or otherwise regarding the Vehicles or request other information, we collect and maintain a record of your contact details, communications and our responses. If you contact us by telephone, more information will be provided during the call.
d) Information about your location
- manually entering an address, city or zip code;
- the Sensors of your Device;
- your IP Address collected through the permission of you Browser or Device.
You can limit our collection of your position by changing your Browser or Device settings, as set out in the “How to control your Data and manage your choices” section below.
This processing is based on Stellantis Europe, Our Network and Car Manufacturers’ legitimate interest in keeping up to data the quality of Personal Data about owners and leads.
This processing is based on the execution of a contractual obligation or pre-contractual measures taken at your request.
In some cases, communications may include product or service promotions from selected Partners. When we send out this type of communications, we can act as Joint Data Controller with the relevant Partners. Specific information and agreements will be in place with such Partners before sending of any communication to you.
On this point, we specify that no communication will be sent to you without your prior consent, which you can provide through specific tick-boxes for this purpose.
The processing is based on our need to guarantee the best Services and on our legitimate interest in avoiding any service disruptions.
This processing is based on our legitimate interest in fastening and reducing or effectively use our marketing budget and on your legitimate interest in not receiving irrelevant communications.
Customized Services and/or communications and/or Content that may be useful to you are based on your behaviour, interests, needs, preferences as well as your profile; such purposes may also be achieved on the basis of Personal Data collected through the use of cookies or other tracking technologies to analyse and predict customer’s preferences providing customer with tailored offers.
Content that may be useful to you:
- is not created using Sensitive Data such as those that may be derived from Information about your location;
- may also be visible on websites and mobile applications other than ours once uploaded to Programmatic Advertising platforms only to the extent that you have authorized us to upload them to these platforms.
As far as possible, we use anonymous or pseudonymous data for these purposes. Only in exceptional cases a personal reference may be possible. In such cases, the following applies: Except for your consent to the customization of our Services, measuring the effectiveness of our Services and the creation of new Services is based on our legitimate interest in creating and maintaining Services that are truly useful to our users.
This processing in based on your prior consent. You may see the full list or categories of Partners with whom we shared you Data directly at: https://privacyportal.stellantis.com.
Some legislations may require us to share your Data with public authorities (e.g., recall notices). If this sharing is not required by law in your country, we may consider sending your Data regardless as parent company of us as explained in more detail in the "Protecting our interests and your interests" section below.
Your Data may also be subject to Combination and/or Crossing, to the extent permissible under applicable data protection law. This allows us to understand, for example, if a single user is utilizing our Services with the same IP Address or Unique Identifiers from the Browser and the Device; or if promotional communications or Content that may be useful to you strictly related to Information about your location or Data provided through your activities or Data collected by your Browser, Device, and the Application. The Combination and/or Crossing of your information for the purposes we process it for (e.g., customizing the Services) can be enabled or disabled as explained in the “How to control your Data and manage your choices” section below.
- Persons authorized by us to perform any of the data-related activities described in this document: our employees and collaborators who have undertaken an obligation of confidentiality and abide by specific rules concerning the processing of your Data;
- Our Data Processors: external subjects to whom we delegate some processing activities. For example, security systems providers, accounting and other consultants, data hosting providers, bank, insurance, etc. We have signed agreements with each of our Data Processors to ensure that your Data is processed with appropriate safeguards and only under our instructions;
- System administrators: our employees or those of Data Processors to whom we have delegated the management of our IT systems and are therefore able to access, modify, suspend or limit the processing of your Data. These subjects have been selected, adequately trained and their activities tracked by systems they cannot modify, as provided for by the provisions of our competent Supervisory Authority;
- Our Network and Car Manufacturers: Our Network in case you requested a service carried out by them (e.g. a request for a test drive close to you) or if your required their assistance or the one provided by the Car Manufacturer;
- Our selected Partners: when you consented to the communication to them of your Personal Data for their own marketing and/or profiling purposes and who act as autonomous Data Controllers.
- Law enforcement or any other authority whose provisions are binding for us: this is the case when we have to comply with a judicial order or law or defend ourselves in legal proceedings.
7. Where your Data is located
- Customer Data processed for Marketing and Profiling purposes, will be retained by the controllers from the moment the customer gives consent until the moment the customer withdraws the consent. Once consent is withdrawn, Data will no longer be processed for Marketing and Profiling purposes, although it might still be kept by the controllers to manage potential claims and/or lawsuits. Data retention in case of Marketing and Profiling is compliant with the local law and with the decisions of the Data Protection Authority.
- Customer Data processing to comply with legal obligations will be retained for the period foreseen by the laws and regulations.
- Customer Data processing to improve the product and the services could be retained for the period deemed strictly necessary to fulfil such purposes and not beyond three years.
- Access your Data (right of access): depending on your use of our Services, we will provide the Data we have about you, such as your name, age, IP Address, Unique Identifiers, e-mails and preferences expressed, together with the Privacy Policy you received when you provided them, and the source of the Data (if, for example, they were provided to us by one of our Partners);
- Exercise your right to portability of your Personal Data (right to data portability): according to your use of our Services, we will provide you with an interoperable file containing the Data we have about you.
- Correct your Data (right to rectification): for example, you can ask us to modify your e-mail address or telephone number if they are incorrect;
- Limit the processing of your Data (right to restriction of processing): for example, when you think that the processing of your Data is unlawful or that processing based on our legitimate interest is not appropriate;
- Delete your Data (right to erasure): for example, when you do not want to use our Services and may not want us to retain your Data any longer;
- Object the processing activities (right to object);
- Withdraw your consents (right to withdrawal).
- contact our Data Protection Officer (DPO), here dataprotectionofficer@stellantis.com
- contact the competent Supervisory Authority, here you can find the list of all the Supervisory Authorities by country https://edpb.europa.eu/about-edpb/board/members_en
- We ensure that your Data is only accessed and used by, transferred or disclosed to Recipients that need to have access to such Data.
- We also limit the amount of Data accessible, transferred or disclosed to Recipients to only what is necessary to fulfil the purposes or specific tasks performed by the Recipient.
- The computers and servers where your Data is stored are kept in a secure environment, are password-controlled with limited access, and have industry standard firewalls and anti-virus software installed.
- Paper copies of any documents containing your Data (if any) are kept in a secure environment as well.
- We destroy paper copies of documents containing your Data that is no longer needed.
- When destroying Data recorded and stored in the form of electronic files that is no longer needed, we make sure that a technical method (for example, low level format) ensures that the records cannot be reproduced.
- Laptops, USB keys, mobile phones and other electronic wireless devices used by our employees who have access to your Data are protected. We encourage employees not to store your Data on such devices unless it is reasonably necessary for them to do so to perform a specific task as outlined in this Privacy Policy.
- We train our employees to comply with this Privacy Policy and conduct monitoring activities to ensure ongoing compliance and to determine the effectiveness of our privacy management practices.
- Any Data Processor that we use is contractually required to maintain and protect your Data using measures that are substantially similar to those set out in this Privacy Policy or required under applicable data protection law.
This Privacy Policy does not cover processing carried out by subjects other than us.
Regarding these cases, we are not responsible for any processing of your Data that is not covered by this Privacy Policy.
Application: means this application if applicable.
Browser: refers to programs used to access the internet (e.g. Safari, Chrome, Firefox, etc.).
Car Manufacturer: singularly or collectively refers to the following entities acting as manufacturer of Vehicles: Stellantis Europe S.p.A., Corso Agnelli 200, 10135 – Turin, Italy; PSA Automobiles S.A. (Stellantis Auto S.A.S.)., 2-10 Boulevard de l’Europe, F-78300 Poissy, France; Opel Automobile GmbH, Bahnhofsplatz, D-65423 Rüsselsheim am Main, Germany.
Combination and/or Crossing: this is the set of fully automated and non-automated operations which we combine with the Information about your location, the Data inferred by your activity, the Data collected by the Browser, Device and the Application, the Data you provide and those collected by Our Partners' Websites and Application used to provide the Services, analysing and improving our Services and creating new services and features, as well as to offer Content that may be useful to you. We may also combine and/or cross information from different sources, such as information collected from Our Website and Application, Our Partners' Websites and Apps and/or Data collected from public or publicly accessible sources.
Content that may be useful to you: for example, if you search for the "Fiat Professional" model, we may display other content related to this model on Our Website and Application or through Programmatic Advertising. Customization of the content may occur through the Combination and/or Crossing of Data.
Cookie: refers to a small text sent to your Browser from our sites or our Partners or Our Network. It allows the site to store information such as the fact that you visited the site, your language and other information. Cookies are used for different purposes, for example, to record your preferences regarding the use of Cookies (technical cookies), analysing and improving our Services and creating new services and features or Customizing our Services, including Content that may be useful to you. Information transmitted by Cookies is subject to Combination and/or Crossing with one of the Other Tracking Technologies where applicable.
Data Controller: refers to the legal person, public authority, service, or other entity which, individually or jointly determines the purposes and means for processing your Personal Data. This definition typically refers to Stellantis Europe S.p.A.. In other cases, it is preceded by the word "Independent" (e.g. "Independent Data Controller") to indicate that your Personal Data is processed by a subject other than Stellantis Europe S.p.A.
Data Processor: refers to an entity that we engage to process your Personal Data solely on behalf of and pursuant to the written instructions of Stellantis Europe S.p.A.
Device Sensors: depending on your device, these are sensors such as accelerometers, gyroscopes, Bluetooth, Wi-fi and GPS which in one way or another share the information they collect through the Device and therefore through the Application. If enabled by the Device settings, these allow us to obtain information about your location.
Device: refers to the electronic device (e.g. iPhone) through which you visit Our Website and Application and/or our Partners’ Websites and Apps.
Indirect Collection: is one of the Services we provide on Our Partners’ Websites and Application. In such cases, it is the Partner which assures us to have received your consent or to have another legal basis that legitimizes the communication/sharing of your Personal Data. On this point, we precise that, before being used, we check how Partners collect and transfer data to us in order to respect your preferences.
IP Address: is a unique number used by your Browser, your Device and the Application in order to connect to the internet. The internet service provider provides this number allowing identification of the provider and/or the approximate area where you are located. Without this data, you cannot connect to the internet and use our Services or use Content that may be useful to you.
Other Tracking Technologies: pixel tags (tracers used with Cookies and embedded in images on web pages or the Application to track certain activities, such as the viewing of Content that may be useful to you, or to see if an e-mail has been read) or Unique Identifiers embedded in links to commercial communications that send us information when clicked on.
Our Events: these are events/showrooms organized by Stellantis Europe, Our Network, or in collaboration with other brands with which Stellantis Europe has signed partnership agreements.
Our Network: these are retailers and/or dealers and/or repairers with whom Stellantis Europe and Car Manufacturers has/have signed commercial agreements for the sale of the Vehicles and/or for providing services/products assistance.
Our Website: includes this Website and our social network pages where this privacy policy is present.
Partners: means third-party entities who may communicate your Personal Data to us only after they have contractually assured us that they have obtained your consent or that they have another legal basis that legitimizes their communication/sharing of such data with us (for example, if you ask one of our Partners to book a test drive, when you purchase, and when you request to receive commercial communications). This definition also includes the selected Partners with whom we may share your Data. Partners may belong to the following product sectors: manufacturing, wholesale and retail trade, financial, bank, transportation and warehousing, information and communication services, professional, scientific and technical activities, travel agencies, business support services, artistic, sports, entertainment and amusement activities, activities of membership organizations, services of physical wellness centers, suppliers of electricity and gas, rental, e-mobility and insurance companies.
Personal Data: means any information relating to an identified or identifiable natural person whether directly or indirectly, as well as any information that is linked or reasonably linkable to a particular individual or household. For example, an e-mail address (if it refers to one or more aspects of an individual), IP addresses, and Unique Identifiers are considered Personal Data. For your convenience, we will collectively indicate all Personal Data mentioned also as “Data”.
Programmatic Advertising: these are platforms that share the information they collect about you, such as your IP Address and the data collected by Cookies and Other tracking technologies, with entities who have an interest in showing you Content that may be useful to you. In our case, if you visualize the "Fiat Professional" model on Our Website and Application, we will ask participants in Programmatic Advertising to grant us an advertising space on one of the websites you visit in order to display Content that may be useful to you. On this point, we would like to reiterate that the communication of your Data to participants in Programmatic Advertising is based on your prior and specific consent provided on the banner when the first visiting Our Website and Application.
Services: collectively, this means all the services available on Our Website and Application, such as "configure and order", "find Our Network", “buy or rent”, test drive bookings, the institutional newsletter, customer service, and Our Events.
Sensitive Data: means Personal Data that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership and the processing of genetic data, biometric data aimed at uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
Vehicle: refers to a vehicle of a brand of Stellantis Group.
Vehicle Data: means any technical, diagnostic and real-world data that is possible to collect via the Vehicle Device installed on the Vehicle (e.g., location, speed and distances, engine running time and turning off time; if the battery cable is cut, battery diagnostics, movements with the key out, presumed collision, as well as diagnostic data such as, but not limited to, oil and fuel levels, tire pressure, and engine status).
UK Authorised Representative
We know that may people we interact with are located in the United Kingdom. As such, and as required by data protection laws, we have appointed Merrion Data Consultants Limited as our authorised representative in the UK. If you are located in the UK, you can contact our UK authorised representative as follows:
By email to: dataprotectionuk@stellantis.com