1. Summary information on data processing
Below you will find information on the processing of your personal data by Brose Antriebstechnik GmbH & Co. KG, Sickingenstr. 29-38, 10553 Berlin, ("Brose", "We", "Us") as the relevant data controller in connection with the use of the Brose eBike app ("e Bike App").
This privacy notice consists of this summary (hereinafter "Summary") and the following section with in-depth data protection information (hereinafter "Detailed Information"). The purpose is to provide you with an overview of Our use, including inter alia the collection, storage, organization, recording, adaptation or alteration, alignment or combination, disclosure or deletion (hereinafter collectively "Processing" or "Process") of information of any kind about you (such as your email address) (hereinafter collectively "Personal Data") in connection with the use of the eBike App.
The eBike App enables the user to connect his or her compatible mobile device (e.g. smartphone) to his or her eBike or components installed therein that are manufactured by Brose ("Brose eBike Products") in order to view and manage technical data of these Brose eBike Products and – via access to third-party map services – to record and plan rides.
References in this privacy notice to GDPR include references to the EU General Data Protection Regulation and to the UK General Data Protection Regulation, as defined in the UK Data Protection Act 2018. This privacy notice is also aligned with the Swiss Federal Data Protection Act (Swiss DPA).
1.1 Processing of your Personal Data (Categories of Personal Data)
We process the following categories of Personal Data: email address, IP address, Product Data (e.g. serial number of the components installed on the eBike), Condition Data (e.g. mileage, battery condition, wheel circumference), Telemetry Data (e.g. speed, cadence, motor temperature) and route data (GPS data) (each of these terms having the meanings given in Section 2.1 below). For more information on the categories of Personal Data that we process, please see Section 2.1 below in the Detailed Information.
1.2 Processing purposes
We process your Personal Data for the following purposes: Provision of the functionalities of the eBike App, Product Improvement, Error Analysis and Quality Assurance, Compliance with legal obligations. For more information on why We process your Personal Data, please refer to Section 2.2 below in the Detailed Information.
1.3 Legal basis of the processing of your Personal Data
We process your Personal Data on the following legal bases: (i) your consent (Art. 6 para. 1 lit. a GDPR); (ii) for the performance of a contract to which you are a party or for pre-contractual measures (Art. 6 para. 1 lit. b GDPR); (iii) for the fulfillment of a legal obligation to which Brose as data controller is subject (Art. 6 para. 1 lit. c GDPR); as well as (iv) for the protection of the legitimate interests of Brose or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject (Art. 6 para. 1 lit. f GDPR). For more information, please refer to Section 2.3 below in the Detailed Information.
1.4 Data transfers and recipients and safeguards of such transfers
We transfer your Personal Data to other Brose Group companies and third parties (e.g. providers of the map services, providers of social media platforms), Our service providers, government authorities, courts, external consultants and comparable third parties. Some of the aforementioned recipients being located in countries outside the European Union ( EU ), the European Economic Area ( EEA ) or respectively the United Kingdom ( UK ) or Switzerland. For more information, please see Section 2.4 below in the Detailed Information.
1.5 Retention periods for and deletion of your Personal Data
Your Personal Data will be deleted as soon as it is no longer needed for the purposes for which it was originally collected or as required by applicable law. For more information, please refer to Section 3 below in the Detailed Information.
1.6 Your legal rights
Under applicable law, you have certain rights with respect to the processing of your Personal Data, in each case in accordance with applicable law, such as the right to access, rectify, erase or receive your Personal Data. You can exercise these rights by using the contact details above. For more information, please refer to Section 2.6 below in the Detailed Information.
1.7 Changes to this Summary and the Detailed Information
This Summary and the Detailed Information may need to be updated from time to time – for example, due to the implementation of new technologies or the introduction of new services or features. We will inform you about material changes.
2. Detailed Information on Our Data Processing
2.1 Categories of Personal Data
We process the following Personal Data in connection with your use of the eBike App:
- E-mail address and password ("Account Data");
- Name, contact details (e-mail address or telephone number), content of user requests ("User Service Data");
- Bike identifier, serial number of the components installed on the e-bike (such as drive, battery), the firmware versions installed on the components installed on the e-bike, wheel circumference ("Product Data");
- Mileage, battery health, battery charging and general technical condition, error codes ("eBike Condition Data");
- Speed, cadence, pedal torque, battery discharge and consumption, light status, timestamp, assistance level set, drive power, rider power, motor temperature, remaining range in kilometers, percentage drive power ("Telemetry Data");
- GPS data, acceleration values ("Route Data");
- Calorie loss estimated based on Route Data, Telemetry Data and eBike Condition Data, we do not collect or process parameters such as your height, weight and gender ("Calorie Data");
- Data related to the mobile device used: operating system, version of the eBike App version, battery level, brightness setting, internet connection used (mobile network or WLAN), memory usage, device ID ("Device Data");
- IP address, in-app navigation ("App Usage Data").
2.2. Processing purposes
Your Personal Data will be processed by Us for the following purposes:
- Provision of the functionalities of the eBike App ("App Functionalities");
- Improvement of the functionalities of the eBike App as well as of Brose eBike Products installed on the eBike ("Product Improvement");
- Ensuring the quality requirements of the eBike App as well as the Brose eBike Products installed on the eBike, analyzing and rectifying any errors that occur ("Error Analysis and Quality Assurance");
- For compliance with legal obligations to which Brose is subject as operator and data controller of the eBike App ("Compliance"); and
- Answering and processing user inquiries via the eBike App, contact form, e-mail or telephone ("User Service").
2.3 Legal basis for the processing of your Personal Data
Brose processes your personal data on the basis of the following legal bases:
We process your personal data insofar as
- you have consented to the processing of your data, Art. 6 para. 1 lit. a GDPR;
- this is necessary for the performance of a contract with Us, to which you are a party, or for the performance of pre-contractual measures, Art. 6 para. 1 lit. b GDPR;
- this is necessary for the fulfillment of a legal obligation to which Brose is subject, Art. 6 para. 1 lit. c GDPR;
- this is necessary for the exercise of Our legitimate interests or the legitimate interests of a third party, unless where such interests are overridden by the interests or fundamental rights and freedoms of the data subject , Art. 6 para. 1 lit. f GDPR.
The following table shows which categories of Personal Data are processed for which purposes and on which legal basis:
|Processing purposes||Relevant categories of personal data in each case||Legal basis|
||Performance of a contract (Art. 6 para. 1 lit. b GDPR)|
||Legitimate interest (Art. 6 para. 1 lit. f GDPR) in improving the functionalities of the eBike App and eliminating errors. Only pseudonymous or anonymized data is processed for this purpose|
||Consent (Art. 6 para. 1 lit. a GDPR)|
|Error Analysis and Quality Assurance||
||Legitimate interest (Art. 6 para. 1 lit. f GDPR) in ensuring that the functionalities of the eBike App run smoothly and that We can fix errors|
||Legal obligation (Art. 6 para. 1 lit. c GDPR) Legitimate interest (Art. 6 para. 1 lit. f GDPR), such as more efficient cooperation with regulators and authorities, establishment, exercise or defence of legal claims, each in court proceedings or in an administrative or out-of-court procedure, involving external counsel|
||Performance of contract (Art. 6 para. 1 lit. b GDPR) Legitimate interest in providing quality user service (Art. 6 para. 1 lit. f GDPR), as the processing of the data is necessary for answering and processing user requests|
||Consent (Art. 6 para. 1 lit. a GDPR)|
2.4 Obligation to provide your Personal Data
If you do not provide us with your Personal Data, certain functionalities of the eBike App cannot be used, for example, you cannot register without providing your name, email address and certain information on your Brose eBike.
3. Data transfers, recipients and transfer tools
To other companies of the Brose Group: Your personal data will be transferred by Us to other companies of the Brose Group, including Brose Fahrzeugteile SE & Co. Kommanditgesellschaft, Bamberg, Berliner Ring 1, 96052 Bamberg.
Third Parties: Certain Personal Data will also be disclosed by Us to third parties, including:
- komoot GmbH, Friedrich-Wilhelm-Boelcke-Strasse 2, 14473 Potsdam (www.komoot.de)
- Strava Inc, 208 Utah Street, San Francisco, CA 94103, USA (www.strava.com)
Data is only transferred if you record the rides, established a connection to the third parties and allow the eBike App to access your location data in the settings of your mobile device.
You have the option to link your eBike App with AppleHealth. This will transfer the data categories you select to Apple Inc, One Apple Park Way, Cupertino, CA 95014, USA (www.apple.com).
If you want to receive push messages even when you are not in the eBike App, you have to enable push messages on your mobile device. If you enable push messages, Device Data and App Usage Data will be transferred to the Firebase Cloud Messaging services of Google (1600 Amphitheatre Parkway, Mountain View, California 94043, United States) (Android) or Apple Push Notifications of Apple (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA) (iOS).
If you have enabled map services and tracking on your mobile device, We use maps provided by Mapbox (Mapbox Inc., 740 15th St NW, 5th Floor Washington, D.C. 20005, USA). In order for our partner to continually improve its service, Mapbox collects data on the use of its maps. You can agree to this transfer in the map view via the information button (Mapbox Telemetry) (www.mapbox.com).
The transfer of your Personal Data to the above-mentioned third parties only takes place after you provided your consent. You can provide your consent via the functions of your mobile device (Android: when installing the app / iOS: when using it for the first time). You can withdraw your consent at any time with effect for the future via the settings of your mobile device.
We may also transfer Your Personal Data to government authorities, courts, external consultants and similar third parties.
Service providers: In orderto provide the eBike App functionalities, We use external service providers to whom Personal Data may also be transferred in some cases for the provision of the services. These are for example cloud service providers, as the eBike App functionalities are provided via a cloud environment, as well as service providers used to provide the user accounts.
3.2 Cross-border data transfers and transfer tools
We sometimes transfer your data to recipients outside of the country in which you reside. Some of the recipients of your Personal Data named above are not located in a member state of the EU, the EEA or respectively the UK or Switzerland (together "Third Countries"). The level of data protection in a Third Country may differ from the data protection level in the EEA or the UK or Switzerland.
For some Third Countries, such as Switzerland or the United Kingdom, the EU Commission / UK government has decided that the data protection level is adequate, Our transfer of your Personal to these countries is based on the EU Commission's / UK government's adequacy decision (Art. 45 GDPR).
For data transfer to Third Countries without such adequacy decision, such as the United States of America, We enter into data transfer agreements (so-called EU Standard Contractual Clauses, or in respect of transfers from the UK, the International Data Transfer Agreement or Addendum) or We ensure other transfer safeguards. If you would like more information about cross-border data transfers, including the recipient countries, or a copy of the transfer mechanism we use, please feel free to contact us at the contact details provided in Section 6.
4. Retention periods for and deletion of your Personal Data
Your Personal Data will only be retained by Us for as long as this is necessary to achieve the purpose for which the Personal Data are processed or if We are subject to a legal obligation to retain your Personal Data.
Brose will typically retain your Personal Data for the duration of your user relationship plus 30 days after termination of our user relationship (i.e. after deletion of your user account for the eBike App). We will retain your Personal Data longer if we are under a legal obligation to retain your Personal Data or when dealing with, including investigating, compliance issues and legal disputes involving you.
Thereafter, We will delete Your Personal Data from Our systems and records and/or take steps to properly anonymize it so that You can no longer be identified from such data.
5. Your data protection rights
You have the following data protection rights in relation to Our processing of Your Personal Data:
5.1 Right of access
You have the right to access your Personal Data.
5.2 Right to rectification
You have the right to request us to correct inaccurate Personal Data concerning you. Depending on the purpose of the processing, you have the right to request the completion of incomplete personal data – also by means of a supplementary declaration.
5.3 Right to erasure (right to be forgotten)
You have the right to request that We delete your Personal Data.
5.4 Right to restriction of processing
In certain circumstances, you have the right to request a restriction of the processing of your Personal Data.
5.5 Right to data portability
If Our processing of your Personal Data is based on consent or the performance of a contract, you have the right to receive Your Personal Data in a structured, common and machine-readable format, and you have the right to transfer this Personal Data to another data controller without hindrance from us.
5.6 RIGHT TO OBJECT
If we process your Personal Data on the basis of legitimate interests, you have the right to object to the processing of your Personal Data by Us at any time on bases relating to your particular situation.
5.7 Right to withdraw your consent
If We process Your Personal Data on your consent, you have the right to withdraw your consent at any time for the future without giving reasons. This does not affect the lawfulness of the processing based on consent before your withdrawal.
5.8 Right to lodge a complaint to the supervisory authority
You also have the right to lodge a complaint with a supervisory authority. The supervisory authority competent for Us are:
if you reside in the EU: Berlin Data Protection Authority (Berliner Beauftragte für Datenschutz und Informationsfreiheit),Alt-Moabit 59-61, 10555 Berlin, email: firstname.lastname@example.org or the EU data protection supervisory authority in your country of residence, using the contact options set out here: edpb.europa.eu
if you reside in Norway: Norwegian Data Protection Authority (Datatilsynet), Postboks 458 Sentrum 0105 Oslo, email: email@example.com
- if you reside in Switzerland: Federal Data Protection and Information Commissioner (FDPIC) (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter), Feldeggweg 1, 3003 Bern, Switzerland
- if you reside in the UK: the Information Commissioner's Office (ICO) using the contact options set out here: ico.org.uk
5.9 Right to set instructions for the management of your Personal Data after your death
For France and when mandatory local French provisions so provide, You have the right to issue directives concerning the retention, deletion and post-mortem communication of your personal data.
If you reside in Spain , people linked to the deceased data subject by means of family, de facto reasons or their successors, may request access to Your personal data and, where appropriate, rectification or deletion of Your personal data.
6. Contact details
If you have any questions or wish to exercise your rights as a data subject, please contact us preferably at the address Brose Antriebstechnik GmbH & Co. KG, Sickingenstr. 29-38, 10553 Berlin, Germany, or by e-mail at firstname.lastname@example.org.
In addition, you are also welcome to contact our data protection officer at email@example.com.