STOAG Stadtwerke Oberhausen GmbH, Max-Eyth-Str. 62, 46149 Oberhausen (“STOAG” or “we”) provide you with the mobile app “Revierflitzer®” (hereinafter referred to as “STOAG app”) for download on your mobile device. The following data protection notices contain information about the processing of personal data for the use of our STOAG app and the services offered by it.
Personal data is all information that relates to an identified or identifiable natural person (Art. 4 No. 1 EU General Data Protection Regulation ("GDPR")). This includes information such as your name, your e-mail address, your postal address or your telephone number as well as your IP address, for example.
Basically, the protection of your privacy is of the utmost importance to us. Therefore, compliance with the applicable statutory provisions, such as the General Data Protection Regulation (hereinafter "GDPR") and the Data Protection Act, is a matter of course for us. In addition, it is important to us that you always know when we collect and save which data and how we use them. STOAG undertakes to comply with all statutory data protection regulations. This is monitored by the STOAG data protection officer. If you have any questions, suggestions or comments on the subject of data protection, please contact our data protection officer at the e-mail address dsb (at) fox-on.com is available for storage, management and analysis.
1. Download the STOAG app
You can download our STOAG app for your operating system in the respective app store. The data collection when the app is downloaded is carried out by the app store provider as the person responsible.
2. Registration and use of the STOAG app and the services provided by it
If you would like to use the services offered via the STOAG app, registration in the STOAG app is required. There is no obligation to provide your personal data. However, the service offered via the STOAG app cannot be provided without registration.
When registering, you will be asked for the personal data required to use the STOAG app. This includes your name, your e-mail address, telephone and - when using the "SEPA direct debit" payment method (if available) - your home or billing address. In addition, depending on the selected payment method, you must enter the data required for the payment method (e.g. IBAN, credit card number, PayPal account information, mobile phone number, etc.).
The legal basis for this processing is Article 6 Paragraph 1 Clause 1 lit. b GDPR.
b) Use of the STOAG app
When using our STOAG app to order services and in the context of the provision and processing of services, we process personal data as follows:
When ordering services via the STOAG app, the following data is recorded: IP address, model and manufacturer designation of the end device used as well as version information, data processed or collected in the course of the ordering process, such as preference for barrier-free vehicles, query time, Pick-up location and time, arrival time and destination (even if the order process is aborted). As part of the service provision, we inform the customer about this shortly before collection and when the vehicle arrives at the collection location by means of a message that is displayed in the STOAG app. The driver of the vehicle used for transport receives the customer name and records the entry and exit of the user in the vehicle. The data processing is justified in accordance with Article 6, Paragraph 1, Sentence 1, Letter b of the GDPR.
If there are communication problems or connection interruptions between the app and the background system, we will save the data related to the error (request / request, error) in your account.
The geographical location of the device is only recorded with your consent (Art. 6 Para. 1 S. 1 lit. a GDPR) in order to provide location-based services. When you order certain services, we record your location to determine the start stop to prepare an offer. The legal basis in these cases is Article 6 Paragraph 1 Sentence 1 Letter b GDPR.
c) Evaluation of usage data
We evaluate usage data, among other things, to determine the vehicle load and route usage profiles as well as for market research of our services. The legal basis in these cases is Article 6 Paragraph 1 Sentence 1 Letter f GDPR. We have a legitimate interest in this processing because it enables us to measure, develop and improve our performance. No user profiles within the meaning of Art. 22 GDPR are created.
d) Use for advertising purposes
If you give us your consent, we will inform you by email about special offers, discounts and surveys from Revierflitzer. You can revoke your consent at any time with effect for the future. To do this, contact revierflitzer (at) stoag.de.
e) Forwarding of personal data
(1) Payment by credit card, SEPA direct debit (if available)
For all payment methods except PayPal (e.g. credit card), your personal data (first and last name, email address, credit card data, possibly mobile phone number as well as data on your respective orders) will be sent to our external payment service provider (currently PayPal (Europe) S. .à rl et Cie, SCA, 22-24 Boulevard Royal, L-2449, Luxembourg, First Merchant Processing (Ireland) Limited, Ireland and Allied Irish Banks plc, Bankcentre, Dublin 4, Ireland) for the purpose of processing the payment. The transfer of the payment data takes place in a secure and encrypted form. These payment service providers are contract processors. Otherwise, the legal basis is Article 6 (1) sentence 1 lit. b and f GDPR. We have a legitimate interest in outsourcing the processing of payments.
You can object to the transmission of data to external payment service providers at any time. In this case we have to refrain from any further processing of your data for this purpose, unless
- there are compelling, legitimate reasons for processing that outweigh your interests, rights and freedoms, or
- The processing is necessary for the establishment, exercise or defense of legal claims.
In the event of an effective objection, it is not possible to order journeys using the credit card or SEPA direct debit payment options.
For security reasons, credit card data is not stored in the STOAG app or the background system of the STOAG app.
(2) "PayPal" (if available)
If we offer payment via the online payment service provider PayPal in the STOAG app, the following applies: The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). If you select PayPal as the payment method, you will be redirected to the PayPal website and the personal data you have entered will be transmitted to PayPal in encrypted form. This usually includes your name, address, telephone number, IP address, email address or other information required for order processing, including information about your order.
The processing of personal data is carried out by PayPal as the responsible body. As far as this is necessary for the fulfillment of the order, data can also be passed on to third parties by PayPal. For the identity and credit check, personal data is also transmitted from PayPal to credit agencies such as SCHUFA. The legal basis is. Art. 6 Para. 1 S. 1 lit.f GDPR. The legitimate interest is to ensure the solvency of the customer.
You can find more information about data processing by PayPal at https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE.
In the event that you fail to meet your payment obligations, your personal data will be used for the purpose of collecting the claims (e.g. through payment reminders / reminders) and enforcing the claims (e.g. in the context of a judicial dunning procedure or cooperation with a law firm in the event of legal enforcement ) passed on to a debt collection company. In this case, the transmission of your personal data is based on Art. 6 Paragraph 1 Clause 1 lit.f GDPR, as enabling the enforcement of our claims represents a legitimate interest in data processing.
(4) Google Maps
The STOAG app uses the Google Maps map service via an API. The provider is Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. The use of Google Maps is in the interest of an appealing presentation of our online offers and an easy findability of the places specified by us in the app. This represents a legitimate interest within the meaning of Art. 6 Para. 1 lit.f GDPR.
When using the service, your browser communicates directly with Google Inc. This information is usually transmitted to a Google server in the USA and stored there. We have no influence on this data transfer.
You can also change the settings in the data protection center so that you can manage and protect your data.
(5) Vehicle operator (subcontractor on behalf of STOAG)
We transmit the data on trips (preference for barrier-free vehicles, pick-up location and time, arrival time and destination) to the operator of the vehicles (subcontractor on behalf of STOAG) to carry out the trips. The legal basis is Article 6, Paragraph 1, Sentence 1, Letter f GDPR. The legitimate interest is to outsource the execution of the trips. You have the right to object to the transmission of the data to the subcontractor. In this case we can unfortunately no longer process your order and cannot transport you.
In addition to payment service providers (see above (1)) and the service providers mentioned in other places in this data protection notice, we also use the following processors:
- IT service provider (ViaVan GmbH, Rosa-Luxemburg-Str. 14, D-10178 Berlin)
- Hosting service provider for the operation of the STOAG app
- Service provider for the technical operation of the STOAG app
- Omniphone (telephone support service provider)
- IT service provider (Microsoft Ireland Operations Ltd, Ireland)
- Service provider for the provision of computing and storage capacity for processing personal data, in particular for analyzing utilization and bundling trips
- Bookkeeping, accounting (billing and verification of payment for services) (ViaVan GmbH, Rosa-Luxemburg-Str. 14, D-10178 Berlin)
(7) Market research service provider
In order to carry out customer surveys (with consent), we may make your personal data available to a service provider. The legal basis is Article 6, Paragraph 1, Sentence 1, Letter f GDPR. The legitimate interest is to gain knowledge to improve our processes.
3. No automated decision-making in individual cases
There is no automated decision-making in individual cases, including profiling within the meaning of Art. 22 GDPR.
4. Data subject rights
Depending on the circumstances of the specific case, you have the following data protection rights:
- To receive information about your personal data processed by us and to request access to your personal data and / or copies of this data. This includes information about the purpose of use, the category of data used, their recipients and authorized users and, if possible, the planned duration of the data storage or, if this is not possible, the criteria for determining this duration.
- to request the correction, deletion or restriction of the processing of your personal data insofar as their use is inadmissible under data protection law, in particular because (i) the data are incomplete or incorrect, (ii) they are no longer necessary for the purposes for which they were collected (iii) the consent on which the processing was based has been withdrawn, or (iv) you have successfully exercised a right to object to data processing; In cases in which the data is processed by third parties, we will forward your requests for correction, deletion or restriction of processing to these third parties, unless this proves impossible or involves a disproportionate effort;
- to refuse your consent or - without affecting the legality of the data processing carried out before the revocation - to revoke your consent to the processing of your personal data at any time; this applies in particular to the processing of your data for advertising purposes (you can exercise your revocation via revierflitzer (at) stoag.de.
- to object to the processing for reasons that arise from your particular situation;
- to request the personal data concerning you that you have provided to us in a structured, common and machine-readable format and to transmit this data to another person responsible without hindrance from us; If necessary, you also have the right to request that we transfer the personal data directly to another person responsible, insofar as this is technically feasible;
- to complain to a competent supervisory authority, e.g. because you are of the opinion that your rights have been violated as a result of the processing of your personal data that is not in accordance with data protection regulations.
5. Duration of storage of personal data
Your personal data will be automatically deleted by STOAG if the purpose of storage no longer applies and no legal regulations require further storage. Statistical evaluations by STOAG are generally only carried out in anonymised form.
6. Update of the data protection information
The above data protection information is valid from September 01.09.2018st, XNUMX. They can be viewed in the app at any time.