Last updated: March 17, 2026
(1) In the following, we inform you about the collection of personal data when using our website. Personal data is all data that can be personally related to you, e.g. name, first name, address, email addresses, telephone number, user behavior, subject and message.
(2) The responsible party according to Art. 4 Para. 7 of the EU General Data Protection Regulation (EU GDPR) and the UK General Data Protection Regulation (UK GDPR) is:
DC Connected Car GmbH
Elchinger Straße 53
89278 Nersingen
Germany
Managing Director: Dennis Christ
Email: info@dc-connected.de
You can reach our Data Protection Officer at:
Marcus Hupfauer
DatAP GmbH
Gerstenfeld 30
86486 Bonstetten
Email: m.hupfauer@datap-gmbh.de
Phone: 08293-96891-0
Fax: 08293-96891-10
Interpretive Note: References to "GDPR" in this policy mean both the EU GDPR (Regulation (EU) 2016/679) and the UK GDPR (as retained under the European Union (Withdrawal) Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019), together with the UK Data Protection Act 2018, unless otherwise specified. DC Connected Car GmbH complies with both frameworks.
(3) When you contact us by email, the data you provide (your email address, if applicable your name, first name, address and your telephone number, as well as subject and message) will be stored by us in order to answer your questions. We delete the data arising in this context after storage is no longer necessary, or restrict processing if legal retention obligations exist.
(4) If we use commissioned service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. We also name the specified criteria for the storage period.
(1) You have the following rights with regard to the personal data concerning you:
(2) You also have the right to complain to a data protection supervisory authority about our processing of your personal data.
(1) When using the website for informational purposes only, i.e. if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server.
If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (legal basis is Art. 6 Para. 1 S. 1 lit. f EU GDPR / UK GDPR). Also listed are the following data, which are not technically necessary, which are only collected if you have given us your consent according to Art. 6 Para. 1 S. 1 lit. a EU GDPR / UK GDPR:
(2) In addition to the aforementioned data, cookies are only stored on your computer when you use our website with your consent, except for technically necessary cookies. Cookies are small text files that are stored on your hard drive associated with the browser you are using and through which certain information flows to the place that sets the cookie (here by us). Cookies cannot run programs or transfer viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.
(3) Use of cookies:
a. This website uses the following types of cookies, the scope and functionality of which are explained below:
b. Transient cookies are automatically deleted when you close the browser. This includes session cookies in particular. These store a so-called session ID, with which various requests from your browser can be assigned to the common session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
c. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete cookies at any time in your browser's security settings.
d. You can configure your browser settings according to your wishes and, for example, refuse to accept third-party cookies or all cookies. Please note that you may not be able to use all functions of this website.
(1) If you have given consent to the processing of your data, you can revoke this at any time. Such revocation affects the permissibility of processing your personal data after you have expressed it to us.
(2) If we base the processing of your personal data on the balancing of interests, you can object to the processing. This is the case if the processing is not particularly necessary for the fulfillment of a contract with you, which is presented by us in each case in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either stop or adjust the data processing or show you our compelling legitimate reasons on the basis of which we continue the processing. Where data processing is based on Art. 6 Para. 1 lit. f EU GDPR / UK GDPR (legitimate interest), you have the right to object at any time pursuant to Art. 21 EU GDPR / UK GDPR. For vehicle tracking and recovery use cases, such objections must be addressed to the fleet operator, vehicle owner, or asset finance provider acting as the data controller.
(3) Of course, you can object to the consent to the processing of your personal data through unnecessary cookies and for purposes of advertising and data analysis at any time. You can inform us of your advertising objection at the following contact details:
DC Connected Car GmbH
Elchinger Straße 53
89278 Nersingen
Germany
Email: info@dc-connected.de
Managing Director: Dennis Christ
(1) On our website we advertise positions to which interested parties can apply by email to the contact address provided.
(2) Inclusion in the application process requires applicants to provide us with all personal data necessary for a well-founded and informed assessment and selection together with the application by email.
(3) The required information includes general information about the person (name, address, a telephone or electronic contact option) as well as performance-specific evidence of the qualifications required for a position.
(4) Which components an application must contain in individual cases for its eligibility for consideration and in what form these components are to be transmitted by email can be found in the respective job advertisement.
(5) After receipt of the application sent using the specified email contact address, the applicant data will be stored by us and evaluated exclusively for the purpose of processing the application. For inquiries arising in the course of processing, we use either the email address provided by the applicant with his application or a telephone number provided, at our discretion.
(6) The legal basis for this processing, including contacting for inquiries, is generally Art. 6 Para. 1, S. 1 lit. b EU GDPR / UK GDPR in conjunction with § 26 Para. 1 BDSG (German Federal Data Protection Act), in the sense of which going through the application process is considered an employment contract initiation.
(7) If special categories of personal data within the meaning of Art. 9 Para. 1 EU GDPR / UK GDPR (e.g. health data such as information on the severely disabled status) are requested from applicants as part of the application process, processing takes place in accordance with Art. 9 Para. 2 lit. b. EU GDPR / UK GDPR so that we can exercise the rights arising from labor law and the law of social security and social protection and fulfill our related obligations.
(8) If the above-described evaluation does not lead to the selection of the applicant or if an applicant withdraws his application prematurely, his data transmitted by email and all electronic correspondence, including the original application email, will be deleted after appropriate notification at the latest after 6 months. This period is based on our legitimate interest in answering any follow-up questions about the application and being able to comply with our obligations to provide evidence from the regulations on equal treatment of applicants, if necessary.
(9) In the case of a successful application, the data provided will be further processed on the basis of Art. 6 Para. 1, S. 1 lit. b EU GDPR / UK GDPR in conjunction with § 26 Para. 1 BDSG for the purposes of implementing the employment relationship.
(1) A registration function is available on our website to access the demo version of our software. Required information for registration is your email address and a secure password.
(2) As part of the registration function, we store:
(3) The storage takes place on the basis of your given consent, Art. 6 Para. 1, lit. a) EU GDPR / UK GDPR.
(4) Authentication is handled via our secure cloud authentication service, which acts as our processor under Art. 28 EU GDPR / UK GDPR. Authentication tokens are stored securely and industry-standard encryption is applied.
(5) IMPORTANT: Demo accounts do NOT have access to real vehicle data. To process actual fleet data, a signed Data Processing Agreement (DPA) is required. See § 9 for details.
(6) This data is not passed on to other third parties unless necessary to fulfill a legal obligation (Art. 6 Para. 1 lit. c) EU GDPR / UK GDPR).
(7) You can request deletion of your demo account at any time by contacting info@dc-connected.de. We will delete your data within 30 days unless legal retention obligations apply.
(1) Our website and demo software infrastructure are built using Lovable Cloud, where certain user account and access data (e.g., login credentials, audit trail) is stored securely.
(2) Our cloud platform provider acts as our technical processor under Art. 28 EU GDPR / UK GDPR and is contractually obligated to apply adequate safeguards, including encryption and access restrictions.
(3) Server locations: The platform is primarily hosted within the European Union (EEA). Where technical operations by sub-processors involve infrastructure outside the EEA (for example, in the context of AWS cloud services provided by Amazon Web Services, Inc., a U.S. entity), the adequate level of protection is ensured through EU Standard Contractual Clauses (SCCs) in accordance with Art. 46(2)(c) EU GDPR and the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs under UK GDPR, supplemented by appropriate technical measures including encryption in transit and at rest.
(4) No sensitive vehicle-related data (VINs, location data, telemetry) is stored or accessible via the demo environment without an additional Data Processing Agreement (DPA).
(5) Data stored in the demo environment:
(6) Legal basis: Art. 6 Para. 1 lit. f EU GDPR / UK GDPR (legitimate interest in providing secure access to the platform).
(7) Retention: Demo account data is retained until the user requests deletion or 3 years of inactivity, whichever comes first.
The Traice platform is designed for use by the following categories of authorised users:
Use of the Traice platform is restricted to the following lawful purposes:
Access to vehicle data on the Traice platform is subject to the following controls:
Individuals whose vehicles are tracked through the Traice platform (such as drivers or customers) must be informed of such tracking through appropriate means. Specifically:
All use of the Traice platform must be for lawful purposes consistent with UK GDPR and EU GDPR. The following conditions apply:
The demo version of our platform does NOT provide access to real vehicle data. If you wish to process actual fleet data (including VINs, location data, consent management, or telemetry), you must:
The DPA will govern:
Processing of vehicle data under the DPA is based on:
Without a signed DPA, no integration with vehicle manufacturers (OEMs) or vehicle telematics interfaces will be activated. Demo accounts use static, non-real vehicle data for testing purposes only.
Where a fleet operator activates a recovery session, location data may be shared in real time with authorized Recovery Agents (external third parties) for the duration of the session. The legal basis for this sharing is Art. 6 Para. 1 lit. f EU GDPR / UK GDPR (legitimate interest in property protection) or, where applicable, a mandate from law enforcement. Recovery sessions are time-limited, logged, and revocable at any time by the fleet operator.
The platform infrastructure is operated using a European cloud service provider. This provider processes user account data (email, session tokens, audit logs) as a processor under Art. 28 EU GDPR / UK GDPR. A complete list of currently engaged subprocessors is available upon request by contacting info@dc-connected.de.
The Traice platform integrates with connected vehicle platforms and telematics services provided by automotive manufacturers (OEMs). These integrations may involve the processing of vehicle-related information such as vehicle identifiers (VIN), telematics data, and location data. Each OEM operates its own connected services infrastructure and maintains its own privacy policy governing how such data is processed.
The following table lists the OEM manufacturers currently supported on the Traice platform, along with links to their respective connected vehicle privacy policies:
The links above are provided for transparency regarding the privacy policies of the respective OEM connected vehicle services. These policies are maintained and controlled by the respective manufacturers. Depending on the manufacturer's configuration, users may be redirected to privacy policy versions applicable to the United Kingdom, the European Union, or other jurisdictions. Traice does not control how OEM providers localize, structure, or present their privacy policies and is not responsible for any regional variations, translations, or jurisdiction-specific versions displayed by those providers.
OEM providers may act as independent data controllers with respect to vehicle data processed through their connected services infrastructure. Traice does not control the data collection performed directly by vehicle manufacturers through their connected vehicle systems. Users should review the relevant OEM privacy policy to understand how vehicle data, telematics data, VIN identifiers, or location data may be processed by the respective manufacturer.
In active recovery sessions, vehicle location data may be processed by:
All subprocessors are bound by data processing agreements under Art. 28 EU GDPR / UK GDPR and are contractually obligated to implement appropriate technical and organizational security measures.
Effective Date: March 2026