Privacy Policy

    Last updated: March 17, 2026

    § 1 Information about the Collection of Personal Data

    (1) In the following, we inform you about the collection of personal data when using our website. Personal data is all data that can be personally related to you, e.g. name, first name, address, email addresses, telephone number, user behavior, subject and message.

    (2) The responsible party according to Art. 4 Para. 7 of the EU General Data Protection Regulation (EU GDPR) and the UK General Data Protection Regulation (UK GDPR) is:

    DC Connected Car GmbH

    Elchinger Straße 53

    89278 Nersingen

    Germany

    Managing Director: Dennis Christ

    Email: info@dc-connected.de

    You can reach our Data Protection Officer at:

    Marcus Hupfauer

    DatAP GmbH

    Gerstenfeld 30

    86486 Bonstetten

    Email: m.hupfauer@datap-gmbh.de

    Phone: 08293-96891-0

    Fax: 08293-96891-10

    Interpretive Note: References to "GDPR" in this policy mean both the EU GDPR (Regulation (EU) 2016/679) and the UK GDPR (as retained under the European Union (Withdrawal) Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019), together with the UK Data Protection Act 2018, unless otherwise specified. DC Connected Car GmbH complies with both frameworks.

    (3) When you contact us by email, the data you provide (your email address, if applicable your name, first name, address and your telephone number, as well as subject and message) will be stored by us in order to answer your questions. We delete the data arising in this context after storage is no longer necessary, or restrict processing if legal retention obligations exist.

    (4) If we use commissioned service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. We also name the specified criteria for the storage period.

    § 2 Your Rights

    (1) You have the following rights with regard to the personal data concerning you:

    • Right to information
    • Right to correction or deletion
    • Right to restriction of processing
    • Right to object to processing
    • Right to data portability

    (2) You also have the right to complain to a data protection supervisory authority about our processing of your personal data.

    § 3 Collection of Personal Data When Visiting Our Website

    (1) When using the website for informational purposes only, i.e. if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server.

    If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (legal basis is Art. 6 Para. 1 S. 1 lit. f EU GDPR / UK GDPR). Also listed are the following data, which are not technically necessary, which are only collected if you have given us your consent according to Art. 6 Para. 1 S. 1 lit. a EU GDPR / UK GDPR:

    • IP address
    • Date and time of request
    • Time zone difference to Greenwich Mean Time (GMT)
    • Content of the request (specific page)
    • Access status/HTTP status code
    • Amount of data transferred in each case
    • Website from which the request comes
    • Browser
    • Operating system and its interface
    • Language and version of browser software

    (2) In addition to the aforementioned data, cookies are only stored on your computer when you use our website with your consent, except for technically necessary cookies. Cookies are small text files that are stored on your hard drive associated with the browser you are using and through which certain information flows to the place that sets the cookie (here by us). Cookies cannot run programs or transfer viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.

    (3) Use of cookies:

    a. This website uses the following types of cookies, the scope and functionality of which are explained below:

    • Transient cookies (see b)
    • Persistent cookies (see c)

    b. Transient cookies are automatically deleted when you close the browser. This includes session cookies in particular. These store a so-called session ID, with which various requests from your browser can be assigned to the common session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.

    c. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete cookies at any time in your browser's security settings.

    d. You can configure your browser settings according to your wishes and, for example, refuse to accept third-party cookies or all cookies. Please note that you may not be able to use all functions of this website.

    § 4 Objection or Revocation Against the Processing of Your Data

    (1) If you have given consent to the processing of your data, you can revoke this at any time. Such revocation affects the permissibility of processing your personal data after you have expressed it to us.

    (2) If we base the processing of your personal data on the balancing of interests, you can object to the processing. This is the case if the processing is not particularly necessary for the fulfillment of a contract with you, which is presented by us in each case in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either stop or adjust the data processing or show you our compelling legitimate reasons on the basis of which we continue the processing. Where data processing is based on Art. 6 Para. 1 lit. f EU GDPR / UK GDPR (legitimate interest), you have the right to object at any time pursuant to Art. 21 EU GDPR / UK GDPR. For vehicle tracking and recovery use cases, such objections must be addressed to the fleet operator, vehicle owner, or asset finance provider acting as the data controller.

    (3) Of course, you can object to the consent to the processing of your personal data through unnecessary cookies and for purposes of advertising and data analysis at any time. You can inform us of your advertising objection at the following contact details:

    DC Connected Car GmbH

    Elchinger Straße 53

    89278 Nersingen

    Germany

    Email: info@dc-connected.de

    Managing Director: Dennis Christ

    § 5 Applications for Job Advertisements by Email

    (1) On our website we advertise positions to which interested parties can apply by email to the contact address provided.

    (2) Inclusion in the application process requires applicants to provide us with all personal data necessary for a well-founded and informed assessment and selection together with the application by email.

    (3) The required information includes general information about the person (name, address, a telephone or electronic contact option) as well as performance-specific evidence of the qualifications required for a position.

    (4) Which components an application must contain in individual cases for its eligibility for consideration and in what form these components are to be transmitted by email can be found in the respective job advertisement.

    (5) After receipt of the application sent using the specified email contact address, the applicant data will be stored by us and evaluated exclusively for the purpose of processing the application. For inquiries arising in the course of processing, we use either the email address provided by the applicant with his application or a telephone number provided, at our discretion.

    (6) The legal basis for this processing, including contacting for inquiries, is generally Art. 6 Para. 1, S. 1 lit. b EU GDPR / UK GDPR in conjunction with § 26 Para. 1 BDSG (German Federal Data Protection Act), in the sense of which going through the application process is considered an employment contract initiation.

    (7) If special categories of personal data within the meaning of Art. 9 Para. 1 EU GDPR / UK GDPR (e.g. health data such as information on the severely disabled status) are requested from applicants as part of the application process, processing takes place in accordance with Art. 9 Para. 2 lit. b. EU GDPR / UK GDPR so that we can exercise the rights arising from labor law and the law of social security and social protection and fulfill our related obligations.

    (8) If the above-described evaluation does not lead to the selection of the applicant or if an applicant withdraws his application prematurely, his data transmitted by email and all electronic correspondence, including the original application email, will be deleted after appropriate notification at the latest after 6 months. This period is based on our legitimate interest in answering any follow-up questions about the application and being able to comply with our obligations to provide evidence from the regulations on equal treatment of applicants, if necessary.

    (9) In the case of a successful application, the data provided will be further processed on the basis of Art. 6 Para. 1, S. 1 lit. b EU GDPR / UK GDPR in conjunction with § 26 Para. 1 BDSG for the purposes of implementing the employment relationship.

    § 6 Registration Function

    (1) A registration function is available on our website to access the demo version of our software. Required information for registration is your email address and a secure password.

    (2) As part of the registration function, we store:

    • Your email address
    • Encrypted password hash
    • IP address and timestamp of registration
    • Organization name (if provided)
    • Login and activity timestamps

    (3) The storage takes place on the basis of your given consent, Art. 6 Para. 1, lit. a) EU GDPR / UK GDPR.

    (4) Authentication is handled via our secure cloud authentication service, which acts as our processor under Art. 28 EU GDPR / UK GDPR. Authentication tokens are stored securely and industry-standard encryption is applied.

    (5) IMPORTANT: Demo accounts do NOT have access to real vehicle data. To process actual fleet data, a signed Data Processing Agreement (DPA) is required. See § 9 for details.

    (6) This data is not passed on to other third parties unless necessary to fulfill a legal obligation (Art. 6 Para. 1 lit. c) EU GDPR / UK GDPR).

    (7) You can request deletion of your demo account at any time by contacting info@dc-connected.de. We will delete your data within 30 days unless legal retention obligations apply.

    § 7 Hosting and Data Storage

    (1) Our website and demo software infrastructure are built using Lovable Cloud, where certain user account and access data (e.g., login credentials, audit trail) is stored securely.

    (2) Our cloud platform provider acts as our technical processor under Art. 28 EU GDPR / UK GDPR and is contractually obligated to apply adequate safeguards, including encryption and access restrictions.

    (3) Server locations: The platform is primarily hosted within the European Union (EEA). Where technical operations by sub-processors involve infrastructure outside the EEA (for example, in the context of AWS cloud services provided by Amazon Web Services, Inc., a U.S. entity), the adequate level of protection is ensured through EU Standard Contractual Clauses (SCCs) in accordance with Art. 46(2)(c) EU GDPR and the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs under UK GDPR, supplemented by appropriate technical measures including encryption in transit and at rest.

    (4) No sensitive vehicle-related data (VINs, location data, telemetry) is stored or accessible via the demo environment without an additional Data Processing Agreement (DPA).

    (5) Data stored in the demo environment:

    • User account data (email, name)
    • Authentication tokens
    • Organization metadata (company name, domain)
    • Audit logs (login times, IP addresses)

    (6) Legal basis: Art. 6 Para. 1 lit. f EU GDPR / UK GDPR (legitimate interest in providing secure access to the platform).

    (7) Retention: Demo account data is retained until the user requests deletion or 3 years of inactivity, whichever comes first.

    § 8 Who May Use Our Platform and For What Purposes

    (1) Authorised User Categories

    The Traice platform is designed for use by the following categories of authorised users:

    • Vehicle owners: individuals or organisations tracking vehicles they own for the purpose of asset protection and security.
    • Fleet operators: leasing companies, rental firms, and fleet management companies responsible for managing vehicle fleets under contractual arrangements.
    • Hire purchase and asset finance providers: finance companies that retain an interest in vehicles subject to hire purchase, conditional sale, or other asset finance agreements.
    • Recovery agents: authorised third parties acting on behalf of the above parties to locate and recover vehicles.

    (2) Permitted Purposes

    Use of the Traice platform is restricted to the following lawful purposes:

    • Vehicle tracking and real-time location monitoring for asset protection
    • Vehicle recovery in the event of contract breach, payment default, or theft
    • Enforcement of contractual rights arising from lease, rental, hire purchase, or finance agreements
    • Asset protection and security monitoring
    • Compliance with legal or regulatory obligations

    (3) Access Controls

    Access to vehicle data on the Traice platform is subject to the following controls:

    • Access is restricted to authorised users who have been verified and assigned to an organisation.
    • Role-based access control (RBAC) ensures that each user can only access data necessary for their role and responsibilities.
    • All data access requests are logged in an immutable audit trail, recording the user identity, timestamp, legal basis, and vehicle details.

    (4) Transparency to Data Subjects

    Individuals whose vehicles are tracked through the Traice platform (such as drivers or customers) must be informed of such tracking through appropriate means. Specifically:

    • The data controller (the vehicle owner, fleet operator, or asset finance provider) is responsible for informing data subjects about the use of vehicle tracking through contractual agreements, privacy notices, or other appropriate means.
    • Such notice must be provided in accordance with the transparency requirements of Art. 13 and Art. 14 UK GDPR / EU GDPR.
    • Traice provides tools to support transparency obligations, including comprehensive audit logs, session records, and consent management features.

    (5) Lawful Use Only

    All use of the Traice platform must be for lawful purposes consistent with UK GDPR and EU GDPR. The following conditions apply:

    • Users must have a valid legal basis (such as legitimate interest under Art. 6(1)(f) EU GDPR / UK GDPR or contractual necessity under Art. 6(1)(b) EU GDPR / UK GDPR) before requesting vehicle location data.
    • Any misuse of the platform, including unauthorised surveillance, stalking, or tracking without a lawful basis - is strictly prohibited and may result in immediate account termination and reporting to relevant authorities.
    • Users are required to comply with all applicable data protection laws and must not use the platform for any purpose that is incompatible with the purposes stated in this section.

    § 9 Data Processing Agreement (DPA) Requirement

    (1) Access to Real Vehicle Data

    The demo version of our platform does NOT provide access to real vehicle data. If you wish to process actual fleet data (including VINs, location data, consent management, or telemetry), you must:

    • Complete the organization verification process
    • Sign a dedicated Data Processing Agreement (DPA) with DC Connected Car GmbH
    • Sign a Service Agreement with DC Connected Car GmbH (governing scope, pricing, and SLA)

    (2) Scope of DPA

    The DPA will govern:

    • Processing of vehicle identification numbers (VINs)
    • Collection and storage of GPS location data
    • Consent management for data access via OEM APIs
    • Telemetry data from connected vehicles
    • Sharing of data with Recovery Agents (external third parties)

    (3) Legal Basis

    Processing of vehicle data under the DPA is based on:

    • Art. 6 Para. 1 lit. b EU GDPR / UK GDPR: Performance of a contract
    • Art. 6 Para. 1 lit. a EU GDPR / UK GDPR: Explicit consent (for demo vehicles and tracking features)
    • Art. 6 Para. 1 lit. f EU GDPR / UK GDPR: Legitimate interest of the contracting vehicle owner, fleet operator, or asset finance provider in the protection of property and enforcement of contractual obligations (e.g. lease return, hire purchase recovery, theft recovery). A balancing of interests in accordance with Art. 6(1)(f) EU GDPR / UK GDPR has been conducted and is documented separately.
    • Art. 28 EU GDPR / UK GDPR: Data processing on behalf of the customer (controller)

    (4) No OEM Integration Without DPA

    Without a signed DPA, no integration with vehicle manufacturers (OEMs) or vehicle telematics interfaces will be activated. Demo accounts use static, non-real vehicle data for testing purposes only.

    (5) Sharing with Recovery Agents

    Where a fleet operator activates a recovery session, location data may be shared in real time with authorized Recovery Agents (external third parties) for the duration of the session. The legal basis for this sharing is Art. 6 Para. 1 lit. f EU GDPR / UK GDPR (legitimate interest in property protection) or, where applicable, a mandate from law enforcement. Recovery sessions are time-limited, logged, and revocable at any time by the fleet operator.

    § 10 Subprocessors and Third-Party Services

    (1) Subprocessors for Platform Infrastructure

    The platform infrastructure is operated using a European cloud service provider. This provider processes user account data (email, session tokens, audit logs) as a processor under Art. 28 EU GDPR / UK GDPR. A complete list of currently engaged subprocessors is available upon request by contacting info@dc-connected.de.

    (2) OEM Connected Vehicle Services and Third-Party Privacy Policies

    The Traice platform integrates with connected vehicle platforms and telematics services provided by automotive manufacturers (OEMs). These integrations may involve the processing of vehicle-related information such as vehicle identifiers (VIN), telematics data, and location data. Each OEM operates its own connected services infrastructure and maintains its own privacy policy governing how such data is processed.

    The following table lists the OEM manufacturers currently supported on the Traice platform, along with links to their respective connected vehicle privacy policies:

    ManufacturerConnected Services Privacy Policy
    Alfa Romeohttps://myalfaconnect.alfaromeo.com/gb/en/european-connected-vehicle-privacy-policy
    Audihttps://www.audi.com/en/privacy-audi-connect/
    BMWhttps://www.bmw.co.uk/en/topics/owners/bmw-connecteddrive/legal-information.html
    Citroënhttps://connected-vehicles-privacy.stellantis.com/
    Cuprahttps://www.cupra.com/en/owners/connectivity/seat-connect-service/legal
    Daciahttps://www.dacia.co.uk/multimedia/connected-services-data.html
    DS Automobileshttps://connected-vehicles-privacy.stellantis.com/
    Fiathttps://myuconnect.fiatprofessional.com/gb/en/european-connected-vehicle-privacy-policy
    Fordhttps://www.ford.co.uk/useful-information/terms-and-privacy/connected-car-privacy-policy
    Jeephttps://myuconnect.jeep.com/gb/en/european-connected-vehicle-privacy-policy
    Kiahttps://connect.kia.com/eu/kia-connect-privacy-notice
    Lexushttps://www.lexus.eu/ToU
    Maseratihttps://www.maserati.com/global/en/others/legal/vehicles-connected-policy
    Mercedes-Benzhttps://www.mercedes-benz.co.uk/passengercars/brand/privacy.html
    MINIhttps://www.mini.co.uk/en_GB/home/terms-and-conditions/mini-connected-legal-information.html
    Opelhttps://connected-vehicles-privacy.stellantis.com/
    Peugeothttps://connected-vehicles-privacy.stellantis.com/
    Polestarhttps://www.polestar.com/global/legal/privacy/car-privacy-notice/
    Porschehttps://www.porsche.com/international/legal/privacy/
    Renaulthttps://www.renault.co.uk/renault-connect/connected-services-data.html
    SEAThttps://consent.vwgroup.io/consent/v1/texts/SEATConnect/gb/en/dataPrivacy/latest/html
    Škodahttps://www.skoda-connect.com/en-GB/legal/index.html
    Teslahttps://www.tesla.com/legal/privacy
    Toyotahttps://www.toyotaconnected.eu/privacy-policy
    Vauxhallhttps://connected-vehicles-privacy.stellantis.com/
    Volkswagenhttps://consent.vwgroup.io/consent/v1/texts/weconnect/gb/en/dataprivacy/latest/html
    Volvohttps://www.volvocars.com/en-de/legal/privacy/privacy-car/

    The links above are provided for transparency regarding the privacy policies of the respective OEM connected vehicle services. These policies are maintained and controlled by the respective manufacturers. Depending on the manufacturer's configuration, users may be redirected to privacy policy versions applicable to the United Kingdom, the European Union, or other jurisdictions. Traice does not control how OEM providers localize, structure, or present their privacy policies and is not responsible for any regional variations, translations, or jurisdiction-specific versions displayed by those providers.

    OEM providers may act as independent data controllers with respect to vehicle data processed through their connected services infrastructure. Traice does not control the data collection performed directly by vehicle manufacturers through their connected vehicle systems. Users should review the relevant OEM privacy policy to understand how vehicle data, telematics data, VIN identifiers, or location data may be processed by the respective manufacturer.

    (3) Subprocessors for Vehicle Location (Recovery Use Case)

    In active recovery sessions, vehicle location data may be processed by:

    • The platform infrastructure provider (hosting, real-time data relay)
    • Recovery Agents named by the fleet operator (authorized third parties)

    All subprocessors are bound by data processing agreements under Art. 28 EU GDPR / UK GDPR and are contractually obligated to implement appropriate technical and organizational security measures.

    Effective Date: March 2026