Data Protection Notice for the use of ZF's Mobile Apps

§ 1 Information about the collection of personal data

(1) In addition to our online offering, we provide you with a mobile app that you can download to your iOS and Android device. Below we provide information about the collection of personal data when using our mobile app.

Personal data is all data that can be related to you personally, e.g. B. Name, address, email addresses, user behavior as well as log data and GPS information.

(2) The person responsible in accordance with Article 4 Paragraph 7 of the EU General Data Protection Regulation (GDPR) is [name, summons able address, email address] (hereinafter referred to as “ZF”, “we” or “us”). You can reach our data protection officer at datenschutz@zf.com or at our postal address with the addition “Regulatory Security Compliance and Data Protection”.

(3) When you contact us by email or via a contact form, we will store your email address and, if provided by you, your name and telephone number in order to answer your inquiries. We delete the data arising in this context after storage is no longer necessary or - in the case of legal retention obligations - restrict processing.

(4) If we use commissioned service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. We also mention the defined storage period criteria.

§ 2 Collection of personal data when using our mobile app

(1) When you download the mobile app, the necessary information is transferred to the App Store, in particular your username, email address and customer number for your account, time of download, payment information and the individual device code. We have no influence on this data collection and are not responsible for it. We only process the data to the extent necessary to download the mobile app to your mobile device.

When you use our mobile app, we collect the following log data, which is technically necessary for us to offer you the functions of our mobile app and to ensure stability and security (legal basis is Art. 6 Para. 1 S. 1 lit. f GDPR):

(3) ZF will not use your personal data for purposes that are not consistent with the original purposes for which they were collected.

We process and use the above data for the purpose of (1) providing ZF apps and their functionalities; (2) improving the functions and functionalities of the ZF Apps; and (3) preventing and detecting misuse and malfunction of the ZF Apps, including troubleshooting.

The processing and use of the data is based on legal provisions, which justify these processes on the basis that the processing is necessary for the fulfillment of the purchase and use contract for the ZF App; or ZF has a legitimate interest in ensuring the functionality and error-free operation of the ZF apps and in being able to offer services tailored to the needs of the user.

(4) Cookies

The mobile app does not use cookies. Nevertheless, cookies may be used when using the app's internal browser. Cookies are small text files that are stored in the device memory of your mobile device and assigned to the mobile app you use. Cookies allow the entity that sets the cookie (here: us) to receive certain information. Cookies cannot run programs or transmit viruses to your mobile device. They serve to make mobile apps more user-friendly and effective overall.

a) This mobile app uses the following types of cookies, the scope and functionality of which are explained below:

b) Transient cookies are automatically deleted when you close our mobile app. These include, in particular, session cookies. These store a so-called session ID, which can be used to assign various requests to your mobile app. This allows your mobile device to be recognized when you use our mobile app again. The session cookies are deleted when you log out or close the app.

c) Persistent cookies are automatically deleted after a specified period of time, which may differ depending on the cookie. You can configure the settings of your mobile operating system and the app according to your wishes, e.g.  Decline to accept third-party cookies or all cookies. We would like to point out that you may not be able to use all functions of our mobile app.]

Possible deviation: Instead of cookies, we use a technology that is comparable in function.

§ 3 Data storage/data deletion

In principle, we only process your personal data as long as this is necessary to provide our offer in connection with the use of our app and associated services or as long as we have a legal obligation to continue storing it (applicable, for example, to contracts and invoices due to tax and commercial law retention obligations).

Log data will be deleted after 90 days if it is no longer required for the purposes described.

§ 4 Transfer of data to partners

ZF is a global company in Germany and part of the ZF Group. The data you provide to us when downloading and using the ZF Apps is stored in our central customer database in Germany and shared within the ZF Group to manage your relationship with ZF and the ZF Group.

The transfer and use of the data is based on legal provisions that justify these processes on the grounds (1) that the processing is necessary for the fulfillment of the purchase and use contract for the app; or (2) ZF has a legitimate interest in sharing this data within the ZF Group for internal administrative purposes.

Due to shared central IT systems within the ZF Group, your personal data may be processed outside your local jurisdiction and the European Economic Area, including in the following countries. Mexico, Canada, Ukraine, Turkey, Russia, China, Switzerland, Serbia, Japan, India, Australia, Singapore, Taiwan, Indonesia, Korea, Thailand, Malaysia, Iraq, Philippines, South Africa, Algeria. If we are not required to transfer your personal data from your local jurisdiction in accordance with the applicable data protection laws in your local jurisdiction, we will take appropriate measures to ensure compliance with these requirements.

Any transfer of your personal data to a third country (i.e. that is not a member of the EU) will continue to comply with all applicable data protection laws.

To the extent that a third country is not recognized by the European Commission or in your local jurisdiction to ensure an adequate level of protection, ZF will take appropriate measures to ensure adequate protection of your data by entering into data transfer agreements with third country recipients with standard contractual clauses in accordance with the Decisions of the European Commission provide for appropriate measures. You can request a copy of these agreements via the ZF data protection officer ("DSB"), whose contact details can be found under § 1.

In order to provide certain applications and services, we share your data with specific third parties who provide services on our behalf. We may use third party service providers to offer or facilitate services on our behalf, such as a newsletter service provider, IT providers, IT support and maintenance, analytics providers, communications service providers, web hosting providers and other service providers acting as data processors act and therefore process the data on our behalf and under our instructions. These third parties are prohibited from using your personal information for their own commercial, promotional or other purposes other than those expressly instructed and must follow our express instructions and maintain appropriate security measures to protect your personal information.

We may disclose personal information if we are otherwise required to do so in the course of a legal proceeding, by legal order, or by applicable law, rule or regulation.

§ 5 Security

ZF takes all necessary technical and organizational measures to ensure an appropriate level of protection of your data and, in particular, to protect against the risks of accidental or unlawful destruction, alteration, manipulation, loss or unauthorized access. All security measures (especially with regard to the confidentiality, availability and integrity of the data) are constantly being improved in line with technological developments.

§ 6 Your rights

(1) You have the following rights towards us with regard to personal data concerning you:

(2) You also have the right to complain to a data protection supervisory authority that is responsible for your place of residence or to the supervisory authority responsible for ZF (the Baden-Württemberg State Commissioner for Data Protection and Freedom of Information) about the processing of your personal data in ours to complain to companies.

(3) Right to withdraw consent

§ 7 Other applications, websites and services

You may be able to access other services and applications that process your personal data via the ZF Apps. This use of personal data is explained in separate data protection notices. Our ZF apps also contain links to other websites. ZF is not responsible for the use and protection of personal data on these other sites. We encourage you to be aware of this when you leave the ZF app and to read the privacy information on these websites.

§ 8 Contact

In the event of a query regarding our use, integrity and/or accuracy of your personal data, or if you wish to exercise any of your rights set out in Section 6, you may contact us by email at datenschutz@zf.com.

The contact details of our data protection officer are as follows:

ZF Friedrichshafen AG

Officer for corporate data protection

Löwentalerstraße 20

88046 Friedrichshafen

Germany

§ 9 Changes to this data protection declaration

Because the collection and processing of your data may change over time, we may also change this privacy policy so that it always accurately reflects our data processing practices. Please read this data protection information again from time to time.

Last change: January 13, 2020