As part of our commitment to you, we ensure that your Personal Data is accurate, confidential, and secure and allow you to access, correct, or erase your Personal Data. Please note that in order to offer our Services, we transfer your Personal Data to Canada and to certain service providers which may be located in other countries.
SPECIAL NOTICE REGARDING CHILDREN
Our Services are not directed to people under 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with Personal Data without the proper consent, please contact the relevant Data Protection Officer at the address listed in Section 15 below and we will take steps to remove such information and terminate the account, as necessary.
Table of Contents
1. Who processes your information?
Your contract and Account may be with PayByPhone Technologies Inc. or one of its subsidiaries, including without limitation PayByPhone US Inc. (United States), PayByPhone Limited (United Kingdom), PayByPhone SAS (France, Monaco, Netherlands, Belgium), PayByPhone Suisse AG (Switzerland), PayByPhone Italia S.r.l. (Italy) or sunhill technologies GmbH (Germany). Collectively, all of these entities are referred to here as “PayByPhone”. The applicable contract party depends on the country from which you open your Account and in which you conduct your Parking Sessions, as set out in the Terms and Conditions in greater detail.
Your PayByPhone contract party and PayByPhone Technologies Inc., incorporated in Canada, are jointly responsible for the processing of your Personal Data, including in the context of the registration for and general use of the Services, product and system development including ensuring IT security, and for advertising and marketing purposes. The controllers have agreed among themselves who will fulfill specific obligations with respect to the data processing and shall work closely together. In particular, they will provide each other with the information necessary to fulfill their respective obligations and to enable the exercise of data subject rights.
PayByPhone is committed to complying with all applicable privacy laws (“Data Protection Laws”), including without limitation the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”), the European General Data Protection Regulation (“GDPR”) and the UK General Data Protection Regulation (“UK GDPR”).
Facilities Operators for the locations where you park process parts of your Personal Data which relate to the Parking Sessions at their parking facilities and which, among other things, enable them to effect parking validation, enforcement and fines.
For information on additional processors of your Personal Data, see section 5 below.
2. What information is processed?
We only collect and process Personal Data that is required to create an Account and to offer the Services you request and to communicate with you.
You and anyone you authorize to use your Account provide some of this information directly when you create an Account, use a Service or contact us for support, including:
In some cases, for example when you permit another party, such as your employer, to pay for parking sessions on your Account through linking your Account to theirs and adding their payment method to your Account, we ask you or the owner of the payment method to provide your:
You may also give us additional information when you choose to open your Account using information from third party services you already have, including:
You may also choose to give us additional information to obtain a Service or receive communications from us including:
You may stop providing us this additional information at any time by adjusting your Account settings in the App, on the Site or by contacting us.
We also collect other data indirectly when our software interacts with your device and when we use technologies like cookies and error messages. This may include:
Please see our Cookies Policy for more information.
We also sometimes obtain data about you from third parties (including parking operators, payment facilitators, parking enforcement agencies and hardware/software manufacturers). For example:
3. Why is your information processed?
We process your information so that we can offer you our Services and communicate with you.
When we process your Personal Data in relation to our Services (including, without limitation, for customer service, security messages, processing payments, sending receipts and reminders of parking session expiry) and our related internal purposes (including administration, risk management, compliance, product development, research, debt collection, financial audit, security and record keeping,) we rely on the lawful basis of having a contractual relationship with you.
When we process your information to communicate with you (including about our and our affiliate promotions, events occurring in localities where you recently parked, targeted advertising and marketing of services), we rely on the lawful basis of consent to process your Personal Data and we are committed to obtaining that consent in a legitimate way.
You can provide your consent in the App, on the Site or verbally to our authorized representatives. You will be asked specifically if you would like to opt-in to each of these communications and you can choose whether to receive some, all, or none of these communications.
Subject to Data Protection Laws, we may collect, use, store or share Personal Data without your consent in the following limited circumstances:
Where permitted by law, we will process your Personal Data on the basis of our legitimate interest, for example when contacting you about new product offerings and conducting customer satisfaction surveys to enhance our services or sending you newsletters and parking, vehicle or road use related service and security messages. For this type of processing, we will always take into consideration the effect of such processing on your fundamental rights and freedoms, and if we believe that the communication would be an infringement on your rights, we will not proceed with that communication.
PayByPhone Technologies Inc. acts on the basis of legitimate interest in the group-wide use of a central IT infrastructure (including for registration and processing of parking transactions, product and system development and ensuring IT security).
4. How is your information processed?
We only process your Personal Data for the purposes for which we have a lawful basis.
Some processing associated with the purpose of providing you our Services include:
Some processing associated with the purpose of communicating with you include:
5. With whom is your information shared?
We will never use or disclose your Personal Data unless we have a lawful basis to do so.
We do not sell your Personal Data to parties outside of PayByPhone. We will not rent, license or exchange customer lists or your Personal Data to other parties outside of PayByPhone, except as we describe below.
No Personal Data will be shared with third parties, except as required to offer the Services to you or as you specifically consent. We may:
6. Where is your information transferred?
We will transfer your Personal Data to PayByPhone in Canada, irrespective of the country in which you reside or from which you provide Personal Data.
The transfer of your Personal Data is done in a secure way and in compliance with Data Protection Laws. The European Commission has found, on the basis of Article 45 of the GDPR, that Canada, while not bound by the GDPR, ensures an adequate level of protection of personal data. This adequacy decision took into account Canada's domestic law, its supervisory authorities and international commitments it has entered into.
We may also transfer your Personal Data to third party suppliers in other countries to provide part of our Service to you. In our agreements with these parties, we require them to protect your Personal Data and to adhere to Data Protection Laws and we make sure that they have provided appropriate safeguards.
Your personal information may be accessible to regulatory, law enforcement and national security authorities of those jurisdictions, and may be subject to disclosure in accordance with the laws of those countries.
7. How is your information kept safe?
We have put appropriate technical and organizational protection measures in place to protect your Personal Data from unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks.
PayByPhone commits to the following security measures:
We will continually review and update our security policies and controls as technology changes to ensure the ongoing security of your Personal Data.
8. How long is your information retained?
PayByPhone will retain your data in accordance with Data Protection Laws.
We will retain your Personal Data (including information related to each parking session and to each of your Transactions) for only so long as is reasonably necessary to fulfil the purposes for which the information was collected or as required by law.
If you create an Account with us, we will retain your Personal Data as long as you have that Account. If you close your Account or if there is no activity on your Account (including no log-ins and no parking sessions) for a period of more than 3 years, we will mark your Account in our database as "Closed," but may have to keep some information for as long as is required to comply with our legal obligations or 7 years, whichever is shortest.
9. What rights do you have with regards to your information?
According to the controller arrangement between your PayByPhone contract party and PayByPhone Technologies Inc., your PayByPhone contract party is responsible for fulfilling the obligations related to data subject rights.
You can contact the relevant local Data Protection Officer at the address set out at Section 15 below with requests related to the rights described below. You are also free to assert your data subject rights against PayByPhone Technologies Inc. at the contact listed in the first line of Section 15 below.
Any request must be made to PayByPhone in writing and provide sufficient detail to identify the Personal Data that it relates to. PayByPhone may request that you verify your identity. PayByPhone will address the request within 30 business days or provide written notice of an extension where additional time is required to fulfil the request.
You have the right to request access to your Personal Data, to know how we use it and to whom we have disclosed it, subject to certain limited exceptions.
You can assert this right by accessing your Account on the Site or the App. You may also contact us with a Personal Data access request and we will take all reasonable steps to assist you with any legitimate request for access.
We may not be in a position to respond to a data access request. If a request is refused in full or in part, we will notify you in writing and provide the reasons for refusal and the recourse available to you.
You have the right to make sure that your Personal Data is accurate.
We make reasonable efforts to ensure that all of our users’ Personal Data is kept accurate and complete. If you are the Account holder, we provide you with tools to access or modify the Personal Data associated with your Account. You may also request that we correct your Personal Data.
If your Personal Data is demonstrated to be inaccurate or incomplete, we will, so far as practicable and as soon as practicable, correct your Personal Data and send the corrected information to any organization to which we disclosed the Personal Data in the previous year. If the correction is not made, we will note your correction request in your file.
You have the right to obtain from us the erasure of your Personal Data.
At any time, you may close your Account and uninstall the App. You may also request that we erase your Personal Data.
In the event that you delete your Account and the App or request erasure of your Personal Data, we will use commercially reasonable efforts to remove your Personal Data from our files, however, we may not be able to delete some of your Personal Data to the extent that it is still required for discharging our legal obligations. We may also retain, use, and share your Anonymized Data that we previously collected prior to your deletion of your Account.
Withdraw consent (when processing is based on consent)
As mentioned above, when PayByPhone is relying on consent as the lawful basis for processing your Personal Data, you may remove such consent at any time, examples of this include:
Please note that changing your consent may result in a change in your Services and experience.
Lodge a complaint
You have the right to communicate with PayByPhone about any issues that you may have relating to your Personal Data.
You may also write to the Privacy Commissioner of Canada or the privacy supervisory authority in your country.
11. App store; links to other websites
Your app store (e.g., iTunes or Google Play) may collect certain information in connection with your use of the App, such as Personal Data, Payment Information, geolocational information, and other usage-based data. We have no control over the collection of such information by a third-party app store, and any such collection or use will be subject to that third party’s applicable privacy policies.
Some pages on the Site and the App include links to third party websites. These third-party sites are governed by their own privacy statements, and we are not responsible for their operations, including but not limited to, their information practices. You should review the privacy statement of those third-party sites before providing them with any personally identifiable information. PayByPhone is not responsible for the processing of Personal Data on those third-party sites. We strongly advise you not to share any personal information about your Account, including your account number or password, on any social media site or with any third-party application that is not operated by PayByPhone.
12. Applicable law
13. Changes to this policy
14. Further questions
If at any time you would like to contact us with your views about our privacy practices, or with any enquiry relating to your personal information, you can do so by emailing us at the addresses listed below.
Contact information for PayByPhone Data Protection Officer:
PayByPhone is owned by Volkswagen Finance Overseas B.V.
Last updated: 2023-02-13