ALTAWKILAT (UMA - Universal Motors Agencies), (“My-car”) a company duly incorporated and organized in accordance with the provisions of the laws of the Kingdom of the Saudi Arabia; Commercial Register No 4030120719 whose address at Jeddah; Palestine Road in front of Sahari center, PO Box 6059 - Jeddah 21442 is responsible for the collection, use, storage, treatment, transfer and protection of the personal data of the owners (the "Owner", or the "Owners", as the case may be), under the terms of the Personal Data Protection Law (PDPL) concerning the Protection of Personal Data in Possession of Individuals (the "Law"), its Regulations (the "Regulations") and other applicable legal provisions (collectively, the "Data Protection Regulations").

For the purposes of this privacy notice (the "Privacy Notice"), "Personal Data" shall be understood as (i) any data relating to an identified person, or one who can be identified directly or indirectly by way of linking data, using identifiers such as name, voice, picture, identification number, online identifier, geographic location, or one or more special features that express the physical, psychological, economic, cultural or social identity of such person; it also includes Biometric Data as defined in the same Law (the "Personal Data"); and (ii) "Sensitive Personal Data" to that information that affects the most intimate sphere of the Data Subject, or whose improper use may give rise to discrimination or entail a serious risk for the Data Subject; in particular, those that may reveal aspects such as racial or ethnic origin, present and future state of health, genetic information, religious, philosophical and moral beliefs, , political opinions, sexual state, in accordance with the Law (the "Sensitive Personal Data").

MY-CAR adheres to the guiding principles for the protection of Personal Data and Sensitive Personal Data:

  1. Lawfulness: The processing of Personal Data carried out by MY-CAR, will be carried out at all times in accordance with and in compliance with the provisions of the Data Protection Regulations.
  2. Consent: The express consent, either in writing or through digital means, of the owner of the Personal Data and/or Sensitive Personal Data, will be required for the processing thereof.
  3. Information: Through this Privacy Notice, MY-CAR discloses to the general public, information regarding the existence and main characteristics of the treatment to which your Personal Data and/or Sensitive Personal Data will be subjected.
  4. Quality: By virtue of this principle, MY-CAR assumes that the Personal Data and/or Sensitive Personal Data that are processed in accordance with this Privacy Notice, are accurate, complete, relevant, correct and updated. It will be understood that such Personal Data and/or Sensitive Personal Data processed by MY-CAR, comply with the above characteristics when provided by the owner thereof.
  5. Purpose: Personal Data and Sensitive Personal Data collected by MY-CAR may only be processed in accordance with the purposes mentioned in this Privacy Notice.
  6. Loyalty: MY-CAR undertakes to treat Personal Data and Sensitive Personal Data in a way that protects the interests and privacy of the owner.
  7. Proportionality: MY-CAR will only request from the owners those Personal Data and Sensitive Personal Data that are necessary, adequate and relevant in relation to MY-CAR's purposes.
  8. Responsibility: MY-CAR is strictly responsible for the totality of the Personal Data and/or Sensitive Personal Data that the owners share with MY-CAR.

MY-CAR uses the strictest security measures to care for, access, use and handle its own information and data, as well as the information and data of MY-CAR's employees, customers, suppliers and any other person, company or entity related to MY-CAR. Likewise, we would like to remark that MY-CAR uses the same security measures in relation to this Personal Data and/or Sensitive Personal Data as it does with its own.

This Privacy Notice is designed to make MY-CAR's privacy practices understandable to individuals in a format that is easy to read, understand and navigate. MY-CAR makes the Privacy Notice available to you for your knowledge, as well as your choices about how information is used:

Defined Terms

· Privacy Notice: Means, this Privacy Notice.

· Biometric Data: Personal Data resulting from processing, using a specific technique, relating to the physical, physiological, or behavioral characteristics of a Data Subject, which allows or confirms the unique identification of such the Data Subject..

· Economic and Financial Data: It is the information on the economic capacity, number and type of credit cards, issuing financial institution, mortgage credits, movable credits and credit history of the holders to which it refers, the resources owned and their capacity to face their debts in case of being authorized an installment sale plan with interest and reservation of title for the purchase of a used vehicle.

· Sensitive Personal Data: Means any data that directly or indirectly reveals a natural person's family, racial origin, political or philosophical opinions, religious beliefs, criminal records, biometric data, or any data related to the health of such person, such as his/her physical, psychological, mental, genetic or sexual condition, including information related to health care services provided thereto that reveals his/her health status

· Telematics Data: Means data obtained through GPS systems that may refer to location, speed, idle times, acceleration or hard braking, fuel consumption, vehicle faults and any other data derived from the use, operation and condition of the vehicle.

· ARCO Rights: Means the rights of access, rectification, cancellation and opposition.

· MY-CAR: Means ALTAWKILAT (UMA - Universal Motors Agencies)I BRANCH

· Law: Means the Personal Data Protection Law (PDPL)

· Data Protection Regulations: Means, jointly, the Law, the Regulations, and other applicable legal provisions regarding Personal Data and Sensitive Personal Data.

· GPS or GPS Systems: Means Geographic Positioning System (Global Positioning System).

· Data Subject(s): Means the owner of the Personal Data or Sensitive Personal Data.

Use of Personal Data

The Personal Data collected by MY-CAR from the Data Controllers will be used, among other things, for the following primary purposes: (i) the maintenance, development, control and implementation of the professional relationship, within the framework of the sale and purchase, lease, installment sale with interest, part-exchange and maintenance, with MY-CAR; (ii) to comply with the applicable regulations regarding the prevention of money laundering; (iii) the performance of the work of billing, clarifications and collection follow-up; (iv) the performance of the work of personnel hiring, selection processes, payroll payments and other related tasks; (v) the determination of the investment and risk profile and transactional profile; (vi) to carry out credit bureau and credit history investigations with Credit Information Companies the company deems convenient; (vii) to provide information about certain products or services related to the object of the professional relationship referred to in point (i) above, and the changes derived therefrom; (viii) to keep the Holder's information duly updated; (ix) notifications on the change in conditions of the services provided, if applicable; (x) to collect, through the GPS of the MY-CAR Vehicle, Telematics Data associated with the performance, use, operation and status of such MY-CAR Vehicle; and (xi) to evaluate the quality of the service.

In addition, MY-CAR will use your personal information for the following secondary purposes that are not necessary for the requested service, but that allow and facilitate the providing of better service, such as (i) sending information, advertising, communications and news; (ii) writing customer service reports as part of MY-CAR's experience process; (iii) other marketing, advertising or commercial prospecting purposes; (iv) home service, (v) customer service; (vi) quality and customer satisfaction surveys; and (vii) market research.

In terms of the provisions of the Data Protection Regulations, when MY-CAR does not inform the Data Subject of this Privacy Notice directly or personally but indirectly, the Data Subject shall have a period of 5 (five) business days from the date the Privacy Notice was made available to them so that they may, if applicable, express their opposition to the processing of their Personal Data or Sensitive Personal Data, since, in the event that such Holder does not express their opposition, it will be understood that they grant their consent regarding the content of this Privacy Notice to MY-CAR.

Specifically, and with respect to each area of MY-CAR, the purposes will be, by way of example but not limited to, the following, with the understanding that at all times, MY-CAR will comply with the Data Protection Regulations:

I. Visitors

  1. Control access.
  2. Maintain security in our facilities through video surveillance.

II. Customers

  1. Establish a business relationship.
  2. To comply with and maintain the contractual obligations arising from the relationship with the Data Subject of the Personal Data and/or Sensitive Personal Data.
  3. To establish security mechanisms for the protection of the people who visit MY-CAR.
  4. Evaluation of the products and services offered.
  5. Advertising services.
  6. For permission to use image, voice, photograph or video for testimonials, commercials and/or MY-CAR capsules.
  7. Call recording through MY-CAR's contact center for quality purposes.
  8. Investigation of credit bureau information and credit history, through credit information companies or bank references, for those cases in which the customer has requested an installment sale plan with interest or the study for the granting of the same.
  9. Process payment transactions.
  10. Protection against and the prevention of fraud and other legal or information security risks.
  11. Payment follow-up.
  12. Returns.
  13. Statistical data.
  14. Answer questions and respond to requests.
  15. Access and services through electronic means.
  16. Provide other services.
  17. Elaboration of databases.

III. Suppliers

  1. Establish a business relationship.
  2. Establish security mechanisms for people visiting MY-CAR.
  3. To comply with and maintain the contractual obligations arising from commercial relations.
  4. Perform internal audits, as well as audits by third parties contracted by MY-CAR.
  5. Make payments and carry out invoicing procedures.
  6. Evaluation of services.
  7. Advertising services.
  8. Elaboration of databases.

IV. Newsletter, website and mobile application

  1. Offering and evaluation of MY-CAR products and services.
  2. Sending information related to MY-CAR.
  3. If applicable, to establish a commercial and/or employment relationship between the Holder and MY-CAR.
  4. Consultations and surveys by MY-CAR.
  5. Knowledge and control of users visiting the website and downloading the MY-CAR mobile application.
  6. Storage of the traffic source.
  7. User behavior monitoring.
  8. Improve the browsing experience on the website and mobile application.
  9. Information gathering.
  10. Attend and follow up on questions, complaints and/or comments.
  11. Use of cookies.

V. Selection and Recruitment

  1. Analyze, select and qualify the most suitable candidates for the position offered within MY-CAR.
  2. Create a physical and/or digital file of the candidate.
  3. Application of tests and evaluations.
  4. To temporarily maintain a portfolio of potential candidates to fill a position within MY-CAR.
  5. Elaboration of databases.
  6. Prepare and submit, if necessary, offer letters to candidates.
  7. Conduct academic, employment and background investigations and request references.
  8. Maintain communication with the candidate during the recruitment and selection process.
  9. Incorporate potential candidates through the referral program.

VI. Administrative Staff

  1. Establish an employment and/or contractual relationship with persons providing services to MY-CAR.
  2. To give continuity and fulfillment to the work and/or contractual relationship with the people who provide their services to MY-CAR.
  3. To establish security mechanisms within MY-CAR facilities.
  4. To comply with the administrative and legal requirements made by the competent authorities and prior written orders, which are related to work and/or contractual relations.
  5. Elaboration of databases.
  6. Safeguarding of personal documentation for the generation of internal files.
  7. Authorize and deliver the necessary accesses to MY-CAR's facilities.
  8. Provide working tools necessary to perform their work.
  9. To arrange major medical and life insurance, if applicable.
  10. Training, coaching and performance evaluations.
  11. Payment and administration of payroll, benefits, salaries, wages, benefits, bonuses, reimbursements, pensions and other benefits.
  12. Recording of video calls.
  13. For authorization to use image, voice, photography or video for internal or external use in printed materials, digital, social networks, among others for internal material, advertising, training, testimonials, commercials and/or MY-CAR capsules.
  14. To carry out statistics, analyses or reviews in order to ensure the confidentiality of MY-CAR's proprietary information (such as trademarks, trade secrets and confidential information) and to measure work effectiveness; for these purposes, MY-CAR may carry out random reviews of information contained in computers and other devices provided as work tools.
  15. Conduct investigations in case of complaints, violations of applicable laws or MY-CAR's internal policies.
  16. To integrate physical and/or digital files of employees.

VII. GPS and in-vehicle monitoring systems

  1. Telematics Data Collection.
  2. Statistical data generation.
  3. Evaluation of the products and services offered.
  4. To comply with and maintain the contractual obligations arising from the relationship with the Holder of the Personal Data and/or Sensitive Personal Data.
  5. Study of driving behavior.
  6. Diagnosis of vehicle problems.
  7. Elaboration of databases.
  8. Real-time geolocation of the MY-CAR vehicle for monitoring, emergency solutions and safety.
  9. Engine immobilization in case of theft.

MY-CAR will periodically update the Personal Data and/or Sensitive Personal Data of the Data Controllers, requesting from the Data Controllers, as required from time to time, the necessary information to carry out such updates and, if applicable, authorizations.

For the above purposes, MY-CAR requires or may require the collection of the following Personal Data and/or Sensitive Personal Data from the Data Controllers, as the case may be and depending on the type of operation to be performed. For those Sensitive Personal Data that MY-CAR collects and processes, the express consent of the Data Owner will be required at all times. The Personal Data and Sensitive Personal Data collected and processed by MY-CAR may belong to the categories of (i) identification data, (ii) employment data, (iii) education data, (iv) banking and billing data, (v) vehicle identity data and (vi) Telematics Data.

I. Customers

Individuals:

Identifiers:

Name, address, SAUDI ID number, home phone number, cell phone number, signature, place and date of birth, nationality, age, proof of address, biometrics consisting of fingerprints, voice, hand geometry and facial features.

Vehicle identity data:

· Unit invoice, vehicle registration card, invoice or rebill endorsements, current, installment sale contracts with interest with reservation of title of the vehicles, telematics data consisting of vehicle performance, usage, operation and condition, speed information, continuous readings, odometer, battery usage management information, electrical system functions, information system data, safety-related data, trip data and distances traveled, repair history and vehicle service history and driving patterns.

Electronic:

E-mail, social networks, geolocation, IP address and digital signature and/or advanced electronic signature.

Legal:

Contracts or purchase orders, official identification.

Economic and Financial:

Bank account numbers, amount of the transaction or contract, amount of the requested monthly payment plan, credit history, quotes, quotations, past and present credit history (which is obtained through the information provided by the Credit Information Society(s)).

Legal entities.

Identifiers:

Name or corporate name, address, proof of address, articles of incorporation, telephone number.

Vehicle identity data:

. Unit invoice, vehicle registration card, invoice or rebill endorsements, current, installment sale contracts with interest with reservation of title of the vehicles, telematics data consisting of vehicle performance, usage, operation and condition, speed information, continuous readings, odometer, battery usage management information, electrical system functions, information system data, safety-related data, trip data and distances traveled, repair history and vehicle service history and driving patterns.

Electronics:

E-mail, social networks, website.

Legal:

Contracts or purchase orders.

Economic and Financial:

Bank account numbers, account statement, Bank where the account is held, amount of the transaction or contract, amount of the requested monthly payment plan, credit history, quotations.

Credit Information Companies:

In the case of requesting an instalment with interest with reservation of title sales plan, your credit history or any other information deemed necessary will be reviewed.

3. Main contact and/or legal representative of a legal entity.

Identifiers:

Name; address, telephone and extension(s), cell phone number, signature, place and date of birth, nationality, age, biometrics consisting of fingerprints, hand geometry and facial features.

Electronics:

Business e-mail, electronic signature and/or advanced electronic signature.

Professional:

Occupation.

Legal:

Power of attorney, contracts or purchase orders and official identification.

II. GPS, Monitoring and/or Geolocation Systems

Through GPS, MY-CAR may collect, store or process certain information from your vehicle, which will vary from model, year, and version of the vehicle.

Telematics Data associated with the performance, usage, operation and condition of your vehicle may be collected for the services MY-CAR provides, as well as vehicle enhancement purposes.

MY-CAR will be able to dynamically connect to your vehicle to diagnose and resolve problems with your vehicle. This dynamic connection also allows MY-CAR to view the current location (geolocation) of your vehicle, but such access is restricted to a limited number of employees or third parties with whom MY-CAR has joint projects under strict confidentiality.

The Data Subject may exercise at any time, under the terms and conditions set forth in the Law, the rights of access, rectification, cancellation and opposition (ARCO Rights) to the processing of the same; to achieve the above, he/she must:

1. Submit your application physically at the address indicated at the beginning of this notice or by e-mail: arco@My-car.com.

2. The request (physical or electronic) for ARCO Rights must state:

a. Name of the Data Subject of the Personal Data and/or Sensitive Personal Data, or if applicable, the name of the minor and the name of the guardian or legal representative of the minor.

b. The address or electronic means to communicate the response to your request.

c. The right you are exercising, that is, if it is the right of access, rectification, cancellation and/or opposition.

d. The clear and precise description of the Personal Data and/or Sensitive Personal Data with respect to which it seeks to exercise any of the rights set forth in the preceding paragraph.

e. In the case of the right of rectification, you must indicate, at least, the Personal Data and/or Sensitive Personal Data that are incorrect, or that you wish to update.

f. In the case of the right of cancellation or opposition, it shall indicate, at least, the Personal Data and/or Sensitive Personal Data on which such rights are being exercised, and any data or information for which the Data Subject considers that such rights should be exercised.

g. It should also point out any element or document that facilitates the location of the Personal Data and/or Sensitive Personal Data.

When exercising one of the ARCO Rights, you must prove that you are the Owner of the information you require or, if applicable, the legal representative accompanied by supporting official document (power of attorney, delegation of powers, etc.), which must be attached to the request and presented, if applicable, at the time you receive the response to your request.

The deadline for MY-CAR to respond to your request is 20 (twenty) days from receipt, and in the event that the response is favorable to your interests, it will be delivered within 15 (fifteen) days; it is not omitted to note that these deadlines may be extended. The response to your request will be made by the same means by which the request was made.

It is important for the Data Subject to take into account that not in all cases will it be possible to respond to his/her request immediately since it is possible that due to some legal obligation, his/her Personal Data and/or Sensitive Personal Data must continue to be processed.

Likewise, the Data Subject must consider that for certain purposes, the revocation of his/her consent will imply that the service he/she requested can no longer be provided, or the termination of his/her relationship with MY-CAR.

The Personal Data and/or Sensitive Personal Data that are delivered to MY-CAR will be safeguarded, preserved and protected in accordance with the provisions of the applicable legislation and its internal policies in order to maintain the confidentiality of such Personal Data and/or Sensitive Personal Data. MY-CAR has sufficient security measures for the protection, confidentiality and assurance in order to restrict access to Personal Data and/or Sensitive Personal Data to unauthorized persons, as well as the processing of Personal Data and/or Sensitive Personal Data in contravention of the provisions of this Privacy Notice. MY-CAR, its employees, representatives, subcontractors, consultants, subsidiaries, affiliates and/or related companies, third-party service providers duly contracted or with whom MY-CAR has a business relationship and/or third parties involved in any phase of the processing of Personal Data and/or Sensitive Personal Data of the Data Subject, shall keep confidentiality regarding these, an obligation that will subsist even after the end of the relationship between such persons and MY-CAR.

Address your ARCO Rights requests to:

Name of the department of Personal Data and/or Sensitive Personal Data: Department of Administration and Finance.

Address: Jeddah; Palestine Road in front of Sahari center, PO Box 6059 - Jeddah 21442

E-mail: arco@my-car.com

Telephone number: 800 244 0233

MY-CAR will delete, without notice, the data and information of the Data Controllers when they are no longer necessary for the fulfillment of the needs referred to in this Privacy Notice.

Those Personal Data of the Registrants who have decided not to purchase a service from MY-CAR will be deleted 72 (seventy-two) months after any registration they have made.

MY-CAR will not be able to delete Personal Data and/or Sensitive Personal Data when there is a contractual or legal impediment or when there is a resolution issued by a competent authority that restricts the deletion of such data.

Methods of collecting Information

MY-CAR may collect information from you or your devices in the following ways:

§  Newsletter, website, app: MY-CAR may collect your information through its websites, software applications, social media pages, email, among other digital means.

§  Application for Installment Sales with interest and other forms: MY-CAR may collect additional information from you or third parties on your behalf on applications for installment payments and other MY-CAR product forms; such information may include your date of birth, banking information, credit information and vehicle information. MY-CAR also receives your information from consumer reporting agencies, such as your creditworthiness and credit history.

§  Information may be collected from other sources, such as public databases, companies with which MY-CAR works together, third party vehicle repair or automotive service centers, as well as social media platforms.

§  MY-CAR centers: MY-CAR may collect your information when you are not connected to any network, i.e., when you visit MY-CAR centers, branches, hubs, workshops, as well as data from your vehicle at such sites.

§  Device: Your device and most browsers collect certain information automatically, such as your Media Access Control ("MAC") address, computer type (Windows or Macintosh), screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type and version, and the name and version of the digital services the Cardholder is using. MY-CAR uses this information to verify that the digital services are working properly.

§  MY-CAR will also collect information in a form that, by itself, does not permit direct association with any specific individual. MY-CAR may collect, use, transfer and disclose, for any purpose, data that does not personally identify an individual. If non-personally identifiable data is combined with an individual's personal information, the combined information will be treated as personal information for as long as it remains combined.

Protection of Personal and/or Sensitive Data

MY-CAR is committed to protect your Personal Data and/or Sensitive Personal Data and to implement appropriate administrative, technical, and physical security measures to protect against any unauthorized or unlawful processing and against any accidental loss, destruction, or damage. These measures include policies, procedures, employee training, physical access control and technical elements related to information access controls.

In the event of a security breach at any stage of the processing of your Personal Data and/or Sensitive Personal Data, which significantly affects your economic or moral rights, MY-CAR will immediately notify you by email or if it cannot contact you by email, then it will use its website or mobile application so that the Data Subject can take the necessary measures corresponding to the defense of his or her rights.

Cookies and Web beacons

MY-CAR uses various technologies that improve the efficiency of its websites, including the user experience when browsing MY-CAR sites, so we consider it necessary to make you aware of the definition of these tools:

Cookies: These are small blocks of information that are used to collect and store information from the websites you visit, to later send it to your browser. You are reminded that, as the Holder, you can disable or adjust the use of cookies by following the procedures of the internet browser you use through the following links:

· Internet Explorer: https://support.microsoft.com/help/17442/windows-internet-explorer-delete-manage-cookies

· Mozilla Firefox: http://support.mozilla.com/en-US/kb/Cookies

·Google Chrome http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95647

· Safari: http://support.apple.com/kb/PH5042

· Opera: http://www.opera.com/browser/tutorials/security/privacy/

· Adobe (flash cookies): http://www.adobe.com/privacy/policies/flash-player.html

In case you disable cookies, you may experience some anomalies or failures when using MY-CAR digital services.

Web Beacons: May refer to a visible or hidden image embedded within our website or email.

 

Privacy Notice Update

MY-CAR reserves the right to make changes or updates to this Privacy Notice at any time to comply with legislative or jurisprudential reforms, internal policies or new requirements, being that the updated and applicable version will at all times be published through the Web Page www.my-car.com.

MY-CAR undertakes to keep the Holder informed of any changes that this Privacy Notice may undergo through the Website www.My-car.com and its mobile application, integrating any modification or update during a maximum period of 10 (ten) working days after the change is made.

Any modification to this Privacy Notice may be notified to the email address you have registered on the website and/or mobile applications of MY-CAR or through any other means, whether oral, printed or electronic that MY-CAR considers suitable for this purpose. In addition, you may request at any time the Privacy Notice by writing to the following email: arco@My-car.com

If you do not express your opposition or refusal to the provisions of this Privacy Notice, it is understood that by using MY-CAR's website and mobile application, you consent to the terms and/or primary and secondary purposes of the processing of your Personal Data and/or Sensitive Personal Data in accordance with this Privacy Notice.

 

Date of last update: Feb 2024