The controller within the meaning of data protection and privacy laws is:
Porsche Cars Australia Pty Ltd
109-111 Victoria Parade
Collingwood VIC 3066
If you have questions or suggestions regarding this Policy or our privacy practices and procedures, please feel free to contact our Privacy Officer at the address shown below. You may also contact us using these details if you wish to access or correct the personal data we hold about you, or to make a complaint.
Porsche Cars Australia Pty Ltd
109-111 Victoria Parade
Collingwood VIC 3066
The subject matter of data protection is personal data. This means any information concerning an identified or identifiable individual (so-called “data subject”). The types of personal data we may collect, use and disclose includes personal information such as your name, postal address, e-mail address or telephone number, and also information that arises during and via the use of the Porsche Digital Service Infrastructure, such as details about the start, end and scope of use of our website and your IP address.
Even if you use our website without logging in, data will be or may be collected. The following text provides an overview of the different types of collection and processing of data and the respective purposes of processing and legal bases.
3.1 Automated data collection
When you access our website, your internet browser automatically transfers data for technical reasons. The following data are stored separately from other data that you may transmit to us:
For the purposes of the GDPR, this data is processed on the basis of article 6(1)(f) of the GDPR, to provide the service, to ensure technical operation and detect and eliminate interference. The purpose of processing is to enable and facilitate the use of our website and its technical functionality. When you visit our website, this data will be processed automatically. Without this provision, you will not be able to use our services. We do not use this data for the purpose of drawing conclusions about you.
We normally delete this data after 13 months, unless by way of exception we need it for the purposes set out above. In such cases, we will delete the data immediately after the purpose ceases to exist.
In addition, this data is also processed without being assigned to a specific person for the purposes of analysis and performance improvements. See paragraphs 3.2 and 3.3 for more detail.
3.2 Data processing for improvement of our online offer
The automated data we collect mentioned in paragraph 3.1 is furthermore used to improve the performance of Porsche Digital Service Infrastructure, to ensure the availability of our platforms, to optimise user experience, to further evaluate your use of the website, to compile reports on website activities for us, and to provide other services related to website and internet usage.
We process your data based on our legitimate interest in the performance and availability of our products, as well as in the analysis of the use behaviour of our website visitors. The data will be stored for 13 months and not assigned to any particular person. In addition, we store cookies as part of the processing described here. See paragraph 3.3 for more detail.
We process information about our users via cookies to fulfil the contract with our users and for our legitimate interest in the user-friendly and secure provision of our websites.
When you register for and use the Porsche Digital Service Infrastructure, personal data are collected, processed, and used, and may be transmitted to third parties as described below, in order to provide you with all services with regard the Porsche Digital Service Infrastructure and to fulfil our contractual obligations that exist in this context. We perform all of the data processing described in this section either – to the extent indicated – based on your consent or to fulfil our contract with you.
4.1 Registration process
To use My Porsche, registration on the Porsche Digital Service Infrastructure is required. Registration can take place in two ways, and you are free to choose the method of registration:
1. Invitation to register from authorised dealer
If you wish, your authorised dealer will enter the data you have communicated to the dealer for you via the dealer’s access to our systems. In this case, you will then receive, for example, a link sent by e-mail via which you are required to confirm your registration. A second feature will be used for additional verification. One example is a code sent via text message that you then enter in My Porsche.
In the event that registration has not taken place via an authorised dealer, you can register yourself and enter your data on your own. In selected countries, you can also add a vehicle and use additional digital services that require vehicle ownership. To do this, you will also have to upload a copy of an identification document and proof of ownership and – if you are not the owner of the vehicle – a power of attorney from the vehicle owner after entering your vehicle identification number. These documents will be reviewed based on our verification criteria. As proof of successful verification, we will also collect, use and store the names, dates of birth, places of birth, addresses, and validity information of the documents shown in the respective identification documents and the vehicle identification numbers, owner names, and addresses shown in the ownership documentation. After the verification process is complete, the copies of the documents will be deleted. Following successful verification, you will receive, for example, a link sent by e-mail via which you are required to confirm your registration. A second feature will be used for additional verification. One example is a code sent via text message that you then enter in My Porsche.
3. Required information during registration
When you register on My Porsche, you will be required – in case of self-registration – to enter your e-mail address (Porsche ID), a password, your name and any titles and suffixes, contact and address information, mobile phone number, and, where applicable, the language in which you wish to communicate with us or – in case of registration through an authorised dealer – to confirm this information in My Porsche. Our collection, use and disclosure of this information is necessary in order to set up and manage a Porsche ID user account for you so that you can use the full range of services and functions offered by My Porsche and the Porsche Connect Store. In selected countries, you can also use our offerings as a potential customer. In this case, you are only required to state your name, e-mail address, and a password. Amongst other things, we need to collect, use and disclose this information – and, where applicable, further information – in order to be able to respond to requests, questions, and criticism. We also store the time of your last login. During registration, we will perform a plausibility check of your name and address information.
4. Voluntary information during registration
Within the scope of your registration, you will also have the opportunity to enter additional voluntary information, such as additional name information (e.g. academic titles, etc.), company contact information, date of birth, additional phone numbers, credit card information (this information is stored exclusively by the payment service provider), and your vehicle license plate number and a personal vehicle name. You can also provide information on your interests and preferences and your desired contact channels. Please note that this information is not required in order to register, and that it is entirely up to you to decide whether you wish to communicate this information to us.
4.2 Porsche Digital Service Infrastructure: Data processing after registration
If you have registered for a Porsche ID user account, we will exchange basic information about your user account and your vehicles with responsible authorised dealers in order to be able to serve you via our dealer organisation. In addition to the vehicle identification number, we transfer and disclose your user name (Porsche ID), the technical or sales availability of services and product offers for your user account or vehicle, as well as relevant events as part of the creation, modification or deletion of your user account, the linking of vehicles, the selection of traders, or the activation or deactivation of services.
If you have selected an authorised dealer and provided your consent, your personal data stored with My Porsche, in particular contact data, support, contractual and service data, as well as data about your interests, vehicles and services used will also be exchanged with the authorised dealer and synchronised with any personal data stored about you. If you no longer wish data to be transferred in the future, you can change this accordingly in your user settings. The aforementioned data will no longer be exchanged with the authorised dealer from that date. For technical reasons, both your consent and the termination of data exchange may take up to 24 hours to take effect. For the purposes of the GDPR, the legal basis for processing your data in this connection is your consent.
4.3 Deletion of your Porsche ID user account
If you delete your Porsche ID user account, your My Porsche profile will also be deleted. As far as data must be stored for legal reasons, these are blocked (so-called processing limitation). The data is for further use, especially for the use of services, and then is no longer available. The functionality of the services may be limited or eliminated. My Porsche will then no longer be available to you. If further responsible individuals within the Porsche Group and its sales organisation process personal data within their own responsibility, the processing of this data remains unaffected. If, on the basis of your consent, data has been exchanged with an authorised dealer of your choice, we inform the dealer about the deletion of your Porsche ID user account.
We may also collect, use and disclose your personal data:
We may disclose your personal data to the following categories of recipients:
Internal recipients: Within PCA, those persons who need this for the purposes mentioned in this Policy have access.
External recipients: We may disclose your personal data to external recipients outside of PCA if this is necessary for the provision of the Porsche Digital Service Infrastructure, for the purposes described in this Policy, if another legal basis for disclosure exists, or if we have your consent.
External recipients may include:
a) Porsche Group companies and third party service providers
Porsche Group companies or external service providers we use for the provision of services, for example in the areas of technical infrastructure and maintenance for the Porsche Connect App. These recipients are carefully selected by us, and regularly checked, to ensure that your privacy is maintained. The service providers may only use data for the purposes specified by us.
b) Public bodies
Authorities and state institutions, such as public prosecutors’ offices, courts or financial or tax authorities, to whom we must disclose personal data for legal reasons.
c) Private bodies
Dealers, cooperation partners or support personnel to whom data is disclosed on the basis of consent, for the execution of a contract with you, or for other purposes in connection with our products, services or offers, such as Porsche Centres, financing banks, other service providers or transport service providers.
We may also disclose your personal data to any new owner of PCA or to third parties in accordance with legal requirements or our legal rights.
We may disclose data, including personal data, to Porsche group companies and our service providers that may be located overseas.
If your personal data is disclosed to a recipient that is located overseas, we ensure before disclosure that there is either an adequate level of data protection and privacy within the recipient’s organisation (e.g. through the operation of data protection laws in the offshore jurisdiction or through self-certification on the recipient’s part for the EU-US Privacy Shield or agreement of “EU standard contractual clauses” with the recipient or other similar contractual protections) and/or that your consent has been received in sufficient form.
You can contact us to receive an overview of the recipients in third countries and a copy of the specificcontractual provisions that have been agreed to ensure an adequate level of data protection and privacy. To do this, please use the information stated in paragraph 1.
Further to the foregoing you consent to the offshore disclosures contemplated by this document (including in paragraph 3), and you understand that we may not be able to, and are not required to take steps to, monitor, control or determine whether the entities mentioned, as located in various countries, are able to handle your data in accordance with the Australian Privacy Principles in the Privacy Act and that you will not be able to seek any redress under the Privacy Act for any mishandling of your personal information.
8.1 Handling payment information
To process payments for paid offers within the framework of My Porsche and the Porsche Connect Store, we use the payment service provider Adyen Australia Pty Ltd (ACN 162 682 411) of 1/255 Riley Street, Surry Hills NSW 2010, Australia. Management of your credit card information as well as the processing of payments is carried out exclusively via systems of the payment service provider. If you enter your credit card information, this is done directly via an input field of the payment service provider, who stores this information independently, and uses it for your payments. We do not collect and store any credit card information from you. Please inform the payment service provider about the type, scope and purpose of the collection and use of your credit card information.
8.2 Care through the Porsche Centre
You have the opportunity to be supported by our network of Porsche Centres when using the Porsche Digital Service Infrastructure. For example, you can have changes made to your personal customer data, as well as online service bookings, and other services through the respective Porsche Centre telephone contact. To do this, you must provide your Porsche ID to your Porsche Centre. After identifying yourself by naming your Porsche ID or other security features, your Porsche Centre accesses your Porsche ID user account or My Porsche directly and makes the desired changes/activities on your behalf. Your Porsche Centre staff only perform the tasks that you explicitly want. In addition, if you have consented to be contacted through the appropriate channels, your Porsche Centre may actively contact you by phone/text message/email/instant messaging as required, to assist with registration, service activation and use.
For the purposes of the GDPR, the legal basis for processing your data via your Porsche Centre is fulfilment of the contract.
8.3 Provision of service and warranty information
In order to provide you with information about your vehicle, ongoing warranties and recall campaigns in My Porsche, we process equipment and vehicle master data, such as the vehicle identification number, ongoing warranties, the model year and a model image. The processing of your personal data takes place for fulfilment of our contract with you, and also for the other purposes outlined in this Policy. The aforementioned data is provided to us for these purposes for the duration of the existence of your vehicle relationship.
8.4 Service appointment request
To request service appointments with authorised dealers and service companies via My Porsche, we may disclose customer and vehicle data to companies of your choice at your request. If you provide us with your consent to do so as part of a service request via My Porsche, we will disclose your name, address, telephone number, email address, Porsche ID, vehicle identification number, vehicle model, the service dates you have selected, the scope of service you desire, and a supplementary message to your inquiry from you, as well as the desired contact channels for the dealer or service company chosen by you for the relevant inquiry. The disclosure of your personal data is based on your consent within the context of the relevant service request.
We store your respective service request for fulfilment of our contract with you, and for the other purposes set out in this Policy, for the duration of the existence of your user account.
As the subject of data processing, you have numerous rights under applicable data protection laws, which may include:
Right to information: You have the right to receive information regarding the data we store regarding you personally.
Right of rectification and cancellation: You may demand the correction of incorrect data, and insofar as the legal requirements are met, the deletion of your data.
Data portability: If you have provided us with data based on a contract or consent, you may, subject to legal requirements, require that you receive the data you provide in a structured, common and machine-readable format, or that we transfer it to another person in charge.
Objection to data processing in the case of the ”legitimate interest” legal basis: You may have the right, for reasons arising from your particular situation, to object at any time to the processing of data by us, insofar as, under the GDPR, this is based on the legal basis ”legitimate interest”. If you make use of your right of objection, we will stop processing your data, unless we can prove, in accordance with the legal requirements, compelling legitimate reasons for further processing that outweigh your rights.
Revocation of consent: To the extent that you have issued a statement of consent to the processing of your data to us, you can revoke it at any time, with effect for the future. The legality of the processing of your data up until the time of revocation will be unaffected by this.
Making a privacy complaint: You may make a complaint to us in relation to privacy by contacting us using the details in paragraph 1. Our Privacy Officer will respond to your complaint as promptly as possible. If our Privacy Officer is unable to resolve your complaint, you may wish to contact the Office of the Australian Information Commissioner.
Right to complain to the supervisory authority: In addition to the above, you can also file a complaint with the relevant supervisory authority if you believe the processing of your data violates applicable law. To do this, you can contact the data protection authority with jurisdiction over your place of residence or country or the data protection authority that has jurisdiction over us.
Your contact with us: In addition, you can contact us free of charge if you have any questions regarding the collection and/or processing of your personal data, your rights as a data subject, and/or any consent that may have been granted. To exercise any of the rights mentioned above, please contact firstname.lastname@example.org or use the mailing address specified in paragraph 1 above. When contacting us, please make sure we are able to clearly identify you personally.
We provide for all necessary technical and organisational measures, in accordance with the state of the art, in order to ensure a level of protection appropriate to the risk in compliance with the applicable statutory requirements.
Websites of other providers that are linked to from this website were and are designed and provided by third parties. We have no influence over the design, content, or functionality of these linked websites. We expressly distance ourselves from all content of all linked websites. Please note that the third-party websites linked to from this website may install cookies of their own on your end device and/or collect personal data. We have no influence over this. Please contact the providers of these linked websites directly as appropriate for information in this regard.
Last updated: 5 November 2018
In My Porsche or the Porsche Connect Store, you can request My Porsche services or Porsche Connect services and activate service licenses. To do this, you must be registered with My Porsche and have a Porsche ID user account. Depending on the service, you can use and manage My Porsche services and Porsche Connect Services via various Porsche apps and My Porsche, and if available for your vehicle, in your vehicle via wireless network connection.
If you have questions or suggestions regarding this statement or our privacy practices and procedures, please feel free to contact our Privacy Officer at the address shown below.
Porsche Cars Australia Pty Ltd
109-111 Victoria Parade
Collingwood VIC 3066
You can request individual or multiple My Porsche services and Porsche Connect services and activate service licenses. When you select the respective service or service package, you can also view the specific information on the collection, processing, use and disclosure of data within the scope of the service in question under the product descriptions for the individual services. To perform and fulfil a request and the contractual relationship with you that is associated with it, we process and use not only the relevant requested information, but also your personal data that was collected upon registration. You can change your billing address before the request process is complete. In this case, we will use this address information that you have provided for billing and invoice processing purposes.
To process payments for paid services within the scope of My Porsche and Porsche Connect, we use the payment service provider Adyen (see paragraph 8.1 of the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store). The management of your credit card information and processing of payments are performed exclusively via systems of the payment service provider. When paid services are requested, we transmit to the payment service provider the amount invoiced and a one-time transaction key that can be used to allocate your payment for purposes of processing the payment. To the extent that you enter your credit card information within the scope of requesting services, this takes place directly via an entry field of the payment service provider, which stores this information independently and uses it for your payments. We do not collect or store any of your credit card information whatsoever. Therefore, please consult the payment service provider for information on the nature, scope, and purpose of the collection and use of your credit card information. For further information regarding the handling of credit card information and processing of payments, please see the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store.
After the request process is complete, you can activate the services. When you do this, the authorisation for use will be stored by the system, and the list of available services will be updated accordingly.
Unless stated otherwise, for the purposes of the GDPR, we carry out the processing described in this section for fulfilment of our contract with you on the basis of article 6(1)(b) of the GDPR.
You can use the My Porsche services and Porsche Connect Services that have been requested, depending on the service, in your vehicle (to the extent available for your vehicle) via wireless network connection or via further end devices in My Porsche, your Porsche Connect App, and, where applicable, also from multiple or all access points. To this end, your vehicle or the respective end device will connect to the Porsche Digital Service Infrastructure.
If you use the online services requested via My Porsche or the Porsche Connect Store in your vehicle or on further end devices, we will process personal data of yours for purposes of enabling the use of the online services, for support purposes, and for further specifically defined purposes, including any purposes notified to you at or around the time we collect your personal data. We collect, use and disclose your personal data to enable the use of the respective My Porsche service or Porsche Connect service and for the other relevant purposes outlined in the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store.
During use of the individual My Porsche services or Porsche Connect services, the following categories of personal data are processed, depending on how the specific service works, in order to provide you with the services in this context and to implement and fulfil the associated contractual relationship with you. For the purposes of the GDPR, the legal basis in each case is contract fulfilment.
a) Identification information, such as the vehicle information number, your Porsche ID, and device and system IDs of your end devices and mobile radio modules that are needed in order to identify you personally or to identify your end device or vehicle to establish connections, for the use of services, or for access to content.
b) Authorisation information that includes the fact that the vehicle or the relevant end device has been activated for the respective Porsche Connect service and that can be associated with your registration data from the Porsche Digital Service Infrastructure.
c) Login information that is needed when you wish to use services of other providers that require a login in your vehicle or on further end devices.
d) Communication information that is necessary in order to establish a connection between your vehicle and/or other end devices and our servers or with the servers of third-party providers of content for Porsche Connect services.
e) Location and movement information that is necessary in order to display location-related content in the vehicle.
f) Voice data that enable voice control and voice entries in certain Porsche Connect services. Voice data are transferred to us from the vehicle or an end device in recording form for the purpose of conversion to text. The text that is then generated by a service provider is transferred back to the vehicle, and the recording is subsequently deleted at our end.
g) Contact information that is used in communication services, for example to send an email or text message.
h) Billing data such as an itemised bill from charging operations: If necessary, we will combine this information with your address and payment information for individual billing purposes.
i) Further content that must be exchanged with us or with service providers in order to be able to perform a service for you.
For detailed information on which data are collected and processed within the scope of which online service, please see the relevant online service descriptions at https://connect-store.porsche.com/au/en/.
We store the service usage in connection with your vehicle identification number and a time stamp for a period of 12 months as part of a database for creating anonymised use statistics.
If you use services of third-party providers that you cannot request via My Porsche or the Porsche Connect Store, content from these services may be displayed in your vehicle or on your end device, and information including personal data may be exchanged between your vehicle or end device and the service provider. By linking a mobile end device with your vehicle, content will only be reflected in your vehicle’s built-in infotainment system (Porsche Communication Management (“PCM”)). We do not access these services of third-party providers, nor do we take note of any content. Therefore, please note the relevant data protection and privacy information provided by the third-party provider.
When you use such third-party services, it is possible that personal data will also be used beyond the scope necessary to perform the service and for the proper functioning of the service.
We have no influence over the collection, processing, use or disclosure processing of data (including personal data) by these third-party providers or over the location of data processing or where data may be used or disclosed. Therefore, please consult the relevant third-party providers for information on the nature, scope, and purpose of the collection and use of personal data with regard to the respective online service.
We perform all of the data collection, processing described in this section, namely the transfer and disclosure to the third-party provider, in order to fulfil our contract with you and for any other relevant purposes outlined in the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store. You consent to the same, including any off-shored disclosures to or by any third-party (including as further noted in respect of offshore disclosures in the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store).
The PCM built into your vehicle and the mobile interface for vehicle-related services (“Connected Gateway” or “cGW”) may, to the extent available for your vehicle, be connected with the Porsche Digital Service Infrastructure via wireless network connections. They enable you to use Porsche Connect services that you have requested via our Porsche Connect Store, along with using third-party services that you have requested elsewhere, independent of our offerings, in your vehicle.
Depending on the features of your vehicle, connectivity can be established by dialling into the vehicle interfaces via a wireless connection provided by an external device or via the wireless network module of your vehicle’s PCM. Depending on the features of your vehicle, the wireless network module of your vehicle’s PCM may have an installed or pre-installed insertable SIM card or a permanently installed SIM card.
Unless expressly noted otherwise, we perform all of the data collection, use, processing and disclosure described in this section to fulfil our contract with you and for any other relevant purposes outlined in the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store.
a) Installed insertable SIM card
Depending on the features of your vehicle, you can establish connectivity in your vehicle yourself by way of a SIM card that you install in the vehicle and that you have received from your respective telecommunications service provider (“installed insertable SIM card”). Your respective telecommunications service provider is responsible for your own installed insertable SIM card and the data-processing processes associated with it. Please contact your respective telecommunications service provider for information on the nature, scope, and purpose of the collection, processing, and use of data and on data security during signal transmission.
b) Permanently installed SIM card
Depending on the features of your vehicle, connectivity can be established by a SIM card that has already been installed directly in your vehicle by the manufacturer and that is not replaceable (“permanently installed SIM card”). A permanently installed SIM card cannot be removed manually to stop connectivity. For information on responsibilities for the data-processing processes in connection with the permanently installed SIM card, please see paragraph 4.1.3.
c) Telecommunications service provider and virtual network operator
The telecommunications service provider operates a telecommunication network and provides the respective participants with access to this network. The virtual network operator puts together individual network solutions based on the infrastructure and technologies of various telecommunications service provider without possessing a network infrastructure of its own.
4.1.2 Data storage during vehicle production
If your Porsche vehicle is equipped with a pre-installed insertable SIM card or a permanently installed SIM card, we collect, store, use and disclose the SIM card numbers (ICCID, IMSI, MSISDN), in conjunction with the respective device and vehicle identification number, during the vehicle production process. This data collection, use and disclosure takes place for the purpose of managing SIM card numbers and to match the vehicle with a SIM card number in the event that government agencies request information from PCA, for example.
4.1.3 Data exchange in the case of permanently installed SIM cards
Wireless network modules in Porsche vehicles with permanently installed SIM cards that are active dial in, where available, to wireless networks of the respective telecommunications service provider – regardless of whether you are registered for Porsche Connect or have requested Porsche Connect services. Telecommunication data (data collected, used and disclosed based on the provision of the telecommunication service or to establish connectivity) may be exchanged for the purpose of the wireless network connection or to establish connectivity and, where applicable, to perform the relevant online functions of the Porsche Connect services you have requested in your vehicle via the wireless networks of the respective network operator, e.g. with wireless cells.
Within the scope of the wireless network connection, it is not impossible that when signals are transmitted via public telecommunication networks outside your vehicle, third parties, especially telecommunications service providers, can access certain information and potentially determine your location. In addition to the respective telecommunications service providers, virtual network operators may also have access to this information in the process.
Provision of connectivity via permanently installed SIM cards takes place through the following virtual network operator:
• Vodafone GmbH, Ferdinand-Braun-Platz 1, 40549 Düsseldorf, Germany.
Please contact the virtual network operator for information on the nature, scope, and purpose of the collection, processing, and use of data and on data security during signal transmission.
4.1.4 Data processing within the scope of telecommunication services
We collect, process, and use your inventory data (such as your name, address, and date of birth) that are collected during registration for My Porsche or the Porsche Connect Store or indicated when you request a telecommunication service in My Porsche or the Porsche Connect Store to establish, amend, or terminate a contractual relationship regarding or to design the content thereof. The aforementioned data are stored for these purposes until the end of the calendar year following termination of the contractual relationship at the latest.
Traffic data generated within the scope of the activity of the wireless network connections (such as the start and end of the respective connection), location data on the mobile connection, the end points of the connection and dynamic IP addresses, are not collected, processed, or used within the Porsche Digital Service Infrastructure, with the exception of SIM card and device numbers and the volume of data used. Please contact the respective telecommunications service provider for information on the nature, scope, and purpose of its collection, processing, and use of data.
4.1.5 Further data processing due to legal obligations
Beyond the data processing described in paragraphs 4.1.3 to 4.1.5, we collect, process, and use telecommunication data (data that are collected, processed, and used based on the provision of the telecommunication service and/or to establish connectivity) based on and in compliance with relevant legal obligations that apply to us – for example, to fulfil our statutory obligations to store personal data for, and release personal data to, security and law enforcement agencies.
For the purposes of the GDPR, the legal basis for the processing of your data is the fulfilment of a legal obligation that applies to us and/or our legitimate interest in complying with statutory requirements.
4.1.6 Identity checks
In some countries, it may be necessary to perform an identity check based on an identification document for legal reasons in order to request certain telecommunication services. The collection, processing, and use of data in connection with the identity check are performed exclusively by and on the responsibility of the external service provider. Please contact the external service provider for information on the nature, scope, and purpose of the collection, processing, and use of data.
To perform the identity check, you will be redirected to the service provider’s external site as part of the service request process. At your prompting, we will transmit the information that is to be verified (your name, address, and date of birth) to the service provider, along with a procedure number in order to be able to match up the result of the identity check later on. Following the identity check, the service provider will let us know the result of the identity check under the procedure number. We do not transmit personal data from this identity check to third parties except where we are legally obligated to do so. We also receive access to a copy of your identification document stored by the service provider in these cases only, in order to fulfil our statutory obligations.
For the purposes of the GDPR, the legal basis for the processing of your data is the fulfilment of a legal obligation that applies to us or our legitimate interest in complying with statutory requirements.
4.2. Setting up a vehicle and establishing a vehicle connection
To be able to use services in your vehicle, your vehicle must be stored in your Porsche ID user account. To this end, you need to enter the vehicle identification number in My Porsche or have this done by your authorised dealer. We will process your vehicle identification number for purposes of verification, to establish a vehicle connection and to match it up within the scope of use of the services, to activate and provide services, and for further purposes defined and explained in detail in the relevant locations or in the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store. To ensure that you can connect your vehicle to the Porsche Digital Service Infrastructure, our system creates and stores a “pairing code” that is displayed to you in My Porsche.
For verification purposes, you will also have to upload a copy of an identification document and proof of ownership and – if you are not the owner of the vehicle – a power of attorney from the vehicle owner after entering your vehicle identification number or present these items to your authorised dealer. These documents will be reviewed based on our verification criteria. As proof of successful verification, we will also collect, use and store the names, dates of birth, places of birth, addresses, and validity information of the documents shown in the respective identification documents and the vehicle identification numbers, owner names, and addresses shown in the ownership documentation. After the verification process is complete, the copies of the documents will be deleted.
After your vehicle has been matched with your Porsche ID for the first time or a subsequent time, the vehicle must be connected to the Porsche Digital Service Infrastructure. To do this, enter the “pairing code” shown in My Porsche in your vehicle’s PCM. In response, your vehicle’s PCM will first use the pairing code and vehicle identification number to log into our system. We need this information to be able to associate your vehicle with your Porsche ID user account during use, meaning, for example, when a service is accessed, and check whether it is authorised to use services. Once a successful match has been made, our system will transfer a list of currently available services to your vehicle’s PCM.
To use services that are especially critical to safety and security, you will have to enter a separate four-digit PIN. You can set up your personal PIN in My Porsche and change it there at any time. The PIN is stored with encryption. When you enter the PIN in your vehicle, it is also encrypted and transmitted to our system for the purpose of checking authorisation.
For the purposes of the GDPR, we process your data to fulfil our contract with you.
4.3 Retrieving the list of available services and accessing services
Each time you start or end a trip, and when you select certain services, your vehicle’s PCM will first use the vehicle identification number to log into the Porsche Digital Service Infrastructure. We need this information to be able to associate your vehicle with your Porsche ID user account and check whether it is authorised to use services. When you log in to start and end a trip, a current list of available services will also be transmitted to your vehicle’s PCM. For the purposes of the GDPR, we process your data to fulfil our contract with you.
As a data basis for generating anonymised usage statistics, we collect, store and use the retrieval of the list of available services and the respective service access in connection with your vehicle identification number and a time stamp for a period of 30 days. We use this data for our anonymised analysis of user behaviour. For the purposes of the GDPR, the legal basis for the processing of your data is our legitimate interest in an anonymized analysis of use behaviour.
4.4 Deactivating services and data exchange
Depending on the type of wireless network connection, the features of your vehicle, and the services that have been activated, the vehicle’s exchange of data can be deactivated in whole or in part by:
a) removing the SIM card or disconnecting your end device, if the wireless network connection is established via an installed or pre-installed insertable SIM card or a Wi-Fi connection; or
b) adjusting the settings accordingly in the options menu of your vehicle’s PCM. Individual services may not function in full or at all if this is done.
By deactivating the PCM wireless module in the system settings, vehicle occupants can deactivate the data exchange performed by your vehicle’s PCM via the wireless network connection.
By activating “private mode” vehicle occupants can deactivate the data exchange of the Connected Gateway and the associated processing of your personal data. This prevents the use of vehicle-related services and access to the vehicle and vehicle-related information (such as the vehicle’s location, for example).
To be able to provide these services in the individual case, it may be necessary, to the extent that your vehicle has these services, for the Connected Gateway to maintain a wireless network connection with wireless cells of the respective wireless network operator despite the activation of private mode (with regard to the exchange of data within the scope of connectivity, please see paragraph 4.1 and, in individual cases, to exchange data via the wireless network connection as specified in the relevant service description at www.porsche.com/connect. Services that cannot be deactivated are marked as such in the options menu under “private mode.”
4.5 Use of the online services by unregistered drivers
If other people use your vehicle [or] your vehicle’s PCM, the data mentioned in paragraph 2(a) to (h) hereof may be collected, processed, and used. To the extent that the other person does not have a Porsche ID user account of his/her own, this information will be collected and stored under your Porsche ID user account. In this case, it is not possible for us to identify this other driver, as we lack identification information. We will also not try to identify this other driver.
4.6 Online software update
If you have activated Online Software Updates in My Porsche, data may be exchanged between our systems and your vehicle for the purpose of updating the software of your vehicle systems and for troubleshooting software failures as part of service activities. For this purpose, your vehicle identification number, device identifications and their current software version, your Porsche ID and authorisation information are exchanged with our systems at regular intervals. In individual cases (e.g. update actions), information about the vehicle equipment as well as information about the technical condition of your vehicle are transferred to our systems. You can terminate Online Software Update and the associated processing of personal data by deactivating the function in My Porsche, but if you do so you will not receive online software updates or the related services described above.
4.7. Product analysis, improvement and swarm data
Depending on your vehicle's equipment, your vehicle may transfer infotainment system usage data, technical vehicle data and related environmental data, along with a temporary identification key, to our systems, providing you agree to transfer data as part of the vehicle installation in the PCM of your vehicle, or activate the function in the PCM of your vehicle. We collect, use and disclose the data transferred for the purpose of analysing and improving our products and services.
Individual services, such as real-time traffic or safety radar, rely on providing information about, for example, the location, the environment and the movement of your vehicle, as well as data from other vehicles, in order to obtain new and more accurate information, such as current traffic and road conditions (“swarm services”). For this purpose, as part of vehicle use, the location, vehicle and environmental data and movement information from your vehicle may be disclosed. We provide the aforementioned data to third parties in aggregated form only, and without reference to you or your vehicle.
The collection, use and disclosure of this data for product analysis and improvement, as well as the collection, use and disclosure of swarm data is based on our legitimate interest in the analysis and improvement of our products and services, as well as the provision of more precise content in the context of swarm services.
You can deactivate the disclosure of data for these purposes at any time in the settings of the PCM of your vehicle under "Porsche Connect". Please note that this may limit the functionality of individual services when deactivated, in particular swarm services such as real-time traffic or safety radar. The exchange of this data can also be prevented by setting "private mode" into operation in accordance with paragraph 4.4.
Including as further outlined in this document, we and various third parties may be able to track and monitor the vehicle’s location using the SIM and/or GPS functionality.
Unless otherwise stated, this tracking will start immediately and will be continuous and ongoing.
You consent to this tracking and warrant and must ensure that all drivers or users of the vehicle are aware of this location tracking and consent to it also. We rely on this consent for the purposes of provision of the services to you and any other driver or user of the vehicle.
We may use, disclose and process this location data (which may include personal data) for the purposes outlined in this Policy.
Please see the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store for further information about the collection, use and disclosure of your personal data, including the purposes for which we collect personal data, the third parties to whom we generally disclose personal data (including any overseas recipients), the main consequences for you if we do not collect your personal data, and how you may access and seek the correction of your personal data or make a privacy complaint.
As the subject of data processing, you may have numerous rights. Please see paragraph 9 of the General Data Protection and Privacy Statement for My Porsche and the Porsche Connect Store for information on this.
We reserve the right to amend this data protection and privacy statement, and by using the relevant products or services, you agree to the terms of our then-current statement. The current version of the data protection and privacy statement can always be accessed at https://connect-store.porsche.com/au/en/t/privacy.
Last updated: 5 November 2018
What are cookies?
To offer you a full range of functions when you visit our website, recognize your preferences, and make the use of our websites more comfortable and convenient, we use “cookies”. Cookies are small files that are stored on your device using your Internet browser.
Categories of cookies
Cookies that are absolutely necessary in technical terms: We use certain cookies because they are absolutely necessary in order for the website and its functions to work properly. These cookies are automatically placed on your computer when you access the website or a certain function, unless you have set your browser to reject cookies.
Session cookies: Most cookies are only needed for the duration of your current website and My Porsche visit or your session, and they are erased or become invalid as soon as you leave our website or your current session expires (termed “session cookies”). Session cookies are used, for example, to retain certain information, such as your Porsche login or shopping cart, during your session.
Permanent cookies: Only in isolated cases are cookies stored for a longer period. This is done, for example, to recognize you when you access our site again at a later time and to be able to access saved settings. This allows you to do things like access our pages faster or with greater convenience, or it eliminates the need for you to set certain options, such as your chosen language, over again. Permanent cookies are automatically deleted after a predefined period when you visit the page or domain from which the cookie was placed on your computer.
Flow cookies: These cookies are used for communication among various internal Porsche servers. They are placed on your computer at the start of a user interaction and deleted after the end of the interaction. Flow cookies are given a unique identification number during the interaction, but this number does not permit any conclusions to be drawn regarding the actual customer or user.
Provider cookies: Cookies are typically placed by the operator of our website, which is commissioned by us, itself when a person visits our website.
We use Google Analytics, a web analytics service provided by Google Inc. (“Google”). Google Analytics uses third-party cookies to identify the frequency of use of certain areas of our website and preferences. The information about your use of our web offer (including your shortened IP address) generated by the cookie is transferred to a server operated by Google in the USA and stored there. Google will use this information on our behalf and on the basis of a contract for processing to evaluate your use of our website, to compile reports on the activities of our website and to provide other services related to the use of the website and Internet usage. For the purposes of the GDPR, the legal basis for the use of Google Analytics is article 6(1)(f) of GDPR; our legitimate interest arises in this respect for the purposes of the use described above, in particular in the analysis, optimisation and economic operation of our website.
Acceptance of cookies when using our website is not mandatory; if you do not want cookies to be stored on your device, you can deactivate the corresponding option in the system settings of your browser. Saved cookies can be deleted at any time in the Internet options of your browser. If you choose not to accept any cookies, however, this can lead to restrictions in the functions offered on our website.
In addition, you can deactivate the use of Google Analytics cookies by means of a browser add-on if you do not want website analysis. You can download this here: https://tools.google.com/dlpage/gaoptout.
Here, a so-called “opt-out” information is stored on your device, which serves to assign your deactivation of Google Analytics. Please note that such opt-out information will only disable Google Analytics for the device and the internet browser from which it was placed. You may also need to reset it if you delete cookies from your device. As an alternative to the browser add-on, such as on mobile devices, you can also prevent collection by Google Analytics by clicking on the following http://optout.networkadvertising.org link. An "opt-out cookie" will be set to prevent the future collection of your data. The opt-out cookie is only valid for the browser used and only for our website offer, and is stored on your end device. If you delete cookies from the browser, you must set the opt-out cookie again.
You can also activate the "Do Not Track Function" on your end device. If this function is activated, your end device informs the respective service that they do not want to be tracked.
Cookie name Technically necessary? Storage duration Cookie provider Purpose
CIAM.s Yes Flow cookie Dr. Ing. h.c. F. Porsche AG This cookie is necessary in order to check whether the user’s browser supports cookies.
CIAM.m Yes Session cookie Dr. Ing. h.c. F. Porsche AG This cookie is necessary for user authentication.
CIAM.h Yes Session cookie Dr. Ing. h.c. F. Porsche AG This cookie is necessary to store the user’s session and login in My Porsche.
CIAM.status Yes Session cookie Dr. Ing. h.c. F. Porsche AG This cookie is necessary to monitor the status of the user’s session in My Porsche.
pcc.cookieAcceptance Yes Permanent cookie (storage duration: one year) Dr. Ing. h.c. F. Porsche AG This cookie stores the user’s decision whether cookies can be stored in his/her browser on the browser side.
nonce.* Yes Flow cookie Dr. Ing. h.c. F. Porsche AG This cookie stores the user’s decision whether cookies can be stored in his/her browser temporarily on the server side.
PF Yes Session cookie Dr. Ing. h.c. F. Porsche AG This cookie is necessary for internal user authentication between different Porsche servers.
CIAM.pcc Yes Session cookie Dr. Ing. h.c. F. Porsche AG This cookie is necessary to store the user session and login in My Porsche.
f5_cspm Yes Session cookie Dr. Ing. h.c. F. Porsche AG This cookie is necessary to redirect the user to a proxy server through the load balancer.
_utma No Permanent cookie (storage duration: two years) Google This cookie stores the number of visits by a user for Google Analytics.
_utmt No Session cookie Google This cookie stores the query type of the user’s access for Google Analytics. A distinction is made between events, transactions, and items.
_utmb No Session cookie Google This cookie stores the duration of a user session for Google Analytics.
_utmz No Session cookie Google This cookie stores the referring page from which the user reached My Porsche for Google Analytics.
_utmv No Session cookie Google This cookie aggregates stored data for Google Analytics so that they can be displayed by Porsche AG in individual, anonymized reports.
NREUM No Session cookie, which is deleted on closing the browser. New Relic Inc. This cookie is only created in browsers that do not support the Navigation Timing API. If a browser supports the Navigation Timing API, a native interface may be used to determine the start time of navigation.
NRAGENT No Session cookie, which is deleted on closing the browser. New Relic Inc. This cookie is used to communicate between the end user metrics of the New Relic Collector and the agents running in its web application. A token identifies and correlates application-layer transaction tracks with corresponding browser tracks.
JSESSIONID No Session cookie, which is deleted on closing the browser. New Relic Inc. This cookie is used to store a session identifier so that New Relic can monitor the session count for an application. The cookie value is generated by Jetty.
Porsche Cars Australia Pty Ltd