Kia Hypercharge - Privacy Notice

1. What personal data do we need?

The purpose of this Privacy Notice is to inform you what personal data is collected from the users of the https://hypercharge.kia.bg website (hereinafter referred to as „the website“) and the Kia Hypercharge mobile application (hereinafter referred to as „the mobile application“), what are the purposes for its collection, whom this data is shared with and what are your rights with respect to the processing of your personal data.

Before you begin using the website and/or the mobile application, you should carefully read and understand this Notice, by providing your explicit consent with its terms and conditions before registering and installing the mobile application. We reserve the right to update this Notice at any time by informing you in a prompt manner.

The Personal data protection policy regulates the use and storage of your data. You can read our Personal data protection policy at the www.kia.bg website.

“KIA BULGARIA” LTD, Unified Identification Code: 204650474, with registered seat and management address in the city of Sofia, 144 “Tsarigradsko shose” Blvd., is the controller of the personal data provided by you (the Data Subject). We use the following of your personal data necessary to provide the charging services for electric vehicles ordered by you and the respective support:

  • Identification data: first, middle and family name;
  • Contact details: address, telephone number, e-mail address;
  • Data on the transactions: history of purchases and used services, transaction information and payment history, bank account number, credit/debit card number, details of the communication exchanged between the provider and the customer;
  • Security data: usernames and passwords, facilities and system surveillance data, information on security-related accidents;
  • IT data: data on the equipment related to the provided services, including technical identifiers, location, communication data and metadata; technical events related to the provided services, including system and application log files, IP address, and mobile device operating system data. If you provide your consent, we can also receive data on your mobile device location while you are using the mobile application so you can be notified of the available electric vehicle charging stations near you, and you can change the settings of your mobile device at any time.

Remark: For the purposes of service delivery, the customer must provide his or her payment card information through direct registration on the website of the payment service administrator.

2. Why the provision of your personal data is necessary?

We need your personal data in order to comply with our legal obligations (points“b” and “c” of Art. 6(1) of the GDPR) and provide you with the following services:

– registration and recording of customers;

– conclusion, administration and fulfillment of contracts;

– customer notification and correspondence handling;

– compliance with statutory requirements, including for accounting purposes;

On the grounds of our legitimate interest for the protection and control of the company assets and its business development (point “f” of Art. 6(1) of the GDPR), we also process personal data for the purposes of:

– establishment, exercise or defence of legal claims;

– statistical analysis and marketing research of the services used by our customers after anonymisation and removal of your personally identifiable data;

With your explicit consent, we may use your contact details to send marketing messages about our services or offers. If you agree that we may process your data for direct marketing purposes, please indicate your consent to the processing of personal data for direct marketing purposes during registration or log in to your personal account and select the function for receiving a newsletter. You can withdraw your consent at any time and refuse to receive newsletters by clicking on the “unsubscribe” link in the emails that we send you.

3. Who has access to your personal data?

Your personal data is processed by “KIA BULGARIA” LTD, 144 “Tsarigradsko shose” Blvd., 1138 Sofia, Bulgaria. The hosting and storage of your data is performed by “Liikennevirta Oy”, with address: Energiakuja 3 00180 Helsinki, phone: +358 (0)800 02200, business ID: 2588986-2. Under guaranteed protection and control measures, access to your data is possessed by “ELBUL INFRASTRUCTURE” LTD, Unified Identification Code: 204701538, with registered seat and management address: city of Sofia 1504, 13B “Yanko Sakazov” Blvd., floor 1, apartment 4 – our service provider, in order to ensure the normal functioning of the electric vehicle charging system and the high quality of our services. The service provider that we work with is obliged to strictly observe its contractual obligations with us, as well as the current legislation for personal data protection, including by undertaking the necessary technical and organizational measures to protect the privacy of your personal information in accordance with the GDPR. In case of justified necessity, we may also share your data in order to prevent fraud, to implement the general terms and conditions for using the mobile application, to guarantee the company's property and our other rights and legitimate interests, as well as to protect the security, rights and interests of our other users or of third parties.

4. What if you do not provide the required data?

During the registration of an Internet account on our website and mobile application, it will be explicitly indicated which data is mandatory in order to provide you with the electric vehicle charging service. The refusal to provide us with the information necessary for the fulfillment of our rights and obligations under the contract may be a reason for its non-conclusion or for its termination. The provision of data for direct marketing purposes is completely voluntary and there will be no adverse consequences for you if you choose not to take advantage of that offer.

4. How long is your personal data stored?

According to the legislation of the Republic of Bulgaria, your data is stored for the following periods of time:

• Internet account data – 6 (six) years from the account creation date.

• Direct marketing data – until the withdrawal of consent or 6 (six) years from the profile creation date.

• Vehicle charging data – for a period of 6 (six) years.

• In the case of administrative or court proceedings initiated by or against customers, all data will be stored for a period of 6 (six) years or until the issue of a final court decision or settlement of the liability.

After the expiry of the above periods, your personal data will be irreversibly erased. All personal data that we store for marketing and service update notifications will be retained by us until you notify us that you no longer wish to receive this information.

5. What are your rights?

• Right to withdraw your consent: You can withdraw your consent at any time, if you have granted it for the processing of your data for a specific purpose, without affecting the processing performed so far. When you have granted your consent for the processing of your personal data for direct marketing purposes, you can opt out of receiving newsletters at any time by clicking the “unsubscribe” link in the emails that we send you or you can change your mobile application settings. If you have granted access to your location via the mobile device so you can find electric vehicle charging stations near you, you can also change the settings that you have selected from your mobile device.

• Right to access your personal data: this right allows you to obtain a copy of the personal data that we store about you, as well as information related to its processing. Through your mobile application account you can access the history of the services you have used and the data provided during the registration process, and you can also submit a special request for access according to the procedure described below.

• Right to rectification: you can request from us to rectify any incomplete or inaccurate information that we store about you. You can always perform promptly any changes to your personal contact details in your Internet account or send us a respective notification. Please contact us via the Data Subject Access Request Form available at the www.kia.bg website.

• Right to erasure: you can request from us to erase your personal data when we have no legitimate grounds to continue processing it, for example – if the purpose for which the data were collected has been fulfilled, or if you have withdrawn your consent. If the legal requirements are met, we will erase your personal data within a period of 1 (one) month, unless we have a legal obligation to continue processing it or the retention of that data is necessary for the establishment, exercise or defence of legal claims.

• Right to restriction of processing: you can request from us to temporarily suspend the processing of your personal data if, for example, you want from us to establish the accuracy of the data or the grounds for its processing.

• Right to data portability: this right is limited to the cases where the data is processed by automated means and is provided to us by you on the grounds of your consent or for the purpose of performance of a contract. This right allows you to require from us to provide your data stored in electronic form to you or to a third party.

• Rights related to automated decision-making and profiling: you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

• Right to lodge a complaint – in case you wish to lodge a complaint regarding the manner in which your personal data is processed, please send the relevant information to e-mail address: data.protection@kia.bg or in writing to postal address: Bulgaria, 1138 Sofia, 144 “Tsarigradsko shose” Blvd. Our Data Protection Officer will review your complaint and will make every effort to resolve the issue. If you still believe that your personal data has not been processed in a lawful manner, you can contact the Commission for Personal Data Protection (PDPC) and lodge a complaint with the Commission on their website: https://www.cpdp.bg/.