PRIVACY
NOTICE
GEOTAB
VITALITY DRIVE PROGRAM
Geotab Vitality, LLC, a Delaware limited liability company (“Geotab Vitality”), operates the Geotab Vitality Drive mobile application (the “App”) and related Geotab Vitality Drive Program (the “Program”). The Program is made available to you through and on behalf of your employer or another provider (“Program Provider”) who has contracted with Geotab Vitality with respect to the Program.
This Privacy Notice (“Notice”) applies only to personal information collected from you and processed in connection with your use of the App and participation in the Program. As used in this Notice, “personal information” means any information that relates to an identified or identifiable individual or as otherwise defined by an applicable data protection law or regulation.
By accessing or using the App or otherwise participating in the Program, you agree and accept the terms of this Notice. Please contact the Program Provider if you do not agree with this Notice or if you otherwise wish to discontinue your use of the App or the Program.
In its capacity as a processor, Geotab Vitality processes certain personal information collected in connection with the use of the App and the Program at the instruction of the Program Provider (the data controller) as outlined below.
As used in this Notice, the terms “controller” and “processor” have the definitions given to those terms in the EU General Data Protection Regulation (GDPR). The concepts of “controller” and “processor” are analogous to the concepts of “business” and “service provider”, respectively, under the California Consumer Privacy Act and other applicable data protection laws that use similar terminology.
Geotab Vitality is a “processor” where it processes personal information on behalf of a controller. A controller is an entity that determines the purposes and means for which personal information is collected. With respect to personal information collected in connection with the App and the Program, the Program Provider is the controller and Geotab Vitality is the processor. Accordingly, if you are looking for information about the privacy practices of the controller (i.e. the Program Provider), please refer to the Program Provider’s privacy policy.
In its capacity as a processor, Geotab Vitality processes certain personal information in connection with your use of the App and participation in the Program as outlined below:
●
first name, last name, e-mail,
mobile number and/or unique identifier;
●
driving performance score
determined in connection with the Program Provider’s use of the Geotab
telematics solution;
●
technical information such as
log data, IP address, device type and operating system;
●
information about how you
engage with the Program;
●
details of rewards you have
earned in connection with your use of the App and the Program; and
●
additional personal information
you provide when you engage with the App or otherwise participate in the
Program.
Geotab Vitality uses the personal information outlined above for the following purposes:
●
to provide, maintain and
improve the App and the Program;
●
to communicate with you;
●
to resolve any complaints or
queries that you may have;
●
to detect and investigate fraud
or security incidents;
●
to fulfill Geotab Vitality ’s
legal obligations; and
●
any other purpose permitted by
applicable law.
The Program Provider is responsible for ensuring it has a legal basis for collecting and processing your personal information in accordance with this Notice.
Geotab Vitality, or its authorized service providers and/or sub-processors, may anonymize or de-identify your personal information to ensure that it no longer qualifies as personal information. Once anonymized or de-identified, your information will be used for statistical, research, or operational purposes including the improvement of the App and Platform and assisting in the creation of new products and services. Anonymization and de-identification processes are performed in such a way that the data can no longer be used to reasonably identify you directly or indirectly. Geotab Vitality will not attempt to re-identify such information except to ensure that such information is de-identified, with your consent or if required to do so by law. Once your personal information has been anonymized or de-identified, it will no longer be subject to the same privacy protections under applicable laws.
Geotab Vitality may engage third-party service providers to process personal information on its behalf ("Subprocessors"). Subprocessors are selected based on their ability to provide the necessary safeguards and security measures to protect personal information in compliance with applicable data protection laws. Before engaging any Subprocessor, Geotab Vitality conducts an assessment to ensure a Subprocessor complies with applicable privacy laws. Geotab Vitality ensures that any Subprocessor it engages only processes personal information in line with Geotab Vitality ’s documented instructions and implements appropriate technical and organizational measures to ensure the security of personal information. Geotab Vitality ’s primary Subprocessors with respect to the App and the Program are Vitality Group International, Inc., Geotab Investments, Inc. and their respective affiliates, each of which administer certain aspects of the Program on behalf of Geotab Vitality.
Geotab Vitality primarily stores personal information on servers located in North America, Europe and Asia, but may also utilize servers located in other regions from time to time for load balancing and other purposes. Accordingly, your personal information may be transferred to a country where the data protection laws do not provide a level of protection equivalent to the laws in your jurisdiction. However, when Geotab Vitality transfers your personal information, we do so in compliance with applicable data protection laws by ensuring your personal information is afforded an adequate level of protection using the following means, where appropriate:
● where possible, transferring personal information to countries that the European Commission has deemed to provide an adequate level of data protection;
● in cases where personal information is transferred to countries without an adequacy decision, we use standard contractual clauses approved by the European Commission to ensure that your personal information is afforded a level of protection comparable to that provided within the EU;
● implementing appropriate physical, technical and organizational security measures to protect personal information against accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access, and against all other unlawful forms of processing; and
● taking other measures to provide an adequate level of data protection in accordance with applicable law.
Geotab Vitality will retain your personal information for as long as we are instructed to do so by the Program Provider and will delete or anonymize your personal information when we no longer have a business need to retain it or otherwise in compliance with applicable data protection laws. If it is no longer reasonably possible to delete your personal information because, for example, it has been archived, Geotab Vitality will securely store the personal information and isolate it from further processing until deletion or anonymization is possible.
Geotab Vitality maintains reasonable technical and organizational security and data storage policies and measures for facilities within its control to prevent your personal information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. We have put in place procedures to deal with any suspected personal information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Under applicable data protection laws, you have certain rights regarding your personal information. Please contact the Program Provider if you wish to exercise those rights. Geotab Vitality is committed to respecting and facilitating these rights and will assist the Program Provider in responding to any data subject request to the extent required by law or our contractual commitments with the Program Provider.
If Geotab Vitality makes any changes to this Notice, we will post an updated policy on the App and/or on our website. You should periodically review this page for any updates. The updated Notice will become effective as of the date stated in the Notice.
If you have questions about this Notice, you can contact us by email at privacy@geotabvitality.com
Non-English translations of the Notice, if any, are provided for convenience only. If any ambiguity or conflict exists between such other translations, this English version will be held as the authoritative version. Translations of this Notice into language in which we offer our products and services can be provided upon request.