Scope and purpose
This policy is applicable to the Processing of customers' Personal Data at all companies included in the Polestar Group ("Polestar", "our", "us" or "we"). The purpose of this policy is to provide our current, former and potential customers (jointly referred to as "customers" or "you") with a general understanding of:
- The circumstances under which we collect and process your Personal Data
- The types of Personal Data we collect
- The reasons for collecting your Personal Data
- How we handle your Personal Data
- Distribution of responsibility for the Processing of Personal Data between various legal entities at Polestar, and
- Contact details for us so you can receive information about and claim your rights in relation to our processing of your Personal Data.
This policy is updated continuously to reflect the measures taken by Polestar in relation to your Personal Data.
Polestar Performance AB (a Swedish legal entity with corporate registration number 556653-3096) is the Controller in relation to Processing of your Personal Data for research and development of new and current car models, and also for certain global services offered to customers. Furthermore, Polestar Performance AB is Controller for any Processing of Personal Data in relation to the monitoring of the quality of the cars and any potential safety recalls as well as to meet regulatory requirements.
Each national sales company within Polestar is generally responsible for marketing, sales and customer relations as well as market specific services in its market. The national sales company is Controller for the Processing of Personal Data for these purposes. In markets without a national sales company, an importer usually has the same responsibility as a national sales company. Therefore, the importer is the Controller in these instances.
Principles of data Processing
The Processing of your Personal data forms an important part of our provision of products and services to you. We appreciate the trust you place in us when providing us with your Personal data, and consider your privacy an essential part of the services we offer. In order to safeguard your Personal Data while increasing the customer value and offering enhanced and safer driving experiences, we adhere to the following five general principles.
Freedom of choice
Your Personal Data belongs to you. We strive not to make any assumptions regarding your privacy preferences and aim to design our services so that you can choose whether or not to share your Personal Data with us.
Balance of interests
Where the Processing of your Personal Data is necessary for the pursuit of a legitimate interest, and where this interest outweighs the need to protect your privacy, we may process certain Personal Data without obtaining your consent if so permitted by law. In certain other situations, we may also process your Personal Data without your consent if so is required in accordance with applicable law. For more information, see the "Consent" section below.
Polestar will only process our customers' Personal Data if it is adequate, relevant and necessary in relation to the purpose for which it has been gathered. We aim to anonymize your Personal Data when a function or service can be achieved with anonymized data. If we combine anonymized or non-Personal Data with your Personal Data, it will be treated as Personal Data for as long as it remains combined.
Transparency and security
Polestar believes in being transparent about which Personal Data we process and for which purposes. On request, Polestar will provide customers with further information regarding our Processing and protection of your Personal Data.
Polestar's policy is to comply with the applicable laws, rules and regulations governing privacy and data protection in each and every country where we operate. Where necessary, we will adjust our Processing of your Personal Data as described in this policy to ensure legal compliance.
The Personal Data collected by Polestar about you and the vehicle will be used:
- to provide you with products and services, including to verify your eligibility for certain purchases and services as well as to offer you enhanced offers and experiences;
- to inform you of updates to, or changes in, our products and services, including but not limited to changes to our terms and conditions and policies;
- to inform you of new products, services and events;
- to provide vehicle support and services (warranty service, recall information, etc.);
- for product development purposes, for example to improve vehicle performance, quality and safety;
- to evaluate and improve our offering to, and communication with customers;
- to comply with legal requirements or lawful authority requests;
- to inform you about our products and services and identify those that may be of interest to you;
- to carry out market research; and
- for analysis and customer profiling purposes (online and social included) done by ourselves and our chosen suppliers.
The following definitions are used in this policy:
- "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data;
- "Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
- "Personal Data" means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- "Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- "Sensitive Personal Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the Processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
You may provide us with information about you or your vehicle when utilising Polestar's services in or outside a vehicle or in other contacts with Polestar, for example through our websites or customer centres (in this context, please note that phone calls may be recorded, with your consent, for quality assurance purposes). We may also obtain such data from our repairers and other third parties. Such data may include:
- your contact information (name, address, telephone number, email address, etc.);
- demographic information (age, marital status, household composition, etc.);
- vehicle information (vehicle identification number (VIN), model, date of purchase, service history, etc.);
- location data generated by your activities (navigation assistance, search queries, location sharing, etc.); and
- data pertaining to your purchase and use of our products and services (customer preferences and settings, purchase history, Polestar ID, etc.).
Your vehicle will also automatically collect data relating to the vehicle and its surroundings, primarily of technical nature and not directly related to you as a person. Such data ("Vehicle-recorded data") is typically connected to the vehicle identification number (VIN) of the vehicle and may therefore be traceable to you. Vehicle-recorded data may include:
- safety information (whether airbags or belt tensioners have been triggered, whether the doors and windows are locked or open, etc.);
- system functionality status (of the battery, engine, throttle, steering, and brakes, etc.);
- driving data (vehicle speed, brake and accelerator pedal use, steering wheel movement, etc.);
- location data (the position of the vehicle in case of an accident, etc.); and
- surroundings data (temperature outside the vehicle, images, etc.).
Information about certain Vehicle-recorded data is also included in the Owner's Manual.
We are particularly careful and apply additional measures if and when collecting and Processing Sensitive Personal Data, as required by applicable law. For the avoidance of doubt, it is noted that applicable law may require other kind of data to also be treated as Sensitive Personal Data.
Where reasonably practical or as required by applicable law, we will, in connection with collecting or registering your Personal data, provide you with (i) specific information regarding the purposes of the Processing of your Personal Data, (ii) the identity of the Controller, (iii) the identities of any third parties to whom the data may be disclosed and (iv) other information which may be necessary to ensure that you are able to safeguard your rights. The above information may, for example, be provided when you purchase a vehicle, in the vehicle's infotainment system, in mobile applications developed by Polestar, at https://www.polestar.com or otherwise in an agreement entered into between you and Polestar.
Where reasonably practical or as required by applicable law, we will obtain your consent prior to collecting or using your Personal Data. The request for your consent will be clear and specific and provide you with a reasonable basis on which to make your decision. We will never take your consent for granted and will make sure that you can provide your consent in a clear and transparent manner. Your consent is voluntary and may always be revoked, for example by terminating a particular service or contacting Polestar at the address indicated in the "Information and access" section below. Please note where your consent is required and you do not give your consent, it may not be possible for you to use certain services or parts of such services.
Collection and Processing of Personal Data without consent
The collection and use of Vehicle-recorded data may be necessary in order for (i) technicians to diagnose and rectify faults in vehicles during the service and maintenance of vehicles, (ii) Polestar's product development, for example enhancements of the vehicles' quality and safety features, (iii) managing Polestar's warranty undertakings and (iv) fulfilment of legal requirements. When collecting or using Vehicle-recorded data for these purposes, and for similar legitimate interests pursued by Polestar, we will generally not seek your consent unless this is deemed necessary in the individual case or required by applicable law.
Third party applications
You may access certain applications and other services linked with the vehicle but provided by a third party, which may, for example, require transmission of location data and other Vehicle-recorded data to such third party. Polestar is not responsible for the collection or use of Personal Data in applications or services provided by a third party, and recommends that you carefully review applicable terms for (and any integrity policy related to) such applications or services before you use them. If you have questions concerning a certain third party's use of your Personal Data, please contact the third party directly.
Polestar may transfer your Personal Data to recipients in countries outside of the European Economic Area that may have differing data protection laws. This includes countries which the EU Commission does not consider to have an adequate level of protection for Personal Data. If this occurs, Polestar will ensure there is a legal ground for the transfer in accordance with applicable data protection legislation. You will also be informed about the legal ground, what safeguards were implemented, and where you can obtain a copy of information on these safeguards.
For most Processing acts, you are able to terminate our use of your Personal Data by updating your preferences, terminating a particular service, revoking your consent to the Processing by contacting Polestar at the address indicated in the "Information and access" section below or as otherwise instructed by us. However, and unless otherwise follows from applicable law, you may generally not opt out of the Processing of your Personal Data:
- in relation to certain acts of collection and further Processing of your Vehicle-recorded data relating to safety, quality and product improvement;
- which we perform in order to send you important notices, such as changes to our terms and conditions and policies or in case of product recalls; and
- which we perform in order to comply with our legal obligations.
We will only retain your Personal Data for as long as it is necessary to fulfil the purposes outlined in this policy or the purposes of which you have otherwise been informed. This means that when you have consented to our Processing of your Personal Data, we will retain the data for as long as the customer relationship lasts (and, where applicable, until the expiry of the warranty period) or until you withdraw your consent. If you have revoked your consent, we may nevertheless retain certain Personal Data for the period required in order for us to meet our legal obligations and defend ourselves in legal disputes. If we have not received your consent for Processing, the Personal Data will only be retained to the extent we are permitted to do so by law.
We strive to ensure that your Personal Data is correct and up to date when processing it. We attempt to delete or correct Personal Data that is incorrect or incomplete. For more information regarding your right to ensure the accuracy of your Personal Data kept by us, please see the "Information and access" section below.
As stated in the "Notice" section above, we may provide you with specific information concerning our Processing of your Personal Data when collecting or registering such data.
You have the right to request (i) a copy of the Personal Data that we store about you, (ii) that we correct or remove Personal Data that you think is inaccurate, and (iii) to have your Personal Data deleted and to have our processing of your Personal Data restricted in certain circumstances. In addition you have the right to object to our processing of your Personal Data as well as to receive the Personal Data you have provided to us, in a structured, commonly used and machine-readable format and to have these transmitted to another Controller.
Requests should be sent to the legal entity set out at the end of this document. Your requests will be dealt with in a prompt and proper manner. Where applicable law provides for an administrative fee for complying with your request(s), such fee may be charged by Polestar. In addition, you may be able to access an overview of certain Personal Data that you have provided directly and that is held by Polestar, and correct or update your information, by logging in to the Polestar consumer portal account, or a similar service offered in your local market. For more information on your rights, please contact our Data Protection Officer. Please see contact details for our Data Protection Officer at the end of this document.
Polestar has taken technical and organisational measures in order to protect your Personal Data against accidental or unlawful destruction, accidental loss or alteration, unauthorised disclosure or access and any other unlawful forms of Processing.
Disclosures to third parties
Polestar may share your Personal Data:
- among Polestar units;
- with the financing company or leasing company you have selected when ordering a vehicle on our website or that you have informed us about, for the purposes of concluding or fulfilling a contract with you, both in the situation where your contract is or will be with Polestar and where your contract is with the financing company or leasing company.
- with Polestar's repairers, for the purpose of distributing product and service offers and other communications to you; with other business partners for the purpose of distributing product and service offers and other communications to you or for research and development purposes;
- with the partners set out in the section on Marketing below;
- in connection with the sale or transfer of a Polestar entity or its assets;
- as required by law, for example in connection with a government inquiry, dispute or other legal process or request;
- when we, in good faith, believe that disclosure is necessary in order to protect our rights, for example in order to investigate potential violations of our terms and conditions or to detect, prevent or disclose fraud or other security issues
- with other business partners or third parties where you have elected to receive a service from them and authorized them to request data from Polestar;
- with our product and service providers who work on our behalf in connection with the above uses, such as pickup and delivery providers, wireless service providers, companies that host or operate our website, send communications, perform data analytics, credit card processors, or system providers necessary to process, store, or manage credit card or financial information; and
- with emergency services providers, such as law enforcement, roadside assistance providers, and ambulance providers, in order to deliver related services (for example, for the On Call Emergency Support).
A Polestar entity being the Controller of your Personal Data will, as a general rule, only disclose your Personal Data to a third party if it has received your consent to do so. However, if permitted by law we may share your Personal Data without your consent, unless we consider your consent necessary in the individual case or your consent is required by law, in the following situations:
- when disclosure is required by law; and
- when disclosure is necessary for the purpose of a legitimate interest pursued by Polestar (for example in order to protect our legal rights, as described above).
Data Processing on our behalf
We restrict access to your Personal Data to Polestar's employees and suppliers who need to use the information in order to process it on our behalf, and who are contractually required to keep your Personal Data secure and confidential. We aim to choose the option for Processing services that best safeguards the integrity of your Personal Data towards any third party. Some of these processing activities might be performed outside of the EEA under a specific legal basis as required by national law.
Marketing based on your online web behavior data
The legal basis for placing, collecting and having access to information from cookies is your consent. The purpose of our processing of the Online Web Behavior Data is to identify you as return visitor to our website, to analyze the behavior of the visitors to our website, to enhance our communication and the structure of our website and to build a profile of your interests to be able to show you relevant ads for our products and services on other websites as well. The profiles we create based on your Online Web Behavior Data may, for example, include, "people that visited the product page, started configuration and chose the color void".
Marketing based on your customer data, third-party data and Online Web Behavior Data
If you consent by clicking the consent box presented in our website banner, we will combine your Online Web Behavior Data with data obtained from third-party data providers. If you provide your consent when interacting with us, e.g., when signing up for a newsletter, we will combine the personal data that you have provided when interacting with us with your Online Web Behavior Data and with data obtained from third-party data providers. Thus, for such processing the legal basis will be consent.
The data obtained from third parties consist of data that have been collected through cookies and may include information regarding your personal preferences, demographics and content consumption, including your browser history. Such data will be provided to us in aggregated form, and the Online Web Behavior Data and the third-party data is combined by matching your unique online identifier collected through cookies. Thus, all information stored about you is connected to an online identifier consisting of a 8-character ID with uppercase letters, lowercase letters, numbers and special characters, as described above. The purpose of combining this data is to enrich your Online Web Behavior Data and create segments to provide you with personalized marketing on our own website, as well as on other websites that you visit. The segments may, for example, be based on your estimated age, education, income and product preferences. Profiling is always conducted on a group level, which means that you will receive the same type of marketing as other individuals included in that same segment.
The Personal Data that you have provided in connection with your interaction with us may consist of your name, email address, phone number, age, gender, country, orders, pre-orders, configuration ID and booked test drives. If you consent, we may combine this data with your Online Web Behavior Data for the purposes of sending you targeted marketing through email, on our websites, at other websites you visit and by sending you mobile push notifications. By combining such data, we are able to create segments and send, for example, customized online marketing that is based on the fact that a customer pre-ordered a car. We are able to match up the different data sets by using a pseudonymized version of your email address, meaning that your real email address is replaced with a combination of numbers and letters using an algorithm. Your email address will, for example, be collected when you register for a Polestar ID, and in this case the email address will be connected to your online identifier. In that way, we will be able to store information regarding your online behavior and connect it to your pseudonymized email address. By doing so, we will able to, for example, send you personalized marketing by email.
If you would like to withdraw your consent to the above processing, please submit your request using this WEB FORM.
The profiles described above are also used to create so-called lookalike audiences, meaning that we create audiences based on the characteristics of the profiles described above to be able to target individuals that have similar interests, behavior or characteristics as the people we already have targeted. In other words, we will use the segments in which you are included to be able to target other individuals. Such processing is based on our legitimate interest in providing targeted marketing to a wider audience based on profiles that we have created using data from our website visitors and customers. When using the profiles in which you are included to create lookalike segments, your Personal Data will be pseudonymized; therefore, it will not be possible to directly identify you. Based on this, we have made the assessment that we have a legitimate interest in processing your Personal Data for this purpose.
You are always entitled to object to this processing by using this WEB FORM.
Sharing of personal data
The Personal Data that we collect for the above purposes of conducting profiling and sending you targeted marketing will be shared with our collaboration partners, including the service provider of our customer data management platform, providers of demand-side platforms such as social media partners and our media agency. These collaboration partners are located within the EU/EEA (including Sweden, Norway, Ireland, Amsterdam, UK, Germany and Belgium) and the U.S. When we transfer your Personal Data to a third country which has a lower level of protection of personal data than the EU/EEA, we use the standard contractual clauses approved by the European Commission to ensure a sufficient level of protection for your personal data.
We will not sell or trade your Personal Data with third parties unless we have your consent to do so. We will not share your Personal Data with third parties for their marketing purposes, unless we have received your consent for such disclosures. If you have provided such consent, but wish to stop receiving marketing materials from a third party, please contact that third party directly. If you wish to unsubscribe to a particular e-mail newsletter or similar communication, please follow the instructions in the relevant communication.
Websites and cookies
When you download or register to use one of our apps, you may submit Personal Data to us such as your name, email address, phone number and other registration information. Further, when you use our apps, we may collect certain information automatically, including technical information related to your mobile device, and information about the way you use the app. Depending on the particular app you use and only after you have consented to such collection, we may also collect information stored on your device, including contact information, location information or other digital content. Further details about the kind of information we collect is set out in the information notice and/or the special notice for each individual app.
Third-party services and apps
Our services are not intended for use by children. We do not knowingly solicit or collect any Personal Data about children under the age of 13 nor market our products or services to them. If a child has provided us with Personal Data, a parent or guardian of that child may contact us to have the information deleted from our records. If you believe that we might have any information from a child under age 13, please contact us. If we learn that we have inadvertently collected the personal information of a child under 13, or equivalent minimum age depending on jurisdiction, we will take steps to delete the information as soon as possible.
As a result of legal requirements, we have to monitor how our system works, including the vehicles we have produced. This means that we collect sample data from these vehicles.
Lodging of complaint to supervisory authority
If you are of the opinion that we are processing your personal data in violation of data protection laws and regulations you have the right to lodge a complaint with your supervisory authority.
To exercise your rights as a data subject, e.g. to obtain information in regards to Polestar's processing of your personal data or to access personal data that Polestar process in relation to you, please use this WEB FORM.
Data Protection Officer
Polestar has appointed a Data Protection Officer for the Group who can be reached via e-mail or via post as set out below:
E-mail address: [email protected]
Postal address: Polestar Performance AB, Attention: The Data Protection Officer, 405 31 Gothenburg, Sweden.