Persónuverndarstefna Nissan
At Nissan we are committed to protecting your privacy, as a priority – this means that we will make sure that any personal data you give to us by purchasing our goods and services, visiting our websites and/or our social media pages is only used for the purposes set out in this policy (hereinafter “Privacy Policy”) and in compliance with the privacy laws applicable.
The aim of this Privacy Policy is to provide you with detailed information on how we process your personal data where you purchase our goods
or services as well as your rights to protect your privacy. This Privacy Policy also applies to everyone who visits our website and social media pages.
For the purpose of this Privacy Policy, the main legal entity responsible for any personal data
you provide to us (known as a “data controller”) is BL ehf. Please note that your personal data may also be processed by Nissan Automotive Europe
S.A.S., acting as well as data controller. Both Nissan entities are referred in this Privacy Policy as “Nissan”, “us” or “we”.
Please read this Privacy Policy carefully and should you have any questions, please contact
Nissan by sending an email to hrafnhildur@bl.is.
1. WHAT KIND OF PERSONAL DATA DO WE COLLECT?
When you purchase our products and services, visit our websites and/or our social media pages, Nissan processes your personal data. Personal
data refers to any information that can be used to identify you either directly (such as your name) or indirectly (such as your customer number).
The personal data we collect depends on our interaction with you and may include (but are not
limited to):
Type of data |
Examples of data |
Identification data |
First name, surname, title, postal address, email address, phone number, voice utterance, etc. |
Special category of personal data (in very limited circumstances only) |
Medical personal data (which you may have provided to us during a complaint or an enquiry) – Please note that such special category of personal data shall only be processed where strictly necessary for providing the user with a service that they requested and with their consent, or to comply with a legal or regulatory obligation. In any case, special categories of personal data will never be used for marketing purposes. We will take appropriate measures to ensure the adequate protection of such special category of personal data.
|
Data relating to your online accounts |
Identification data abovementioned and any data relating to your online account (e.g., date of creation, settings configured, etc.). |
Payment and transaction data |
Payment method, billing address, etc. |
Purchase details and order history |
Data relating to any service agreements for products and services between you and Nissan, any authorized dealer or repairer or our financing partner (such as agreement length and parity date), order number, data related to the products you order, order amount, time and date of your purchase / of your use of our services, discount granted, details of services provided by Nissan group companies and authorised dealers that you have received or for which you have registered, details of any transactions between you and Nissan or any authorised dealer or repairer; etc. |
Details relating to your warranties / insurance policies |
Data relating to your service plan, warranty, and extended warranty, information about the insurance policies relating to your vehicle (such as the type, level, and period of cover, which we receive from insurance companies or brokers), etc. |
Data relating to your interactions with Nissan |
Data relating to aftersales services and/or other relevant services, including our customer service, voice recordings from calls between you and Nissan and you and the Dealer, “live chat” records, etc. |
Vehicle identification data |
Vehicle model, registration, registration number, vehicle identification number (VIN), service reminders and warranty information, etc. |
Use of the vehicle |
Mileage, journey, use of multimedia, etc. |
Data relating to connected services |
Geolocation data (where you have permitted access to this), data allowing control of the vehicle (such as locking/unlocking doors, activating headlamps or horn, etc.), battery-related data (battery state of charge, charge programming), vehicle pre-heating or cooling) data relating to driving mode (such as use of controls, acceleration, braking) or to the provision of connected services or on-board applications, etc.
|
Data relating to marketing programs |
Loyalty, direct marketing, market research or survey actions (such as your vehicle preferences). Where you act on behalf of a business, business telemarketing relating data. |
Connection and browsing data |
Date and time of connection, IP address, browser type, browser language, devices used, event logs and any data related to the use of our websites, GPS location (where you have permitted access to this), etc. |
Cookies |
This Privacy Policy does not cover the use of cookies. For more information on the use of cookies or to change your preferences regarding such cookies, please visit our Cookie Policy here: [add link].
|
Please note that the products and services that we offer are primarily for adults. Therefore, we do
not carry out any specific personal data processing on minors.
Any personal data we hold is collected via the purposes outlined in Section 2. We may also rely on anonymized statistical data or work with third party companies to enrich our knowledge
about you. Certain personal data may be mandatory or optional, depending on your request or your use of our products / services. Mandatory data will be marked as such at the point of collection. If you refuse to provide mandatory
data, we may not be able to provide the products / services you have requested.
We encourage you to keep us updated of any changes to your personal data, in particular by exercising your rights as further detailed in Section 5 of this Privacy Policy.
2. WHY DO WE COLLECT YOUR PERSONAL DATA?
Nissan processes your personal data for the purposes listed below.
2.1. MANAGE OUR PRELIMINARY EXCHANGES
Purposes |
Examples of use of your personal data |
Legal basis |
Providing information you might have requested (whether from us or our authorized dealership network)
(as part of customer and prospect relationship management) |
To respond to your enquiry or fulfil any requests you make regarding test drives, service requests, brochure requests or information about specific vehicles, to share the request to the relevant dealer
|
This processing is based on the pre-contractual relationship resulting from your request or our legitimate interest (to provide a quality service)
|
2.2. MANAGE OUR CONTRACTUAL RELATIONSHIP
Purposes |
Examples of use of your personal data |
Legal basis |
Creating and managing your account
(as part of customer and prospect relationship management and provision of connected services and provision of online services on the Nissan website) |
To create your account, to enable you to sign-in on our websites /apps, to enable you to track your current order and access your order history, to enable you to update your account
|
This processing is based on the performance of the contract you have entered into with us
|
Managing vehicle orders
(as part of customer relationship management) |
To process your order and delivery, to manage invoicing and payments, to manage the customer relationship, repairs, warranties and any other relevant assistance, sending you information such as information about your existing warranty or warranty extension |
This processing is based on the performance of the contract you have entered into with us |
Providing you with connected services and on-board driving assistance applications
(as part of the provision of connected services)
|
To provide you with services such as advance messages, eco-driving, park assist, live traffic, geofencing, remote control functionalities, eCall, etc. |
This processing is based on either consent (e.g., live traffic because of geolocation data processing), the performance of the contract you have entered into with us (e.g., park assist), or on legal obligation (e.g., eCall) – For more information, please refer to the NissanConnect Services Terms and Conditions
|
Sending you relevant information about your vehicle(s) and our services
(as part of customer relationship management) |
To send you information about system updates, service or MOT reminders |
This processing is based either on our legal obligations (for example, sending you information about recalls on your vehicle), performance of a contract (for example, sending you information about your existing warranty agreement with us) or legitimate interest (for example, sending you information about system updates, service or MOT reminders or aftersales services such as information about your existing warranty or warranty extension)
|
Managing after-sales service
(as part of customer relationship management) |
To answer your questions, to address your complaints, to process refunds, measuring the performance of our sales and after sales services |
This processing is based on the performance of the contract you have entered into with us or our legitimate interest (to ensure that the services we are providing meet our quality and standards) |
Call recordings of your interactions with Nissan and Nissan dealers
(as part of customer relationship management) |
To ensure the quality of the calls and for training purposes |
This processing is based on our legitimate interest (and those of the Nissan dealer) for quality and training purposes |
Security of the vehicle
(as part of customer relationship management & provision of connected services)
|
To recall vehicles for quality issues, ensure the cybersecurity of our systems |
This processing is based on our legal obligations or our legitimate interest (to provide you for secured systems) |
Compliance with legal and regulatory obligations
(as part of customer relationship management, provision of connected services, data subjects request management & claims and litigation management)
|
To comply with legal and regulatory obligations, in particular to comply with regulations regarding accounting, eCall, Intelligent Speed Assistance Systems and On-Board Fuel Consumption Monitoring, to process your requests to exercise your rights |
This processing is based on our legal obligations |
2.3. CONDUCT PERFORMANCE ANALYSIS AND STATISTICS
Purposes |
Examples of use of your personal data |
Legal basis |
R&D of new products and services
(as part of Advanced Analytics) |
To carry out R&D based on customer feedback. |
This processing is based on our legitimate interest (to improve our products and services)
Where possible, we will be using anonymized or pseudonymized data
|
Feedback and customer satisfaction
(as part of marketing for customers and prospects)
|
To carry out satisfaction surveys (unless you object to such processing) |
This processing is based on our legitimate interest (to improve our products and services) |
Measuring the performance of our advertisements (including the effectiveness of marketing campaigns)
(as part of marketing for customers and prospects and advanced analytics)
|
To draw up statistics, to implement marketing intelligence |
This processing is conducted based on our legitimate interest (to measure the performance of our activities), where possible using pseudonymized data
|
2.4. CONDUCT OUR MARKETING ACTIVITIES
We conduct marketing activities, which notably allows us to:
· launch marketing campaigns;
· analyze your personal data to better understand your preferences and interests and suggest you more adapted and personalized ads or content on our websites and apps as well as on social media.
When you have given your consent to receive direct marketing electronic communications from Nissan (such as email or SMS) (e.g., when creating your Nissan account or through a dedicated form), we process your personal data to provide you with content tailored to your needs. Using your personal data allows us to know a bit more about you and helps us targeting you with personalized advertising. You can withdraw your consent at any time by using the unsubscribe link in the communications sent to you or by contacting our Contact Centre (Tel: +354 5258000 or through our contact form).
In particular, we:
· collect and analyze the personal data you directly provided to us to build internal profiles about your interests and preferences (e.g., hybrid car rather than diesel car, a SUV rather than a city car) and keep them in our database;
· collect and analyze the personal data provided by our business partners to enrich your profiles (e.g., age range, green profile, etc.);
· send or display to you relevant and personalized online advertising on social media (such as Facebook or Instagram) based on your profiles. Determining your profile also enables us not to send you advertising or offers that would not correspond to your interests as well as to limit the number of times the same advertising is presented to you;
· ask social media providers such as Meta to identify profiles similar to yours in order to create “lookalike” audiences to which relevant and personalized online advertising will be sent or displayed.
We never process special category of personal data for marketing purposes.
Please see below the legal bases on which we rely to conduct such marketing activities:
Purposes |
Examples of use of your personal data |
Legal basis |
Managing our client / prospect database
(as part of marketing for customers and prospects)
|
To enrich our database, update our database |
This processing is based on our legitimate interest (to maintain an up-to-date customers and prospects database) |
Marketing communications by email to current customers, or by phone, postal mail or directed to current or potential customers (prospects)
(as part of marketing for prospects / customers and event management) |
To send you newsletters, customized communications, new offers on a new car, implement events and communication in relation to special events organized for customers or prospects |
This processing is based on our legitimate interest to send relevant commercial communications to (i) current customers on services or products similar to those previously purchased (by email, SMS, instant messages e.g. WhatsApp, text messages, etc.), and (ii) to customers and prospects (by telephone or post). |
Marketing communications by email directed to potential customers (prospects)
(as part of marketing for prospects and event management) |
To send you newsletters, customized communications, new offers on a new car, implement events and communication in relation to special events organized for prospects |
This processing is based on your consent to receiving of commercial communications, (by email, SMS, instant messages e.g. WhatsApp, text messages, etc.) |
Profiling to improve our customer and market knowledge
(as part of profiling & predictive marketing/advanced analytics and social media)
|
To create profiles using segmentation tools and external personal data |
This processing is based on our legitimate interest (to get to know the preferences and interests of our customers and prospects better) |
Displaying targeted ad through our social media and advertising placement partners based on profiling
(as part of profiling & predictive marketing/advanced analytics and social media)
|
To display to you online targeted ad about our vehicles, products and services on social media or relevant websites |
This processing is based on our legitimate interest (to provide you with relevant ad content, when it is likely to be relevant to you)
|
Creating lookalike audience
(as part of profiling & predictive marketing/advanced analytics and social media)
|
To share your personal data with social media to identify profiles similar to yours |
This processing is based on our legitimate interest (to identify prospects that are likely to be interested in our products and services) |
2.5. DISPUTES AND LITIGATION MANAGEMENT
Purposes |
Examples of use of your personal data |
Legal basis |
Claim, litigation / pre-litigation, disputes management/ investigations
(as part of litigation and claim management) |
To manage claim, litigation / pre-litigation and disputes from any individuals; manage internal investigations, including audit and compliance related investigations
|
This processing is based on our legitimate interest (to protect our rights in the event of a litigation) |
3. HOW LONG DO WE KEEP YOUR PERSONAL DATA?
As a general rule, we are committed to holding your personal data only for the time necessary to achieve the objective pursued, to meet your needs, or to meet our legal obligations.
In the absence of applicable exceptions, we will retain your personal data:
- until the deletion of your account, or three (3) years since the last activity on your account;
- if you do not have an account, for the duration of our commercial relationship.
In addition to this, we will retain your personal data for three (3) years from the end of our commercial relationship for personal data processed for marketing purposes, five (5) years from the end of the commercial relationship for personal data retained for the proof of legal
claims, and for ten (10) years from the end of the relevant fiscal year for personal data retained for accounting purposes.
When we no longer need to use your personal data, it is deleted from our systems and records or made anonymous so that we can no longer identify you. However, it may be necessary
to archive some of your personal data in order to be able to respond to any legal proceedings, throughout the statute of limitations provided for in the applicable legislation.
4. WHO DO WE SHARE YOUR DATA WITH?
We share your personal data with our partners and/or service providers in order to provide you with the services, as well as continuously improve them. We make sure that they are as committed as we are to protecting your personal data and information.
4.1. DEALERS
Our dealers use your personal data to provide you with a high quality service. This includes handling special requests, personalised offers, and keeping you informed of information or news.
In most cases, Nissan and the dealers will process your personal data as “independent data controllers”.
4.2. SOCIAL MEDIA
We share your personal data to social media (such as Google and Meta) for marketing purposes as described in Section 2.4. Nissan and Google
or Meta are regarded as “joint controllers” for such processing.
For instance, when you visit our Nissan Facebook
Fanpage, Nissan and Facebook jointly process your personal data (including but not limited to your username, any comments that you post, direct messages that you send to us and your activities (such as the time and date of your posts and
“likes”), via the Facebook Insights services).
Social media are solely responsible for any further
processing of your data, with no input or influence from Nissan – please refer to Facebook’s privacy policy here: www.facebook.com/privacy or Google’s privacy policy here: https://policies.google.com/privacy, for a description of their processing activities and
information on your rights.
4.3. SERVICE PROVIDERS
We share your personal data with companies that provide services on our behalf or as as “independent data controllers”. This includes:
Category |
Services |
Provision of services and products |
· Website hosting including the operation and/or maintenance of our databases, websites, and mobile applications · Vehicle financing partner · Roadside assistance [to be provided by each country], Car Care Plan or other provider of services directly to you · Prospect & Customer order management systems · Credit / debit card payment processors (where relevant – e. g. for pre-order of a vehicle online) · Our insurance partner(s) (only where you have agreed to benefit from an insurance related offer from our insurance partner) · Any associated or connected motor manufacturer from whom we purchase or hire goods (and their group companies) · Authentication services
|
Performance analysis and statistics |
· Data analytics · Customer research and satisfaction surveys · Auditing and statistical analysis
|
Communication & Marketing |
· Services relating to our marketing, including the sending of commercial offer · Sweepstakes sponsors & organisation of contests, promotions, and events · Customer service including customer relations management (such as call centers, communication tools) · Email services |
Insurance & Debt collection (only where relevant) |
· Third party insurance providers (e.g. for providing you with extended warranty) · Debt collection agencies (only where relevant) |
For all of this data sharing, we ensure that we only work with trusted companies and secure these
relationships (contracts, audits, guarantees and security tests, etc.). These companies all have strict obligations to protect your information.
4.4. CORPORATE AFFILIATES
We may share information with other Nissan companies and transfer it to a third party in case of a merger, reorganisation or similar event.
4.5. COMPLIANCE AND SECURITY
It may be necessary for us to disclose your personal data to public and governmental authorities for reasons of national security,
law enforcement or other issues of public importance. In particular, we may share your personal data to:
- the police, fraud prevention and identity authentication entities, other law enforcement agencies, government, and tax authorities in the European Union or abroad in order to detect, investigate and prevent crime (please note that
fraud prevention agencies may also enable law enforcement agencies to access and use your personal data to detect, investigate and prevent crime);
- the courts in the European Union or abroad as necessary to comply with a legal requirement, for the administration of justice, to protect vital interests and to protect the security or integrity of our business operations.
Where legally permitted we will inform you ahead of such transfer.
We may also disclose personal information if we
determine in good faith that disclosure is necessary to protect our rights, resolve legal conflict, enforce our terms and conditions, investigate fraud or protect our users or infrastructures.
5. WILL YOUR PERSONAL DATA BE TRANSFERRED OUTSIDE OF THE EUROPEAN UNION?
Your personal data may be processed outside of the European Union (EU) / European Economic Area (EEA) (i.e. the Member States of the
European Union from time to time, together with Norway, Iceland, Switzerland and Liechtenstein).
In particular, we share your personal data with several stakeholders (such as social media platforms located in the United States,
invoicing service providers located in Japan or our corporate affiliates located in many countries of the world, including Nissan Motor Company Limited in Japan) for the purposes set forth in this Policy.
Please note that where your personal data are
transferred to a country outside of the EU / EEA that does not guarantee a level of data protection equivalent to that of the EU, such transfer will
either:
- rely on an adequacy decision (this
is the case for transfers to Japan or recently to U.S, with the adoption of the Data Privacy Framework) or;
- rely on appropriate safeguards such as standard contractual clauses issued by the European Commission that we undertake to implement each time, after having conducted an assessment of your rights on the territory of the third country and implemented any relevant supplementary
measures.
6. HOW DOES NISSAN PROTECT YOUR PERSONAL DATA?
We want to make sure that your personal data is stored and processed in a way which is secure. We have implemented technical and organizational measures in order to protect your personal data, in particular against potential data breaches likely to cause, either by accident or unlawfully, the destruction, loss, modification, unauthorized access or divulgation of your personal data.
These measures will guarantee a level of security adapted to the data and will take into account the state of the art and the cost of implementation in
relation to the risks and nature of the data to be protected.
We guarantee that all members of our personnel and any other person processing your personal data will respect the internal rules and procedures related to the processing of personal data, including the technical and organizational security measures put in place to protect your personal data.
7. WHAT ARE YOUR RIGHTS?
You have various rights in relation to the personal data which we hold about you. You can
exercise these rights at any time by contacting us through through our DPO (hrafnhildur@bl.is).
- Right to object
This right enables you to object to us processing your personal data. If you object, we will stop using your data unless we can demonstrate compelling legitimate grounds (which overrides your interests) or if our use of your data is necessary for the establishment, exercise, or defense of legal claims. In addition, you have a discretionary right to
object to direct marketing at any time (see section 8 below).
- Right to withdraw consent
Where we have obtained your permission to process your personal data for certain
activities, you may withdraw this consent at any time. If you ask us to do this, we’ll stop using your data unless we consider that there is an alternative legal reason to justify our continued processing of your data for this purpose, in which case we will tell you.
- Right to access your data
You may ask us for a copy of the information we hold about you at any time thanks to
the form abovementioned. We will respond to your request within one month. That
period may be extended by two further months where necessary, taking into
account the complexity and number of requests. We may request proof of identification to verify your request. If you request further copies of this information from us, we may charge you a reasonable administrative cost. Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will always tell you the reasons for doing so.
- Right to erasure
You have the right to request that we "erase" your personal data in certain
circumstances. We would only be entitled to refuse to comply with your request
for erasure in limited circumstances and we will always tell you our reason for doing so.
- Right to restrict processing
You have the right to request that we restrict our processing of your personal data in
certain circumstances, for example if you dispute the accuracy of the personal data that we hold about you or you object to our processing of your personal data for our legitimate interests. If we have shared your personal data with third parties, we will notify them about the restricted processing unless this is impossible or involves disproportionate effort. We will, of course, notify you before lifting any restriction on processing your personal data.
- Right to rectification
You have the right to request that we rectify any inaccurate or incomplete personal data
that we hold about you. If we have shared this personal data with third parties, we will notify them about the rectification unless this is impossible or involves disproportionate effort. You may also request details of the third parties that we have disclosed the inaccurate or incomplete personal data to. Where we think that it is reasonable for us not to comply with your request, we will explain our reasons for this decision.
- Right to portability
You have the right to request to receive your data in a structured, commonly used, and machine-readable format and or request us to transmit such personal data to a third party, acting as a data controller.
- Right to communicate your “last wills and instructions”
If you reside in France, you may communicate your “last wills and instructions” to be applied to your personal data in the event of your death (for example, their deletion or transfer to a person of your choice).
- Right to complain
You also have the right to lodge a complaint with a supervisory authority – depending on the country where you reside (e.g., for France, you may contact the CNIL and in the
United Kingdom the ICO). We encourage you to contact us first, so that we may
attempt to resolve your problem together.
8. CHANGE YOUR MARKETING PREFERENCES
You may change your marketing preferences and stop receiving marketing communications from us (including online targeted advertising) at any time
by:
- using the unsubscribe link in the communications sent to you or;
by contacting our Contact Center (Tel: +354 5258000 or via our webform.
9. HOW TO CONTACT US
If you have any queries about this Privacy Policy, including your rights in relation to your personal data, please contact our customer services team by email at: bl@bl.is
Alternatively, you can contact our Data Protection Officer by email at: hrafnhildur@bl.is or the DPO for Nissan Europe at: dpo@nissan-europe.com.
10. MODIFICATION OF THIS POLICY
We may amend this policy from time to time. We will inform you and/or seek your consent whenever necessary or required. We therefore recommend that you consult this policy each
time you visit our website in order to review the latest version.
Version 02 updated on 19.03.2024.