en
de
porsche.comStart

Rental

StartPricesReservationStationsVoucherFAQ
Subscription
Log in
Data Protection and Privacy Information of Porsche Financial Services GmbH & Co. KG and Porsche Financial Services GmbH
Porsche Financial Services GmbH & Co. KG and Porsche Financial Services GmbH (hereinafter "we" or "Porsche Financial Services") are pleased about your interest in our products. Your privacy is an important issue for us. We take protecting your personal data and handling them confidentially very seriously. Your personal data is exclusively processed within the scope of the statutory provisions of the data protection laws of the European Union, in particular the General Data Protection Regulation (hereinafter "GDPR") and the German Federal Data Protection Act (Bundesdatenschutzgesetz).

In the following, we would like to inform you about the collection and processing of your personal data. Personal data (hereinafter "Data") means any information concerning an identified or identifiable natural person. With this data protection and privacy information, we inform you about the type, scope, and purpose of the collection of Data by Porsche Financial Services and how we process this Data. In addition, we inform you about the rights you have with respect to the processing of your Data.

Porsche Financial Services GmbH & Co. KG is a leasing company and sole "controller" within the meaning of the GDPR for the processing of your Data required for the conclusion, performance and termination of leasing contracts and any related purposes. Within the scope of its operations, Porsche Financial Services GmbH & Co. KG is supported by Porsche Financial Services GmbH as "processor" within the meaning of the GDPR.

Porsche Financial Services GmbH is the sole "controller" within the meaning of the GDPR for the processing of your Data required for the brokerage of and/or assistance in financings (Porsche Finance), insurances (e.g. Porsche CarPolicy Flex, Porsche Approved, Porsche Assistance), credit cards (e.g. Porsche Card S) and renting within the scope of Porsche rental products (e.g. Porsche Drive Rental, Porsche Drive Abo and Porsche Drive Flex) and any related purposes.

Summary of the data protection and privacy information

The following summary of our data protection and privacy information is intended to give you an overview of the processing of your Data. On the pages following this summary, please find the complete data protection and privacy information. The corresponding sections of the complete data protection and privacy information can also be accessed through a link at the end of each of the following sections.
For consolidated information on the processing of your Data, the processing purposes and legal bases in connection with specific rental products of Porsche Financial Services GmbH, please refer to Section 6 of this summary.

1. Scope
With respect to the processing of your Data by Porsche Financial Services GmbH & Co. KG, this data protection and privacy information shall apply to the conclusion, performance and termination of leasing contracts with Porsche Financial Services GmbH & Co. KG and any related purposes (e.g. sureties).
With respect to the processing of your Data by Porsche Financial Services GmbH, this data protection and privacy information shall apply to the brokerage of and/or assistance in financings, insurances, credit cards and renting within the scope of Porsche rental products (e.g. Porsche Drive Rental, Porsche Drive Abo and Porsche Drive Flex) and any related purposes. For further information, please refer to Paragraph I, Section 1 of the complete data protection and privacy information or use the following link.

2. Contact
If you wish to exercise your rights as a data subject or have any questions about this information, you can email the controller at financial.services@porsche.de or the controller's data protection officer directly at pfs-datenschutz@porsche.de , stating wherever possible the relevant controller's name. For further information, please refer to Paragraph I, Section 2 of the complete data protection and privacy information or use the following link.

3. Processing of your Data
First, we process Data that you provide us in connection with the initiation and conclusion of the contract. Which Data is processed in detail and how it is used primarily depends on the individual services applied for by you and/or agreed with you. This may be the following Data in particular: Your name and other master and identification data, your contact data, contract data, vehicle data, your bank details, your income and assets situation, information on your personal circumstances (e.g. employer), corporate customer data and other data in connection with the performance of the respective business relationship, if applicable. For further information with respect to Porsche Financial Services GmbH & Co. KG, please refer to Paragraph II, Section 1 (link) and with respect to Porsche Financial Services GmbH to Paragraph III, Section 1 (link) of the complete data protection and privacy information.

4. Processing purposes
The processing purposes shall be largely determined by the individual services applied for or agreed upon. Your Data can be processed for the following purposes: Drafting and performance of contracts (e.g. leasing contracts and/or guarantee contracts), credit standing checks, scoring and rating, identity checks, prevention of and protection against violations of law (in particular criminal offenses), prevention of fraud and money laundering, fight against terrorist financing, customer inquiries including complaint management, refinancing by sale and assignment of receivables, audit, accounting and taxes, ensuring legally compliant action, assertion of and defense against legal claims, retention and archiving, ensuring availability, operation and safety of technical systems as well as technical data management, controlling, business/risk control, process and product improvement (including development and enhancement of systems (including artificial intelligence) for process improvement), disclosure within the scope of official/court measures and customer and prospect are/advertising. For further information with respect to Porsche Financial Services GmbH & Co. KG, please refer to Paragraph II, Section 2 (link) and with respect to Porsche Financial Services GmbH to Paragraph III, section 2 (link) of the complete data protection and privacy information.

5. Legal bases for the processing of your Data
We process your Data only if an appropriate legal basis is in place. For further information with respect to Porsche Financial Services GmbH & Co. KG, please refer to Paragraph II, Section 2 (link) and with respect to Porsche Financial Services GmbH to Paragraph III, Section 2 (link) of the complete data protection and privacy information.

6. Product-specific information on rental products (Porsche Drive)
Porsche Financial Services GmbH processes Data that you provide us in connection with the reservation, initiation and conclusion of the contract as well as the performance of the contract. This is the following Data in particular: master data, contact data, communication data, Identification data and driver's license data, bank details and/or credit card data, inquiry and contract data, vehicle and driving data as well as, in exceptional cases, location data of the vehicle, data on the provision of a security, insurance and adjustment of damages data, investigative data, corporate customer data, if applicable, and other data. Your Data can be processed for the following purposes: Sale and redemption of vouchers, conclusion and performance of the leasing contracts (including reservations) and vehicle handover, credit standing checks, scoring, rating, registration by credit bureau, taking back of vehicles during or after the end of the rental period, identity checks, ensuring accuracy of the Data, prevention of fraud and prevention of and protection against violations of law (in particular criminal offenses), law enforcement and prosecution of criminal offenses and administrative offenses, disclosure within the scope of official/court measures, customer inquiries including complaint management, audit, accounting and taxes, assertion of and defense against legal claims, retention and archiving, ensuring availability, operation and safety of technical systems as well as technical data management, controlling, business/risk control, process and product improvement (including development and enhancement of systems (including artificial intelligence) for process improvement), customer and prospect care/advertising. For further information on the respective rental product, please refer to Paragraph IV (link).

7. Data transfers and recipients and legal justification for such transfers
At Porsche Financial Services, only those departments needing your Data within the scope of their activity do actually receive it. We disclose your Data to recipients outside Porsche Financial Services (e.g. dealers, credit bureau, marketing agencies) only if this is required for the handling or processing of your inquiry or for the performance of the contract or if otherwise permitted under statutory law (e.g. a prevailing legitimate interest exists) or if we have obtained your valid consent. For further information, please refer to Paragraph V, Sections 2 (link) and 5.1 (link) of the complete data protection and privacy information. Further data protection information on the implementation of customer and prospect care at Porsche can be found in Paragraph V, Section 3 (link) of the full data protection information.

8. Profiling including automated decision-making
In the context of assessing your creditworthiness, we use, among other things, a scoring procedure. This is based on a mathematically and statistically recognized and proven procedure. Within the scope of processing existing customer inquiries, in particular when checking and evaluating your creditworthiness documents, we make use of automated decision-making to a certain extent in order to be able to make a fair and responsible decision. To this end, we use the information you provide to us via the self-disclosure form and substantiate with supporting documents, external creditworthiness information from reputable service providers (e.g. SCHUFA), and information about your previous payment history. For the Porsche rental products Porsche Drive Abo and Porsche Drive Flex, our experience from previous business relationships and certain information from credit bureaus (SCHUFA, Creditreform) are taken into account in the creditworthiness decision. Currently, we only carry out fully automated decision-making processes in the event of an indicative assessment of a positive decision on your request. You can find more information on this under Paragraph V, Section 5 (link).

9. Storage periods and erasure of your Data
We will delete your Data as soon as it is no longer needed for the purposes for which it was initially collected or if this is required in accordance with the applicable statutory provisions unless there are contractual or statutory storage periods or storage rights in place precluding the erasure. For further information, please refer to Paragraph V, Section 6 of the complete data protection and privacy information or use the following link.

10. Your statutory rights
According to the applicable statutory provisions in each case, you have certain rights, e.g. the right of access to your Data and the right to rectification, erasure or restriction of processing of your Data as well as the right to data portability. If you have any questions, please use the contact details provided in Paragraph I, Section 2 of the complete data protection and privacy information. For further information, please refer to Paragraph V, Section 5 of the complete data protection and privacy information or use the following link.


Complete data protection and privacy information

I. General information

1. To whom does this data protection and privacy information apply?
With respect to the processing of your Data by Porsche Financial Services GmbH & Co. KG, this data protection and privacy information shall apply to the conclusion, performance and termination of leasing contracts with Porsche Financial Services GmbH & Co. KG and any related purposes, which are in particular described in more detail in Paragraph II, Section 2.

With respect to the processing of your Data by Porsche Financial Services GmbH, this data protection and privacy information shall apply to the brokerage of and/or assistance in financings (Porsche Finance), insurances (e.g. Porsche CarPolicy Flex, Porsche Approved, Porsche Assistance), credit cards (e.g. Porsche Card S) or renting within the scope of Porsche Drive Rental, Porsche Drive Abo, Porsche Drive Flex and any related purposes as well as in the event of the assignment of receivables from Baden-Württembergische Bank, Stuttgart, to Porsche Financial Services GmbH and as in particular described in more detail in Paragraph III, Section 2.

For information on offers of other Group companies of the Dr. Ing. H.c. F. Porsche AG (hereinafter “Porsche Group”), our cooperation partners and credit bureaus, please refer to the respective data protection and privacy statements of these services and/or cooperation partners.

2. Who is responsible for the data processing and whom can you contact in data protection matters?

2.1 The independent controller within the scope of leasing contracts is:
Porsche Financial Services GmbH & Co. KG
Porschestraße 1,
74321 Bietigheim-Bissingen, Germany
Phone: +49 711 911-12003
Email: financial.services@porsche.de


2.2 The independent controller within the scope of the brokerage of and/or assistance in financings, insurances, credit cards and rental products is:
Porsche Financial Services GmbH
Porschestraße 1,
74321 Bietigheim-Bissingen, Germany
Phone: +49 711 911-12003
Email: financial.services@porsche.de


2.3 Joint control
With regard to processing within the scope of intra-group administration and division of responsibilities by way of centralized systems, we are generally joint controllers together with other Group companies of Dr. Ing. h.c. F. Porsche AG. Joint processes in particular relate to the operation and use of jointly used databases, platforms and IT systems. For information on joint controlling in relation to customer and prospect care, please refer to Paragraph V, Section 3.1.

Joint controlling of Porsche Financial Services GmbH exists with Dr. Ing. h.c. F. Porsche AG and the Porsche Centres with regard to the processing of personal data in the context of the contract management of Porsche Assistance and Porsche Approved with respect to the joint use of the central IT systems “World Warranty System”, which is provided and operated by Dr. Ing. h.c. F. Porsche AG.

Joint control with Porsche Sales and Marketplace GmbH (Porscheplatz 1, 70435 Stuttgart, Germany) as regards the processing of personal data exists on the part of
Porsche Financial Services within the scope of processing specific inquiries and/or transactions via the One Marketplace platform (Porsche Online Shop) of Porsche. Joint control relates to the inquiry and order process as services of Porsche Financial Services are chosen on the platform. In addition to technical services, Porsche Sales and Marketplace GmbH then contributes the customer's account data (Porsche ID) and renders customer support services in accordance with the platform concept.
Porsche Financial Services GmbH within the scope of the registration and login procedure, integrating the Porsche ID for the conclusion and processing of rental products (Porsche Drive) via corresponding websites. Information on data protection and privacy when using the website can be found in the respective online application form. For more information please refer to Paragraph IV, Section 1.

If you have chosen vehicle financing through Baden-Württembergische Bank (Kleiner Schlossplatz 11, 70173 Stuttgart) with support from Porsche Financial Services GmbH, there is a joint responsibility with the Bank with regard to the processing of personal data. The joint responsibility extends on the part of Porsche Financial Services GmbH to the processing of customer and prospect inquiries, customer care and care within the framework of complaint management. Porsche Financial Services additionally supports the credit assessment with regard to the development and validation of a joint scorecard as well as the use of experience from previous business relationships and the protection against and prevention of legal violations.

The exchange of personal data between us and further Group companies as joint controllers is usually based on Article 6 (1) point (f) GDPR, because we have a legitimate interest in the effective implementation of the processing within the scope of the intra-group administration and division of responsibilities by way of centralized systems. The exchange of personal data between us and the Baden-Württembergische Bank as joint controllers is generally based on Article 6 (1) point (f) GDPR. We have a legitimate interest in a practicable organization of the processes within the joint business relationship and the exchange of data for the fulfillment of legal requirements for the performance of creditworthiness or credit checks of customers as well as the protection against criminal acts endangering assets.

With respect to the joint processes, we determine the purposes and means of the processing of personal data together with the respective Group companies In an arrangement on joint control pursuant to Article 26 GDPR, we have determined with the relevant companies the way the respective tasks and responsibilities in the processing of personal data are designed and who is to comply with which obligations under data protection laws. In particular, we determined how an adequate level of security and your rights as a data subject can be ensured, how we can jointly comply with the duties to provide information under data protection laws, and how we can monitor potential data protection incidents. This also includes that we can ensure compliance with our reporting and notification obligations (to the extent we are subject to such obligations). You can request further information on this arrangement via the above-mentioned contact details. In legitimate cases, we will provide you with the relevant regulations.

Porsche Financial Services remains at your disposal as your central point of contact. You can, however, also assert your rights with respect to any processing under joint control vis-à-vis a jointly responsible Group company. To the extent you contact us, we will coordinate with the relevant companies within the meaning of the arrangement pursuant to Article 26 GDPR in order to answer your inquiries and guarantee your rights as a data subject.

2.4 Contact details of the data protection officer
Please do not hesitate to contact our data protection officer if you have any data protection-related questions, stating wherever possible the name of the controller addressed. You can write them to the controller's address provided above, adding "Data Protection Officer, PFS Group Data Protection" or email them at pfs-datenschutz@porsche.de.

2.5 Secure communication
We would like to inform you that any communication by email will not be encrypted, and that authenticity and integrity of the data is, thus, not warranted. Please feel free to submit your documents in encrypted format. For information on the various options, please visit our website at www.porsche.de/pfs/datenaustausch. In case you do not want to make use of these options, we kindly ask that you send sensitive information by mail to the above-mentioned address.

II. Data processing by Porsche Financial Services GmbH & Co. KG

1. Where is your Data from and which Data will be processed?
We process your Data in accordance with the principles of data reduction and data economy only to the extent that this is required, we are permitted to do so under applicable legal requirements, we are required to do so by statutory law, or you have given your consent.

1.1 General Data under the business relationship
First, we process Data that you provide us in connection with the initiation and conclusion of the contract. Which Data is processed in detail primarily depends on the services applied for by you and/or agreed with you. Relevant Data usually includes:
master data (in particular first name and last name, date of birth)
contact details (in particular address, telephone numbers, email addresses)
communication data (e.g. data from postal, electronic and telephone communication)
bank details (e.g. bank name, IBAN/BIC, account holder)
contract data (e.g. commencement and end date, terms, purposes of use and authorized drivers)
legitimation data (Data contained in the identity card or any other legitimation documents presented) and other Data for money laundering and fraud prevention purposes (e.g. Data on politically exposed persons or beneficial owners)
biometric signature data (coordinates, print, time response, incl. time of recording)
Income and assets situation, including the origins of assets (e.g. income, expenses, residential property)
information on personal circumstances (e.g. profession, employer, marital status, maintenance obligations, health insurance)
insurance and adjustment of damages data (e.g. liability loss or own damage, theft)
investigative data (e.g. official inquiries regarding tickets, fines, fees) corporate customer data (e.g. business results, shareholding structures, authorized signatories) for corporate customers as well as any data in connection with the performance of the respective business relationship, if applicable.

1.2 Data from other sources
Subject to compliance with the legal requirements and for purposes of investigating addresses, performing credit standing checks, collecting receivables or perform risk management, information on your person may also be requested from third-party sources (e.g. Data from credit bureaus, sanctions/money laundering/terrorist financing databases, Data from lists of debtors, land registers, commercial registers and registers of associations, press, media or other public bodies as well as Data from address investigation companies and collection agencies). For more information on the use of external creditworthiness information from reputable service providers (SCHUFA, Creditreform Boniversum, possibly GRIF Bürgel), please refer to Paragraph V, Section 5.1 link.

Moreover, we also receive further Data from third parties (in particular from dealers) such as vehicle data (e.g. vehicle identification number, license plate number, information on the condition). To the extent that the vehicle is not otherwise trackable, the seizure of the vehicle offers the opportunity to have the service provider determine the location of the vehicle via GPS tracking in order to enforce our claim for surrender in the event of theft or misappropriation.

2. For what purposes and on which legal basis will your Data be processed?

We process your Data always for a specific purpose and only to the extent this is necessary to accomplish that purpose. Your Data is processed based on the following legal bases:

You have given your consent (Article 6 (1) point (a) GDPR); The processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (Article 6 (1) point (b) GDPR). The processing is necessary for compliance with a legal obligation to which Porsche Financial Services GmbH & Co. KG is subject (Article 6 (1) point (c) GDPR); and/or The processing is necessary for the purpose of the legitimate interests pursued by Porsche Financial Services GmbH & Co. KG or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of the Data (Article 6 (1) point (f) GDPR).

The following overview specifies the legal basis on and the purposes for which the Data listed in Paragraph II; Section 1 is processed.
PurposeExamplesLegal basisLegitimate interest
after balancing of interest
Drafting and performance
of leasing contracts
Preparation and processing of offers, collection
of payments, answering of inquiries, return
process (vehicle value determination, seizure,
and recycling of vehicles), handling of all
services included (e.g. maintenance processes,
CO2 compensation), assistance in adjustment
of claims, coordination of recall actions
Initiation and performance of
contract (Article 6 (1) point (b) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR
Practicable structuring of the processes
within the scope of the business
relationship
Creditworthiness checks,
scoring and rating (for more
information in this context,
please see Paragraph V,
Section 5)
Exchange of Data with credit bureaus
(e.g. SCHUFA, Creditreform, CRIF Bürgel) as
well as subsequent internal use of Data for the
purpose of creditworthiness checks (within the
scope of the application consideration and
contract performance), testing of Data quality
and score card development/validation,
reporting of contract-infringing or fraudulent
behavior
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests
(Article 6 (1) point (f) GDPR)
The exchange of Data with credit bureaus
(e.g. SCHUFA) is in our legitimate interest
and serves the purpose of compliance with
statutory requirements to perform credit
standing and/or creditworthiness checks
with respect to customers (section 505a
German Civil Code (Bürgerliches Gesetzbuch;
BGB), section 18a German Banking Act
(Kreditwesengesetz; KWG)).
Reduction of default risks
Identity checks (please take
note of the additional data
protection information
concerning the use of the
video identification
procedure (Video-IdentProcedure)
Advanced electronic signature,
Authentication control, verification
of legal competency, legitimation
under anti-money laundering laws
Initiation and performance of
contract (Article 6 (1) point (b)
GDPR); compliance with legal
obligations (Article 6 (1) point (c)
GDPR), consent (Article 6 (1) point
(a) GDPR)
Prevention of and
protection against violations
of law (in particular
criminal offenses),
prevention of fraud and
money laundering, fight
against terrorist financing
Data analyses to identify hints, handling of
suspected cases within the scope of leasing
contracts
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR)
Protection against financial crimes
Customer inquiries
including complaint
management
Processing of general or extra-contractual
inquiries and requests of prospects and
customers, processing of complaints
(exchange with dealers and other Group
companies to clarify facts and circumstances,
as applicable)
Initiation and performance of
contract (Article 6 (1) point (b)
GDPR); balancing of interests (Article 6
(1) point (f) GDPR)
Practicable structuring of the processes
within the scope of the business
relationship
Refinancing by sale and
assignment of receivables
Within the scope of the
refinancing of the leasing contracts, aliased and encrypted
transfer of the Data to a trustee who will store
them until the occurrence of a defined risk
(trigger event); transfer of Data in the case of
assignment of receivables.
Balancing of interests (Article 6 (1) point (f) GDPR)Prevention of loss of receivables and
assurance of continuity of contracts,
improved conditions for customers
AuditAudits/special audits, internal investigationsCompliance with legal obligations
(Article 6 (1) point (c) GDPR)
Balancing of interests (Article 6 (1)
point (f) GDPR)
Effectiveness and appropriateness of risk
management, in particular of the internal
control mechanism, correctness and
efficiency of activities and processes
Accounting and taxesManagerial accounting (external and internal
accounting, statistics, and comparative
calculation, as well as budgeting), statutory
documentation, consolidated accounting
Compliance with legal obligations
(Article 6 (1) point (c) GDPR)
Ensuring legally compliant
action, asserting of and
defending against legal
claims
Defense in legal disputes, collection of
receivables, seizure of vehicles (by using
GPS tracking, as applicable), Authentication of
signatures
Performance of contract (Article 6
(1) point (b) GDPR); balancing of
interests (Article 6 (1) point (f)
GDPR), Assertion and defense of
legal claims (Article 9 (2) point f
GDPR)
Assertion and defense of our rights
Retention and archivingArchiving on the basis of retention obligations
under tax, trade and regulatory laws
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR)
Securing evidence for asserting and
defending our rights (e.g. collection of receivables)
Ensuring availability,
operation and safety of
technical systems as well as
technical data management
Back-up, preparing minutes and
reporting, tests and analysis
of weaknesses
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR)
Risk/quality management, warranty of
safety objectives (integrity and
confidentiality, availability and
transparency
Controlling, business/risk
control
Anonymized or aliased statistical analyses
concerning corporate management, reporting
concerning economic parameters
Compliance with legal obligations
(Article 6 (1) point (c) GDPR)
Balancing of interests (Article 6 (1)
point (f) GDPR)
Analyses concerning steering of business
processes, cost control
Improvement of processes
and products (including
development and
enhancement of systems
(including artificial
intelligence) for process
improvement)
Enhancement of products, services and
aftersale services, as well as other measures for
steering business transactions and processes,
improvement of the product quality,
development and use of new technologies for
task automation, training of data processing
artificial intelligence, which should replace the
manual preparation of decision making and
thereby accelerate manual processing
(including decision-making)
Balancing of interests (Article 6 (1)
point (f) GDPR)
Ongoing optimization of processes and
products
Disclosure within the scope
of official/court measures
Disclosure of Data within the scope of controls
(KWG, German Money Laundering Act
(Geldwäschegesetz; GwG), tax laws) and
reports to public bodies (e.g. financial services
authorities, Deutsche Bundesbank and the
Federal Financial Supervisory Authority)
required under statutory law, forwarding of
contact data in case of tickets, fines, fees or the
like, to the respective authorities
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR)
Proof of proper business organization
and compliance with statutory requirements,
assertion and defense of our rights
Customer and prospect
care/advertising
See Paragraph V, section 3.
Consent (Article 6 (1) point (a)
GDPR), balancing of interests
(Article 6 (1) point (f) GDPR) to the
extent admissible under statutory
law
Ensuring customer and interest-oriented
care



III. Data processing by Porsche Financial Services GmbH

Please note: For information on the processing of your Data in connection with rental products of Porsche Financial Services GmbH, such as Porsche Drive Rental, Porsche Drive Abo and Porsche Drive Flex, please refer to Paragraph IV.

1. Where is your Data from and which Data will be processed?
We process your Data in accordance with the principles of data reduction and data economy only to the extent that this is required, we are permitted to do so under applicable legal requirements, we are required to do so by statutory law, or you have given your consent.

1.1 General Data under the business relationship
First, we process Data that you provide us in connection with brokerage and assistance and/or in connection with the initiation and conclusion of the contract. Which Data is processed in detail primarily depends on the services applied for by you and/or agreed with you.
Relevant Data usually includes:
master data (in particular first name and last name, date of birth)
contact details (in particular address, telephone numbers, email addresses)
communication data (e.g. data from postal, electronic and telephone communication)
bank details (e.g. bank name, IBAN/BIC, account holder)
contract data (e.g. commencement and end date, terms)
as well as any other data in connection with the performance of the respective business relationship, if applicable.

In particular within the scope of any vehicle financing and assignment of receivables from Baden-Württembergische Bank, Stuttgart, to Porsche Financial Services GmbH, these may also include
identification data (Data contained in the identity card or any other identification documents presented) and other Data for money laundering and fraud prevention purposes (e.g. Data on politically exposed persons or beneficial owners)
biometric signature data (coordinates, print, time behavior, incl. time stamp)
Income and assets situation, including the origins of assets (e.g. income, expenses, residential property)
information on personal circumstances (e.g. profession, employer, marital status, maintenance obligations, health insurance)
insurance and adjustment of damages data (e.g. liability loss or own damage, theft)
corporate customer data (e.g. business results, shareholding structures, authorized signatories) for corporate customers as well as any data in connection with the performance of the respective business relationship, if applicable.

If you have already registered Data on the "My Porsche" portal, this Data is automatically inserted in the "Personal Data" fields of the electronic application.

1.2 Data from other sources
Subject to compliance with the legal requirements and for purposes of investigating addresses or collecting receivables, information on your person may also be requested from third-party sources (e.g. Data from address investigation companies and collection agencies, Data from lists of debtors, land registers, commercial registers and registers of associations, press, media or other public bodies). Moreover, we also receive further Data from third parties (in particular from dealers) such as vehicle data (e.g. vehicle identification number, license plate number).

2. For what purposes and on which legal basis will your Data be processed?

We process your Data always for a specific purpose and only to the extent this is necessary to accomplish that purpose. Your Data is processed based on the following legal bases:
You have given your consent (Article 6 (1) point (a) GDPR).
The processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (Article 6 (1) point (b) GDPR).
The processing is necessary for compliance with a legal obligation to which Porsche Financial Services GmbH & Co. KG is subject (Article 6 (1) point (c) GDPR); and/or
The processing is necessary for the purpose of the legitimate interests pursued by Porsche Financial Services GmbH & Co. KG or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of the Data (Article 6 (1) point (f) GDPR).

The following overview specifies the legal basis on and the purposes for which the Data listed in Paragraph III; Section 1 is processed.

PurposeExamplesLegal basisLegitimate interes
after balancing of interest
Preparation and
implementation of
brokerage of and/or
assistance in financings,
insurances and credit cards
Preparation and processing of offers, collection
of payments, answering of inquiries, assistance
in adjustment of claims
Initiation and performance of
contract (Article 6 (1) point (b) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR
Practicable structuring of the processes
within the scope of the business
relationship
Processing of additional
services for credit cards
("convenience services")
Checking and invoicing of additional services
provided to the customer by service providers,
answering inquiries
Initiation and performance of
contract (Article 6 (1) point (b)
GDPR)
Identity checks (please take
note of the additional data
protection information
concerning the use of the
video identification
procedure
Authentication control, verification of legal
competency, creation of an advanced electronic
signature
Initiation and performance of
contract (Article 6 (1) point (b)
GDPR); compliance with legal
obligations (Article 6 (1) point (c)
GDPR), consent (Article 6 (1) point
(a) GDPR)
Customer inquiries
including complaint
management
Processing of general or extra-contractual
inquiries and requests of prospects and
customers, processing of complaints
(exchange with dealers and other Group
companies to clarify facts and circumstances,
as applicable)
Initiation and performance of
contract (Article 6 (1) point (b)
GDPR); balancing of interests (Article 6
(1) point (f) GDPR)
Practicable structuring of the processes
within the scope of the business
relationship
AuditAudits/special audits, internal investigationsCompliance with legal obligations
(Article 6 (1) point (c) GDPR)
Balancing of interests (Article 6 (1)
point (f) GDPR)
Effectiveness and appropriateness of risk
management, in particular of the internal
control mechanism, correctness and
efficiency of activities and processes
Accounting and taxesManagerial accounting (external and internal
accounting, statistics, and comparative
calculation, as well as budgeting), statutory
documentation, consolidated accounting
Compliance with legal obligations
(Article 6 (1) point (c) GDPR)
Ensuring legally compliant
action, asserting of and
defending against legal
claims
Evaluation of experience from previous business
relationships for protection against and
prevention of legal violations, defense in legal
disputes, collection of receivables, seizure of
vehicles (by using GPS tracking, as applicable),
authentication of signatures
Performance of contract (Article 6
(1) point (b) GDPR); balancing of
interests (Article 6 (1) point (f)
GDPR), Assertion and defense of
legal claims (Article 9 (2) point f
GDPR)
Protection against crimes endangering
assets, assertion and defense of our rights
Retention and archivingArchiving on the basis of retention obligations
under tax, trade and regulatory laws
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR)
Securing evidence for asserting and
defending our rights (e.g. collection of
receivables)
Ensuring availability,
operation and safety of
technical systems as well as
technical data management
Back-up, preparing minutes and
reporting, tests and analysis
of weaknesses
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR)
Risk/quality management, warranty of
safety objectives (integrity and
confidentiality, availability and
transparency)
Controlling, business/risk
control
Anonymized or aliased statistical analyses
concerning corporate management, reporting
concerning economic parameters, Scorecard
development/validation as well as use of
experience from previous business relationships
for reduction of default risks
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6 (1)
point (f) GDPR)
Analyses concerning steering of business processes
,cost control, reduction of default
risks
Improvement of processes
and products (including
development and
enhancement of systems
(including artificial
intelligence) for process
improvement)
Enhancement of products, services and
aftersale services, as well as other measures for
steering business transactions and processes,
improvement of the product quality,
development and use of new technologies for
task automation, training of data processing
artificial intelligence, which should replace the
manual preparation of decision making and
thereby accelerate manual processing
(including decision-making)
Balancing of interests (Article 6 (1)
point (f) GDPR)
Ongoing optimization of processes and
products
Disclosure within the scope
of official/court measures
Disclosure of Data within the scope of
implementing controls required under statutory
law (e.g. tax audit)
Compliance with legal obligations
(Article 6 (1) point (c) GDPR);
balancing of interests (Article 6
(1) point (f) GDPR)
Demonstration of compliance with statutory
requirements
Customer and prospect
care/advertising
see Paragraph V, section 3Consent (Article 6 (1) point (a)
GDPR), balancing of interests
(Article 6 (1) point (f) GDPR) to the
extent admissible under statutory
law
Ensuring customer and interest-oriented
support


IV. Product-specific information on rental products (Porsche Drive)

Porsche Financial Services GmbH offers to you the products Porsche Drive Rental, Porsche Drive Abo and Porsche Drive Flex (hereinafter jointly "Porsche Drive"). For more information about these products, please click the following link.
The below information refers to all Porsche Drive Rental, Porsche Drive Flex and Porsche Drive Abo, unless expressly referring to only one of those.


1. Where is your Data from and which Data will be processed?
We process your Data in accordance with the principles of data reduction and data economy only to the extent that this is required, we are permitted to do so under applicable legal requirements, we are required to do so by statutory law, or you have given your consent.

You can contact us to make a reservation request via the online application process for Porsche Drive Rental (available here). For long-term rentals (Porsche Drive Abo and Porsche Drive Flex), you have the option of making a vehicle reservation and submitting a non-binding request via the respective online application process Porsche Drive Abo (available here) and Porsche Drive Flex (available here). The conclusion of the rental contract and the associated provision of further data takes place at the service provider or dealer commissioned by us to fulfill the contract at the location you have chosen to pick up the vehicle.

1.1 General Data under the business relationship
First, we process Data that you provide us in connection with the initiation and conclusion of the contract. Which Data is processed in detail primarily depends on the services applied for by you and/or agreed with you. In case of rental products, the relevant Data generally comprise:
master data (in particular first name and last name, date of birth)
contact details (in particular email address, telephone number, address)
communication data (e.g. data from electronic communication)
ID-card and driver's license data (cf. Paragraph IV, Section 1.2 for details)
Credit card data
reservation information
inquiry and contract data (e.g. commencement and end date, terms, location of rental and vehicle handover, purposes of use and authorized drivers, as applicable)
vehicle and driving data (in particular, type and category of vehicle, service life and mileage, vehicle condition) as well as location data of the vehicle, as applicable (cf. Paragraph IV, Section 1.2 for details)
the amount of security provided or payment information with respect to the provision of a security
insurance and adjustment of damages data (e.g. protection against accidents, theft)
investigative data (e.g. official inquiries regarding tickets, fines, fees)
corporate data, if the service is used as a corporate customer (e.g. company, location, tax number, shareholder)
other Data (e.g. Data provided within the scope of customer reviews or customer inquiries).

This Data is required for the conclusion and processing of the rental contract unless the information is marked as voluntary.

If you have already registered Data in your Porsche ID user account, this account data is automatically inserted in the respective fields of the application. The Porsche ID account is operated by Porsche Sales and Marketplace GmbH. With respect to data processing at Porsche Sales and Marketplace GmbH, we refer to their data protection and privacy information which is accessible here.

1.2 Specific Data

ID card and driver's license data: In order to fulfill our obligation to provide proof of a valid driver's license, you will be asked to provide a picture of the front and back of your driver's license as part of the online application process. Before handing over the vehicle and signing the rental contract, you will also be asked to present the original driving license for comparison (visual inspection). In a further step, we record the number, date and place of issue of your identification document (identity card or passport) in the system. We collect this data to ensure the correctness of the customer data (e.g. exclusion of spelling mistakes, assignment of first and last names, as well as for verification and security reasons (e.g. identity check, forwarding of data to the competent authorities in the event of a criminal offense or administrative offense in connection with the rented vehicle).

Creditworthiness checks: For Porsche Drive Abo and Porsche Drive Flex, we use our experience from previous business relationships and certain information from credit bureaus (any negative facts, score ranges) to check creditworthiness. For more information please refer to Paragraph V, Section 5 (link).

Location data: The vehicles are equipped with a tool to track their location. A vehicle's location will exclusively be tracked (i) if there is justified suspicion of misappropriation or fraud or the like, or (ii) if you alerted us on a possible theft, or (iii) to comply with official and/or legal requirements or obligations, such as, requests by public authorities, the prosecutor's office or a judge. Only a limited circle of staff will be given access to the location data.

Additional drivers: In the case of Porsche Drive Rental, we collect the surname, first name and driving license details of the additional drivers you use.

Porsche Connect: In addition, within the scope of Porsche Connect services available in the vehicle and their use by you, Data may be produced that we and our service provide will exclusively process for the purpose of rendering these services. The Porsche Connect services are offered by Porsche Sales and Marketplace GmbH. For information on the processing of your Data by Porsche Sales and Marketplace GmbH, please click here

1.3 Data from other sources
Subject to compliance with the legal requirements and for purposes of investigating addresses, performing credit standing checks, collecting receivables or perform risk management, information on your person may also be requested from third-party sources (e.g. Data from credit bureaus, sanctions/money laundering/terrorist financing databases, Data from lists of debtors, land registers, commercial registers and registers of associations, press, media or other public bodies as well as Data from address investigation companies and collection agencies). For more information on the use of external creditworthiness information from reputable service providers (e.g. SCHUFA), please refer to Paragraph V, Section 5 (link).

Moreover, we also receive further Data from third parties (in particular from dealers and service providers) such as vehicle data (e.g. vehicle identification number, license plate number, information on the condition).

2. For what purposes and on which legal basis will your Data be processed?

We process your Data always for a specific purpose and only to the extent this is necessary to accomplish that purpose. Your Data is processed based on the following legal bases:
You have given your consent (Article 6 (1) point (a) GDPR). The processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (Article 6 (1) point (b) GDPR).
The processing is necessary for compliance with a legal obligation to which Porsche Financial Services GmbH is subject (Article 6 (1) point (c) GDPR); and/or
The processing is necessary for the purpose of the legitimate interests pursued by Porsche Financial Services GmbH or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of the Data (Article 6 (1) point (f) GDPR).

The following overview shall set forth in detail the respective purpose of processing of the data categories described in Paragraph IV, Section 2.1, as well as the respective legal bases for such processing.

PurposeExamplesCategories of dataLegal basisLegitimate interest
after balancing of interests
Sale and redemption of
vouchers (at Porsche
Drive Rental)
Preparation of vouchers,
payment processing
Name, address, credit card data of the
acquirer of the voucher, information for
personalization, as applicable
Initiation and performance of
contract (Article 6 (1)
point (b) GDPR)
Conclusion and
performance of rental
contracts (including
reservations) and
handover of vehicles
Preparation of offers,
processing of offers and
reservations, collection of
payments, answering inquires,
handling of all services
included (depending on the
product, e.g. Connect Services,
maintenance processes),
adjustment of claims,
coordination of recall actions
Master data, contact data,
communication data, payment
information for the rental amount,
reservation information, request and
contract data, information on the
provision of a security, vehicle and
driving data
Initiation and performance of
contract (Article 6 (1)
point (b) GDPR); balancing
of interests (Article 6 (1)
point (f) GDPR)
Practicable structuring of
the processes within the
scope of the business
relationship
Creditworthiness checks
(for more information in
this context, please see
Section 5) in case of
Porsche Drive Abo and
Porsche Drive Flex
Exchange of Data with credit
bureaus (e.g. SCHUFA,
Creditreform) as well as
subsequent internal use of
Data for the purpose of
creditworthiness checks
Creditworthiness data (Paragraph IV,
Section 1.2)
Initiation and performance of
contract (Article 6 (1)
point (b) GDPR); compliance
with legal obligations
(Article 6 (1) point (c)
GDPR); balancing of
interests (Article 6
(1) point (f) GDPR)
The exchange of Data with
credit bureaus is in our
legitimate interest and
serves the purpose of
compliance with statutory
requirements to perform
creditworthiness checks
with respect to customers
(sections 505a, 506 BGB).
Reduction of default risks.
Registration with credit
bureaus
Notification of non-contractual
or fraudulent behavior to
SCHUFA (Paragraph V, Section
5.1)
Master data, contract data, payment
information, creditworthiness data
Balancing of interests
(Article 6 (1) (f) GDPR)
Protection against
over indebtedness of the
applicant, reduction of default risks
Taking back the vehiclesTaking back (and, as
applicable, seizure of) a vehicle
at the end of the rental period
or, in case of Porsche Drive
Flex, during the contract
period, valuation and damage
assessment
Master data, contact data, payment
information for settlement, time of
return, mileage, vehicle condition data.
Initiation and performance of
contract (Article 6 (1)
point (b) GDPR); balancing
of interests (Article 6 (1)
point (f) GDPR)
Practicable structuring of
the processes within the
scope of the business
relationship
Identity check, ensuring
accuracy of the Data
Identity check, driver's license
check, check that customer
details are correct.
ID card data,
driver's license data
Initiation and performance of
contract (Article 6 (1) point
(b) GDPR), balancing of interests
(Article 6 (1) point(f) GDPR).
Ensuring accuracy of the
Data
Prevention of and
protection against
violations of law (in
particular criminal offenses), prevention of fraud
Data analyses to identify hints,
handling of suspected cases
Master data, contact data, driver's
license data, ID card data, inquiry and
contract data
Balancing of interests
(Article 6 (1) point (f) GDPR).
Protection against financial
crimes, Combating
economic crime
Law enforcement and
prosecution of criminal
offenses and
administrative offenses,
disclosure within
the scope of official/court measures
Disclosure of names, ID card
data as well as driver's license
data to the competent
authorities or a court in case of
a criminal offense or
administrative offense in
connection with the rental
vehicle; assertion of claims in
cases of damage or breaches
of contract by the renter
Master data, contact data, driver's
license data, ID card data, investigation
data, contract data, vehicle as well as
driving data
Compliance with legal
obligations (Article 6
(1) point (c) GDPR);
balancing of interests
(Article 6 (1) point (f) GDPR)
Enforcement of our rights
and claims, protection
against financial crimes
Customer inquiries
including complaint
management
Processing of general or, as the
case may be, extra-contractual
inquiries and requests of
prospects and customers,
Processing of complaints
(exchange with dealers and
other Group companies to
clarify facts and
circumstances, as applicable)
Master data, contact data,
communication data, inquiry and
contract data
Initiation and performance of
contract (Article 6 (1)
point (b) GDPR); balancing
of interests (Article 6 (1)
point (f) GDPR)
Practicable structuring of
the processes within the
scope of the business
relationship
AuditAudits/special audits, internal
investigations
Master data, contact data,
communication data, inquiry and
contract data, payment information for
the rental amount, driver's license data,
ID card data, information on the
provision of a security, vehicle and
driving data
Compliance with legal
obligations (Article 6 (1)
point (c) GDPR); balancing of
interests (Article 6 (1)
point (f) GDPR)
Effectiveness and
appropriateness of risk
management, in particular of
the internal control
mechanism, correctness and
efficiency of activities
and processes
Accounting and taxesManagerial accounting
(external and internal
accounting, statistics and
comparative calculation, as
well as budgeting), statutory
documentation, consolidated
accounting
Master data, contact data, payment
information
Compliance with legal
obligations (Article 6 (1)
point (c) GDPR)
Ensuring legally
compliant action,
asserting of and
defending against legal
claims
Defense in legal disputes,
collection and sale of
receivables, seizure of
vehicles, tracking the location
of the vehicle in case of
justified suspicion of
misappropriation, fraud or
theft (cf. Paragraph IV,
Section 1.2)
Cf. Paragraph IV, Section 1.1Performance of contract
(Article 6 (1) point (b)
GDPR); balancing of
interests (Article 6 (1) point
(f) GDPR)
Asserting, exercising and
defending our rights;
preventing the loss of the
vehicle, protection against
financial crimes
Retention and archivingArchiving on the basis of
retention obligations under
tax, trade and regulatory laws
Cf. Paragraph IV, Section 1.1Compliance with legal
obligations (Article 6
(1) point (c) GDPR);
balancing of interests
(Article 6 (1) point (f) GDPR)
Securing evidence for asserting
and defending our rights (e.g.
collection of receivables)
Ensuring availability,
operation and safety of
technical systems as
well as technical data
management
Back-up, preparing minutes
and reporting, tests and
analysis of weaknesses.
Cf. Paragraph IV, Section 1.1Compliance with legal
obligations (Article 6
(1) point (c) GDPR);
balancing of interests
(Article 6 (1) point (f) GDPR)
Risk/quality management,
warranty of safety objectives
(integrity and confidentiality,
availability and transparency)
Controlling,
business/risk control
Anonymized or aliased
statistical analyses concerning
corporate management,
reporting concerning
economic parameters.
Inquiry and contract dataCompliance with legal
obligations (Article 6
(1) point (c) GDPR);
balancing of interests
(Article 6 (1) point (f) GDPR)
Analyses concerning steering
of business processes, cost control
Improvement of
processes and products
(including development
and enhancement of
systems (including
artificial intelligence) for
process improvement)
Enhancement of products,
services and aftersale
services, as well as other
measures for steering
business transactions and
processes, improvement of
the product quality,
development and use of new
technologies for task
automation, training of data
processing artificial
intelligence, which should
replace the manual
preparation of decision making
and thereby accelerate manual
processing (including
decision-making)
Cf. Paragraph IV, Section 1.1 and, as
part of the development and
enhancement of systems, also
creditworthiness data (Paragraph IV,
section 1.2.)
Balancing of interests
(Article 6 (1) point (f) GDPR)
Ongoing optimization of
processes and products
Customer and prospect
care/advertising
see Paragraph V, section 3Master data, contact data,
communication data, inquiry and
contract data, vehicle as well as driving
data, i.a. (for more information, please
refer to Paragraph V, Section 3 and
here)
Consent (Article 6
(1) point (a) GDPR),
balancing of interests
(Article 6 (1) point (f) GDPR
) to the extent admissible
under statutory law
Ensuring customer and interest-oriented care


V. Further information about Porsche Financial Services GmbH & Co. KG and Porsche Financial Services GmbH

The below information applies to both Porsche Financial Services GmbH & Co. KG and Porsche Financial Services GmbH as the respective independent controllers.

1. Is there a duty to provide personal data?
Within the scope of our business relationship, you will only have to provide the Data required to perform the contract or to take steps prior to entering into the contract, the Data we are obliged to collect under statutory law or the Data required to safeguard the legitimate interests of Porsche Financial Services. If you fail to provide the respective Data to us, it may be impossible to provide certain services. To the extent that the processing of your Data is not mandatory for the conclusion and performance of the contract, you provide such Data on a voluntary basis, and it will be marked as optional.

2. Who will receive your Data?
At Porsche Financial Services, only those departments needing your Data within the scope of their activity do actually receive it. We disclose your Data to third-party recipients only if this is required for the handling or processing of your inquiry or for the performance of the contract or if otherwise permitted under statutory law (e.g. a prevailing legitimate interest exists) or if we have obtained your valid consent.

2.1 Data transfers to the competent dealer and other enterprises and/or business units of the Porsche Group
Your responsible Porsche dealer will receive your Data [in his capacity] as a broker and/or contact partner for the purpose of performing the contract and for the implementation of possible warranty claims (e.g. Paragraph XIII, Section 2 of the leasing agreement), as the case may be. The dealer will receive all information for the purpose of attending and providing advice to you to the necessary extent. For more information, please refer to Paragraph V, Section 3.
Enterprises and/or business units of the Porsche Group will centrally take care of certain Data processing tasks for the Group's affiliates within the scope of a joint control or as processor (such as, e.g., the provision of IT services) on behalf of Porsche Financial Services. If you enter into contracts with us, certain Data may be transferred for internal administrative purposes (for instance, the central administration of address data, dial-in customer service, processing of contracts and services, receivables management, joint processing of the mail or internal audit) within the Porsche Group, and centrally processed by any Porsche Group company. For more information on joint controlling with other enterprises / business units of the Porsche Group, please refer to Paragraph I, Section 2.3.

Moreover, Data (e.g. vehicle identification numbers) may be disclosed to Dr. Ing. h.c. F. Porsche AG for the purpose of joint consolidated accounting in accordance with international accounting standards or also to Porsche Deutschland GmbH for the purpose of subsidizing contracts.

2.2 Porsche Financial Services GmbH as processor of Porsche Financial Services GmbH & Co. KG
In the area of the leasing business Porsche Financial Services GmbH & Co. KG as lessor will transfer your Data to Porsche Financial Services GmbH which will process them as processor on behalf of Porsche Financial Services GmbH & Co. KG. For carrying out risk assessments in the context of leasing, financing and certain rental products (Porsche Drive Abo and Flex), Porsche Financial Services GmbH will use Refinitiv group of companies ("Refinitiv") as an additional processor, which will process your Data by means of the risk intelligence tool "World-Check" and assist us in complying with the statutory requirements as regards the fight against economic crime. In some cases, Refinitiv may also process your Data for own purposes as independent controller (for instance, with respect to running and operating the Refinitiv databases). Such processing shall be based on the Refinitiv data privacy statement available at https://www.refinitiv.com/de/policies/privacy-statement.

2.3 Transmission of Data to additional processors
Porsche Financial Services will revert to a number of additional third-party service providers for assistance in the provision of the listed services, which will be commissioned on behalf of Porsche Financial Services within the scope of the strict requirements for data processing under data protection laws. Among the service providers used by, and providing services on behalf of, us are, for instance, IT service providers and other business partners and auxiliary persons (e.g. logistics, call centers, marketing agencies).

2.4 Transmission of Data to additional controllers
In addition, we may disclose your Data to the following categories of recipients acting as controllers under data protection laws, to the extent required to achieve the above- described purposes:
cooperation and other business partners (e.g. consultancy services providers, lawyers, tax advisors, financial auditors and other external auditors, collection agencies, guarantors, address investigation service providers, experts, financing banks and refinancing partners, credit bureaus, insurances),
public authorities within the scope of their respective competencies (e.g. tax offices, police, public prosecutor`s offices, courts, financial services authorities, fines offices),
other responsible third parties.
The transmission will then be effected on the basis of compliance with legal obligations (Article 6 (1) point (c) GDPR) or a balancing of interests (Article 6 (1) point (f) GDPR).

2.5 Miscellaneous
Furthermore, in connection with the review and the conclusion of an assumption of contract and/or a guarantee contract, Data may be disclosed to the respective obligor, to the extent necessary for the performance of contract (Article 6 (1) point (b) GDPR) or consent was given (Article 6 (1) point (a) GDPR).

3. How is customer and prospect care implemented at Porsche?
In the following, we would like to provide you with further information on the implementation of customer and prospect care at Porsche in accordance with data protection law. The measures serve to ensure that customer and prospect care is appropriate.

3.1 Joint customer and prospect care at Porsche
The measures within the scope of customer and prospect care (in particular service and support, implementation of legal requirements, requirement analyses, individual support via the desired communication channels) are generally not carried out by the responsible person alone. In addition to the respective Porsche Centers, Porsche Deutschland GmbH as importer, Dr. Ing. h.c. F. Porsche AG as manufacturer and its affiliated companies in the areas of financial and mobility services, digital services and lifestyle products are also involved in customer and prospect support under the Porsche brand. An up-to-date list of the companies involved with their contact details is available at https://www.porsche.com/germany/joint-customer-care/.

By using a central platform, we avoid the situation where information on your products, contact data and interests is not available from your contact at Porsche and you may therefore first have to be referred to another participating company. By exchanging and comparing data, we ensure that you receive the best possible service and advice. Of course, only the participating companies have access to your data that actually need it for operational purposes.

In certain cases, joint customer and prospect support can lead to joint controlling. For this reason, the participating companies have stipulated in an agreement pursuant to Article 26 of the GDPR how the respective tasks and responsibilities for processing personal data are structured and who fulfills which data protection obligations. In particular, it was determined how an appropriate level of security can be achieved and how your data subject rights and data protection information obligations can be guaranteed. Porsche Deutschland GmbH (Porschestr. 1, 74321 Bietigheim-Bissingen, https://www.porsche.com/international/privacy/contact/) is available to you as a central contact in addition to the other companies involved.

3.2 Individual customer and prospect care.
Insofar as you have given your voluntary consent to individual customer and prospect support, contact data, support and contract data, service information and data on interests, vehicles and services used will be used by the companies involved in joint customer and prospect support to send you personally tailored information and offers on vehicles, services and other products from Porsche, invitations to events and surveys on satisfaction and expectations via the desired communication channels and to create an individual customer profile.

The specific data used for this purpose depends on the data collected on the basis of orders and consultations or provided by you. If appropriate approvals have been given, other data sources (data from the vehicle or on online usage) may also be included. You will receive more detailed information on how the data is combined when the relevant approval is given.

In order to offer an inspiring brand and customer care experience with Porsche and to make communication and interaction as personal and relevant as possible, the aforementioned data is used for needs analyses and customer segmentation. On this basis, affinities, preferences, and customer potential, for example, can be determined by the companies involved as part of individual customer and prospect care. Examples of such measures to individualize support are key figures on your likely product interests and on your satisfaction. This personal evaluation and allocation in a customer profile only takes place if you have given your voluntary consent to individual customer and prospect care. Without your consent, we will use the aforementioned data in the context of customer and prospect care only to perform general evaluations based on the aggregated data of customers and prospects in order to optimize our offers and systems and align them with overarching interests. Please note that evaluations of your data may also be carried out beyond customer and prospect care, in which case this is done on the basis of your specific consent or another legal basis.

When we send e-mails for individual customer and prospect support, we may use standard market technologies such as tracking pixels or click-through links. This allows us to analyze which or how many e-mails are delivered and/or rejected and/or opened. The latter is done in particular by means of tracking pixels. Measuring the opening rate of our e-mails by means of tracking pixels is not fully possible if you have deactivated the display of images in your e-mail program. In this case, the e-mail will not be displayed to you in full. However, it is still possible for us to track whether an e-mail has been opened if you click on text or graphic links in the e-mail. By using click-through links, we can analyze which links in our e-mails are clicked on and deduce what interest there is in certain topics. When clicking on the corresponding link, you are guided through our separate analysis server before calling up the target page. Based on the analysis results, we can make e-mails more relevant as part of individual customer and prospect support, send them in a more targeted manner or prevent them from being sent.

4. Will your Data be transferred to a third country or to an international organization?
If a data transfer takes place to entities whose registered office or place of data processing is not located in a member state of the European Union, another state party to the Agreement on the European Economic Area or a state for which an adequate level of data protection has been determined by a decision of the European Commission, we will ensure prior to the transfer that either the data transfer is covered by a statutory permit, that guarantees for an adequate level of data protection with regard to the data transfer are in place (e.g., through the agreement of contractual warranties, officially recognized regulations or binding internal data protection regulations at the recipient), or that you have given your consent to the data transfer.

If the data is transferred on the basis of Articles 46, 47 or 49 paragraph 1, subparagraph 2 GDPR, you can obtain from us a copy or reference to the availability of the guarantees for an adequate level of data protection in relation to the data transfer. Please use the information provided under Paragraph I, Section 2.

5. To what extent is there profiling and automated decision-making?

5.1 Data exchange with credit bureaus and scoring/rating
We process all data that is necessary to carry out the credit assessment of the contractual partners (including the personally liable partners and guarantors). This includes the information that you provide to us via the self-disclosure form and prove by means of supporting documents. Depending on the product, information about your income and financial circumstances, including the origin of assets, as well as information about your personal circumstances (e.g. marital status, maintenance obligations, professional status) is collected and processed. Subject to compliance with the legal requirements, information about you may also be requested from third party sources for the purpose of credit assessment.
In the context of assessing your creditworthiness, we use, among other things, a scoring procedure. This is based on a mathematically and statistically recognized and proven procedure. The score values calculated help us to make decisions when concluding contracts and are included in ongoing risk management. This involves calculating the probability that you will be unable to service the installments in the future (known as the probability of default). The calculation includes application, self-disclosure and behavioral data as well as external creditworthiness information from reputable service providers (SCHUFA, Creditreform, Creditreform-Boniversum, possibly CRIF Bürgel). This includes, for example, income and financial circumstances, professional (e.g. length of employment) and personal circumstances (e.g. number of persons in the household), your payment history or our experience from previous business relationships as well as information from credit bureaus. In addition to the data protection notices of the credit bureaus described below (Paragraph V, Section 5.2), please also refer to their complete data protection notices at www.porsche.de/pfs/auskunfteien. Your data will then be transferred on the basis of the legal requirements described here.

Depending on the legal form, additional data is taken into account when scoring corporate customers (e.g. sector, company age, business results). In addition, a rating is carried out for corporate customers above a certain business volume, in which the current business figures in the form of annual financial statements and business evaluations are also included. In this case, the rating is used in addition to our own experience of your payment behavior and the information from the credit bureaus when making the credit decision. The aforementioned information is processed in the credit check process.

In the case of the Porsche rental products Porsche Drive Abo and Porsche Drive Flex, our experience from previous business relationships and certain information from credit bureaus (SCHUFA, Creditreform) are included in the creditworthiness decision.

Data protection and privacy information of SCHUFA Holding AG

Porsche Financial Services shall transfer personal data - collected within the scope of the leasing contractual relationship – regarding the application, development and termination of the business relationship to SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, Germany. This also applies to information regarding any behaviour in breach of the contract or fraudulent conduct in leasing, loan or rental agreements. The permissibility of these data transfers is founded upon Article 6 (1) point (b) and Article 6 (1) point (f) GDPR. Data may only be transferred on the basis of Article 6 (1) point (f) of the GDPR if this is necessary to defend the legitimate interests of Porsche financial Services or third parties and does not outweigh the interests or fundamental rights and freedoms of the affected party requiring the protection of personal data. Data is also exchanged with SCHUFA to fulfil legal obligations of Porsche Financial Services or of the cooperation partners concerning the performance of customer credit rating checks (Sections 505a and 506 of the German Civil Code; Section 18a of the German Banking Act). In this respect, the customer also releases the cooperation partners from banking secrecy. SCHUFA shall process the data it receives and also use this for profiling (scoring) purposes, in order to provide its contractual partners in the European Economic Area, Switzerland and any other third countries (provided the European Commission has declared such countries as appropriate or standard contractual clauses have been agreed, which can be viewed at www.schufa.de) with information used for credit rating checks on natural persons and other purposes. More detailed information on SCHUFA’s activities can be found on the SCHUFA-Information in accordance with Article 14 of GDPR, and online at www.schufa.de/datenschutz.

Data protection and privacy information of Boniversum GmbH

Porsche Financial Services transfers personal data such as the name, address, date of birth, previous address, if applicable, as well as the reason for the inquiry for the purpose of credit rating checks to credit bureau Creditreform Boniversum GmbH, Hammfelddamm 13, 41460 Neuss, Germany. In order to describe your creditworthiness, Creditreform Boniversum GmbH calculates a score based on your data. The legal basis for this transfer is Article 6 (1) point (b) and Article 6 (1) point (f) GDPR. Transfers on the basis of Article 6 (1) point (f) GDPR are only admissible to the extent that this is required to safeguard the legitimate interests of Porsche Financial Services or third parties and unless the interests are overridden by the data subject's interests or fundamental rights and freedoms. The exchange of information with Creditreform Boniversum GmbH also serves the purpose of compliance with legal obligations of Porsche Financial Services or its cooperation partners to perform creditworthiness checks with respect to customers (Sections 505a and 506 of the German Civil Code; Section 18a of the German Banking Act). In this respect, the customer also releases the cooperation partners from banking secrecy. More detailed information on Creditreform Boniversum GmbH's activity as well as their information according to GDPR are available online at https://www.boniversum.de/eu-dsgvo/informationen-nach-eu-dsgvo-fuer- verbraucher/.

Data protection and privacy information of Creditreform Stuttgart Strahler KG

In case of contracts about to be concluded and in specific cases where a legitimate interest exists, Porsche Financial Services will check your credit standing on a regular basis. For this purpose, we cooperate with Creditreform Stuttgart Strahler KG, Theodor-Heuss-Str. 2, 70174 Stuttgart, Germany, which provides us with the required Data. To this end, we transfer your name and contact data to Creditreform Stuttgart Strahler KG. For any further questions and information on the processing of Data, please refer to the guidelines "Information pursuant to Article 14 EU GDPR". This information is available online at https://www.creditreform.de/stuttgart/datenschutz .


5.2 Automated decision making
In the course of processing inquiries from existing customers, in particular when checking and evaluating your creditworthiness documents, we make use of automated decision- making to a certain extent in order to be able to make a fair and responsible decision. To this end, we use the information you provide to us via the self-disclosure form and substantiate with supporting documents, external creditworthiness information from reputable service providers (SCHUFA, Creditreform, Creditreform-Boniversum, possibly CRIF Bürgel), and information about your previous payment history. For more information, please refer to Paragraph V, Section 5.1. To ensure that the methods used to assess creditworthiness are fair, effective and independent, they are regularly reviewed by us.

Currently, we only carry out fully automated decision-making in the case of an indicative assessment of a positive decision on your request. If the automated indicative assessment is rather negative, a manual review and decision on your request will be made. Please note that due to the non-exclusive automated decision-making in the context of the rejection of your request, your right to review the rejected request pursuant to Article 22(3) of the GDPR is not applicable.

If you wish to exercise your rights under Article 22(3) of the GDPR (the right to obtain the intervention of a person, the right to express your own point of view, and the right to challenge the decision) with regard to your exclusively automated approved request, please contact the controller via financial.services@porsche.de or the data protection officer of the controller via pfs-datenschutz@porsche.de. For more information, please refer to Paragraph I, Section 2 of the full data protection information or to the following link.

6. How long will your Data be stored?
We will store your Data as long as necessary for fulfilling the purpose for which we collected your Data. This means that, as a rule, we will store your Data at least for the duration of our business relationship, unless the Data has to be deleted earlier.

Irrespective of the purpose for which we collected your Data we will store your Data to the extent required to comply with our retention and documentation duties. Such duties may inter alia result from the German Commercial Code (Handelsgesetzbuch; HGB), German General Tax Code (Abgabenordnung; AO) as well as KWG and GwG). The periods specified therein for storage and documentation are up to 15 years, taking into account assessment periods and operational necessities.

Finally, the storage period may also be determined by the statutory avoidance and limitation periods, i.e. the time period for which the Data might still be required to satisfy or avoid claims that are not statute-barred (e.g. for the collection of receivables and securing evidence). In accordance with sections 195 et seqq. BGB, these periods may e.g. cover up to thirty years.

Under certain circumstances, it may also be required to store your Data longer, e.g. in connection with official or court proceedings. After that, we will erase your Data from our systems and records and/or take measures to properly anonymize your Data so that you can no longer be identified based on your Data.

7. What rights do you have?

As a data subject, you have the following data protection rights under statutory law:

Data protection rightDescriptionAccessYou have the right to obtain information as to whether or not Porsche Financial Services processes Data concerning you. You are further
entitled to claim information on the Data concerning you stored by Porsche Financial Services as well as on the scope of our processing
activities and the Data transfers made by us and to obtain a copy of the stored Data.
RectificationYou have the right to request rectification of any inaccurate or incomplete Data concerning you stored by Porsche Financial ServiceErasureYou have the right to request erasure of your Data stored by Porsche Financial Services if the relevant statutory requirements have been met.
This is in particular the case when
-your Data is no longer required for the purposes for which it was collected;
-you withdraw your consent on which the processing is based and there is no other legal ground for the processing;
-you have objected on grounds relating to your particular situation to processing based on the legal basis of legitimate interests
and we are unable to demonstrate compelling legitimate grounds for the processing which override your interests;
-your Data has been unlawfully processed; or
-your Data has to be erased for compliance with a legal obligation.
Where we share your Data with third parties, we will inform such third parties of the erasure to the extent that this is required under statutory
law. Please note that your right to erasure is subject to certain restrictions. We are e.g. not obliged or allowed to erase Data that have t
o be retained to comply with the statutory storage periods. As a rule, your right to erasure does further not apply to Data that we require for the
legitimate establishment, exercise or defense of legal claims
Restriction of processingYou have the right to request restriction of processing (i.e. the marking of your Data with the aim of limiting their processing in the future)
where one of the following applies:
-The accuracy of the Data is contested by you and we need to verify the accuracy of the Data
-the processing is unlawful and you oppose the erasure of the Data and request the restriction of their use instead
-we no longer need the Data for the purposes of the processing, but they are required by you for the establishment, exercise or
defense of legal claims;
you have objected to processing pending the verification whether our legitimate grounds override yours.
Where processing has been restricted, the Data will be marked accordingly and - with the exception of storage - will only be processed with
your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person
or for reasons of important public interest of the EU or of a EU Member State
Data portabilityYou have the right to receive your Data, which you have provided to us, in a structured, commonly used and machine-readable format and to
transfer that Data to another controller without hindrance from us, where the processing is based on your consent or on a contract and the
processing is carried out by automated means. You also have the right to have the Data transferred directly from one controller to another,
where this is technically feasible and does not adversely affect the rights and freedoms of others.
Withdrawal of consentWhere you have given your consent for certain purposes, the relevant purposes result from the content of the respective declaration of
consent. You have the right to withdraw your consent at any time free of charge and with effect for the future. Withdrawals of consent should
be addressed to the contact details indicated under Paragraph I, Section 2 of the complete general data protection and privacy information.
The central contact for consent, revocation and queries regarding the declaration of consent for individual customer and prospect care is
Porsche Deutschland GmbH, Porschestr. 1, 74321 Bietigheim-Bissingen – a short message by mail or via the contact form
https://www.porsche.com/germany/privacy/contact/ is sufficient. When doing so, please ensure that we are able to clearly identify you.
When revoking consent, you can alternatively choose the contact method used when giving your consent.
Please note that the withdrawal only takes effect for the future. A withdrawal of consent does not affect the lawfulness of processing based
on consent before its withdrawal. As a result of your withdrawing your consent, we may no longer be able to perform some or all of our services
without processing this Data. We will erase the Data if you have withdrawn your consent and no other legal basis for processing your Data
applies. If another basis for processing applies, we will erase the Data after that legal basis ceases to apply
Objection to direct
advertising
If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your data by us
for this purpose. If you exercise your right to object, we will stop processing your data for this purpose
Right to objectYou have the right to object, on grounds relating to your particular situation, at any time to the processing of your Data on the legal basis of
"legitimate interests" (Article 6 (1) point (f) GDPR). This also applies to profiling within the meaning of Article 4 no. 4 GDPR, i.e. the processing
of your Data for credit standing purposes based on the above provision.
If you exercise your right to object, we will no longer process your Data unless we can - in accordance with the statutory requirements -
demonstrate compelling legitimate grounds for processing your Data that demonstrably establish an overriding legitimate interest of Porsche
Financial Services in processing your Data.
The lawfulness of the processing of your Data before the objection remains unaffected thereof


Furthermore, you can lodge a complaint with the competent data supervisory authority if you believe that the processing of your Data violates applicable law. Your right to lodge a complaint applies without prejudice to any other administrative or judicial remedy. For this purpose, you can refer to the data protection authority competent for your habitual residence or country or to the data protection authority competent for us.

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (the Commissioner for Data Protection of the German Land Baden-Württemberg) Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Phone: +49 (0) 7 11/61 55 41-0, fax: 07 11/61 55 41- 15
Email: poststelle@lfdi.bwl.de

8. How to contact us and how to exercise your rights
In addition, you can contact us free of charge in case of questions with respect to the processing of your Data, your rights as Data subject and a consent given, if applicable. Please contact us at pfs-datenschutz@porsche.de or send a letter to the address specified above in Paragraph I, Section 2 of the complete data protection and privacy information to exercise any of your rights mentioned above or obtain more information on data protection at Porsche Financial Services, stating wherever possible the name of the controller/s addressed. Please ensure that clear identification of your person is possible for us.

9. Updating this data protection and privacy notice
We reserve the right to review and update this data protection and privacy notice on a regular basis. Any changes will be published at: www.porsche.de/pfs/datenaustausch.
Therefore, you should visit this website regularly to stay up to date with the latest version of the Data Protection and Privacy Information.

Last updated: 08/2024
Valid as of August, 2024

Privacy Policy
Porsche Financial Services Websites Porsche Drive

We, Porsche Smart Mobility GmbH (hereinafter referred to as "we" or "PFS GmbH"), are pleased about your use of our websites https://www.porsche.com/germany/porsche-drive/ (hereinafter also referred to as "website") and your interest in our company and our products. We take the protection of your personal data very seriously. Your personal data will only be processed in accordance with the provisions of data protection legislation, in particular the General Data Protection Regulation (hereinafter "GDPR").

This Privacy Policy provides information about the processing of your personal data and your privacy rights as a data subject in connection with your use of the Porsche Digital Service Infrastructure and our services. For information on the individual services, please refer to the Specific Privacy Policy and, if applicable, the further Special Data Protection Notices of the respective service.

You can use our websites to conclude the products Porsche Drive Rental, Porsche Drive Flex and Porsche Drive Abo (hereinafter also referred to as “Porsche Drive”) This requires you to be registered with My Porsche and have a Porsche ID user account. Some features on our websites are also available without registration. For further details see Point 2.3.

In addition, you can use the Online Marketplace to access the extended range of products and services offered by our Group companies and third-party providers. Customers with a Porsche ID user account can use the Marketplace sections Porsche Finder and Porsche Store.

1. Data Controller and Data Protection Officer

Unless otherwise expressly stated in this or a Specific Privacy Policy based thereon and, if applicable, in the further Special Data Protection Notices of the respective service, the entity responsible for data processing within the meaning of the data protection laws is:
Porsche Financial Services GmbH
Porschestraße 1
74321 Bietigheim-Bissingen
Germany
E-mail: financial.services@porsche.de

Please do not hesitate to contact us if you have any questions or ideas relating to data protection.

You can contact our data protection officer as follows:

Porsche Financial Services GmbH
Data Protection Officer
Porschestraße 1
74321 Bietigheim-Bissingen
Germany
Contact: pfs-datenschutz@porsche.de

In relation to certain processing operations, we may be joint controllers with Dr. Ing. h.c. Porsche AG (Porscheplatz 1, 70435 Stuttgart, Germany, e-mail: info@porsche.de, hereinafter "Porsche AG"), its group companies and/or third parties ("we" then also stands for these joint controllers). In relation to such joint processes, we jointly determine the purposes and means of processing personal data. In such cases, in an agreement on joint responsibility pursuant to GDPR Article 26, we accordingly also define the respective tasks and responsibilities in the processing of personal data and the responsible parties to fulfil data protection obligations. In particular, we define how an appropriate level of security and your rights as a data subject can be ensured, how we can jointly comply with information obligations under data protection law and how we can monitor potential data protection incidents. This also includes ensuring that we can fulfil our reporting and notification obligations. Insofar as you contact us, we will come to an agreement in accordance with the aforementioned agreement pursuant to GDPR Article 26 in order to answer your enquiry and guarantee your data subject rights. You can find out in which areas and with which companies joint responsibility exists in the Specific Privacy Policy and, if applicable, in the further Special Data Protection Notices of the respective service.

2. Object of data protection
The object of data protection is the protection of personal data. This is any information that relates to an identified or identifiable natural person (so-called data subject). This includes details such as name, postal address, e-mail address or telephone number, but also other information that arises in the course of using our Porsche Digital Service Infrastructure and vehicle usage data.

3. Purposes of and legal grounds for data processing

In the following, you will find an overview of the purposes and legal basis of data processing in connection with the Online Service. In any case, we process personal data in accordance with the legal requirements, even if in individual cases a different legal basis should be relevant than that stated below.

The provision of personal data by you may be required by law or contract or may be necessary for the conclusion of a contract. We will point it out separately if you are obliged to provide personal data and what possible consequences the non-supply would then have (e.g. a loss of claims or our position not to provide the requested service without providing certain information). The use of the Online Service is generally possible without registration. The use of individual functions may require prior registration. Even if you use the Online Service without registration, personal data may still be processed.

3.1 Performance of a contract and pre-contractual measures

We process your personal data if this is necessary for the performance of a contract to which you are a party or for the implementation of pre- contractual measures taken in response to your request. The data processing is based on Article 6 paragraph 1 letter b) GDPR. The purposes of processing include enabling the use of our specific products and services within the scope of the Online Service. Please also note the details in the respective documents describing our products and services further to this Privacy Policy.

In particular, these are the following functions:
Registration process and creation of a user profile
[Registration is not possible without the mandatory data. The mandatory data required for the registration and creation of a user profile are marked with an "*" in the respective input field: salutation, first and last name, address and email address. When creating a user profile, you have the option of voluntarily providing additional information, such as company contact data, profession, date of birth, etc. Please note that these details are not required for registration and that you alone decide whether you wish to provide us with these details. If you do not provide us with this information, we may not be able to fully comply with your wishes when using this function. The data you provide will be used by us to create your user profile and to identify you later on each login. Depending on the function for which you are registering, further data, e.g. a vehicle configuration selected by you, may be collect-ed and then linked to your profile data. When using the functions described in detail below, further personal data may also be collected and processed (e.g. payment data when placing orders) and, if necessary, transmitted to third parties (e.g. Porsche Centers) in order to provide you with these functions.

3.2 Compliance with legal obligations

We process your personal data to comply with legal obligations to which we are subject. The data processing is based on Article 6 paragraph 1 letter c) GDPR. These obligations may arise, for example, from commercial, tax, money laundering, financial or criminal law. The purposes of the processing result from the respective legal obligation; as a rule, the processing serves the purpose of complying with state control and information obligations.

3.3 Safeguarding of legitimate interests

We also process your personal data to pursue the legitimate interests of ourselves or third parties, unless your rights, which re-quire the protection of your personal data, outweigh these interests. The data processing is based on Article 6 paragraph 1 letter f) GDPR. The processing to safeguard legitimate interests is carried out for the following purposes or to safeguard the following interests.

Further development of products, services and support offers as well as other measures to control business transactions and processes;
Improvement of product quality, elimination of errors and malfunctions;
Processing of data in a central prospective customer and customer care platform as well as upstream and downstream systems for customer retention and sales purposes;
Needs analysis and customer segmentation, e.g. calculation and evaluation of affinities, preferences and customer potential;
Handling of non-contractual inquiries and concerns;
Risk management;
Ensuring legally compliant actions, prevention of and protection against legal violations (especially criminal offences), assertion of and defense against legal claims, internal and external compliance measures;
Ensuring availability, operation and security of technical systems as well as technical data management;
Answering and evaluation of contact requests and feedback

When you call up the Online Service, data relating to your end device and your use of the online offer are processed and stored in a so-called log file. This concerns in particular technical data such as date and time of access, duration of the visit, type of terminal device, operating system used, functions used, amount of data sent, IP address and referrer URL. We process this data to ensure technical operation and to determine and eliminate faults. In doing so, we pursue the interest of permanently ensuring technical operability. We do not use this data for the purpose of drawing conclusions about your person.

When we send emails for customer and prospect management, we may use commercially available technologies such as tracking pixels or click-through links. This enables us to analyse which or how many emails are delivered and/or rejected and/or opened. The latter is done in particular using tracking pixels. It will not be possible to fully measure the opening rate of our emails using tracking pixels if you have deactivated the display of images in your email program. In this case, the email will not be dis-played completely. However, we are still able to track whether an email has been opened if you click on text or graphic links in the email. By using click-through links, we can analyse which links in our emails are clicked and derive what interest there is in certain topics. When you click on the corresponding link, you are guided through our separate analysis server before the target page is called up. Based on the results of the analysis, we can make emails more relevant, send them in a more targeted manner or stop them from being sent. If you do not want such data to be collected and tracked, do not click on text or graphic links in emails.

3.4 Consent

We process your personal data on the basis of corresponding consent. The data processing is based on Article 6 paragraph 1 letter a) GDPR. If you give your consent, it is always for a specific purpose; the purposes of processing are determined by the content of your declaration of consent. You may revoke any consent you have given at any time, without affecting the legality of the processing that has taken place on the basis of the consent until revocation.

If you have given your consent, the companies listed in the declaration of consent can use the data on this basis, e.g. for individual customer and prospective customer support and contact you for these purposes via the communication channels you have requested. Your data will be used in this context to offer you an inspiring brand and customer care experience with Porsche and to make communication and interaction with you as personal and relevant as possible. Which of your data is actually used for individual customer and prospective customer support depends in particular on which data has been collected on the basis of orders and consultations (e.g. when buying or servicing Porsche products) and which data you have provided (e.g. your personal interests) at the respective contact points (e.g. at the Porsche Center).

3.5 Change of purpose

If we process your personal data for a purpose other than that for which the data was collected, beyond the scope of a corresponding consent or a mandatory legal basis, we will take into account, in accordance with Article 6 paragraph 4 GDPR, the compatibility of the original and the now pursued purpose, the nature of the personal data, the possible consequences of further processing for you and the guarantees for the protection of the personal data.

3.6 Profiling

We do not carry out automated decision making or profiling in accordance with Article 22 GDPR. Profiling is only carried out to protect our legitimate interests as described above.

4. Special notes on the use of our website

4.1 Provision of our website

To a certain extent, it is possible to use this website without logging in. Even if you use the website without registration, personal data may still be processed. Below you will find an overview of the type, scope, purposes of and legal grounds for automated data processing that takes place when using our website. For information on the processing of personal data when using the individual specific features and services, please refer to Point 5 below.

The following data will be processed by us when you access our website with your device:

Date and time of access,
Duration of visit,
Type of device,
Operating system used,
The features you use,
Amount of data transmitted,
Type of event,
IP address,
Referrer URL,
Domain name


We process this data on the basis of the GDPR Article 6 Paragraph 1 (b) and (f) for the purpose of providing the website, safeguarding its technical operation and identifying and resolving malfunctions. In doing so, we also pursue the aim of permanently ensuring the technical functionality of the website, improving performance and optimising the user experience. This data is processed automatically when you access our website. Without the provision of data, you cannot use our website. We do not use this data for the purpose of drawing conclusions about your person or your identity.

4.2 Cookies and comparable technologies

We use cookies and similar technologies within the framework of the website, which serve to communicate with your terminal device and to exchange stored information (hereinafter collectively "cookies"). These cookies are primarily used to make the functions of the website usable. General examples in which the use of cookies is technically necessary in this sense are the storage of a language selection, login data or a shopping or watch list. Accordingly, technically necessary cookies may be used by us to enable the processing operations described above and to ensure the proper and secure operation of the website. Data processing takes place on the basis of the GDPR Article 6, Paragraph 1 (b) and (f), as this is necessary for implementation of the functions that you select and in order to safeguard our legitimate interest in the functionality of our website.

If we also use cookies to analyse the use of the website and to target it to your interests and, if applicable, to provide you with interest-based content and advertisements, this will only be done on the basis of your voluntary consent in accordance with Article 6 Paragraph 1 (a) GDPR. You then have the option of making your corresponding settings via the consent management at https://www.porsche.com/germany/privacy/cookie-policy/. You can revoke your consent at any time with effect for the future. Further information on the cookies and their function in detail, as well as on setting and revocation options, is available directly in the corresponding areas of the consent management. Please note that we only provide consent management as part of the website if consent-based cookies are to be used in addition to the technically required cookies mentioned above.

If you do not wish to use cookies in general, you can also prevent any storage by means of the relevant settings on your device. Stored cookies can be erased at any time using the system settings of your device. Please note that blocking certain types of cookie may result in impaired use of our website.

4.3 Device access permissions

When using individual features such as "Closest Porsche Drive Rental location", you may be asked to grant access to your location.

Granting permissions is voluntary. However, if you wish to use the relevant features, you must grant the corresponding permissions, otherwise you will not be able to use these features.

Permissions remain active unless you revoke them in your device and/or Internet browser by deactivating the relevant setting.

5. Special services and features

You can voluntarily provide personal information or register for services or features when using our website. When registering and using the services and features described below, personal data will be collected, processed and used by us as shown below.

It is necessary to register in advance and to create a Porsche ID user account in order to use the services and features described in Point 5.1. The services and features described in Point 4.1 can be used partly without prior registration.

5.1 Registration process and creation of a Porsche ID user account under joint controlling

We offer a registration and login process for our online services that uses Porsche ID. This means that you do not have to remember any new login data for our online services. The Porsche ID and the corresponding service are provided by Porsche Sales and Marketplace ("PSM GmbH"). Information on the registration process and the creation of your Porsche ID user account can be found in the Privacy Policy of PSM GmbH (https://www.porsche.com/international/connect-privacy/).

The processing of data within the course of the registration and login process using the Porsche ID takes place on the basis of Article 6 (1) (b) and (f) DSGVO so that we can register you with your user account for our online service and/or identify you when you log in. We pursue - in addition to the conduct of the procedure or process requested by you
the interest of making the process of registration and login efficient and convenient. In this regard, we are jointly responsible with PSM GmbH and jointly determine the purposes and means of processing personal data.
In an agreement with the relevant Marketplace participants on joint responsibility, we have defined, pursuant to GDPR Article 26, the respective tasks and responsibilities in the processing of personal data and the responsible parties to fulfil data protection obligations. In particular, we have defined how an appropriate level of security and your rights as a data subject can be ensured, how we can jointly comply with data protection information obligations and how we can monitor potential data protection incidents. This also includes ensuring that we can fulfil our reporting and notification obligations. If you have contacted us (for PFS listed under Point 1) or PSM GmbH using the contact information provided, we will consult with each other to address your inquiry and ensure your rights as data subject.

5.2 Using the individual features with registration/login

When using the registration and login procedure using the Porsche ID, you will be redirected to the login/registration screen of the PSM GmbH for the Porsche ID. Here you log in with your User name and password for the Porsche ID, if you are not already logged in via single sign-on.

We then receive a message from the PSM GmbH that you have successfully logged in and the registration or login for our online service is completed. In the process, we ourselves do not come in contact with the User name and password for the Porsche ID. As part of the registration and login process, you confirm to the PSM GmbH that we may access the profile data of your Porsche ID user account for this purpose. This then also applies, if applicable, to the payment data stored there. Thus, you do not have to re-enter or maintain (e.g., if your address changes) your profile data and, if applicable, payment data in order to create your user profile for our online service. Conversely, changes to the profile data in the user account of our service will then also be synchronized accordingly in your user account for the Porsche ID.

The functions within the scope of our service on our website as well as the personal data processed in each case, purposes and legal bases are described below.

6. Booking services

Product-specific information about vehicle rental as well as the handling of personal data can be obtained in section IV from the General Data Privacy Information of Porsche Financial Services GmbH & Co. KG and Porsche Financial Services GmbH (https://porschedrive.porsche.com/germany/en-DE/custom-page/privacy).

7. Integrated third party services

Insofar as we integrate services of other providers within the framework of our website in order to offer you certain content or functions (e.g. playing videos or route planning) and we process personal data in the process, this is done on the basis of Article 6 Paragraph 1 (b) and (f) GDPR. This is because the data processing is then necessary to implement the functions you have selected or to safeguard our legitimate interest in an optimal range of functions. Insofar as cookies may be used within the scope of these third-party services, the explanations under section 1.1.3 apply. Please also inform yourself about the privacy policy of the respective provider with regard to the third-party services.

Services of other providers that we include or to which we refer are provided by the respective third parties. Third-party services generally also include services offered by Porsche AG and other group companies. As a matter of principle, we have no influence over the content and function of third-party services and are not responsible for the processing of your personal data by their providers, unless the third- party services are designed entirely on our behalf and then integrated by us under our own responsibility. Insofar as integrating a third-party service leads to our establishing joint processes with the service provider, we establish an agreement with this provider on joint responsibility pursuant to GDPR Article 26, defining the respective tasks and responsibilities in the processing of personal data and the responsible parties for fulfilling data protection obligations. Insofar as cookies are also to be set on the basis of your consent, you will receive further information on the responsibility for setting these cookies or any associated third-party services in the corresponding areas of the consent management.

Unless otherwise stated, profiles on social media are only integrated as links to the corresponding third-party services. After clicking on the embedded text/image link, you will be redirected to the service of the respective social media provider. After forwarding, personal data may be collected directly by the third-party provider. If you are logged into your user account of the respective social media provider during this time, the provider may be able to assign the collected information of the specific visit to your personal user account. If you interact via a "Share" button of the respective social media provider, this information may be stored in the personal user account and possibly published. To prevent the collected information from being directly assigned to your user account, you must log out before clicking on the embedded text/image link.

8. Rights of data subjects

As the person whose data is being processed, you have numerous rights at your disposal. For details, please refer to section V, Point 7 from our General Data Privacy Information of Porsche Financial Services GmbH & Co. KG and Porsche Financial Services GmbH, which can be retrieved at https://www.porsche.com/germany/accessoriesandservices/porsche financialservices/contact/. In particular, you may object to the use of cookies or similar technologies at any time. For more information, please refer to point 5 of our Cookie Policy https://www.porsche.com/germany/privacy/cookie-policy/.

9. Changes to this Privacy Policy and version

We reserve the right to modify this Specific Privacy Policy. The current version of the Privacy Policy can always be found at https://porschedrive.porsche.com/germany/en-DE/custom-page/privacy.

Date: 18.07.2024