Tire Profiles LLC - European Union General Data Protection Regulation (“GDPR”) Privacy Notice

Last Updated: 26-June-2020

Contents:

Tire Profiles LLC is a United States based organization that serves as the industry leader for tire and alignment measurement and diagnostic systems and instruments.

We may be contacted by the following numbers and address:

Tire Profiles LLC Privacy Team

Phone: +1 844-276-3024

Physical Mailing Address: Tire Profiles LLC, 3010 Story Road Irving TX 75038

E-mail: privacy@tireprofiles.com

Tire Profiles LLC, as Data Processor - Customers using the systems provided including but not limited to TreadSpec, Groove Glove and the TreadSpec Website will act as the Data Controller for any vehicle owner personal data made available to Tire Profiles LLC in connection with their use of services.

The Data Controller determines the purposes and means of processing personal data, while the Data Processor, processes data on behalf of the data controller.

Tire Profiles LLC, as the Data Controller - Tire Profiles LLC processes and stores personal data on behalf of our direct customers with accounts in our systems in connection with providing the services to those customers and data obtained in the creation and maintenance of the accounts within the systems.

Organizations under the GDPR may be required to have a Data Protection Officer (“DPO”) if they meet certain requirements.

Regardless, privacy questions and concerns can be sent to us as follows:

privacy@tireprofiles.com

Tire Profiles LLC, 3010 Story Road

USA

Irving TX 75038

We use your personal data for the following reasons:

  • to provide and maintain the Services;
  • to address and respond to service, security, and customer support issues;
  • to detect, prevent, or otherwise address fraud, security, unlawful, or technical issues;
  • as required by law;
  • to fulfill our contracts;
  • to improve and enhance the Services;
  • to provide analysis or valuable information back to our Customers and users.

Some specific examples of how we use the information:

  • Create and administer your account
  • Send you an order confirmation
  • Facilitate and improve the usage of services you have ordered
  • Assess the needs of your business to determine suitable products
  • Send you product updates, marketing communication, and service information.
  • Respond to customer inquiries and support requests
  • Analyze information, including through automated systems and machine learning to improve our services and/or your experience
  • Provide you information about your use of the services and benchmarks, insights and suggestions for improvements.

We rely on a variety of bases for processing your personal data in a fair and legal manner. We will not rely on a single basis. We will use any of the following bases, depending on how we use your personal data

1. Consent – you may provide us your consent to use your personal data. You should provide it to it freely and it should be clear that you are providing it to us voluntarily.

2. Contract – we may need to use your personal data for a contract to which you are a party to

3. Compliance – we may need to use your personal data to comply with a legal obligation for our company

4. Vital interests – there may be rare circumstances where we may need to use your personal data to protect you or others

5. Public good – it is unlikely that we will utilize this method as this requires use of your personal data to be for the public good. This is often used by health care organizations.

6. Legitimate interests – this is a balancing test where we will use your personal data except where your rights and freedoms are at risk

We may share your personal information with:

  • third party service providers;
  • business partners;
  • affiliated companies within our corporate structure and
  • as needed for legal purposes.

Third party service providers have access to personal data only as needed to perform their functions and they must process in accordance with this Notice.

Examples of how we may share information with service providers include:

  • Fulfilling orders and providing the services
  • Payment processing and fraud prevention
  • Providing customer support
  • Sending marketing communications
  • Providing cloud computing infrastructure

Examples of how we may disclose information for legal reasons include:

  • As part of a merger, sale of company assets, financing or acquisition of all or a portion of our business by another company where customer information will be one of the transferred assets.
  • As required by law, for example, to comply with a valid subpoena or other legal process; when we believe in good faith that disclosure is necessary to protect our rights, or to protect your safety (or the safety of others); to investigate fraud; or to respond to a government request.

We may also disclose your personal information to any third party with your prior consent.

Our company operates globally and has a global infrastructure. We utilize cloud computing which means your personal data may be transferred to a country with data protection laws not as strong as where you reside.

We will transfer your personal data to countries deemed having adequate levels of data protection as determined by the European Commission. For those countries that do not have adequate levels of protection as determined by the European Commission, we will rely on a variety of methods for lawful cross border transfers.

We may utilize Standard Contractual Clauses (or Model Clauses) in contracts with third parties in these third countries.

Another method we may rely upon is your consent to the transfer of your personal data to third countries. We take measures within our company to ensure that your personal data is secured. This includes using vendors we trust, holding vendors to contractual provisions that provide appropriate Technical and Organizational Measures. Examples of things we do are:

  • Using unique IDs and passwords
  • Utilize malware protection
  • Maintain physical controls to keep unauthorized personnel out of company areas that may contain personal data
  • Require our employees and vendors follow a duty of confidentiality related to processing of personal data
  • Use of encryption technology, where appropriate
  • Engage in practices to ensure the integrity and availability of your personal data in the event of an unforeseen event (disaster and backup recovery)

For a complete list of the Technical and Organizational Measures we use, please contact us at: privacy@tireprofiles.com

We will retain personal data we process on behalf of our customer as needed to provide services to our customer. Also, we will retain this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Under the GDPR, EU residents have the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability.

We will do this in a timely manner as specified by the GDPR. If we need more time to fulfill your request, we will let you know in advance. We will not exceed the legally specified time limit under any circumstance.

You may exercise these rights by contacting us as follows:

privacy@tireprofiles.com

Tire Profiles LLC, 3010 Story Road

USA

Irving TX 75038

If we utilize consent as the legal basis for processing your personal data, you may withdraw your consent at any time. Please note that withdrawal of your consent does not prohibit us from using your personal data to meet legal and compliance obligations. Please contact us (as listed above) to withdraw consent. We will verify your identity and comply with your request.

The GDPR allows EU citizens to file a complaint to a supervisory authority if they feel that their rights and freedoms have been violated. While we hope that you would work with us to resolve your issue, you may also file a complaint to the applicable supervisory authority through this link:

https://edpb.europa.eu/about-edpb/board/members_en

Our company does not use your personal data for automated decision making or profiling. An example of this is when you apply for a bank loan. Some companies may use an algorithm or automated process to decide about your loan. Again, this does not apply to our organization or the use of your personal data.