GTM debug

Privacy policy description purposes

Explanation note: 

[1] Processing operation covered by legal ground of legitimate interest pursuant Art. 6 (1) letter f) GDPR is highlighted in text. 

[2] Legitimate interest is pursued only if conditions for opt-out direct marketing communication to existing customers or legal persons under Art. 13 of the ePrivacy Directive (2002/58/EC) (as implemented) are met.  If not met, processing is based on a consent. 

1.   Provision of toll services

Specification of purpose and legitimate interest[1]

  • Provision of toll services by reseller:

It includes especially: (i) Scan of ID Cards, (ii) processing of payment documentation, (iii) Basic data for toll registration, (iv) processing of technical data and invoicing, (v) processing WAG OBU data. 

  • Provision of toll services by agent:  

It includes especially: (i) processing of technical data and cross invoicing, request for payment, (ii) Basic data for toll registration, (iii) Scan of ID Cards, (iv), (v) Payment documentation, (vi) WAG OBU data.

  • Prevention of identity frauds:

It includes especially: (i) verification of user identity based on processing copies of IDs, signatures and CCTV records and evaluation of potential risk patterns by specialised software during customer’s onboarding procedures.

2.   Provision of telematic services

Specification of purpose and legitimate interest[1]

  • Fleet management for customers:

It includes the processing of personal data necessary for: (i) Fleet Management Data, (ii) Telematic system innovation data and telematics.

  • Assistance services for customer’s drivers:

It includes the processing of personal data necessary for: (i) Telematics data.

  • Monitoring of driver’s behaviour: 

It includes the processing of personal data necessary for processing of: (i) processing of telematics data, (ii) telematic system innovation data.

  • Prevention of identity frauds:

It includes especially: (i) verification of user identity based on processing copies of IDs, signatures and CCTV records and evaluation of potential risk patterns by specialised software during customer’s onboarding procedures.

3.   Provision of fuelling services

Specification of purpose and legitimate interest[1]

  • Provision of fuelling services:

It includes especially: (i) Realisation of antifraud system, (ii) Provision of FUEL services, (iii) Manual and phone authorisation of customers (iv) Provision of EW Petrol station CCTV (Monitoring of fuelling for customer’s needs), (v) Provision of E-mobility services. 

  • Prevention of identity frauds:

It includes especially: (i) verification of user identity based on processing copies of IDs, signatures and CCTV records and evaluation of potential risk patterns by specialised software during customer’s onboarding procedures.

4.   Provision of financial services

Specification of purpose and legitimate interest[1]

  • Provision of financial services:

It includes especially:(i) Reporting EWMC (provide payment services), (ii) Factoring services, (iii) Insurance services, (iv) Reporting for customers (Finance reporting a business analyses).

5.   Provision of tax services

Specification of purpose and legitimate interest[1]

  • Provision of tax services:

It includes especially (i) Early Money Collection (refund of VAT on behalf of the customer), (ii) Tax refund and Registration Process (refund of VAT on behalf of the customer), (iii) Tax refund and Registration Process (fuel tax refunds), (iv) MiniWAGes (fuel tax refunds). 

  • Prevention of identity frauds:

It includes especially: (i) verification of user identity based on processing copies of IDs, signatures and CCTV records and evaluation of potential risk patterns by specialised software during customer’s onboarding procedures.

6.   Provision of additional services

Specification of purpose and legitimate interest[1]

  • Provision of additional services:

It includes especially: (i) Washing services, (ii) Parking services, (iii) MiniWAGes services (mediation of trade), (iv) provision of services via DXX platform, including internal analysis of the obtained platform data.

  • Prevention of identity frauds:

It includes especially: (i) verification of user identity based on processing copies of IDs, signatures and CCTV records and evaluation of potential risk patterns by specialised software.

7.   Support and customer care

Specification of purpose and legitimate interest[1]

  • Support and customer care:

It includes especially: (i) Identification persons in internal system (contact details, ADAC), (ii) Onboarding process, (iii) Provision of service support, (iv) Provision of technical support, (v) Provision of education, promotion and training for users, (vi) Solving of customers issues.

8.   Conclusion, performance, and basic management of contractual relations

Specification of purpose and legitimate interest[1]

  • Conclusion, performance, and basic management of contractual relations:

It includes especially: (i) concluding, amending and fulfilling any contract concluded between the controller and data subject, (ii) approval and revision of contracts by the legal department, (iii) communication between the contracting parties, including the processing of contact person data and statutes of the contracting parties and further processing of personal data necessary for the proper conclusion, fulfilment and changes of contractual relationships in which the persons concerned do not act as contractual parties of the given legal relationship, (iv) records of internal and external powers of attorney, (v) records of supplier-customer contractual relationships between the controller and its customers, partners and suppliers.

9.   Sharing customer data within a group for internal administrative purposes

  • Sharing customer data within a group for internal administrative purposes: It includes especially: (i) Sharing of customers data and providing of reports regarding customers.

10. Credit risk assessment

Specification of purpose and legitimate interest[1]

  • Credit risk assessment:

It includes especially: (i) Assessment of credit risk of customers, (ii) Realisation of credit risk screening of the customers, (iii) Preparing of credit scoring model and payment behaviour reporting of customers.

11. Pricing and B2B relationship management

Specification of purpose and legitimate interest[1]

  • Pricing and B2B relationship management:

It includes especially: (i) Management of B2B relationship, (ii) Preparation of B2B pricing policy and discounts for customers.

12. Creating a network of partner suppliers

  • Creating a network of partner suppliers:

It includes especially the processing of personal data necessary for creating and management of network of partner suppliers.

13. Fulfilment of legal obligations

  • Accounting and tax compliance:

It includes especially: (i) Processing of payments, (ii) Payments/Invoicing, (iii) Early Money Collection, (iv) Processing of payment documentation, (v) Fulfilling of accounting and tax obligations, (vi) Invoicing, (vii) Tax refund and Registration Process, (viii) MiniWAGes.

  • AML Agenda:

It includes especially: (i) Copy of ID card, (ii) AML Onboarding process, (iii) EWMC,  (iv) Quick sanction list screening, (v) AML Check process (vi) Reporting EWMC.  

  • Reporting and recording of anti-social activity (whistleblowing):

It includes especially: (i) performing actions related to the protection of the whistleblower of anti-social activity by the employer, (ii) receiving, evaluating and recording notifications within the internal notification verification platform, (iii) Internal investigation.

  • ESG reporting:

It includes especially: (i) processing data for creation Environmental, Social and Government reports primarily for the purpose of evaluating the impact on the environment, including fuel consumption and mileage.

14. Defending, claiming, and proving legal claims

Specification of purpose and legitimate interest[1]

  • Legal agenda:

It includes especially: (i) ensuring the typical agenda of the internal legal department, (ii) control of legal matters and internal legal advice, (iii) reporting various facts to public authorities (including notifications of various delicts and criminal acts) or insurance companies (e.g. insurance claims), (iv) use of legal representation and legal advice from law firms; (v) conducting due diligence, including providing data to potential buyers and their advisors, (vi) management of the corporate agenda and fulfilment of all obligations in accordance with respective law, (vii) preparation, securing and storage of various legal filings and evidence containing personal data, (viii) early recovery of outstanding debts, i.e. Exit report in JIRA and Early Money Collection, (ix) conducting various administrative proceedings, lawsuits and other legal proceedings (e.g. concluding reconciliations, settlement agreements, payment schedules), (x) verifying the facts before a notary and ensuring official translations, (xi) Security management, (xii)  Internal transfer of claims (late recovery of outstanding debts), (xiii) Assignment of receivables from subsidiaries to WAG Group.

15. Security of personal data and IT systems

Specification of purpose and legitimate interest[1]

  • IT security:

It includes especially: (i) control, withdrawal and management of access authorisations, (ii) monitoring and evaluation of suspicious events based on log analysis through specific software applications, (iii) creation of security logs capturing behaviour users in important applications and systems, (iv) creation of security backups, (v) vulnerability scanning and anti-malware activity, (vi) management of security incidents and personal data breaches, (vi) management of information security in the WAG Group, (vii) penetration testing and performance of security audits with the possibility of access to protected data, (viii) monitoring of users network and systems.  

  • Development, improvement and testing of software:

It includes especially: (i) development, improvement and diagnostic of security systems, (ii) integration and configuration tests of corporate information systems by intermediaries when migrating from old systems, (iii) service interventions and ongoing software modifications performed by remote access of our intermediaries based on our requests and instructions, (iv) system recovery tests based on backed-up data.

16. Property protection and security

Specification of purpose and legitimate interest[1]

  • CCTV systems:

It includes especially: (i) operation of camera systems monitoring clearly marked defined areas and objects used in the business activities of the WAG Group including EW Petrol station CCTV or HQ CCTV security system. 

  • Physical access control:

It includes especially: (i) recording the personal data of visitors entering protected areas and objects of WAG Group, (ii) fingerprinting at the entrance to the protected area, (iii) recording of personal cards at the entrance to the protected area.

17. Direct marketing and PR purposes

Specification of purpose and legitimate interest[1]

  • Direct marketing communication:

It includes especially: (i) customising and sending marketing electronic mail – newsletters (e-mail, SMS) to existing customers, (ii) creating, customising, and sending flyers or printed address forms of marketing, (iii) realisation of tele-marketing activities including campaigns for current customers and voice records, (iv) Sales activities of external call centre and internal telesales, (v) creation of purchaser database. Where the law requires to use consent for unsolicited communication or cookies, we rely on consent.[2]  

  • Targeting and personalisation of advertising content:

It includes especially: (i) customisation and display of advertising and campaign on social networks, (ii) customisation and display of banner advertising and sponsored links during searches when using the Internet. Where the law requires us to consent for unsolicited communications or cookies, we rely on consent.

  • Raising awareness of the WAG Group:

It includes especially: (i) management and administration of content on official profiles set up on social networks, (ii) organising events, including sending invitations to the event even without consent and making photos and videos capturing the participants of the event and publishing them during promotion (usually based on consent), (iii) publishing content and posts containing personal data as part of various PR content (PR articles, press releases, posts published on social networks).

  • Collection and analysis of customer feedback:

It includes especially collection and analysis of customers feedback from all marketing activities by using of Qualtrics service.

18. Statistics purposes

  • Statistics purposes:

It includes especially: (i) compilation of statistical outputs, reports, reports, reports, analyses and various work and analytical documents necessary for the internal statistical purposes of the WAG Group, state authorities and other legal entities, (ii) creation of anonymised and aggregated statistical data from personal data processed for other legitimate purposes of processing personal data that have a legal basis and of which the persons concerned have been properly informed in accordance with recital 50 and Art. 89 GDPR.

Explanation note: 

[1] Processing operation covered by legal ground of legitimate interest pursuant Art. 6 (1) letter f) GDPR is highlighted in text. 

[2] Legitimate interest is pursued only if conditions for opt-out direct marketing communication to existing customers or legal persons under Art. 13 of the ePrivacy Directive (2002/58/EC) (as implemented) are met.  If not met, processing is based on a consent.