1. What is this Privacy Policy about?
Genesis Motor Deutschland GmbH (“Genesis”, “we”, “us”, “our”) is committed to protecting the privacy and the security of your personal data.
Below you will find information on how we use your personal data, for which purposes your personal data is used, with whom it is shared and what rights you have with regard to your personal data processed by us. For further information about how we handle your personal data (for example, with regard to cookies, sales and after-sales services etc.), we invite you to navigate the tabs in the ribbon menu displayed above.
To learn more about how your personal data is processed specifically on the Used Vehicle Locator, please click here to view the dedicated Privacy Policy.
This Privacy Policy applies to personal data that we collect for the purposes described below (through this website, in-person interactions or other media).
If we collect your information otherwise (for example when registering with other Genesis services), information on the processing of your personal data for such services will be provided separately. If you have any questions regarding the processing of your personal data related to other services provided by us, please use the contact information provided below.
You are not obliged to provide your personal data. However, your personal data may be necessary for the provision of certain services and functionalities (for example, newsletters, “contact us”, etc.). Therefore, without your personal data, we may not be able to provide the requested service.
2. Who is responsible for processing my data?
The responsible data controller for any personal data collected and processed as set out in this Policy is:
Genesis Motor Deutschland GmbH, Strahlenbergerstraße 110-112, 63067 Offenbach am Main, Germany
privacy@de.genesis.com
3. How can I contact the controller and the data protection officer?
3.1. If you have any questions about or in connection with this Privacy Policy or would like to complain about how we handle your personal data or you would like to exercise any of your rights (see section 9 below), please contact us by using the contact details provided in section 2.
3.2. Alternatively, you may also contact our data protection officer via the contact details provided in section 2.
4. What categories of personal data are processed, for what purposes and on what legal basis?
4.1 Informational use of this website
When you visit this website for informational reasons, i.e. without registering for any of our provided services and without providing us with personal data in any other form, your browser transfers certain data to our web server. This occurs for technical reasons, and it is necessary to make the requested information available to the user.
Purpose of processing:
- To provide access to the contents on our website;
- To ensure system stability and efficiency;
- To implement proper safeguards as to the security of our website and services.
Categories of data subjects:
- Website users.
Scope of personal data processed:
- Access data and server log files (IP address, date and time of your access, which pages on our website you visited, including the notification if access was successful, the volume of transferred data, the referrer URL of your previously visited website and your used browser type and version). The IT systems responsible for the correct operations of the website automatically collect your data.
Legal basis for processing:
- Our legitimate interest (Article 6(1)(f), GDPR): to enhance our systems, make your usage of the websites more convenient or ensure the security of our websites.
Period of processing:
- Seven days from the collection.
Recipients of your personal data:
- Data processors that provide us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
4.2 Contacting us
If you have any questions, we offer you the opportunity to contact us using the form provided on the website. You can also send Genesis a question or an inquiry via email or our social media pages, call us or visit us in person.
Purpose of processing:
- To receive and handle your inquiries;
- To establish, protect, or exercise our rights (for example, in the case a legal action is taken against us based on the content of the inquiry and subsequent interactions).
Categories of data subjects:
- Website users;
- Prospective customers;
- Customers.
Scope of personal data processed:
- Contact data (salutation, first and last name, postal code, city, country, e-mail address, title, mobile or landline phone number);
- Company name (if you are a business user);
- Purchase intent;
- Vehicle data (model of interest, VIN, plate number);
- Content of the inquiry and subsequent interactions.
Legal basis for processing:
- Our legitimate interest (Article 6(1)(f), GDPR) to handle and to follow up on your request; necessity for establishing, exercise or defense of legal claims.
- The processing of your personal data is necessary to conclude or to perform a contract with you (Article 6(1)(b), GDPR).
Period of processing:
- Up to 1 year from our last interaction unless you showed an interest in our products or services and agreed to be recontacted at a later time;
- In case of complaints, 3 years from the end of the year in which the complaint was received by us.
Recipients of your personal data:
- Genesis Motor Europe GmbH;
- Authorized agents and repairers;
- Contact centers;
- Data processors that provide us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
4.3. Call recording
With your consent, we will record our phone calls with you.
Purpose of processing:
- To assess customer satisfaction, train and develop staff, review call quality, and have access to a verbal record of what it is said in the event of a subsequent complaint.
Categories of data subjects:
- Prospective customers;
- Customers.
Scope of personal data processed:
- Digital recording of the telephone conversation and your telephone number.
Legal basis for processing:
- Your consent (Article 6(1)(a), GDPR).
Period of processing:
- Up to 1 year from the recording.
Recipients of your personal data:
- Genesis Motor Europe GmbH;
- Authorized agents and repairers;
- Training providers;
- Quality management software providers;
- Contact centers;
- Data processors that provide us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
4.4. Newsletter and personalized advertising
Newsletter
We offer you the possibility to subscribe to a newsletter if you wish to receive advertising about our vehicles as well as invitations and information about product launches, satisfaction surveys and information about our existing or new services, also based on your geographic area.
Purpose of processing:
- To communicate with you through newsletters.
Categories of data subjects:
- Prospective customers;
- Customers.
Scope of personal data processed:
- Salutation, title, first name, surname, e-mail address, postcode/city, country.
Legal basis for processing:
- Your consent (Article 6(1)(a), GDPR).
Period of processing:
- Until you unsubscribe.
Recipients of your personal data:
- Genesis Motor Europe GmbH;
- Authorized agents and repairers;
- Data processors for support of the operations related to customer relationship management, in particular supporting our email marketing platform and contact centers;
- Data processors that provide us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
Personalised advertising and market research
We offer you the opportunity to receive personalized advertising about our products and events, including surveys, and to be invited to take part in our market research.
Purpose of processing:
- To send you marketing communications, surveys and invitation to events and market research.
Categories of data subjects:
- Prospective customers;
- Customers.
Scope of personal data processed:
- Customer account data (salutation, title, first name, last name, e-mail address, postal code/city, country, telephone number, current car model, model of interest, etc.);
- Service and interaction history;
- Vehicle data.
Legal basis for processing:
- Your consent (Article 6(1)(a), GDPR).
- If you are our customer or showed a genuine interest in purchasing our products and/or services, we will process your data based on our legitimate interest (Article 6(1)(f), GDPR). We want to make sure you receive all the communication about our services and products similar to those purchased by you or in which you showed a genuine interest. You will also receive invitations to take part in surveys, events and market research because we are interested in understanding your satisfaction and expectations. You can object to such use of your personal data at any time and without any costs.
Period of processing:
- If you give us your consent, until you withdraw it (e.g. by unsubscribing from such communications);
- If we process your data based on our legitimate interest, we will process your data either for a period of one year after the expiration of the contract or for a period of one year from your last display of interest in our products or services, unless you object to such use of your personal data (e.g. by unsubscribing from such communications).
Recipients of your personal data:
- Genesis Motor Europe GmbH;
- Authorized agents and repairers;
- Data processors for support of the operations related to customer relationship management, in particular supporting our email marketing platform, contact centers and market research agencies;
- Data processors that provide us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
Whenever you actively subscribe to our marketing communication, we use the so-called double opt-in procedure to confirm your email address. In this process, a confirmation request is sent to the e-mail address you entered with your subscription to confirm your consent. In connection with the double opt-in procedure, we store and document the IP address, date and time of submission of your newsletter subscription via web form as well as the IP address, date and time of your confirmation of the double opt-in email.
You can withdraw your consent at any time free of charge with effect for the future via the "Unsubscribe" link contained in every newsletter/personalized advertisement e-mail or via the following e-mail address: privacy@de.genesis.com.
As soon as you unsubscribe from the newsletter/personalized advertisement, your personal data provided for the newsletter/personalized advertisement will be deleted, except for your email address that will be stored in an email suppression list to document that you do not wish to receive our marketing communication or unless other statutory retention periods apply.
4.5. Data analysis to improve our business
In order to continuously improve our business processes and services, we analyse data of our visitors, prospective customers and customers that interact with our products and services.
Purpose of processing:
- To perform analysis and predictions in order to improve our business processes, products and services.
Categories of data subjects:
- Website users;
- Prospective customers;
- Customers.
Scope of personal data processed:
- Visitor data of Genesis studios or websites (e.g. number of visitors in the studios, unique visitor ID);
- Private contact and identification data (e.g. postcode);
- Customer database data (e.g. account number, order number, vehicle identification number);
- Interaction data (e.g. requests to call center, requests for test drive, registration for newsletter, quotations, orders or sales).
Legal basis for processing:
- Our legitimate interest (Article 6(1)(f), GDPR): to improve our business processes and operations; to improve our product or service offerings; to generate insights about user behavior and trends.
Period of processing:
- 5 years from data collection.
Recipients of your personal data:
- Genesis Motor Europe GmbH;
- Providers of data transformation services;
- Providers of data analytics services;
- Data processors that provide us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
In the course of the processing, in order to comply with the principle of data minimisation, the personal data concerned is properly pseudonymized. This includes the removal of all direct personal identifiers (e.g. name, email), which are then replaced by an Account ID. Indirectly traceable identifiers are retained. After pseudonymisation, the data is analysed in Genesis' analytics systems. At no point is the direct personal reference restored.
The results of the analysis (in particular, dashboards and key figures) are always aggregated and presented as anonymous data.
4.6. Social media
Our website includes links to social networks. In order to protect your personal data while visiting our website we do not use social plugins. Instead, we embedded HTML-links in our website, enabling easy sharing in social media platforms. Embedding the link prevents a direct connection with various social media network servers when opening a page from our website. When clicking on one of the buttons, a browser window opens and directs the user to the respective website of the social network provider on which (after you have logged in) for example, the “Like” or “Share” button can be used.
Through our social media pages, we collect and process your personal data.
Purpose of processing:
- To communicate with you based on your contact request or feedback and/or for marketing and services.
Categories of data subjects:
- Website users;
- Prospective customers;
- Customers.
Scope of personal data processed:
- Contact data (e.g. e-mail, telephone numbers);
- Content data (e.g. entries in online forms);
- Usage data (e.g. websites visited, interest in content, access times);
- Meta/communication data (e.g. device information, IP addresses).
Legal basis for processing:
- The personal data is necessary to provide our social media pages and our legitimate interest in order to interact with you on social media so that we can improve our offer and make it more interesting for you as a user (Article 6(1)(f), GDPR).
Recipients of your personal data:
- Social network providers;
- Social media agencies;
- Data processors that provide us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
For more information on the purpose and scope of data processing and further use of your personal data by the social network provider and their websites as well as your rights and possible settings to protect your privacy, please refer to the privacy policy of the respective social network provider.
Facebook: Social network, service provider: Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Meta Platforms Inc, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Opt-out: Ads settings: https://www.facebook.com/settings?tab=ads.
Instagram: Social network; service provider: Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2,, USA; parent company: Meta Platforms Inc, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.instagram.com; Data protection policy: https://instagram.com/about/legal/privacy.
X: Social network, service provider; Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; parent company: Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; privacy policy: https://twitter.com/en/privacy; Personalization and settings: https://help.twitter.com/en/personalization-data-settings.
YouTube: Social network and video platform, service provider; Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; privacy policy: https://policies.google.com/privacy; opt-out: https://adssettings.google.com/authenticated.
LinkedIn: Social network, service provider; LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Our Facebook page
We are jointly responsible with Meta Platforms Ireland Ltd. for the collection (but not further processing) of data from visitors to our Facebook page (known as a "Fan Page"). This data includes information about the types of content users view or interact with, or the actions they take (see under “Your activity and information you provide” in the Facebook Data Policy: https://www.facebook.com/about/privacy), as well as information about the devices users use (e.g., IP addresses, operating system, browser type, language settings, cookie data; see under "App, browser and device information" in the Facebook Data Policy Statement: https://www.facebook.com/about/privacy). As explained in the Facebook Data Policy under "How do we use your information?", Facebook also collects and uses information to provide analytics services, called "Page Insights," to Page operators to provide them with insights into how people interact with their Pages and with content associated with them. We have entered into a special agreement with Facebook ("Page Insights Information", https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfill the data subject rights (i.e., users can, for example, send information or deletion requests directly to Facebook). The rights of users (in particular, to information, deletion, objection and complaint to the competent supervisory authority), are not restricted by the agreements with Facebook. Further information can be found in the "Information on Page Insights" (https://www.facebook.com/legal/terms/information_about_page_insights_data).
5. With whom is my data shared?
Any access to your personal data is restricted to those individuals that have a need to know in order to fulfil their job responsibilities.
We may transfer your personal data for the respective purposes to the recipients and categories of recipients listed below and as stated in section 4.
- Unaffiliated private third parties – In certain cases, we may share your personal data with trusted, unaffiliated third parties who assist us in delivering our products and services to you efficiently.
These are in particular, but not limited to:- Our network of authorized agents: we may share your data with our network of agents for the purpose of customer relationship management (including administration and update of customer profile and contact history), customer satisfaction surveys, event management, marketing and market research activities.
Our agents act as joint controllers. Joint controllers are entities that, together with us, determine the purposes and means of processing your data. These joint controllers are bound by strict agreements ensuring that your data is handled with the same level of care and protection as we provide. If you have any inquiries regarding the specifics of this joint controller arrangement, please refer to the contact information provided in this Privacy Policy. The list of the agents of Genesis is available here. - Our networks of authorized repairers for the purpose of customer relationship management, customer satisfaction surveys, event management, marketing and market research activities.
- Our network of authorized agents: we may share your data with our network of agents for the purpose of customer relationship management (including administration and update of customer profile and contact history), customer satisfaction surveys, event management, marketing and market research activities.
- Affiliated private third parties – We are part of the Hyundai group. In some cases, after careful review, we may transfer your personal data to other entities in the group (e.g. our local entities in your country of residence), each of which will process your personal data as an independent data controller or as a joint controller with us (for example, for administrative support etc.).
These are in particular, but not limited to:- Hyundai Motor Company, 12 Heolleung-ro, Seocho-gu, Seoul, South Korea;
- Genesis Motor Europe GmbH, Strahlenbergerstraße 110-112, 63067 Offenbach am Main, Germany.
- Data processors – Certain third parties, whether affiliated or unaffiliated, may receive your personal data to process such data on behalf of us under appropriate instructions as necessary for the respective processing purposes. The data processors will be subject to contractual obligations to ensure the implementation of appropriate technical and organisational security measures to safeguard the personal data, and to process the personal data only as instructed.
The current data processors are involved in particular, but not limited to in the following processes:- We are using data processors for providing us with services relating to our IT infrastructure (e.g. hosting or operation and maintenance of our IT systems and platforms).
- We engage data processors for the operation and maintenance as well as content creation for our website.
- We are using data processors for the support of the operations related to customer relationship management.
- We transmit your personal data to certain third party service providers (contact centers, market research companies and event management companies etc.).
- Governmental authorities, courts, external advisors, and similar third parties that are public bodies as required or permitted by applicable law. Some disclosures are required by law (for example, court orders or requests from the police). In these cases, we will process your data because we are subject to a legal obligation (Article 6(1)(c), GDPR) to do so.
If you click on an external link, for example for our brochure, some of your data such as your IP address will be transmitted to the link’s destination. This is technically necessary due to the TCP/IP protocol on which the Internet is based.
6. Is my data transferred abroad?
Within the scope of the activities set out above, your personal data may be transferred to other countries (including countries outside the EU or EEA) which may have different data protection standards than your country of residence. In this case we have applied appropriate safeguards with the involved third parties in place to ensure an adequate level of protection for personal data. Please note that personal data processed in a foreign country may be subject to foreign laws and accessible to foreign governments, courts, law enforcement, and regulatory agencies. However, we will endeavour to take reasonable measures to reach an adequate level of data protection also when sharing your personal data with such countries (for example, by concluding specific agreements the recipient of your data, or we will ask for your explicit consent to such transfer).
7. How is my data secured?
We have reasonable state of the art security measures in place to protect against the loss, misuse and alteration of personal data under our control. For example, our security and privacy policies are periodically reviewed and enhanced as necessary and only authorised personnel have access to personal data. In order to protect your personal data transmitted via our website, we use SSL encryption. You can recognise such encrypted connections by the prefix https:// in the address bar of your browser.
Whilst we cannot ensure or guarantee that loss, misuse or alteration of information will never occur, we use all reasonable efforts to prevent it.
IP address shortening:
If IP addresses are processed by us or by the service providers and technologies used and the processing of a complete IP address is not required, the IP address is shortened (also referred to as "IP masking"). In this process, the last two digits or the last part of the IP address after a period are removed or replaced by ‘wildcard’ characters, such as asterisks. The shortening of the IP address is intended to prevent or significantly complicate the identification of a person by means of their IP address.
8. How long will my data be stored?
Your personal data is generally stored for as long as necessary in relation to the purposes and in order to provide you with our services. Besides, we generally store your data to the extent needed to meet our legal obligations and to protect our rights: for example, we will store your data in accordance with statutory retention periods.
Insofar more specific retention periods will apply, you can refer to the information on the period of processing of your personal data as indicated in section 4 above.
9. What rights do I have and how can I exercise them?
You have certain rights in relation to your personal data that you can exercise towards us. In accordance with applicable data protection laws these rights may be restricted under certain conditions.
You can always exercise your rights at any time by contacting us via the contact information as stated in section 3.
Generally, you have the following rights:
9.1. Right of access: You have the right to obtain from us confirmation as to whether or not we process your personal data and, where that is the case, to request access to your personal data. You also have the right to obtain a copy of your personal data which we process.
9.2. Right to rectification: You have the right to the rectification of any inaccurate personal data concerning you. Depending on the purposes of the processing, you have the right to have incomplete personal data updated, including by means of providing a supplementary statement.
9.3. Right to erasure (“right to be forgotten”): Under certain circumstances, you have the right to the erasure of your personal data and we may be obliged to erase your personal data.
9.4. Right to restriction of processing: Under certain circumstances, you have the right to have a restriction placed on the processing of your personal data. This means that your data will generally not be processed by us with the exception of storage.
9.5. Right to data portability: Under certain circumstances, you have the right to receive the personal data, which you have provided to us, in a structured, commonly used and machine-readable format. You have the right, without hindrance from us, to transfer this data or have it transferred directly by us to another entity.
9.6. Right to object: You have the right to object to processing of personal data for the purposes of direct marketing and, under certain circumstances, when the processing of data for other purposes is based on legitimate interest.
9.7. Right to complain: You also have the right to make a complaint with the competent data protection supervisory authority in your country.
9.8. Right to withdraw consent: If you have given your consent to the processing of your personal data, you can withdraw your consent at any time with the effect for future processing. The withdrawal of the consent does not affect the processing that took place prior to the withdrawal of the consent.
10. Changes to the Privacy Policy
We may change and/or supplement this Privacy Policy from time to time in the future. Such changes and/or supplements may be necessary due to the implementation of new technologies or the introduction of new services. We will publish the changes on https://www.genesis.com/de/en/privacy-policy.html and/or inform you accordingly (for example, via email or hard copy letter).
Where we provide addresses and contact information of companies and organizations in this privacy policy, please note that both may change over time. Therefore, we recommend checking the relevant information before contacting us.
Date: January 2024