Protection of personal data
The purpose of this notice is to inform customers about how MOBILIS (a subsidiary of APRR) uses and protects personal data, as well as the reasons why it processes this data. MOBILIS (represented by the FULLI brand) attaches great importance to privacy and is therefore committed to processing personal data in accordance with the amended French Data Protection Act 78-17 of January 6, 1978, and the General Data Protection Regulation (GDPR) No. 2016/679.
Preamble
What is personal data?
This is any information relating to a natural person who is identified or can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to that person.
Who is responsible for processing?
MOBILIS is the data controller: MOBILIS SASU with capital of €525,160.00, registered in the Dijon Trade and Companies Register under number 808 639 801 RCS Dijon, whose registered office is located at 36 rue du Docteur Schmitt, SAINT APOLLINAIRE (21850).
Data processed and associated purposes
I. Subscription to an electronic toll payment service, billing and collection management, online management of customer accounts and badges:
The following data is collected from forms completed by the customer and attached documents: Subscriber's identity and date of birth data relating to journeys in order to calculate the cost of the journey (time stamp and network entry and exit points), vehicle registration data and characteristics (linked to certain subscription contracts) and bank details for billing purposes.
II. Subscription to an electric charging plan, management of billing and collection of transactions from charging stations
The following data is collected directly from the customer at the time of subscription or indirectly via charging stations: Identity data and date of birth, contact details (address, email, telephone number), contractual data (including card number, type of offer with options chosen, number of cards), bank details, charging-related data (electricity consumption, location of the charging station, number of charges, charging time, power and timestamp, charging amount), registration data and vehicle characteristics (related to certain subscription contracts)
III. Customer relationship management:
MOBILIS collects and processes personal data during all contact with the customer.
As part of improving customer service quality, satisfaction surveys may be conducted and telephone conversations may be monitored on an ad hoc basis.
The data collected is necessary to provide customers with an appropriate response to any request, complaint, or query.
The data processed is as follows: Customer identity, telephone number, postal address, email address, subject of the request.
IV. Management of unpaid bills and fraud:
a) Prevention of unpaid bills and management of renewals:
Customer identity, date of birth, postal address, email address, telephone number, subscriber number, support number, bank details, subscription date, information related to payment request rejection (amount, reason provided by the bank, corresponding invoice), number of electronic toll tags or cards, average consumption amount, history of unpaid bills.
b) Management of payment method fraud (e.g., use of false IBAN when subscribing):
Bank account holder identity, credit card number or IBAN, email and postal address, phone number, date of birth.
V. User registration for commercial offers and the newsletter:
Registration allows users to discover new services and commercial offers, events, and all the advice they need for safe driving. The sending of the newsletter and commercial offers is subject to the express consent of users. Data processed: email address.
VI. Management of targeted services in real time using geolocation (via the mobile application)
The following data is collected directly from the customer when they access the service after consenting to geolocation: GPS coordinates and timestamps
Legal basis for the processing of personal data
MOBILIS is authorized to process personal data in the context of, in particular:
• The performance of the electronic toll subscription contract and rechargeable cards, in all its aspects
• The legitimate interest in managing billing and collection, customer relations, and
• Consent to subscribe to the services offered: sending newsletters and commercial offers and services via geolocation
Retention period for processed data
In accordance with the principles defined by the regulations, MOBILIS retains personal data only for the time necessary to fulfill the purpose for which it was collected.
The following retention periods are therefore observed:
I. Subscription to an electronic toll payment service, billing and collection management, online management of customer accounts and badges:
5 years after the final termination of the subscription contract, in accordance with regulations relating to legal requirements.
10 years in accordance with regulations relating to billing management.
II. Subscription to an electric charging plan, management of billing and collection of transactions from charging stations
5 years after the final termination of the subscription contract, in accordance with regulations relating to legal requirements.
10 years in accordance with regulations relating to billing management
1 year for technical data records relating to charging
III. Customer relationship management:
Data relating to non-subscribing users is retained for 2 years from the last request.
IV. Management of unpaid bills and fraud:
a) Prevention of unpaid bills and management of re-subscription: Data is kept on the opposition list until the unpaid bill is settled and for 5 years if it is not settled.
If the unpaid amount is not paid in full: re-subscription is not permitted for a period of 5 years.
b) Management of payment method fraud:
When a subscription request is not accepted due to fraud, the data is automatically deleted 18 months after collection.
V. User registration for commercial offers and newsletters:
The data is kept for as long as the person is subscribed to the service offered.
VI. Management of real-time targeted services using geolocation (via the mobile app)
The data is kept for 12 hours to enable information to be communicated to customers while they are traveling on the highway.
Recipients of the processed data
I. Subscription to an electronic toll payment service, billing and collection management, online account and badge management by the customer:
The data is accessible to authorized internal departments of MOBILIS. Their subcontractors are recipients of the data within the framework of contracts that comply with regulations relating to the protection of personal data.
II. Subscription to an electric charging subscription, management of billing and collection for transactions made at charging stations
The data is accessible to authorized internal departments of MOBILIS. Their subcontractors are recipients of the data within the framework of contracts that comply with regulations relating to the protection of personal data.
III. Customer relationship management:
Personal data is processed by authorized internal departments at MOBILIS.
IV. Management of unpaid bills and fraud:
a) Prevention of unpaid bills and management of renewals:
Personal data is processed by authorized internal departments at MOBILIS
b) Management of payment method fraud:
Personal data is processed by authorized internal departments at MOBILIS
V. User registration for commercial offers and the newsletter:
The data is accessible to authorized internal departments at MOBILIS. Their subcontractors are recipients of the data within the framework of contracts that comply with regulations relating to the protection of personal data.
VI. Management of targeted services in real time using geolocation (via the mobile application)
The data is accessible to authorized internal departments at MOBILIS. Their subcontractors receive the data under contracts that comply with regulations on personal data protection.
Security measures applied to personal data
Personal data is subject to all necessary technical and organizational measures to ensure its confidentiality and security against any data breach, destruction, loss, alteration, disclosure, reproduction, or unauthorized access.
MOBILIS' subcontractors are subject to the same confidentiality and security obligations.
Location of personal data
Data is not transferred outside the European Union.
Automated decision making
Data processing is not subject to automated decision-making.
Rights of persons whose personal data are processed
In accordance with regulations, all individuals concerned have the following rights: Right of access, rectification, erasure, objection on legitimate grounds, restriction, and portability of personal data. All of these rights may be exercised by contacting the data protection officer at MOBILIS:
• Electronically via this form
• By post to the following address: MOBILIS, Data Protection Officer, 36 rue Dr Schmitt 21850 St Apollinaire
Any person concerned by the processing of their personal data may, after contacting the data controller and if they consider that their rights have not been respected, lodge a complaint with the CNIL.