Privacy Policy
Information on the collection of personal data
In the following, we provide information about the collection of personal data when using our portal. Personal data is any kind of data that can be related to you as an individual, e.g. name, address, e-mail addresses, user behaviour.
1. Who is responsible for the processing of your personal data?
Controller
Controller in line with Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is Toyota Insurance Management SE, Toyota-Allee-2, 50858 Cologne, Germany.
Data Protection Officer
You can reach our data protection officer at datenschutz@toyota-versicherung.de or at our postal address Toyota Insurance Management SE, Toyota-Allee-2, 50858 Cologne with the addition “Data Protection Officer”.
2. Collection of personal data when you visit our website
Logfiles
If you wish to view our website, we collect certain data that is technically necessary for us to ensure the security and stability of the website.
For this purpose, we process IP address, date and time of the request, content of the request (specific page), access status/HTTP status code, and details of device, operating system and browser version.
We base this data collection on legitimate interest (Art. 6 para. 1 sentence 1 f) GDPR) to ensure IT security, stability and misuse of the portal.
Your data is stored within the relevant log files between 14 and 30 days. Certain technical logs, which however do not contain any of the above information about you, are stored for 90 days.
Log-in area
In order to enable you to log into your account, we collect and process the following personal data from you:
Email address, password, first and last name, role (installer, dealer, back office, administrator), access rights (country, company).
The data is used exclusively to enable you to visit our portal, to ensure the functioning of the services contained therein and for a clear assignment of each user to their role, country and legal entity when logging in.
The information is anonymized in the portal as soon as the account has been deleted and there are no further reasons for retaining the data (e.g. ongoing analysis of a theft that has occurred, invoicing, overview of built-in boxes).
The legal basis for this is our legitimate interest in managing access to our portal in accordance with defined roles and access rights (Art. 6 para. 1 sentence 1 f) GDPR).
Dealer Access
In addition to the use of our website described above, certain data is collected on our website and forwarded to the manufacturer AvMap S.R.L., Viale Zaccagna 6, 54033 Carrara (MS), Italy (“AVMAP”), in order to process your hardware orders and provide an invoice to you. This includes name, contact, email address, VAT number, (billing) address. AVMAP processes the received order and billing information as a controller in their own right.
Your dealer access also contains an overview of the hardware you have installed in combination with the associated vehicle number.
The legal basis for this is the initiation or execution of a contractual relationship between you and AVMAP for any hardware orders as well as the legitimate interest on our part in the correct processing of hardware orders, and an exact assignment of all installed hardware to a specific dealer.
3. Cookies/Analysetools:
A cookie is a small piece of data (text file) that your browser stores on your device at the direction of a website you visit to “remember” information about you, such as your language preferences or login information. These cookies are set by us and are known as first-party cookies. We use these cookies to support our security efforts. In particular, we use cookies and other tracker technologies for the following purposes.
First party cookies
We have the following cookies installed on the webpage:
Cookies | Purpose | Retention period |
Pll_language | Evaluate language settings | 1 year |
WordPress_test_cookie | WordPress core cookie shows if the browser allows cookies | End of the browser session |
Your information will be processed by AVMAP as our data processor. For the above mentioned purposes, we rely on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
4. Recipients of your data
Your usage data can be viewed by the administrators of the portal, who have been appointed per country to maintain the portal and follow up on confirmed theft reports.
In the context of a confirmed theft, contact data (e.g. installing car dealership or theft officer in the respective country) could be forwarded to the responsible authorities.
In addition, your data will be transmitted to AVMAP for the purpose of billing you.
In some cases, we use external service providers as processors to process your data. These have been carefully selected and commissioned by us, are bound by our instructions and are regularly checked.
5. Data subject rights and right to complain
- Information: You can request information at any time about which personal data we process about you, where it comes from and for what purpose and in what way we process the data. Your right to information is regulated in Art. 15 GDPR.
- Right to data portability: If the requirements of Art. 20 GDPR are met, you have the right to receive your personal data that you have provided to us in a common, structured machine-readable format and to transfer your personal data to a third party of your choice or to have it transmitted by us.
- Correction of your data: If you notice an error in your personal data or notice that it is incomplete or inaccurate, you can request that we correct or complete this data in accordance with Art. 16 GDPR.
- Restriction of processing: If the requirements of Art. 18 GDPR are met, you have the right to demand a restriction of the processing of your personal data (for example, while an inaccuracy of your personal data asserted by you is being examined by us).
- Deletion: In addition, you can ask us to delete data about you under the conditions set out in Art. 17 GDPR, unless there is a statutory exception.
- Objection: In accordance with Art. 21 para. 1 GDPR, you have the right to object at any time to the processing of personal data concerning you that we carry out on the basis of legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR for reasons arising from your particular situation. We will no longer process the personal data concerning you unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. If the personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising, in accordance with Art. 21 (2) GDPR; this also applies to profiling, insofar as it is related to such direct advertising. If you object to the processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes.
- Withdrawal of consent: You can revoke consent at any time with effect for the future. This does not affect the lawfulness of the processing carried out on the basis of consent before its revocation.
- Complaint to a supervisory authority: You are also entitled to lodge a complaint with you local data protection authority and in the event that you believe that the applicable regulatory provisions have not been respected.
The data protection supervisory authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf
6. Deletion
Beyond the above-mentioned storage periods, your data will be deleted as soon as it is no longer needed.
If storage is necessary due to statutory regulations (e.g. when concluding contracts with us or AVMAP as the manufacturer of the hardware supplied),your data will be stored in line with these requirements; this will usually be for a period of ten years.
7. Data transfer to a third country
If we transfer personal data to service providers outside the European Economic Area (EEA), the transfer will only take place if the third country has been confirmed by the EU Commission to have an adequate level of data protection or if other appropriate data protection guarantees (e.g. binding corporate data protection regulations or EU standard contractual clauses) are in place. Detailed information on this and on the level of data protection of our service providers in third countries can be requested under the contact information mentioned above.
Last update: 04/08/2026