Privacy policy for the Brose ebike app

Stand: 30 Jun 2021

1. Summary information on data processing

Below you will find the essential information regarding the processing of your personal data by Brose Antriebstechnik GmbH & Co. KG, Sickingenstr. 29-38, 10553 Berlin, ("Brose", "We", "Us") in connection with the use of the Brose ebike app ("ebike app").

This privacy policy consists of this summary information (section "Summary Information") and the following detailed data protection information (section "Full Information") on data processing in order to provide you with an overview of Our procedures regarding the collection, storage, use, disclosure or deletion (collectively "Processing" or "Processing") of information of any kind about you (such as your email address) (collectively "Personal Data") in connection with the use of the ebike app.

The ebike app enables the user to connect his compatible mobile device (e.g., smartphone) to his e-bike or components installed therein that are manufactured by Brose ("Brose Products") in order to view and manage technical data of these Brose Products and - via access to third-party map services - to record and plan rides.

1.1. Processing of your Personal Data (Categories of Personal Data)

We process the following categories of Personal Data: Email address, IP address, product data (e.g., serial number of the components installed on the e-bike), condition data (e.g., mileage, battery condition, wheel circumference), telemetry data (e.g., speed, cadence, motor temperature) and route data (GPS data). For more information, please refer to Section I. of the Complete Information.

1.2. Processing purposes

Your Personal Data is processed for the following purposes: Provision of the functionalities of the E-Bikes App, product improvement, error analysis and quality assurance, compliance with legal obligations. For more information, please refer to section II. of the Full Information

1.3. Legal basis of the processing of your Personal Data

We process your Personal Data on the basis of the following legal grounds: (i) your consent (Art. 6 para. 1 lit. a DS-GVO) (ii) for the performance of a contract to which you are a party or as far as necessary for the performance of pre-contractual measures (Art. 6 para. 1 lit. b DS-GVO); (iii) for the performance of a legal obligation to which Brose as the controller is subject (Art. 6 (1) lit. c DS-GVO; and (iv) if necessary, to protect the legitimate interests of Brose or a third party, unless your interests or fundamental rights requiring the protection of personal data override (Art. 6 (1) lit. f DS-GVO). For more information, please refer to Section III. of the Complete Information.

1.4. Data transfers and recipients and legal justification for such transfers

We transfer your Personal Data to other Brose Group companies and third parties (e.g., card service providers, social media platform providers), Our service providers and, in accordance with applicable legal requirements, government authorities, courts, external consultants and similar third parties, some of the recipients being located in countries outside the EU. For more information on this, please see Section IV. of the Complete Information

1.5. Retention periods for and deletion of your Personal Data

Your Personal Data will be deleted as soon as it is no longer needed for the purposes for which it was originally collected or as required by applicable law. For more information, please refer to section V. of the Complete Information.

1.6. Your legal rights

Under applicable law, you have certain rights with respect to the processing of your Personal Data, in each case subject to applicable legal requirements, such as the right to access, rectify, erase or surrender your data. Please direct your questions to the contact details above. For more information, please refer to Section VI. of the Complete Information.

1.7. Changes to this summary and the complete data protection information

This Summary and the Complete Information may need to be updated from time to time - for example, due to the implementation of new technologies or the introduction of new services or features. We reserve the right to change or amend this Privacy Policy at any time. We will inform you about changes accordingly (e.g., by e-mail).

2. Complete information on data processing

2.1. Categories of personal data

We process the following Personal Data in connection with your use of the E-Bikes App:

- Email address and password ("Account Data")
- Name, contact details (email address or phone number), content of user requests ("User Service Data")
- Bike identifier, serial number of the components installed on the e-bike (such as drive, battery), the firmware versions installed on the components installed on the e-bike, wheel circumference ("Product Data")
- Mileage, battery health, battery charge and general technical condition, error codes ("Condition Data")
- Speed, cadence, torque, battery discharge and consumption, light status, timestamp, assistance level set, drive power, rider power, motor temperature, remaining range in kilometers, percentage drive power ("Telemetry Data")
- GPS data, acceleration values ("route data")
- Calculated calorie consumption ("Calorie consumption")
- Data related to the mobile device used: operating system, e-bikes app version, battery level, brightness setting, internet connection used (mobile network or WLAN), memory usage ("device data")
- IP address ("app usage data").

3. Processing purposes

Your Personal Data will be processed by us to the extent permitted by law for the following purposes:

- Providing the functionalities of the E-Bikes App ("App Functionalities")
- Improvement of the functionalities of the E-Bikes App and of Brose products installed on the E-Bike ("Product Improvement")
- Ensuring the quality requirements of the E-Bikes App as well as of Brose products installed on the E-Bike, analyzing and rectifying any errors that occur ("Error analysis and quality assurance")
- For compliance with legal obligations to which Brose is subject as operator of the E-Bikes App ("Compliance")
- Answering and processing user inquiries via e-mail or telephone ("User Service").

4. Legal basis for the processing of your personal data

Brose processes your personal data as long as:

- You have consented to the processing of your data, Art. 6 para. 1 lit a DSGVO ("Consent")
- this is necessary for the performance of a contract with Us, to which you are a party, or for the performance of pre-contractual measures, Art. 6 (1) lit. b DS-GVO ("performance of contract").
- this is necessary for the fulfillment of a legal obligation to which Brose is subject, Art. 6 para. 1 lit. c DS-GVO ("Legal obligation")
- this is necessary for the protection of Our legitimate interests or the legitimate interests of a third party, unless your interests or fundamental rights and freedoms requiring the protection of personal data override, Art. 6 (1) (f) DS-GVO ("Legitimate Interest")

The following table shows which categories of Personal Data are processed for which purposes and on which legal basis this processing is based off:

Personal data  
Processing purposesRelevant categories
of personal data
Legal basis
App-functionalitiesAccount data
State data
Telemetry data
Calorie consumption
Distance data
App usage data
Contract fulfillment, Art. 6 para. 1 lit. b DS-GVO
Product improvementProduct data
Condition data
Telemetry data
Legitimate interest, Art. 6 para. 1 lit. f DS-GVO in the improvement of the functionalities of the E-Bikes app and the elimination of any existing errors. Only pseudonymous or anonymized data is processed for this purpose.
Product improvementRoute dataConsent, Art. 6 para. 1 lit. a DSGVO
Error analysis and quality assuranceProduct data
Condition data
Telemetry data
Device data
Legitimate interest, Art. 6 para. 1 lit. f DS-GVO in ensuring the functionalities of the E-Bikes app and its permanent provision.
ComplianceAccount dataLegal obligation, Art. 6 para. 1 lit. c DS-GVO

Legitimate interest, Art. 6 para. 1 lit. f DS-GVO
User serviceAccount data
User service data
Contract fulfillment, Art. 6 para. 1 lit. b DS-GVO

Legitimate interest, Art. 6 para. 1 lit. f DS-GVO, as the processing of the data is necessary for answering and processing user requests

You are not obliged to provide Us with your Personal Data. If you do not provide Us with your Personal Data, certain functionalities of the E-Bikes App cannot be used, for example, you cannot register.

5. Data transfers and recipients and legal basis for such transfers

5.1. Recipient

To other companies of the Brose Group: Your personal data will be transmitted by Us to other companies of the Brose Group within the scope of the data processing required by Art. 6 Para.

Third Parties: Certain Personal Data is also shared by Us with third parties. These are in particular the providers of the map services komoot GmbH, Friedrich-Wilhelm-Boelcke-Stra├če 2, 14473 Potsdam and Strava Inc, 208 Utah Street, San Francisco, CA 94103, USA, insofar as you have chosen to link your user account with the respective provider to the E-Bikes App and if you use the "Start Ride" function in the E-Bikes App to capture and record your rides. The transmission of the data takes place exclusively, during the recording of the rides and as far as you allow the E-Bikes App to access your location data in the settings of your mobile device. In accordance with applicable law, we also transfer Your Personal Data to government agencies, courts, outside counsel and similar third parties.

Service providers: To provide the E-Bikes app functionalities, Brose uses external service providers to whom Personal Data is sometimes also transferred for the provision of the services. These are cloud service providers, as the app functionalities are provided via a cloud environment, as well as service providers used to provide the user accounts.

5.2. Cross-border data transfers

We sometimes transfer your data to recipients outside of the country in which you reside. Some of the recipients of your Personal Data named above are not located in a member state of the European Union ("EU") or within the European Economic Area ("Third Countries"). The level of data protection in a Third Country may differ from that guaranteed within the EU.

To the extent that the recipients are located in countries for which the EU Commission has made an adequacy decision, the transfer is thus subject to an adequate level of protection from the perspective of EU data protection (Art. 45 GDPR).

We safeguard any other data transfer to third countries in accordance with data protection law requirements by concluding appropriate data transfer agreements based on the standard contractual clauses (2010/87/EU and/or 2004/915/EC) or by means of other appropriate means to ensure an adequate level of data protection for the Personal Data transferred. A copy of the appropriate means can be obtained by contacting us using the contact details below.

6. Retention periods for and deletion of your Personal Data

Your Personal Data will be stored by Us only for as long as is necessary to achieve the particular purpose on which the collection of the data was based and as is necessary and permissible under applicable data protection laws.

Thereafter, we will remove your Personal Data from Our systems and records and/or take steps to properly anonymize it so that you can no longer be identified from it, unless We are subject to legal retention obligations. As a rule, Brose will retain Your data for 30 days after termination of the usage relationship.

7. Your legal rights

Under the conditions established by applicable law (i.e., the GDPR), you have the following rights:

7.1. Right of access

You have the right to request information about whether Personal Data concerning you is being processed; if so, you have the right to request information about the Personal Data. The information about which information may be requested includes the purposes of the processing, the categories of Personal Data concerned and the recipients or categories of recipients to whom the Personal Data have been or will be disclosed.

You have the right to obtain a copy of the Personal Data that is the subject of the processing. For any additional copies you request, we may charge a reasonable fee based on administrative costs, if applicable.

7.2. Right to rectification

You have the right to request that We correct any Personal Data that is inaccurate about you. Depending on the purpose of the processing, you have the right to request the completion of incomplete Personal Data - also by means of a supplementary declaration.

6.3. Right to erasure (right to be forgotten)

You have the right to request that We delete your Personal Data.

7.4. Right to restriction of processing

You have the right to request a restriction of the processing of your Personal Data. In this case, the relevant data will be marked and may only be processed by Us for specific purposes.

7.5. Right to data portability

You have the right to receive the Personal Data relating to you that you have provided to Us in a structured, commonly used and machine-readable format, and you have the right to transfer such Personal Data to another entity without hindrance from us.

7.6. Right of objection

You have the right to object to the processing of your Personal Data by Us at any time on grounds relating to your particular situation, and We may be obliged to stop processing your Personal Data. If you exercise a right to object, we will no longer Process Your Personal Data for these purposes. No costs will be incurred as a result of exercising this right. Such a right to object may not exist under certain circumstances, in particular if the processing of your Personal Data is necessary to take measures prior to the conclusion of a contract or to fulfill a contract that has already been concluded.

7.7. Right of revocation for consents

As far as data processing is based on your consent, you have the right to revoke your consent at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation. Please address your revocation to the following contact details.

7.8. Right of complaint to the supervisory authority

In case of complaints, you also have the right to lodge a complaint with the competent supervisory authority, in the Member State of your habitual residence or of the alleged breach of the GDPR.

8. Contact

If you have any questions or wish to exercise your rights as a data subject, please contact us preferably at the address Brose Antriebstechnik GmbH & Co. KG, Sickingenstr. 29-38, 10553 Berlin or by e-mail to service.ebike@brose.com.

In addition, you are also welcome to contact our data protection officer at datenschutz@brose.com with questions, suggestions and complaints regarding data protection.