Personal Data Protection Policy

1. Introduction

Information about Axus Luxembourg
Axus Luxembourg SA, a public limited company with its registered office at route d’Arlon 270, L-8010 Strassen, Luxembourg, registered in the Trade and Companies Register of the Grand Duchy of Luxembourg under number B23299 (hereinafter referred to as "Axus Luxembourg" or "we"), is a provider of mobility solutions specializing in long-term operational leasing and corporate fleet management services. Axus Luxembourg is a member of the ALD Group, a subsidiary of the Société Générale Group.

As part of its activities and services, Axus Luxembourg processes, among other things, the personal data of its customers and its customers' employees (drivers). With regard to these processing activities, Axus Luxembourg acts as the "data controller" and is responsible for protecting your personal data. As such, Axus Luxembourg strives to comply with applicable data protection legislation, including, as of May 25, 2018, the European General Data Protection Regulation 2016/679 (the "Regulation or "GDPR") and applicable national laws implementing EU Directive 95/46 on the processing of personal data or supplementing the GDPR.

Respecting your privacy is a priority for us
Axus Luxembourg strives to be a trusted partner and, for this reason, endeavors to respect and protect your personal data or that of your employees.
This personal data protection policy aims to explain how we collect, store, use, and disclose your personal data when you use our products and services, our websites, or when you interact with us. This personal data protection policy also describes your rights and explains how you can exercise them.

Please read this Privacy Policy carefully to ensure that the processing of your personal data is as transparent as possible.
Please also ensure that your employees are aware that their personal data is processed by Axus Luxembourg and that their consent to this data processing, as described in this Privacy Policy, is obtained where necessary.

The following principles are central to how we process your personal data 

  • Transparency and fairness: when we collect and process your personal data, we tell you who collects and receives this data, as well as the reasons for collecting it.
  • Legitimacy: Axus Luxembourg does not collect or process personal data without a legitimate reason. Where required by law, we always ask for your consent in advance (for example, to the extent necessary, before launching a direct marketing campaign).
  • Purpose: We only use your personal data for relevant business purposes (e.g., to provide services, manage customer relationships, manage customer vehicle fleets, perform accurate billing, conduct marketing activities, better serve customers, conduct satisfaction surveys, prepare reports, and comply with our legal obligations). We never use your personal data for purposes that are incompatible with the objectives described in this Personal Data Protection Policy or that are communicated to you elsewhere.
  • Necessity and proportionality: we only collect personal data that is necessary for data processing, in accordance with this Personal Data Protection Policy. We only collect sensitive information when it is relevant. We take all reasonable measures to ensure that your personal data is accurate, complete, and up to date. We only provide your data to business partners and suppliers to the extent necessary to provide you with our services or to comply with legal obligations.

These principles are detailed in several sections below.

2. What activities are covered by the data collection?

This Policy applies to all sources of data collected and processed by Axus Luxembourg in the course of its various commercial activities, including commercial vehicle rental, car rental for private individuals, fleet management, mobility solutions (bike rental, etc.), vehicle sales, use of our websites, etc.

3. What personal data do we process?

We may collect and process your personal data if you fall into one of the following categories:

  • customers (professionals or individuals);
  • employees of clients or other persons authorized by clients to benefit from a contract between the client and Axus Luxembourg (i.e., vehicle drivers);
  • customer contacts;
  • fleet managers;
  • prospects;
  • used car buyers;
  • guarantors;
  • website visitors/users;
  • company directors;
  • shareholders;
  • etc.

4. How do we collect your personal data?

Axus Luxembourg may collect your personal data in various ways.

  • We collect your personal data directly from you when we interact with you (for example, when you contact Axus Luxembourg, Axus Luxembourg may keep a record of this correspondence), when you fill out an online form (application form, order form, accident report form, etc.), when you create an account on one of our websites, etc.
  • We may ask you to respond to surveys used for research or improvement purposes, although you are not obligated to respond.
  • We may record certain details about your visits to our websites, including but not limited to traffic, location data, weblogs, and other communication data and the resources you access.
  • We may collect information about your computer or device, including your IP address, operating system, or browser type. This information is collected to ensure the proper management and functioning of our websites. Cookies are used to collect this information.
  • We may receive personal data from your employer with whom Axus Luxembourg has entered into a contract (contact details, vehicle category, etc.).
  • We may receive personal data about you from our suppliers providing services in connection with the performance of any contract (e.g., fuel card suppliers, etc.).
  • We may receive your personal data from authorities (for example, in connection with fines).

5. What types of personal data do we collect?

We collect the following types of personal data:

  • Identification and contact details, including your last name, first name, address, phone/mobile number, or email address;
  • Professional information, including your job title, department, or work contact details;
  • Financial or credit information, including the date your credit(s) was/were approved or information about your contract, bank account, loans, etc.;
  • Personal characteristics, including your gender, date of birth, nationality, language, family situation, etc.;
  • Your voice, which may be recorded when you call Axus Luxembourg Customer Service;
  • Data relating to you as a driver, including driver's license number/duplicate or employee driver code;
  • Data relating to operations performed on the vehicle and to the use of the vehicle, including information about the vehicle (e.g., the vehicle's license plate number, the date of the vehicle's last service, etc.) and its use (e.g., fuel consumption);
  • Data on driver behavior, such as vehicle usage taxes (road tolls and parking fees, etc.), accident history.

We may also sometimes collect sensitive data. For this data, please refer to section 12.

6. Cookies and other tracking tools

To improve your experience when you visit our websites, we collect certain information by automated means, including cookies, web beacons, browser analysis tools, server logs, and web tags (e.g., Google Analytics).
If you use our websites, we may collect information about the browser you use and your browsing behavior.

7. For what purposes do we use your personal data?

    Axus Luxembourg processes your personal data for the following purposes, as applicable, and for any other purposes that may be compatible with these:

  • To perform customer checks, credit checks, and to get to know our customer through the "Know Your Customer" process: to process and perform customer assessments before entering into a contract or before selling a used vehicle.
  • To comply with legal obligations and protect the rights and assets of Axus Luxembourg: we will use personal data to respond to legitimate requests from supervisory and tax authorities, to detect and prevent money laundering, to conduct due diligence on a counterparty, etc.
  • To create and manage customer accounts.
  • To communicate with you: you can contact us in various ways (via our website, by phone, by email, etc.) to ask questions, request information, share comments, etc. We will use your personal data to communicate with you or to respond to your questions.
  • To provide you with vehicle and mobility services included in the contract:

– vehicle ordering,
– vehicle delivery,
– repairs, maintenance, and tires,
– vehicle insurance,
– accident and repair management,
– fuel card management,
– roadside assistance,
– replacement vehicle,
– vehicle return management (vehicle collection, etc.).

  • To provide managers with fleet management tools.
  • In connection with the use of web portals.
  • To generate fleet reports for customers related to vehicle usage (fuel consumption, accident history, etc.).
  • For billing and accounting (invoicing, payment collection, etc.).
  • To manage disputes (collection of unpaid amounts, legal cases, etc.)
  • To manage fines and all taxes, fees, and administrative penalties related to the use of the vehicle, including parking, as well as all offenses.
  • To inform customers of the results of satisfaction surveys.
  • For administrative reports, including audits, internal control, and data analysis.
  • To retain business and professional records for legal, administrative, and auditing purposes. We also use the information to meet legal, insurance, and processing requirements.
  • To manage access and security for Axus Luxembourg's premises and assets.
  • For the sale of vehicles.
  • For marketing purposes: we may use your information to contact you about new offers or services and special offers that we think may be of interest to you, or to send you advertising messages or newsletters. We may analyze your profile and preferences as a customer and undertake multi-channel advertising campaigns using automated tools, contact you by text message or email, or send you brochures.
  • For customer/driver satisfaction surveys based on marketing tools and targeted analyses, we can send you qualitative surveys about our products and services.
  • We may also invite you to participate in events, games, or advertising quizzes via our websites.
  • For websites, cookies, and newsletters: we may collect information via cookies to gain experience and give us a better idea of your browsing habits, in particular to store your preferences and settings to save time (including language preferences), enable login, combat fraud, and analyze the performance of our website and services.

This information helps us improve our websites and learn more about the products and services you prefer.
We also use cookies for web analytics to determine website activity and the most visited areas of the websites.

Although we may set functional cookies to facilitate your visit to our websites, you can indicate your preferences regarding cookies used for behaviorally targeted advertising using your browser's privacy settings to prevent the storage of information on the device or the processing of information already on the device, unless you enable the feature to allow such storage or processing.

For more information, please see our cookie policy available on our websites.

For profiling: to better understand your interests and concerns, we may use your personal data to improve our website and services, to personalize your experience with us, and to tailor our marketing activities to your needs and interests.

8. On what basis do we process your personal data?

Axus Luxembourg processes your personal data based on the following legal grounds, as applicable:

  • the performance of the contract you have entered into with Axus Luxembourg or the preparation of a contract you intend to enter into with Axus Luxembourg;
  • your prior informed consent, when required;
  • compliance with our legal obligations (e.g., anti-money laundering legislation, provisions of the law of July 25, 2015 establishing the automated control and sanction system, etc.);
  • the legitimate interests of Axus Luxembourg or a third party, insofar as these rights take precedence over your fundamental rights and freedoms, such as, where applicable, detecting and preventing money laundering, conducting a preliminary audit of a counterparty, providing you with useful information, etc.

9. Who do we share your personal data with?

In order to provide our services, we sometimes need to engage partners or processing entities for the purposes described above. We limit the sharing of your personal data to the following categories of recipients:

  • internal departments such as Sales, Customer Service/Quality, Marketing, IT, Support, and Maintenance;
  • within the ALD Group, other entities of the group;
  • our partner, through whose network you received the rental offer.
  • our client (your employer, if applicable);
  • our service providers, including: credit insurers, vehicle insurance companies, data hosting providers, IT service providers, marketing partners, call centers, third parties performing modifications, maintenance, mechanical repairs, tire changes, damage assessments, damage repairs, assistance, etc.
  • the authorities when required by law, for example in response to a subpoena, including law enforcement agencies and courts, requests from tax authorities, etc.
  • when necessary to sell or transfer business assets, in the event of bankruptcy, to enforce our rights, protect your property or the rights, property, or safety of others, or as necessary to support external audit, compliance, and corporate governance functions.

We know that you do not want us to pass on your personal data directly to third parties for their own marketing purposes without your consent.

Please note that we may also use and disclose personal data about you that is not personally identifiable, i.e., personal data in aggregate form that no longer identifies you.

10. How is your personal data stored and transferred?

Axus Luxembourg aims to ensure that your personal data is:

  • protected against accidental or intentional destruction/loss;
  • used correctly; and
  • inaccessible to unauthorized persons.

All information you provide to us is stored on our secure servers. Your personal data is stored either in our databases or in the databases of our service providers.

We may transfer your personal data to service providers involved in maintenance and support services (located in countries such as India), or involved in the provision of any other tools used for the processing of personal data of our customers and prospects.

When we transfer information outside the European Economic Area, we ensure adequate protection of the transfer of personal information to recipients in those countries by entering into data transfer agreements with those recipients based on the European Commission's standard clauses where necessary.

11. How long do we keep your personal data?

In general, we retain your personal data for as long as necessary for the purposes described in section 7 of this Privacy Policy, or in accordance with applicable laws.

For example, we retain your personal data for as long as necessary in the context of your business relationship with Axus Luxembourg and, where applicable, after the end of that relationship, or for as long as necessary to comply with Axus Luxembourg's legal obligations.

In the event of a dispute, we may retain your personal data until the dispute is fully resolved. We will delete or archive this data in accordance with applicable law.

12. Sensitive data

We are sometimes required to process sensitive data, mainly legal information such as fines, traffic violations, and criminal data relating to accidents (police reports, etc.).

We process this data exclusively for the following purposes:

  • For the management of claims and related litigation (recovery of amounts incurred in connection with claims during the rental period, etc.).
    If necessary, this data may be transmitted to the customer (employer), insurers and brokers involved in the management of the claim, professional experts appointed by us or by them (lawyers, legal experts in charge of the case), any subcontractors involved in the management of claims, as well as to the authorities and courts.
  • For the management of fines and administrative penalties, as well as all offenses related to the use of the rented vehicle.

Axus Luxembourg, as well as any subcontractor responsible for managing fines, may be required to:

  • process information concerning traffic fines, administrative penalties, and traffic violations, including the location of the violation, the date and time, the violation itself, and the amount to be paid; and
  • transmit personal data to the competent authorities to enable identification (via fax/email); and, where applicable,
  • forward the data relating to the fine or administrative penalty to the customer (often the driver's employer) to enable the fine or penalty to be managed and invoiced.

13. How do we ensure the security and integrity of your personal data?

We protect your data with technical and organizational security measures against accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access, and any other form of unlawful processing.
When we outsource data processing, we impose contractual obligations to protect your information.

14. How can you control and indicate your preferences regarding the use of your personal data?

You may exercise a number of rights with regard to the processing of your personal data by Axus Luxembourg, to the extent that you actually have these rights under applicable data protection legislation, such as the GDPR.
To exercise the rights set out in this section at any time, please contact the Axus Luxembourg data protection officer (see section 15), who will process your request.

Objection. You have the right to object at any time to the processing of your personal data based on Axus Luxembourg's legitimate interest, for example when it is used for (direct) marketing purposes, to create your profile in order to send you targeted advertising, or when your data is shared with third parties or other entities within the ALD group.

Withdrawal. If you have previously consented to the processing of your personal data, you may withdraw this consent at any time. The lawfulness of processing based on consent prior to withdrawal remains unaffected.

Access. You may request access to the personal data we hold about you, or request a copy of it. You may also request information about the purposes of processing, the categories of data, the categories of recipients, the terms of data retention, etc.

Portability. You may have the right to obtain a copy of all personal data we hold about you in our records, in a format compatible with enabling you to exercise your right to data portability.

Restriction. You have the right to request that the processing of your personal data be restricted in the following cases:

  • for a period allowing Axus Luxembourg to verify the accuracy of your personal data, in the event that you dispute the accuracy of such data;
  • if the processing is unlawful and you wish to restrict the use of your personal data rather than delete it;
  • if you want Axus Luxembourg to retain your personal data because you need it to defend yourself in legal proceedings;
  • if you have objected to the processing, but we need to verify whether the legitimate grounds for this processing override your own rights.

Rectification. You may also have the right to rectify inaccurate personal data and to complete incomplete personal data.
Erasure. You have the right to request the erasure of your personal data in the following cases:

  • if your personal data is no longer necessary for the purposes for which it was collected or processed;
  • if you have withdrawn your consent and there is no other legal basis for the processing;
  • if you have objected to the processing of the data and there is no compelling legitimate reason for Axus Luxembourg;
  • if the personal data has been unlawfully processed;
  • if the personal data must be erased to comply with a legal obligation to which Axus Luxembourg is subject.

In the event of erasure, we will take reasonable steps to inform other entities within the ALD group that may be involved in processing this data of the erasure.

Complaint. You also have the right to lodge a complaint with the competent supervisory authority if you have doubts about the conditions under which Axus Luxembourg processes your personal data (Commission Nationale pour la Protection des Données, Avenue du Rock’n Roll 1, L-4361 Esch-sur-Alzette, Luxembourg, www.cnpd.lu).

15. Who should you contact if you have questions or concerns about the processing of your personal data?

The Société Générale Group has appointed a joint Data Protection Officer for the SG Group entities operating in Luxembourg, including Axus Luxembourg. This Data Protection Officer can be contacted at lu.dpo@axus.lu.

In addition, Axus Luxembourg has appointed a Data Protection Correspondent within its organization,
The Data Protection Correspondent is the Customer's first point of contact for questions relating to personal data protection or for exercising their rights.

In this regard, all questions, complaints, or comments regarding this Personal Data Protection Policy or our data processing principles should be sent by email to the following address: lu.privacy@axus.lu.

For the avoidance of doubt, this person does not have the authority of a data protection officer within the meaning of the GDPR.
The data protection officer at Axus Luxembourg will then act as a second point of contact for any questions concerning (presumed) non-compliance with the regulations and/or laws in force regarding data protection.

16. What happens when we amend this Personal Data Protection Policy?

Our Privacy Policy may change from time to time to reflect changes in how we process your personal data. We encourage you to regularly visit our websites for the latest information on our data protection principles. We will notify you of any significant changes as required by law.

You can check the date of the last revision of this Data Protection Policy at the very beginning of this document.