HEREIN REFERRED TO AS THE (ENTITY)
Privacy Policy for Service Station Operations
Effective: 1 May 2025
1. Introduction
We, the (“Entity”), are committed to protecting the privacy of our customers, suppliers, and partners in line with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable national privacy laws. This privacy policy explains how we handle personal data within the operation of our service stations and fuel delivery services.
2. Data Controller
The Entity is the Data Controller for all personal data processed during the provision of services at our fuel stations, stores, car service bays, and through our digital platforms.
3. What Personal Data We Collect
We may collect and process:
Identification Data: Name, vehicle registration, driver’s license (when required for service or compliance)
Contact Details: Phone number, email, billing address
Transaction Data: Receipts, loyalty program details, fuel card usage, payment methods
Service Interaction Data: Car servicing records, fuel delivery requests, complaints or queries
Surveillance Data: CCTV footage on-site for safety, theft prevention, and legal compliance
Website and App Data: IP address, contact forms, booking records, cookie consent logs
Sensitive data is only collected when necessary (e.g., for accident reports or lost property) and always under strict safeguards.
4. Lawful Basis for Processing
We rely on:
Consent (Art. 6(1)(a)) – loyalty programs, newsletter signups, promotional communications
Contractual Necessity (Art. 6(1)(b)) – purchases, fuel delivery, vehicle servicing
Legal Obligation (Art. 6(1)(c)) – tax records, safety logs, CCTV under crime prevention obligations
Legitimate Interest (Art. 6(1)(f)) – site security, customer service analytics, operations improvement
5. Purposes of Data Processing
We process personal data to:
Deliver fuel, car-related services, and in-store purchases
Respond to customer inquiries and service requests
Fulfill legal and insurance-related obligations
Monitor site security and prevent fraud or theft
Maintain service records and customer preferences
Communicate promotions (where consent is provided)
6. Data Sharing and Recipients
We may share your data with:
Fuel card providers, payment processors
Maintenance and technical service contractors
Security firms for CCTV and on-site safety
Accountants, tax auditors, legal advisors
Government and law enforcement (as legally required)
All third parties operate under GDPR-compliant agreements (Art. 28 GDPR).
7. Data Retention
Service and Transaction Records: 7 years (standard retention)
CCTV Footage: Up to 30 days, unless required for legal purposes
Customer Complaints/Queries: 2 years
Loyalty or Marketing Data: Until consent is withdrawn or after 2 years of inactivity
8. Data Subject Rights
Under GDPR, individuals may:
Request access to their data (Art. 15)
Request correction of inaccurate data (Art. 16)
Request erasure under defined conditions (Art. 17)
Request restriction of processing (Art. 18)
Object to certain uses (Art. 21)
Withdraw consent at any time (Art. 7(3))
9. International Transfers
We do not regularly transfer personal data outside the EEA. If such transfers are necessary (e.g., cloud services), appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions apply.
10. Data Security
We apply strict safeguards, including:
Controlled access to service systems and fuel logs
Encrypted financial records and online contact forms
CCTV monitoring with restricted playback access
Employee training in data protection and confidentiality
11. Data Breach Notification
Any personal data breach is reported to the Supervisory Authority within 72 hours, and to affected individuals if required by law.
12. Automated Decision Making
We do not use automated profiling or decision-making that has a legal or significant impact on individuals.
13. Data Protection Impact Assessments (DPIA)
DPIAs are conducted for:
New customer-facing technologies (e.g., fuel apps or kiosks)
Large-scale CCTV expansions
Remote fuel ordering or delivery systems
14. Cookies and Website Tracking
Cookies are used strictly for essential functions and anonymous analytics. No advertising or third-party tracking cookies are activated without your explicit consent.
15. Complaints
You may lodge a complaint with your Supervisory Authority if you believe your rights are infringed via CONTACT SUPERVISORY AUTHORITY below.
16. Use of Artificial Intelligence (AI) and Automated Tools
We may use Artificial Intelligence (AI) or automated technologies to support the delivery, analysis, or improvement of our services. Any deployment of AI is conducted in accordance with applicable laws, including the GDPR and forthcoming EU AI Act, and is subject to the following safeguards:
Transparency: Where AI tools are used to process personal data (e.g., chatbots, service optimization, fraud detection), individuals are clearly informed at the point of interaction.
Human Oversight: All AI-supported functions are subject to human review and final decision-making. No fully automated decisions with legal or similarly significant effects are taken without human intervention.
Fairness and Accuracy: AI systems used by the Entity are regularly monitored to ensure outputs are non-discriminatory, accurate, and aligned with intended purposes.
Data Minimization: Personal data used in AI models is limited to what is strictly necessary, and anonymization or pseudonymization is applied wherever feasible.
Third-Party AI Providers: If AI services are sourced from external vendors, they are required to comply with our data protection standards and are bound by GDPR-compliant agreements (Art. 28).
Rights of Individuals: Data subjects retain all applicable GDPR rights, including the right to object to automated processing (Art. 21) and to receive meaningful information about the logic and implications of any AI-supported decisions (Art. 22).
This clause will be updated as legal frameworks governing AI continue to evolve.
17. Updates
This policy is reviewed annually and updated to reflect changes in law or service station operations.
We the ENTITY take your privacy seriously and treat your personal information with the same care and respect we would expect for our own. This policy has been developed to comply with relevant data protection laws in our jurisdiction and, where applicable, with those of international clients and partners. If you have any concerns or believe there are areas where our data handling may fall short, please contact us using the details at the end of this policy. We are committed to transparency and prompt resolution of any issues.
A specialized compliance team has created this policy:
1. Data Protection Officer (DPO) – Regulatory Oversight
Ensures all policies comply with GDPR core principles (lawfulness, fairness, purpose limitation, data minimization)
Coordinates legal review of processing bases, data subject rights, and international data flows
Oversees DPIAs and data breach response strategies
2. Consulting Practice Compliance Lead – Sector-Specific Applicability
Aligns privacy standards across business verticals (e.g., finance, logistics, retail)
Ensures compliance with relevant industry-specific frameworks and confidentiality obligations
Validates data practices in business transformation, audits, and advisory sessions
3. Cybersecurity Expert – Data Security & Technical Controls
Reviews encryption standards, access controls, and network protection across all client data storage platforms
Conducts security assessments of document management systems and cloud services used in consulting delivery
Oversees breach mitigation protocols
4. Contract & Legal Counsel – Service Agreements & Data Use
Validates legal bases in B2B engagements, NDAs, and subcontractor arrangements
Advises on client contract terms related to data confidentiality, liability, and third-party access
Confirms legal validity of consent and legitimate interest where applied
5. Financial Data Analyst – Billing & Regulatory Compliance
Ensures secure processing of client billing records, purchase orders, and financial audits
Validates use of accounting software in accordance with GDPR and local tax laws
Reviews cross-border invoicing and data sharing with financial institutions
6. HR & People Data Compliance Advisor – Internal Governance
Manages internal employee data policies, recruitment data, and training records
Validates lawful handling of consultant performance data and internal access logs
Monitors use of productivity tools and personal identifiers
7. Business Intelligence & Analytics Advisor – Data Minimization & Ethics
Validates anonymization of client project data for analytics and reporting
Ensures dashboard tools and feedback systems align with consent and proportionality principles
Oversees compliance in data visualization tools and automated reporting
8. Cross-Border Transfer Specialist – International Data Governance
Ensures use of SCCs, BCRs, and adequacy mechanisms in multinational consulting projects
Verifies transfer logs, third-country recipient agreements, and GDPR Articles 44–50 compliance
Supports data transfer impact assessments (TIA) when required
9. Digital Transformation Lead – Tech-Driven Advisory Services
Reviews AI, automation, and decision-support tools for data ethics and compliance
Ensures privacy notices cover emerging tech use (e.g., CRM AI plugins, HR analytics)
Aligns service model updates with EU AI Act and GDPR where applicable
10. Marketing & CRM Advisor – Outreach and Consent
Ensures lawful processing of prospect data under consent or legitimate interest
Reviews marketing automation, campaign analytics, and subscription mechanisms
Validates GDPR-compliant unsubscribe features and tracking tools
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
"✱" indicates required fields
wdt_ID | Country | Organisation | Address | Phone | Fax | Website | |
---|---|---|---|---|---|---|---|
1 | Austria | Österreichische Datenschutzbehörde | Hohenstaufengasse 3 1010 Wien |
+43 1 531 15 202525 | +43 1 531 15 202690 | dsb@dsb.gv.at | VISIT |
2 | Australia | Office of the Australian Information Commissioner | Level 3, 175 Pitt Street Sydney NSW 2000 |
+1300 363 992 | +61 2 9284 9666 | enquiries@oaic.gov.au | |
3 | Belgium | Commission de la protection de la vie privée | Commissie voor de bescherming van de persoonlijke levenssfeer Rue de la Presse 35 / Drukpersstraat 35 1000 Bruxelles / 1000 Brussel |
+32 2 274 48 00 | +32 2 274 48 35 | commission@privacycommission.be | VISIT |
4 | Bulgaria | Commission for Personal Data Protection | 2, Prof. Tsvetan Lazarov blvd. Sofia 1592 |
+359 2 915 3580 | +359 2 915 3525 | kzld@cpdp.bg | |
5 | Croatia | Croatian Personal Data Protection Agency | Martićeva 14 10000 Zagreb |
+385 1 4609 000 | +385 1 4609 099 | azop@azop.hr, info@azop.hr | |
6 | Cyprus | Commissioner for Personal Data Protection | 1 Iasonos Street, 1082 Nicosia P.O. Box 23378, CY-1682 Nicosia |
+357 22 818 456 | +357 22 304 565 | commissioner@dataprotection.gov.cy | |
7 | Czech Republic | The Office for Personal Data Protection | Urad pro ochranu osobnich udaju Pplk. Sochora 27, 170 00 Prague 7 |
+420 234 665 111 | +420 234 665 444 | posta@uoou.cz | |
8 | Denmark | Datatilsynet | Borgergade 28, 5 1300 Copenhagen K |
+45 33 1932 00 | +45 33 19 32 18 | dt@datatilsynet.dk | |
9 | Estonia | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) | Väike-Ameerika 19 10129 Tallinn |
+372 6274 135 | +372 6274 137 | info@aki.ee | |
10 | Finland | Office of the Data Protection Ombudsman | P.O. Box 315 FIN-00181 Helsinki |
+358 10 3666 700 | +358 10 3666 735 | tietosuoja@om.fi | |
11 | France | Commission Nationale de l’Informatique et des Libertés | 8 rue Vivienne, CS 30223 F-75002 Paris, Cedex 02 |
+33 1 53 73 22 22 | +33 1 53 73 22 00 | nomail@cnil.fr | |
12 | Germany | Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit | Husarenstraße 30 53117 Bonn |
+49 228 997799 0, 49 228 81995 0 | +49 228 997799 550, +49 228 81995 550 | poststelle@bfdi.bund.de | |
13 | Greece | Hellenic Data Protection Authority | Kifisias Av. 1-3, PC 11523 Ampelokipi Athens |
+30 210 6475 600 | +30 210 6475 628 | contact@dpa.gr | |
14 | Hungary | National Authority for Data Protection and Freedom of Information | 33 Soderlund Drive | +36 1 3911 400 | not available | peterfalvi.attila@naih.hu | |
15 | Iceland | Icelandic Data Protection Agency | Rauðarárstíg 10 105 Reykjavík |
+354 510 9600 | +354 510 9606 | postur@personuvernd.is | |
16 | Ireland | Data Protection Commissioner | Canal House Station Road, Portarlington Co. Laois |
1890 25 22 31, +353 57 868 4800 | +353 57 868 4757 | info@dataprotection.ie | |
17 | Italy | Garante per la protezione dei dati personali | Piazza di Monte Citorio, 121 00186 Roma |
+39 06 69677 1 | +39 06 69677 785 | garante@garanteprivacy.it | |
18 | Latvia | Data State Inspectorate | Blaumana str. 11/13-15 1011 Riga |
+371 6722 3131 | +371 6722 3556 | info@dvi.gov.lv | |
19 | Liechtenstein | Data Protection Office | Kirchstrasse 8, P.O. Box 684 9490 Vaduz, Principality of Liechtenstein |
+423 236 6090 | not available | info.dss@llv.li | |
20 | Lithuania | State Data Protection | Žygimantų str. 11-6a 011042 Vilnius |
+370 5 279 14 45 | +370 5 261 94 94 | ada@ada.lt | |
21 | Luxembourg | Commission Nationale pour la Protection des Données | 1, avenue du Rock’n’Roll L-4361 Esch-sur-Alzette |
+352 2610 60 1 | +352 2610 60 29 | info@cnpd.lu | |
22 | Malta | Office of the Data Protection Commissioner | 2, Airways House High Street, Sliema SLM 1549 |
+356 2328 7100 | +356 2328 7198 | commissioner.dataprotection@gov.mt | |
24 | Netherlands | Autoriteit Persoonsgegevens | Prins Clauslaan 60 P.O. Box 93374, 2509 AJ Den Haag/The Hague |
+31 70 888 8500 | +31 70 888 8501 | info@autoriteitpersoonsgegevens.nl | |
25 | New Zealand | Privacy Commissioner | Level 13, 51 – 53 Shortland Street Auckland, New Zealand |
+64 9 302 8680 | +64 4 474 7595 | enquiries@privacy.org.nz | |
26 | Norway | Datatilsynet | The Data Inspectorate P.O. Box 8177 Dep, 0034 Oslo |
+47 22 39 69 00 | +47 22 42 23 50 | postkasse@datatilsynet.no | |
27 | Portugal | Comissão Nacional de Protecção de Dados | R. de São. Bento, 148-3° 1200-821 Lisboa |
+351 21 392 84 00 | +351 21 397 68 32 | geral@cnpd.pt | |
28 | Romania | The National Supervisory Authority for Personal Data Processing | B-dul Magheru 28-30 Sector 1, BUCUREŞTI |
+40 21 252 5599 | +40 21 252 5757 | anspdcp@dataprotection.ro | |
29 | Slovenia | Information Commissioner | Zaloška 59 1000 Ljubljana |
+386 1 230 9730 | +386 1 230 9778 | gp.ip@ip-rs.si | |
30 | Spain | Agencia de Protección de Datos | C/Jorge Juan, 6 28001 Madrid |
+34 91399 6200 | +34 91455 5699 | internacional@agpd.es | |
31 | Sweden | Datainspektionen | Drottninggatan 29 5th Floor, Box 8114, 104 20 Stockholm |
+46 8 657 6100 | +46 8 652 8652 | datainspektionen@datainspektionen.se | |
32 | Switzerland | Data Protection and Information Commissioner of Switzerland | Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter Mr Adrian Lobsiger, Feldeggweg 1, 3003 Bern |
+41 58 462 43 95 | +41 58 462 99 96 | contact20@edoeb.admin.ch | |
33 | United Kingdom | The Information Commissioner’s Office | Water Lane, Wycliffe House Wilmslow – Cheshire SK9 5AF |
+44 1625 545 745 | not available | international.team@ico.org.uk |