Petrolina (Holdings) Public Ltd (hereinafter “Petrolina” or “we”), owner of MyPetrolina (the “MyPetrolina”), is committed to protecting your privacy and handling your personal data in a transparent and legal manner. This privacy notice (together with our Terms and Conditions as set out at [www.petrolina.com.cy] relates to the personal data Petrolina collects from you as a data controller in connection to MyPetrolina when you use:
- the MyPetrolina mobile application (the “App”), once you have downloaded a copy of the App onto your mobile telephone or handheld device (the “Device”);
- any of the services accessible through the App (the “App Services”), and
- the website of MyPetrolina, [www.mypetrolina.com.cy] (the “Website”) and any of the services accessible through the Website (the “Website Services”).
- provides an overview of how Petrolina collects and processes your personal data when you become a member of MyPetrolina and informs you about your rights under the European Union General Data Protection Regulation (“GDPR”) and the national law supplementing the GDPR;
- is directed to natural persons who are current or past users of MyPetrolina, and
- contains important information about what personal data we collect, what we do with such personal data, who we may share it with and why and your rights in relation to the personal data you have given us when using MyPetrolina.
- when we refer to “personal data” we mean data which identifies or may identify you and which may include, for example, your name, address, identity card number, telephone number, email address and date of birth;
- when we refer to “sensitive data” we mean special categories of personal data which uniquely identify a person; GDPR considers as sensitive personal data revealing the following (1) race or ethnic origin; (2) political opinions; (3) religious and philosophical beliefs; (4) trade union membership; (5) sex life or sexual orientation; (6) physical or mental health or conditions; and (7) genetic data and biometric data for the purpose of uniquely defining a natural person;
- when we refer to “processing” we mean the handling of your personal data by us, including collecting, protecting, and storing your personal data; and
- when we say or refer to “we” or “us” or “Petrolina” we mean Petrolina (Holdings) Public Ltd as described in Section 1 below, which act as a data controller with respect to the personal data processed in connection to MyPetrolina.
Notice: Some of the links on our websites lead to non-Petrolina websites with their own privacy notices, which may be different to this Statement. You will need to make sure you are happy with their privacy notices when using those other sites.
1. Who we are
Petrolina (Holdings) Public Ltd is a public listed company in the Cyprus Stock Exchange (CSE), registered in the Republic of Cyprus under registration number ΗΕ1018 with a registered office and head offices at 1 Kilkis, 6015 Larnaca, Cyprus.
2. How we collect your personal data
We obtain your personal data mainly through the information you provide directly to us when registering on and using MyPetrolina or through information provided indirectly by you through your Device. Below is a list of ways in which we collect your personal data.
(a) Personal data collected directly from you. This is the information you give us initially by completing the registration form either on the App or on the Website or by corresponding with us (for example, by email or by phone) when you have a query, concern or wish to discuss any other matter connected to MyPetrolina. It additionally includes information you provide when you use the App Services or the Website Services such as when you redeem any points or stamps you have accumulated.
(b) Information we collect from your Device. Upon your registration on the App we will automatically collect some data in connection to your Device and/or stored on your Device.
3. What personal data we collect
We may process the following personal data about you:
- Identity Data including your full name, date of birth, gender and district of residence within the Republic of Cyprus.
- Contact Data such as your telephone number and e-mail address.
- Profile Data i.e. information that we obtain from your use of the App or Website. This includes details of the points or stamps you have collected per transaction, your accumulated points, transaction details such as the service station in which the transactions were made, date of the transaction, details of the amount of money spent on each transaction and how such money was spent e.g. on fuel, oil change etc. and details on how the stamps or points were redeemed.
- Technical Data including your internet protocol (IP) address, your login information, your browser type and version (when using the Website Services), your time zone setting and location and your operating system and platform.
- Device Data including the type of mobile device you use, a unique device identifier (for example, your Device’s IMEI number, the MAC address of the Device’s wireless network interface or the mobile phone number used by the Device), mobile network information, your mobile operating system and the type of mobile browser you use.
- Location Data i.e. your location coordinates when you have selected to search for Petrolina service stations which are close to your real-time location.
- Marketing and Communications Data including your preferences in the way you wish to receive marketing from us (i.e. whether you wish to receive such marketing through email, SMS or push notifications).
- Records of any correspondence and/or communications we have with you.
We do not collect any sensitive data about you nor do we collect information about criminal convictions and offences.
Where we ask you to provide us with certain personal data on the registration form (in the fields which we indicate as mandatory) and you fail to provide such data, you will not be able to complete the registration and we will therefore be unable to provide you with the App Services and/or the Website Services.
Recording: To help keep you and our business interests safe, we may record details of your interactions with us. We may keep track of conversations you have with us including phone calls and emails. We may use these recordings to assess, analyse, and improve our App Services and our Website Services, train our people, manage risk or to prevent and detect fraud and other crimes.
4. Why we need your personal data
4.1 Personal data
We shall process and use your information where we have your consent, or we have lawful reason for using it subject to applicable law. Most commonly, we will use your personal data in the following circumstances:
When you register as a new member of MyPetrolina and agree to the Terms and Conditions, we will process your personal data in order to:
- provide you with the App Services and/or Website Services (as applicable), including enabling you to collect points and stamps, participate in our draws, redeem your points and stamps and receive the products you have selected to purchase through MyPetrolina.
- ensure the proper operation of MyPetrolina and manage our relationship with you in accordance with the Terms and Conditions, including notifying you of changes to the App, Website, App Services or Website Services (including changes to this Statement and/or the Terms and Conditions), delivering products or prizes to you and liaising with you in order to resolve any issues or concerns you may have.
We will process your data when we are required to comply with certain legal and regulatory obligations which may involve the processing of personal data (e.g. pursuant to tax or consumer law).
We may process your personal data pursuant to our legitimate interests, provided your interests and fundamental rights are not overridden by our interests. More specifically, we may process your personal data in order to:
- administer and protect our business, including the App and Website, and develop our services (including the App Services and the Website Services as well as MyPetrolina as a whole);
- manage the security of our network and information systems,
- identify, prevent and investigate fraud and manage our risk exposure,
- maintain our accounts and records,
- receive professional advice (e.g. tax or legal advice),
- defend, investigate or prosecute legal claims,
- demonstrate transparency in our draws through, among other things, publishing the winners’ names on our website and our social media pages.
- send you marketing communications with respect of MyPetrolina so that you are aware of new draws, additional products which you can purchase at a discount through the redemption of your points or stamps, new features of the App or Website and/or other information which may be of interest to you with respect to MyPetrolina. You can opt-out of receiving such information by adjusting your marketing options in the App or Website, by contacting us using the contact details in section 1 above or by following the opt-out links on any marketing message we send you.
We will ask for your consent in very limited circumstances. For example, if you are the selected winner of one of the draws, we may need to obtain your consent in order to be able to further promote our draws and MyPetrolina through, among other things, publishing your name, photograph and/or video footage of the prize receipt on our website, our social media pages and/or the media.
When you complete any of the optional fields we provide on our registration form in the App or Website, you give us your consent to use them for statistical analysis and in order to provide you with marketing which is more customised to your own preferences or characteristics. You can withdraw such consent by deleting such information from your account on the App or Website or by asking us to delete it for you by contacting us using the contact details in section 1 above.
5. With whom we may share your personal data
- Service providers we have chosen to support us in the effective provision or marketing of MyPetrolina to you by offering technological expertise, system administration services, solutions, and support;
- Professional advisers including lawyers, bankers, auditor and insurers who provide consultancy, banking, legal, insurance and accounting services;
- Tax authorities, regulators and other governmental bodies or agencies who may require reporting of our processing activities in certain circumstances; and
- Governmental and regulatory bodies, including law enforcement authorities in connection with enquiries, proceedings, or investigations by such parties.
Although we do not share any of your personal data with recipients located in third countries (i.e. countries outside the European Economic Area (EEA)), in case we ever do, we will require recipients in third countries to comply with European data protection standards and to provide appropriate safeguards in relation to the transfer of your data in accordance with GDPR.
6. Safeguarding your data
We use a range of administrative, technical, and technological measures to keep your information safe and secure both physically and electronically. We require our staff and any third parties who carry out any work on our behalf or at our premises or servers to comply with appropriate compliance standards including obligations to protect any information and applying appropriate measures for the use and transfer of information.
We additionally ensure that all service station owners participating in MyPetrolina have very limited access to your personal data and only as required in order to help us in the proper administration and operation of MyPetrolina.
How long we keep your personal data (retention)
We will retain all personal data collected about you in connection to MyPetrolina for a period of two years from the date of deletion of your account on MyPetrolina for any reason and/or from the date when you stopped using your account on MyPetrolina. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
In rare circumstances, such as for example in anticipated or ongoing litigation proceedings, we may retain your personal data for longer than the two-year retention period.
7. Your rights
You have the following rights in terms of the personal data and information we hold about you:
- Receive access to your personal data. This enables you to receive a copy of the personal data we hold about you and to be informed on how we are lawfully processing it.
- Request correction (rectification) of the personal data we hold about you. This enables you to have any incomplete, inaccurate, or out of date information we hold about you corrected.
- Request erasure of your personal data. This enables you to ask us to erase or remove your personal data where there is no good reason for us continuing to process it. This may be the case for example when you wish to delete your account. However, we may continue to retain your information if we are entitled or required to retain it under applicable law or if there is legitimate interest (e.g. there is a claim against you or Petrolina).
- Object to processing of your personal data where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground. In such a case, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interest, rights, and freedoms.
- Request the restriction of processing of your personal data. This enables you to ask us to restrict the processing of your personal data if:
- it is not accurate;
- it has been used unlawfully but you do not want us to delete it;
- it is not relevant anymore, but you want us to keep it for use in possible legal claims concerning you;
- you have already asked us to stop using your personal data, but you are waiting for us to confirm if we have legitimate grounds to use your data.
- Request to receive a copy of the personal data concerning you in a format that can be easily re-used or request the transfer of such data to other organisations.
- Withdraw the consent you gave us regarding the processing of your personal data for certain purposes, such as to allow us to promote our products and services to you.
In certain cases, we may not be able to satisfy your request. If it is legally permitted, we will let you know in due course why we could not satisfy it. We endeavour to address all requests promptly. Should you not be satisfied with the way we have responded to your concerns you have the right to submit a complaint to us (please refer to Section 10. Right to complain).
Accuracy of personal data information: We endeavour to keep personal data collected as accurate, complete, and current taking into consideration the purposes for which it was collected and is being used.
We rely on you to maintain the accuracy and completeness of the personal data provided by you and so you should inform us if your personal details change. You can do this yourself by changing your personal data on the App or on the Website.
8. Right to complain
You also have the right to complain to the Office of the Commissioner for Personal Data Protection. You can visit their website at https://www.dataprotection.gov.cy.
10. Automated Decision Making
We do not use automated decision making as such is defined in the GDPR. Automated decision making means a decision that produces legal effects concerning you or which significantly affects you and which is based solely on automated processing of data (i.e. no human intervention in the process).