ZEEKR APP PRIVACY POLICY

Last updated: 6th November 2023

What does this policy cover?

This policy describes how Zeekr EU B.V. (also referred to as "Zeekr", "we" or "us") will make use of your data when you interact with us, the Zeekr mobile applications (the "Zeekr App"), and the connected services provided by us in the Zeekr App ("Services").

It also describes your data protection rights, including the right to object to some of the processing which Zeekr carries out. More information about your rights, and how to exercise them, is set out in the "Your choices and rights" section.

For more information about the services provided in the Zeekr App, please read the respective service description in our App Terms of Use.

Personal data we may collect about you

Where we refer to personal data below, we mean any information relating to an identified or identifiable living person.

Depending on your use of the Zeekr App, we collect and process personal data about you as follows:

CategoryDetails
Registration Information
Your name, email address, country/state, language preference, register device (e.g. brand and type), register time, verification PIN code
Phone Device Information
Hardware model, operating system and version, device identifier, IP address, mobile network data
User Center Information
Your profile name, profile photo and profile introduction
Order Information
Your purchase details including first name, last name, email address, phone number, address, invoicing information, vehicle model
Payment Information
Confirmation from our third party payment providers in relation to the payment status of your order (including the refund of your deposit), bank account number
Financial Service Information
Car configuration and car price, first name, last name, email address, phone number, financing request details (including order number, initial down payment, financing duration/number of instalments, balloon/final payment, included mileage in km per year)
Car Preference Information
First name, last name, email address, address, preferred car series, preferred car model, preferred purchasing date, preferred purchasing method
Car Information
Car licence plate number, Vehicle Identification Number (VIN) and car mileage
Vehicle Sharing Information
Guest user's ID, guest user's name, guest user's phone, guest users' photo
Settings and Login Information
Your email address, password, login/logout, account information, country/state, language preference, notification settings, permission settings
Discover Information
Your likes for articles, your article sharing records
Remote Park Assist Information
Your User-ID, your vehicle identification number, car status, gear status
Vehicle Control Information
Your vehicle identification number, vehicle registration number, odometer information, SIM ID, time and date, vehicle status information (e.g. information on vehicle engine and gear status, battery, distance to empty information, smart key status information, lights, tire status information, heating, ventilation and air conditioning status information, brake and engine oil status)
Location Information
Your GPS location and the GPS location of your vehicle
Navigation Information
Your GPS data, search keywords, your location data and location of the vehicle, speed, time, waypoint information, vehicle identification number, vehicle registration number, SIM card, smartphone language preference, address, weather push data
Vehicle Management Information
Your User-ID, email, phone, vehicle identification number
Safety Information
Your car location, status of different parts of your car
Analytics and Behavioural Information
Your interaction with us and your usage of our Zeekr App including content viewed and which parts of the Zeekr App that are clicked on and consent choices
Virtual Identity and Authentication Information
Account number, digital certificate and related verification code, dynamic password, IP address
Appointment Information
First name, last name, email address, phone number, showroom / store location, appointment time
Test Drive Information
If provided by you: your driving history / experience, your postcode, country, test drive address, preferred car model
Maintenance Information
Your remark, indicated failure type, requested after-sale service; vehicle identification number, contact address.If provided by you: Images or videos you submit to us for us to understand the vehicle's current condition or your request
Calendar Information
When signing in to synchronize Google or Outlook account calendars, the following data will be collected: Event titles, description, attendees’ names and email addresses, event location data, event dates and times.

How do we use this information, and what is the legal basis for this use?

We will only use your personal data for the legal bases and purposes set out below:

Purposes for which your personal data are processedLegal basis of the processing (and legitimate interests pursued, if applicable) applicable) Categories of recipients of your personal data
Registration Information, Phone Device Information, User Center Information, Settings and Login Information to register and create an account on our Zeekr App, to connect the end user's device (where the mobile application is installed) and the respective Zeekr vehicle, keep them synchronized, and provide you with services.
Performance of contract or in order to take steps at the request of the data subject prior to entering into a contract (GDPR Article 6(1)(b))
Our hosting providers and service providers enabling push notifications, and our customer relationship management service.
We will collect and use Order Information, Car Information, Car Preference Information, Payment Information in order to send you service communications and keep you informed about your order.
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers and service providers enabling push notifications, our e-commerce platform for orders and our customer relationship management service.
We will collect and use Order Information, Car Information, Appointment Information, Maintenance Information and Payment Information to fulfil your request for products and services (including repair and maintenance services).
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers and service providers enabling push notifications, our e-commerce platform for orders and our customer relationship management service.Payment providers in relation to pay the orders.Our Zeekr group companies assisting with car repair and maintenance including fault diagnostics.
We will collect and use your Payment Information to help proceed with your order or request for a deposit refund, an order refund, and monthly payments.
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers.Payment providers in relation to pay the orders.
We will collect and use your Financial Service Information to help proceed with your request for a car loan or car leasing.
Necessary in order to take steps at your request prior to entering into our contract with you (GDPR Article 6(1)(b)) or if we do not enter into a contract with you our legitimate interest in offering you financing options of third parties at your request (GDPR Article 6(1)(f))
Our hosting providers.Third party financial service providers enabling car loans and car leasing at your request.
Discover Information to provide you the discover features (e.g. news and tips including content detail, like and forward) in the Zeekr App.
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers.
Phone Device Information, Remote Park Assist Information, Vehicle Control Information and Location Information to inform you of the status of your Zeekr vehicle through the Zeekr App. Such functions may include remote parking assistance status, distance to empty status information (which tell you approximately how many miles your Zeekr vehicle has left before it needs to be charged), vehicle notifications, [quick controls for doors, windows, trunk, lock].
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers and service providers enabling location determination and push notifications.
Phone Device Information, Vehicle Control Information and Location Information to enable you to control certain vehicle functions externally and remotely outside your Zeekr vehicle (e.g. locking/unlocking, opening/closing the charging cover and the windows, control the car climate functions, checking the tire pressure and activating the sentinel mode, trunk horn and flash).
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers and service providers enabling location determination and push notifications.
Phone Device Information, Location Information, Navigation Information to enable you to see you and your current car position on the map display, to use vehicle navigation (including last mile navigation on your smartphone after you have parked your car), and geofencing in your Zeekr vehicle.
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers and service providers enabling location determination, navigation and push notifications.
Vehicle Management Information to enable the download and installation of software in order to implement new functions and conduct fault correction (Over-the-Air software updates) and to [check the vehicle list under users' account with VIN, and to set the vehicle name.]
Consent (GDPR Article 6(1)(a)) where such consent is required and obtained otherwise our legitimate interests (GDPR Article 6(1)(f)) (to analyse the effectiveness of our products improve them)
Our hosting providers.
Vehicle Management Information and Vehicle Sharing Information to share your vehicle with others.
Performance of contract (GDPR Article 6(1)(b) for the Vehicle Management Information and our legitimate interest (GDPR 6(1)(f)) for the Vehicle Sharing Information (our legitimate interest in providing the guest user with the shared vehicle upon your request)
Our hosting providers and our service providers enabling the vehicle sharing function.
Safety Information to enable your use of the sentinel mode which will send you a notification in your app if your car is detected to be damaged.
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers and service providers enabling push notifications.
Phone Device Information, Analytics and Behavioural Information, Vehicle Control Information, Location Information, Virtual Identity and Authentication Information to manage and operate and continuously enhance the performance and quality of our Zeekr App and the Services and to pursue legal rights or defend litigation.
Consent (GDPR Article 6(1)(a)) where such consent is required and obtained otherwise our legitimate interests (GDPR Article 6(1)(f)) (to operate our Zeekr App and improve the App's operation)
Our hosting providers and our service providers for App crash detection.
Registration Information, Phone Device Information, User Center Information, Settings and Login Information, Vehicle Control Information, Location Information, and Navigation Information when applicable law requires us to process personal data about you. This could be the case in the event of warranty matters, when we receive a mandatory order for disclosure of data from law enforcement agencies or courts, as well as ensuring our compliance with applicable tax, money laundering, criminal and financial law.
Legal obligation (GDPR Article 6(1)(c))
Our hosting providers.
Appointment Information and Maintenance Information to fulfil your request for products and services (including repair and maintenance services).
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers.
We will collect and use Test Drive Information and Appointment Information to confirm your reservation for a test drive appointment and provide you with further service information about your reservation.
Performance of contract (GDPR Article 6(1)(b))
Our hosting providers.
When using the Calendar and Meeting Apps, we will collect Calendar Information, including appointments, meetings, and reminders, to provide you with scheduling and productivity features, and your contacts to show the participants in your events/meetings
Consent (GDPR Article 6(1)(a)) where such consent is required and obtained, and which can be withdrawn at any time
Our hosting providers and other calendar/meetings services providers based on your own choices (ex. Google for Google Calendar/Google Meet, Microsoft for your Microsoft calendar/Teams).
When using the Virtual Guide App, we will collect your Location Information and your Virtual Identity and Authentication Information to present information about nearby places and areas.
Performance of contract (GDPR Article 6(1)(b)) and consent (GDPR Article 6(1)(a)) where such consent is required and obtained, and which can be withdrawn at any time.
Our hosting providers and our services providers for Virtual Guide App (HERE Technologies).

For Location Information and Navigation Information the third-party data recipients are:

  • -

    Google LLC for the Google Maps location SDK to locate you and your vehicle when you use our app on Android in context of vehicle remote control features. You can find more information about how Google LLC processes your personal data here: https://policies.google.com/privacy?hl=en

  • -

    Apple Inc. for the Apple Location Services to locate you and your vehicle when you use our app on iOS in context of vehicle remote control features. You can find more information about how Apple Inc. processes your personal data here: https://www.apple.com/legal/privacy/data/en/location-services/

  • -

    Here Europe B.V. for the Here Map SDK to locate you and your vehicle when you use our app on Android or iOS in context of navigation. You can find more information about how Here Global B.V. processes your personal data here: https://legal.here.com/en-gb/privacy

For Calendar and Meetings App the third-parties recipients are:

  • -

    Google LLC for Google Calendar and/or Google Meet to connect your Google account and facilitate the use of Google Meet. You can find more information about how Google LLC processes your personal data here: https://policies.google.com/privacy?hl=en

  • -

    Microsoft for Outlook Calendar and/or Microsoft Teams to connect your Microsoft account and facilitate the use of Teams. You can find more information about how Microsoft processes your personal data here: https://learn.microsoft.com/en-us/microsoftteams/teams-privacy

There are instances where we have a legitimate interest to use your data. Our legitimate interest will vary depending on what we are using your data for, and we explain above what the interest is and how it relates to the processing operations that we are carrying out. Where we process personal data on the basis of a legitimate interest, then – as required by data protection law – we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals' interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of the policy.

Where we transfer your personal data

Personal data that we collect from you may be transferred to and stored at a destination outside the EU/EEA. Due to the global nature of our business, your personal data will be disclosed to service providers outside of the EU and the EEA, in particular to USA, including for assisting us with services such as hosting and maintenance of the mobile applications, enabling location determination, navigation, push notifications and App crash detection. Where these locations do not provide an adequate level of data protection, we ensure appropriate safeguards are in place to protect the transfer of your personal data to these countries, in particular by using the EU Standard Contractual Clauses (SSC) adopted by the European Commission, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.

CategoryMechanismCountry
Phone Device Information, Location Information, Analytics and Behavioural Information
Adequacy Decision (EU-US Data Privacy Framework (available at https://commission.europa.eu/system/files/2023-07/Adequacy%20decision%20EU-US%20Data%20Privacy%20Framework_en.pdf)) and EU Standard Contractual Clauses (SCC)
USA
Maintenance Information
EU Standard Contractual Clauses (SCC)
China

Your choices and rights

You have the following rights:

RightSummary
The right to information
Enables you to receive information regarding whether we are processing your personal data
The right of access
Enables you to receive a copy of your personal data
The right to rectification
Enables you to correct any inaccurate or incomplete personal data we hold about you
The right to erasure
Enables you to ask us to delete your personal data in certain circumstances
The right to restrict processing
Enables you to ask us to halt the processing of your personal data in certain circumstances
The right to object
Enables you to object to us processing your personal data on the basis of our legitimate interests (or those of a third party), including processing for direct marketing purposes - your objection will be upheld, and we will cease processing your personal data, unless the processing is based on compelling legitimate grounds or is needed for the exercise or defence of legal claims that may be brought by or against us
The right to data portability
Enables you to request us to transmit personal data that you have provided to us, to a third party without hindrance, or to give you a copy of it so that you can transmit it to a third party, where technically feasible

These rights may be limited, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.

If you wish to exercise any of these rights, please contact us at the contact details set out below.

Wherever we rely on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. We may however have other legal grounds for processing your data for other purposes, such as those set out above.

In some cases, we are able to send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing, at any time. You can do this by following the instructions in the communication where this is an electronic message, or by contacting us using the details set out below.

If you have unresolved concerns, you have the right to lodge a complaint to a data protection authority in the country that you reside in or, the country of your place of work or the country where the alleged infringement took place. A list of data protection authorities in the EU/EEA is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en#memberhere. For non-EU countries, please refer to the website of your local data protection authority.

Security

We protect your personal data from loss, misuse, disclosure, alteration, unavailability, unauthorised access and destruction and maintain the confidentiality of your personal data. This is also ensured using appropriate technical and organisational measures. We choose our security measures taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons and continuously improve them.

How long we retain your personal data

We only maintain the personal data we collect for as long as it is necessary for us to provide our services, for as long as it is required to fulfil the purposes of the processing of personal data, or as required by law.

Where we process personal data for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data so that we can respect your request in future.

Updates to this privacy policy

We reserve the right to update this Privacy Policy at any time, and we will provide you with a new Privacy Policy when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal information.

Contact us

The data controller for your personal data is Zeekr EU B.V., corporate registration number 88529789, with address Jachthavenweg 112, 1081 KJ Amsterdam, the Netherlands.

If you have questions about this Privacy Policy or wish to contact us for any reason in relation to our personal data processing, please contact our data protection officer at dataprivacy@zeekr.eu.