1. Scope
This privacy policy explains how personal data is processed when you visit and use mgautotech.de, including its associated publicly accessible pages.
Independently operated platforms or subdomains with their own privacy policy are governed by the privacy notices published there. This applies in particular to the File Service platform at file.mgautotech.de.
Where this website incorporates external services, widgets or links, these are explained separately below.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
MG AutoTech
Owner: Melih Gökkaya
Böckinger Str. 32
70437 Stuttgart
Germany
Telephone / WhatsApp: +49 151 51561670
Email: [email protected]
Privacy enquiries may be sent to the email address above with the subject “Data protection”.
3. General information and legal bases
Personal data means any information relating to an identified or identifiable natural person. This includes, in particular, names, contact details, IP addresses, communication content, and vehicle and order details where these can be linked to a person.
We process personal data only where a lawful basis exists. The relevant legal bases include in particular:
- Article 6(1)(a) GDPR, where you have given us your consent;
- Article 6(1)(b) GDPR, where processing is necessary for a contract or to take steps before entering into a contract;
- Article 6(1)(c) GDPR, where we must comply with legal obligations;
- Article 6(1)(f) GDPR, where processing is necessary for our legitimate interests or those of a third party, unless your interests or fundamental rights override those interests.
Where information is stored on or read from your device, the German Telecommunications and Digital Services Data Protection Act (TDDDG), particularly section 25 TDDDG, also applies.
4. Website delivery and server log files
When you access our website, the web server or our hosting provider processes the connection and access data technically required to deliver it.
This may include the following data in particular:
- IP address of the accessing device;
- date and time of access;
- page or file requested;
- volume of data transferred;
- HTTP status code;
- previously visited page or referrer URL;
- browser type and version;
- operating system;
- hostname of the accessing device;
- technical error and security information.
Processing is necessary to provide the website technically, deliver content correctly, identify faults, prevent attacks and misuse, and ensure the security of our systems.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable and cost-effective operation of our website and the prevention and investigation of misuse and security incidents.
Server log data is deleted or anonymised once it is no longer needed for these purposes. It may be retained longer if a specific security incident must be investigated or statutory evidence or retention obligations apply.
5. TLS/SSL encryption
Our website is transmitted in encrypted form over HTTPS. Encryption is intended to prevent unauthorised third parties from reading or altering data during transmission.
An encrypted connection can be identified in particular by “https” in your browser’s address bar.
6. Cookies, local storage and consent management
Our website may use cookies and comparable technologies such as local browser storage. Cookies are small pieces of information that can be stored on your device or read during a later page visit.
Technically necessary technologies may be used in particular to:
- store your privacy and consent settings;
- provide website functions you have expressly requested;
- store language preferences;
- enable security functions;
- ensure the website displays correctly.
Technically necessary technologies are used on the basis of section 25(2) TDDDG. Subsequent processing of personal data is based, where applicable, on Article 6(1)(c) or (f) GDPR.
Non-essential technologies, particularly those for external media, statistics or marketing, are activated only after you have agreed through our consent management system. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR.
To document your choice, the following information may be processed in particular:
- consents granted or refused;
- date and time of the choice;
- version of the consent information displayed;
- technical consent identifier;
- technically necessary browser or device information.
This record demonstrates that valid consent was obtained or that your refusal was respected.
You can change your choice at any time using “Manage consent” or withdraw consent with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before it.
The specific services, categories, purposes and retention periods are also displayed in the consent management system.
7. Contact by email or telephone
If you contact us by email or telephone, we process the data you provide to deal with your enquiry.
The data processed may include in particular:
- name and, where applicable, business name;
- telephone number and email address;
- content and time of your enquiry;
- vehicle model, engine and year of manufacture;
- vehicle identification number or registration number, if you provide it;
- fault codes and diagnostic information;
- photos, videos or technical files;
- work requested and service enquiries;
- appointment, quotation and order information.
Where the communication concerns entering into or performing a contract, processing is based on Article 6(1)(b) GDPR.
For general enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is in handling incoming enquiries properly, traceably and cost-effectively.
Data is deleted once the enquiry has been fully dealt with and there are no contractual, statutory or evidence-preservation reasons for further retention.
8. Contact via WhatsApp
Our website provides links for contacting us via WhatsApp. A connection to WhatsApp is generally established only when you click the relevant link or open WhatsApp yourself.
The provider for users in the European Economic Area is:
WhatsApp Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland
If you contact us via WhatsApp, the following data may be processed in particular:
- your mobile number;
- the name you use on WhatsApp and, where applicable, your profile picture;
- date and time of communication;
- message content;
- voice, image, video and file attachments;
- technical communication and connection data;
- vehicle, diagnostic and order data you provide.
MG AutoTech processes this data to deal with your enquiry. The legal basis is Article 6(1)(b) GDPR where your message concerns entering into or performing a contract. Other enquiries are processed on the basis of Article 6(1)(f) GDPR.
WhatsApp also processes data as an independent controller under its own privacy policy. Processing by companies in the Meta group and in countries outside the European Economic Area cannot be ruled out.
Using WhatsApp is voluntary. You can alternatively contact us by email or telephone. For particularly confidential documents or large technical files, an appropriate transfer method should be agreed in advance.
Your WhatsApp contact details are used for advertising only where a separate legal basis or appropriate consent exists.
WhatsApp messages are deleted when no longer needed for handling and documentation. Messages relevant to contracts or billing may be archived for the statutory retention periods.
9. Customer, vehicle, diagnostic and order data
In connection with service enquiries, quotations, appointments, diagnostics, coding, chiptuning, control-unit work, ECU/TCU files and other vehicle software services, we may process the following data in particular:
- customer and contact details;
- business, workshop and contact-person details;
- invoicing and payment information;
- vehicle manufacturer, model, type, year of manufacture and engine;
- vehicle identification number, registration number and mileage, where necessary;
- control-unit, hardware and software identifiers;
- fault codes, measurements and diagnostic information;
- original files, backups and modified files;
- photos and videos of the vehicle or individual components;
- details of modifications, technical problems and requested work;
- quotation, appointment, order, billing and statutory warranty data;
- communication and handling notes.
The data is processed to:
- review technical enquiries;
- assess whether a service is feasible;
- prepare quotations;
- manage appointments and orders;
- provide the agreed services;
- document original states and backups;
- handle follow-up questions and support;
- review statutory warranty and liability cases;
- meet payment and accounting obligations;
- establish, exercise or defend legal claims.
The legal bases are Article 6(1)(b) GDPR for pre-contractual steps and contract performance, Article 6(1)(c) GDPR for legal obligations, and Article 6(1)(f) GDPR for documentation, quality assurance, IT security and the defence of legal claims.
Vehicle and control-unit data generally comes from you, from the vehicle or control unit supplied by you or your client, or from a workshop or business partner you have instructed.
Business customers, workshops and other clients may provide personal data relating to their customers, vehicle keepers, employees or contacts only where a sufficient legal basis exists. Only data needed for the relevant order should be provided.
Technical files are generally treated as confidential and made accessible only to internal or external parties whose involvement is necessary for the relevant order.
10. Vehicle and project photos, gallery and customer feedback
During our work, we may take vehicle, component and project photos, or customers may provide them to us.
Images are published on our website only if:
- they no longer relate to an identifiable person, particularly because registration numbers, vehicle identification numbers, people and other identifying features cannot be recognised; or
- there is a sufficient legal basis or the data subject has consented.
Where publication is based on consent, the legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.
Anonymised images that cannot be linked to a person or a particular vehicle keeper no longer involve the processing of personal data.
Following a valid withdrawal, we remove the relevant publication from our own systems unless another legal basis applies. Copies already stored by search engines, internet archives or third parties may be beyond our direct control.
11. Bensky tuning database / vehicle-selection widget
We embed an external tuning database and vehicle search on our website as an iframe. The technical provider is:
Ben Sky Limited
5 Carrwood Park, Selby Road
Leeds, LS15 4LG
United Kingdom
Company registration number: 8348493
No connection to Bensky is established without your consent to the “External media” category. Only after you agree does your browser load content from portal.bensky.co.uk, in particular the vehicle-selection iframe and a technically necessary script that resizes it.
When connecting to Bensky, the following data may be sent to or processed by the provider in particular:
- IP address of the accessing device;
- date and time;
- page accessed and referring page, referrer or origin;
- browser, device, language and connection information;
- access, error and security information;
- your interactions with the tuning database;
- vehicle details you select, such as manufacturer, model, year of manufacture, engine or variant.
Bensky may set a session cookie called “PHPSESSID” to provide the widget technically. Depending on use, the embedded iframe may also reference content or functions from other providers, particularly Google reCAPTCHA, jsDelivr, cdnjs or ipapi.co. This may create further connections to those providers.
The integration provides interactive vehicle selection and displays available tuning data. The legal bases for loading the external content and the associated data processing are your consent under section 25(1) TDDDG and Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future through “Manage consent” or the cookie settings. After withdrawal, the Bensky iframe is removed from our website and will not load on subsequent visits unless you consent again.
Ben Sky Limited is based in the United Kingdom. Processing outside the European Economic Area therefore cannot be ruled out. We have only limited influence over further processing by Bensky and any services it incorporates.
Alternatively, you can provide your vehicle details through the contact channels listed on this website without using the Bensky tuning database.
12. Google reviews via review-widget.net
Our website may display publicly available Google reviews and an overall rating through an external review service.
The technical provider of the review widget used is:
SKAJ Ventures GmbH
Sonnenlandstraße 4
14471 Potsdam
Germany
Email: [email protected]
Loading the widget may establish a connection to the provider’s servers. In particular, the following technical data may be processed:
- IP address;
- browser type and version;
- page accessed;
- date and time;
- referrer information;
- technical error and connection data.
The widget is activated only after you have agreed through our consent management system. The legal basis for processing technical visitor data is Article 6(1)(a) GDPR. Where information is stored on or read from your device, section 25(1) TDDDG is an additional legal basis.
You may withdraw your consent at any time with effect for the future through “Manage consent”.
The reviews displayed may include the author’s publicly visible name, star rating, review text, publication date and public profile picture. The source of this data is MG AutoTech’s publicly accessible Google Business Profile.
Publicly submitted reviews are displayed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is in presenting customer experiences and the quality of our service transparently and authentically.
The technical widget provider is not affiliated with Google and is not a Google service. If you click a Google link within the widget, you leave our website. From that point, Google may process personal data under its own privacy policy.
13. External links
Our website may contain links to external websites and services, particularly WhatsApp, Google or our File Service platform.
With an ordinary external link, data is generally transmitted to the linked provider only when you click it. The external provider may then process your IP address, technical browser data, referrer information and other usage data in particular.
Processing on the external website is governed by that provider’s privacy policy. We generally have no influence over processing by external providers after you leave our website.
14. Recipients and categories of recipients
Within MG AutoTech, personal data is made available only to people who need it to perform the task concerned.
Depending on the processing operation, the following categories of recipients may receive data:
- hosting, cloud, database and IT service providers;
- email, telecommunications and business communication providers;
- providers of consent management and embedded widgets;
- technical service providers, specialist partners or subcontractors where necessary for a specific order;
- tax advisers, accountants and other professional advisers;
- banks and payment service providers;
- lawyers, insurers or experts;
- authorities, courts or other public bodies where a legal obligation exists.
Service providers processing personal data on our behalf are engaged under a data processing agreement pursuant to Article 28 GDPR where legally required.
Recipients who process data as independent controllers are themselves responsible for complying with statutory data protection requirements.
We do not sell personal data.
15. Transfers to third countries
When using certain service providers, it cannot be ruled out that personal data may be processed outside the European Union or European Economic Area, or accessed from there.
Transfers to a third country take place only in compliance with Article 44 et seq. GDPR, particularly on the basis of:
- an adequacy decision of the European Commission;
- the EU–US Data Privacy Framework, where the relevant US recipient holds valid certification;
- European Commission standard contractual clauses and, where appropriate, additional safeguards;
- binding corporate rules; or
- a statutory exception under Article 49 GDPR.
Despite contractual and technical safeguards, certain third countries may present a residual risk that state authorities can access data under local law and that European data-subject rights cannot be enforced to the same extent.
Information on the safeguards used in a particular case may be requested through the contact details above.
16. Retention periods
We retain personal data only for as long as it is needed for the relevant purpose or statutory retention obligations apply.
The following criteria apply in particular:
- Enquiry and communication data is deleted once fully dealt with, provided no contract is concluded and further retention is not required to preserve evidence or defend legal claims.
- Contract, order and service data is retained for the contractual relationship and then until the applicable statutory limitation and retention periods expire.
- Tax and business documents are generally subject to retention periods of six, eight or ten years depending on the document type. Accounting vouchers generally must be retained for eight years.
- Vehicle, diagnostic, original and backup files are retained for as long as necessary for service delivery, restoration, documentation, statutory warranty matters, support or the defence of legal claims.
- Server and security logs are deleted or anonymised once no longer needed for operation, security and the prevention of misuse.
- Consent records are retained for as long as necessary to demonstrate consent and defend against potential claims.
- Publicly displayed content is retained until the publication purpose no longer applies or consent is validly withdrawn, unless another legal basis exists.
Where a statutory retention obligation applies, access to the data concerned is generally restricted for that period and it is processed only for the purpose required by law.
17. Rights of data subjects
Subject to the statutory conditions, you have the following rights in particular:
- right of access under Article 15 GDPR;
- right to rectification under Article 16 GDPR;
- right to erasure under Article 17 GDPR;
- right to restriction of processing under Article 18 GDPR;
- right to data portability under Article 20 GDPR;
- right to object under Article 21 GDPR;
- right to withdraw consent under Article 7(3) GDPR;
- right to lodge a complaint with a data protection supervisory authority under Article 77 GDPR.
You can contact [email protected] to exercise your rights.
To protect personal data against unauthorised access, we may request appropriate proof of identity where there are reasonable doubts. We request only information needed to verify your identity.
18. Specific right to object under Article 21 GDPR
WHERE WE PROCESS PERSONAL DATA ON THE BASIS OF ARTICLE 6(1)(F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION.
WE WILL THEN STOP PROCESSING THE DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.
WHERE DATA IS PROCESSED FOR DIRECT MARKETING, YOU MAY OBJECT TO THAT PROCESSING AT ANY TIME WITHOUT GIVING REASONS.
19. Right to complain to the supervisory authority
You have the right to complain to a data protection supervisory authority. The authority responsible for MG AutoTech is in particular:
The State Commissioner for Data Protection
and Freedom of Information Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Postal address:
PO Box 10 29 32
70025 Stuttgart
Telephone: 0711 615541-0
Email: [email protected]
The right to complain is without prejudice to other administrative or judicial remedies.
20. Obligation to provide data
Simply visiting our website generally does not create a legal or contractual obligation to provide us with additional personal data.
However, certain data is necessary if you wish to request a quotation, technical assessment, appointment or service, or enter into a contract with us.
Without the contact, vehicle, diagnostic or billing data required for the relevant order, we may be unable to assess the enquiry or provide the requested service.
21. Automated decisions and profiling
We do not use decisions based solely on automated processing within the meaning of Article 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
The website functions currently in use do not automatically create personal usage or interest profiles.
22. Technical and organisational security measures
We use appropriate technical and organisational measures to protect personal data against loss, alteration, unauthorised disclosure and unauthorised access.
These may include in particular:
- encrypted data transmission;
- role- and permission-based access;
- access restrictions;
- secure passwords and authentication methods;
- regular updates;
- data backups;
- logging of security-related events;
- private or access-restricted file storage;
- data minimisation;
- organisational confidentiality requirements.
Measures are reviewed and adapted in line with the state of the art, the processing risk and the nature of the data processed.
Despite appropriate safeguards, completely risk-free data transmission or storage cannot be guaranteed.
23. Changes to this privacy policy
We may amend this privacy policy if legal requirements, our services, the technical systems used or our data-processing procedures change.
The current version published on this website applies.