We welcome your interest in our platform and would like to make your visit as enjoyable as possible. The operator and controller for the processing of your personal data through this platform is:
- MAHLE SMARTBIKE SYSTEMS S.L.U. (onwards, MAHLE SMARTBIKE SYSTEMS)
- CIF: B34273367
- Address: C / De Los Orfebres, 10, Palencia, 34004, Palencia, (España)
- Phone: (+34) 810 101 201
Together with an easy, efficient operability, we consider the protection of your personal data to be a top priority. The protection of your privacy is a key concern for us when processing personal data and we take this into account in all our business processes.
Therefore, our processing of personal data collected during a visit to our platform always takes place in line with the respective provisions governing data protection.
This data protection statement will let you know which of your personal data are collected and retained when you visit our platform or use our services offered through the platform. You will also receive information on how and on what legal basis your data are used, your rights regarding the use of your data, and which contact methods are available for you.
Definitions used in this Policy
Personal Data: any information related to an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not it is done by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Platform: platform means the web application (https://www.ebikemotion.com/app/login.php) and the mobile application (app) of MAHLE SMARTBIKE SYSTEMS.
User: the natural person (data subject) who registers on the platform and uses its services, regardless of whether or not he/she associates an electric bicycle.
Mobile App: MAHLE SMARTBIKE SYSTEMS’s application for mobile devices, in its version for iOS or Android.
Web application: MAHLE SMARTBIKE SYSTEMS’s application, intended to be executed in Internet browsers through the address https://www.ebikemotion.com/app/login.php
Route (or activity): when a user activates the start of an activity in the mobile app, the route recording will begin, including departure point, arrival point, route, and other information associated with the route (meteorology, geography, difficulty, etc.).
ebike: abbreviation of electric bicycle (electric bike).
1. Group’s Data Protection Officer contact
Dr. Alexander Deicke
Kaffeeberg 11, 71634, Ludwigsburg, Germany
Tel: +49 (0) 7141-9475320
2. What personal data do we process?
We process personal data to provide services and activities through our platform.
We might collect various types of personal data about the user, and personal characteristics directly associated with the user, including: name, surname, email, sex, weight, height, age, geolocation, kilometres travelled, images, heart rate or calories consumed.
[In the case of heart rate, it requires a specific device in addition to the mobile app to measure these characteristics (such as a smart watch or a heart rate monitor, linked to the mobile app that transmits the information)].
The data referred to the geolocation refer exclusively to the routes that the user decides to voluntarily upload to the platform, and the last connection point of the electric bicycle.
Other types of data collected on the platform are: IP-address, access date and URL. For the optimization of our platform, we also collect the device information: id_push, device_id, type, model, brand, carrier and user_agent (the last one is a summary with various information, as platform or app version, for example).
We can also collect technical data related to the electric bicycle usage, such as: electric consumption, pedalling cadences, time of use, and average speeds.
To use our platform, a valid email address and a user-specific password are the only mandatory data.
Information about cookies is specifically described in the Cookies policy.
2.1. Purpose of collecting/processing data
We process personal data for different purposes, but always related with the use of the platform:
- Identify the user on the platform: Identification is made through your email, submitted in the initial registration.
- Manage user profile: from "My Profile" menu, the users can update their data, add new additional information such as weight, height or age, or delete them. They can also delete their user account.
- My electric bicycles ("My ebikes" menu): the user can select his ebike model and check a summary of his bike status and specific data, such as the date of manufacture or the activation and sale (in the store) moments.
- Activities recording: the users can voluntarily record their activities on the platform, activating the activity recording system before starting a route, and deactivating the system once it has been completed. When recording an activity, the following data, related to the user's route, will be processed: name of the activity, difficulty, date of completion, total time spent on the route, distance travelled, type of activity, type of terrain, visibility and rating or route score. The route details are completed with the following data: altimetry (maximum and minimum levels and gradient %), pedalling speeds and cadences, meteorology (temperature, humidity, wind), caloric expenditure and heart rate and maximum pulsations (only if a specific device is linked to the app). An activity or route can be shared by the user in different ways, from the "Activities" menu. A route is shared, by default, as private:
- Private activity: only visible by the user (owner of the account).
- Public activity: visible by all users of the platform worldwide.
- My friends' activity: visible only to certain users of the platform with which the owner user has decided to share via the Facebook® friendship link. It is a personalized visibility only for Facebook® friends who are also registered on the MAHLE SMARTBIKE SYSTEMS platform.
- Image gallery: The users can voluntarily upload images for two purposes:
The only objective of this functionality is to know the characteristics of the route, helping to a better understanding of the terrain, its difficulty and its geography, in general.
- Avatar image, for their user profile.
- Images of activities, in order to expand the textual description of an activity or route, it is possible to add visual information about it.
- Events: The users can create events from the "Create Events" menu to organize routes in their calendar, describing the type of activity to be programmed. Events can be shared in the same way as the "Activity Log" (private, public or for my friends).
- Documentation: the users can consult at any time guides about the platform (web or app), as well as technical manuals of use and about different components. In this section the latest versions of the documents will be available and we will be able to notify the users about the updates that take place in order to keep them informed about new functional features on the platform, as well as on electric bicycles and their associated devices or components.
- Electronic communications: the users can receive electronic communications (via email) from MAHLE SMARTBIKE SYSTEMS to keep them informed about their products and services, related to electric bicycles and their electronic components.
- Alert mode: the alert mode can be activated by the user. The alert mode is to be activated if the electric bicycle is stolen, so the users can receive emails warning them about the activation of their ebike, in order to perform the actions deemed convenient. Personal information will not be displayed.
2.2 Change of purpose
Your personal data will only be processed for purposes other than those described insofar as this is permitted by law, or if you have consented to a change of data processing purpose. In the case of data being processed for purposes other than those for which they were originally collected, we shall inform you of this different purpose prior to the processing, and shall provide you with all relevant information.
3. With what legitimation do we process personal data?
We process personal data under the following legitimate basis:
- Execution of a contract, understood as such the use of the platform (via web or via app) that is subject to Service Agreements, whose content regulates the access, use, rights and responsibilities of the services we offer. This legitimate basis groups all the purposes described in point 2.1 that do not depend on the user's consent.
The legal basis for data processing is Art. 6 I b) GDPR.
- The user’s vital interest. This legitimate basis applies to exceptional or emergency treatments.
The legal basis for data processing is Art. 6 I d) GDPR
- Consent of the user. In certain situations in which it is not possible to legitimize the data processing with the necessary use of the services of the platform, or with the necessity to take care of the safety and integrity of the users, we will request a specific and informed consent to the user to authorize processing. Any consent granted by the user may be withdrawn in “my profile” on the platform, or by contacting MAHLE SMARTBIKE SYSTEMS, e.g. through the email address indicated in point 6.1. The withdrawal of the consent does not affect the lawfulness of processing based on consent before its withdrawal.
The legal basis for data processing is Art. 6 I a) GDPR.
- Legitimate interest. There is a relevant and appropriate relationship between MAHLE SMARTBIKE SYSTEMS and the user, in which the latter uses the services of MAHLE SMARTBIKE SYSTEMS as a registered user through the platform. This legitimate basis applies to the processing of electronic communications, although it is also legitimated by the application of article 21 of Law 34/2002, of July 11, on services of the information society and electronic commerce.
The legal basis for data processing is Art. 6 I f) GDPR
- Legal obligations, processing is necessary for compliance with legal obligations to which the controller is subject (courts and other judicial authorities or law-enforcement authorities).
The legal basis for data processing is Art. 6 I c) GDPR
4. Disclosure of data to third parties / recipients of data
To fulfil the purposes mentioned in point 2.1, we share your personal data with:
- Service providers performing services on our behalf, and executing the necessary processes for the maintenance of the platform. In this sense, we work with AMAZON WEB SERVICES EMEA SARL: https://aws.amazon.com/legal/aws-emea/, with whom we have signed a contract of access to personal data, in accordance with current data protection regulations. We rely on contractually bound third-party companies and external service providers (“processors”) to supply our range of products and services. In such cases, personal data is disclosed to these processors to enable further processing thereof. These processors are carefully selected and regularly checked to ensure that your privacy remains protected. The processors may only process the data for the specified purposes, and they are also contractually obliged to process your data in compliance with this data protection statement and applicable data protection laws. Data is disclosed to processors on the basis of Article 28(1) GDPR, alternatively on the basis of our legitimate interest in the economic and technical benefits provided by the use of specialized processors, and based on the fact that your rights and interests in protecting your personal data are not overridden, point (f) of Article 6(1) GDPR. If necessary, we will obtain your consent to disclose your personal data to processors, in which case the legal basis is based in point (a) of Article 6(1) GDPR.
- Users of the platform, only with the consent of the user, who can share routes and activities in a public or personalized way, as described in point 2.1.
- Brand users, brand users can be either points of sale (shops) or brand distributors of MAHLE SMARTBIKE SYSTEMS products that, with the consent of the user (via a pop-up notice in which the user will accept or decline that communication of the data), will have access to their identifying data (user name, email, brand of electric bicycle and technical data extracted from the activities of the routes carried out), so the brand user can offer personalized services and products of interest to these users who have authorized the transfer of their data.
- Judicial authorities, state agencies, law enforcement agencies or public bodies, if we are required in compliance with legal obligations.
4.1. Additional information on data disclosures
The data disclosures of point 4 can be required by:
- Service providers performing services on our behalf, which execute the necessary processes for the maintenance of the platform. It is a necessary requirement for the operation of the platform and for it to be operative for the user. If the users do not provide their information, they will not be able to use any service of the platform.
- Users of the platform and brand users. It is a voluntary requirement to the users, who are not required to provide the data for this disclosure if they do not wish to do so.
- Judicial authorities, state agencies, security forces and bodies or public bodies. It is a legal requirement to comply with public duties, requirements or court orders or legal mandates. In these cases, MAHLE SMARTBIKE SYSTEMS cannot deny the disclosure of the data, as that would not comply with current legislation.
4.2. International Personal Data Transfers
We inform that there are no international transfers of personal data outside the European Economic Area.
5. How long do we keep personal data?
We will keep personal data: (i) during the necessary time to fulfil the purpose for which they were collected and to determine the possible liabilities that may derive from said purpose and the processing of data, in accordance with the applicable regulations that are applicable to MAHLE SMARTBIKE SYSTEMS in Spain; (ii) when point (i) does not apply, the maximum storage period for the data of a user requesting the cancellation of his account will be 6 months.
In the event of a user maintaining an active account without access for one year, MAHLE SMARTBIKE SYSTEMS will proceed to delete the personal data associated with such account.
6. What are your rights and how can you exercise them?
In accordance with the General Data Protection Regulation (GDPR), you, as a data subject, can exercise the following rights:
- Right of ACCESS: "What data do you have about me, what are they used for and with whom do you share them?" You can obtain information related to the processing of your personal data and a copy of such personal data. (Art. 15 GDPR)
- Right of RECTIFICATION: "I want to rectify or modify my data" If you consider that your personal data are inaccurate or incomplete, you can request the modification of such personal data. (Art. 16 GDPR)
- Right of ERASURE: "I want to delete my data" You may require the deletion of your personal data, under certain circumstances. (Art. 17 GDPR)
- Right of PROCESSING LIMITATION: "I want to limit the extent of processing" You can request the limitation of the processing of your personal data, under certain circumstances. The limitation is the marking of stored personal data in order to limit their processing in the future. (Art. 18 GDPR)
- Right of OBJECTION: "I do not want my data to be used for a specific purpose" You can object to one (or several) specific processing of your personal data, for reasons related to your particular situation. (Art. 21 GDPR)
- Right of PORTABILITY: "Return my data or give them to a third party" Under certain circumstances, you have the right to recover the personal data you have given us or, when technically possible, to transmit them to a third party with your authorization. (Art. 20 GDPR)
- Right of not being subject of automated individual decisions: "Stop shaping me and making decisions automatically" This is to ensure that you are not subject to a decision based solely on the processing of your data, including profiling, that produces legal effects on you or significantly affects you in a similar way.
You also have the right to withdraw the provided declaration of consent regarding data protection at any time, with immediate effect. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
If more information is needed or in order to exercise the aforementioned rights, please contact us
Please note that access can only be granted if you provide, in full: your first name and surname, your current and, if necessary, previous address, your date of birth, and your email address. This information is used exclusively for correlation purposes, which in turn ensures that no unauthorized third party can obtain your personal data. Any product, operation, and/or contract numbers which we might have sent to you are also useful and helpful, but not necessary, in enabling us to identify the relevant data quicker.
The maximum response time will be 30 days from receipt.
6.1 Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedies, you shall have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement, if you are of the opinion that the processing of your personal data infringes the applicable data protection law. The competent supervisory authority in our case is the Spanish Data Protection Agency.
7. About automated decisions or profiling
Currently, MAHLE SMARTBIKE SYSTEMS does not use computer algorithms to make automated decisions producing legal effects on users, nor do we develop individual profiles following a programmed logic with consequences for users.
9. Can minors register?
10. Cookies information and social networks