Last updated on 02.10.2025
Autolevi collects the personal data of users of www.autolevi.ee website and other subdomains operated by Autolevi (“Platform”). The collection and use of personal data enables us to provide you with the services offered on the Platform, in particular to enable you to establish rental relationships with other users for the provision and use of rental vehicles, and to provide you with a better user experience on the Platform. Autolevi collects and processes personal data in accordance with this Privacy Policy (“Privacy Policy”) which explains, among other things, which types of personal data Autolevi collects, the purposes for which data is used and who has access to the personal data.
This Privacy Policy has been prepared and personal data shall be processed in compliance with the General Data Protection Regulation (EU) 2016/679 and the Personal Data Protection Act of the Republic of Estonia. Please read this Privacy Policy carefully as it contains, among other things, important information on your rights as a data subject.
Data Controller
For the purposes of applicable data protection legislation, the controller of your personal data is Autolevi OÜ, registry code 12547241, registered address Rotermanni 8, 10111 Tallinn, Estonia (“Autolevi”, “we”,“us” or “our”). If you have any questions regarding this Privacy Policy or the personal data we process about you, please contact us by e-mail at [email protected].
1. WHAT DATA DO WE COLLECT AND HOW DO WE USE IT?
In this Privacy Policy, “personal data” means any information relating to an identified or identifiable natural person. Taking into account the services, features and communication channels offered on the Platform, we may process the personal data listed below. Autolevi may also process other personal data listed below that you as a data subject may provide to us at your own discretion.
1.1. Information required for creating a user account on the Platform
To create a user account on the Platform, we may request you to provide your name, e-mail address and password. For the purposes of authenticating the user account, we also collect, in accordance with Autolevi’s procedures, unique data provided by Autolevi to you as a user (username, password, means of authentication or signature, type and result of the relevant activity, timestamp, IP address).
The legal basis for the collection of personal data is the performance of pre-contractual measures relating to a contract to be concluded with you (or the company represented by you).
In addition, we may collect your personal data to verify that you are indeed the person you claim to be during registration. For this purpose, we share your data with a trusted partner who assists in identity verification. You will be asked to provide an image of your driver’s license and a selfie for identification purposes.
In such cases, the legal basis for processing your personal data is our overriding legitimate interest in protecting Autolevi users from fraud.
1.2. Information relating to the contractual rental relationship already concluded or to be concluded
For the purposes of concluding a rental relationship, we may ask you to provide your personal identification number and date of birth (and, if you represent a legal entity, the name and registry code of the represented entity), mobile phone number, home address, bank account number, and if you are submitting an offer to use a rental vehicle, information on your driving licence (driving licence number and photographs of both sides of the driving licence) and other information on any additional conditions. In case of a business customer, we may also request you to provide information on your position, general information of the represented entity (including registry code, VAT number), bank account number, contact details and, if necessary, the existence of an authorisation (right of representation).
If you present a vehicle on the Platform to offer it to other users for the purpose of establishing a rental relationship and thereby provide vehicle-related information (e.g., vehicle model, licence plate number, photos of the vehicle offered, description of vehicle’s condition and other additional terms and conditions associated with renting the vehicle), we may disclose your personal data to third party users who browse the offers presented on the Platform and require data you have provided to access the rental items and related terms and conditions through the Platform.
If you submit an offer on the Platform for the use of a vehicle offered by another user, we may disclose the data you have provided for entering into a rental relationship (including data on booking details) to the user offering the rental item so as to enable the preparation and entry into a contractual rental relationship, the performance of the concluded rental agreement and management and administration of the contractual relationship. We may also disclose your personal data to a service provider who offers insurance policies for the vehicles rented through the Platform. After the rental period, we enable you to provide feedback on another user’s vehicle, which may be made public on the Platform.
The legal basis for collecting and disclosing information in relation to the rental relationship is the performance of a contract concluded with you (or the company you represent) or the performance of pre-contractual measures. Regarding the feedback on another user’s vehicle, we will process the data on the basis of our legitimate interest.
1.3. Information for verifying the trustworthiness of contractual partners
We may collect personal data (e.g., debt data) in order to assess your potential creditworthiness or of the company you represent (including the date the debt was incurred, the date it ended, the amount of the debt and other data obtained from debt collection or credit information providers).
In such a case, the legal basis for collecting personal data is our legitimate interest in verifying your (or your company’s) trustworthiness as a contractual partner.
1.4. Transaction information
When you submit an offer to rent or an order for a rental item on the Platform for the purpose of establishing a rental relationship, we collect information about your payments and transactions and other transaction-related data, such as payment method, bank account number and holder, bank name and other relevant information.
The legal basis for collecting transaction data is the performance of a contract condluded with you (or the company you represent) or the performance of pre-contractual measures.
We also process the collected personal data to fulfil our obligations under applicable accounting and tax laws. In such a case, the processing of personal data is based on mandatory legal provisions which require us to process personal data.
1.5. Platform usage data
We are constantly developing and improving the Platform in order to make it more convenient and attractive to users. To do this, we have to know which information is of the most interest to users of the Platform, how frequently users visit the Platform, which web browsers and/or devices they are using, how do users navigate on the Platform, etc.
When you visit the Platform, certain data may be collected without you noticing it, using various technologies such as cookies, web tags and web beacons, and also navigation data (log files, server logs, click data, web scripts). Some of the information is automatically transmitted by your web browser or mobile device – e.g., the URL of the website you are browsing or have visited previously, the IP address of your computer or mobile device and the version of the web browser you are currently using – we also store the time of your visit to the Platform and the pages that you specifically visit on the Platform.
The legal basis for the collection of personal data is the performance of a contract concluded with you (or the company you represent) or the performance of pre-contractual measures in order to provide you (or the company you represent) services on the Platform and/or our legitimate interest in developing the Platform and the provided services.
1.6. Personalised notifications on the Platform
When using the Platform, you may voluntarily opt-in to receive notifications, which may include various banners and other notices appearing on the Platform. The purpose of such notifications is to make personalised offers to users based on their preferences and interests, which we have identified during their use of our services.
For these purposes, Autolevi uses the user’s name, activities and other interactions related to the use of the services, contact information, identifiers of the devices used and other related data. You can opt out of receiving these notifications at any time by changing the settings of your web browser.
The legal basis for sending you marketing communications is your consent or our legitimate interest in promoting the Platform and providing you information on Autolevi and the services offered on the Platform.
1.7. Direct marketing
If you consent to receive marketing communications related to the Platform through your chosen communication channel(s) (e.g., e-mail, SMS, social media, LinkedIn, etc.), we may use your contact information to send you news, offers and other marketing communications.
The legal basis for sending you marketing communications is your consent (or, alternatively, our legitimate interest) in promoting the Platform and providing you information on Autolevi and the services offered on the Platform. You may withdraw your consent for receiving direct marketing materials at any time by following the instructions provided in the marketing communications or by contacting us by e-mail at [email protected].
1.8. Inquiries and responses
If you submit an inquiry to us through the Platform or to our contact address, we process your contact details and the content of the inquiry in order to respond to you. The legal basis for the collection and processing of such personal data is our legitimate interest in responding to inquiries relating to us and our provided services.
1.9. Information relating to legal claims
Where necessary, we may process personal data in order to pursue our legitimate interest in asserting, exercising and defending legal claims arising from a contract concluded with you (or the company you represent). We also process the collected personal data to fulfil our obligations under applicable accounting and tax laws.
1.10. Cookies
What are cookies?
Cookies are small text files which the Platvorm may store on your device during your visit. Cookies facilitate the use of the Platform by storing your choices and preferences so that you do not have to re-enter these upon each visit or on each web page.
What cookies do we use?
The Platform uses cookies to store your IP-address and browsing information, including information on the visited webpages and the time spent on each page, and to store information about your device and your preferences for using the Platform.
We also use cookies to monitor web traffic and user activity on the Platform – we use this information to analyse user behaviour and improve your user experience.
Cookies enable us to:
● improve your user experience when visiting the Platform,
● allow you to set personal preferences;
● collect usage statistics on the Platform; and
● measure the effectiveness of advertisements.
We use the following types of cookies on the Platform:
Functionality cookies
Functionality cookies are essential in order to enable you navigate on the Platform and use its features. Functional cookies are used, e.g., to store your login details.
Statistical cookies
Statistical cookies collect anonymous statistical information on how visitors use the Platform. For example, statistical cookies may help us understand how users browse and use the Platform and which parts of the Platform are most frequently used. Statistical cookies are stored on your device and used only on the basis of your consent.
Advertising cookies
Advertising cookies collect information about your browsing habits. They are used to choose the advertising that is more relevant to you and meets your interests. We may also use these cookies to limit the number of times you see an advert, or to estimate how the advertisements on the Platform reach our users. Advertising cookies are usually placed by third party advertising networks to collect information about your interests based on your online behaviour. Advertising cookies are stored on your device and used only on the basis of your consent.
Third-party cookies
The Platform may also use social media cookies. These cookies allow you to share information related to your use of the Platform on social networks, such as Facebook. We are not responsible for third-party cookies and these are stored on your device and used only on the basis of your consent. Please read the privacy policies of these third parties carefully.
How long are cookies stored on my device?
Cookies are divided into two categories depending on how long they are stored on your device.
Session cookies
Session cookies are set for each session and are stored on the device until you close your browser or mobile application. Session cookies are not stored on the hard drive of your device.
Persistent cookies
Persistent cookies are stored on your hard drive until you delete them or until they expire. We may store information from persistent cookies for a maximum of 2 years.
Cookies are stored on your device only on the basis of your consent, except for the cookies necessary for technical functioning of the Platform. Please note that if you do not consent to the use of cookies, you may not be able to use certain functions of the Platform.
Please also note that third parties (e.g., advertising networks, web traffic analysts and other external service providers) may use cookies which are beyond our control.
How to manage cookies?
You can manage and/or delete cookies at your own discretion – see more details at www.youronlinechoices.com. You have the possibility to delete all cookies from your device and most web browsers can be set to refuse cookies. However, if you do this, you may be required to manually re-enter certain preferences upon each visit and certain services and features may not function.
2. TRANSFER AND DISCLOSURE OF PERSONAL DATA
We will make our best efforts to keep your personal data protected and demand our staff and partners to ensure strict security and confidentiality.
We may disclose your personal data to:
– third parties, if this is necessary for the performance of pre-contractual measures, e.g., to enable persons to access a rental offer made by you on the Platform;
– third parties, if it is necessary to improve the efficiency of debt recovery proceedings; please note that we have the right to transfer personal data to debt collection providers in accordance with applicable law as of the time when you breach of the obligations set out in a contract concluded with us;
– our trusted service providers who provide services to us or to you in accordance with our instructions (e.g., analytics or insurance for rented vehicles). The use of your personal data is always under our control and we are responsible for it;
– competent authorities, if disclosure is mandatory under the law or if an authority submits a lawful enquiry to us; and
– companies belonging to the same group of companies with Autolevi; and
– if we are involved in a merger, acquisition, or sale of all or a portion of our company’s assets.
We may additionally disclose your personal data to:
– our staff responsible for customer cooperation and supporting customer relationships, as well as to our staff involved in accounting, IT maintenance, business analysis and planning functions;
– suppliers of IT systems used for our customer relations management, cloud service providers and auditors;
– other authorised staff and other persons involved in performance of the contract;
– banks; and
– persons who assist us in exercising our rights under the contract (debt collection service providers, legal advisors, credit information agencies, verification service providers, etc.).
Generally, we do not transfer your personal data outside the European Economic Area. If we do so, we will implement appropriate safeguards to ensure that such transfers comply with applicable law and are secure. In case of transfers of personal data to countries that do not offer an adequate level of data protection, Autolevi uses appropriate safeguards when transferring personal data, for example by using the European Commission’s standard contractual clauses in contracts for the transfer of personal data. You may request information on the applicable protection measures by contacting us at the e-mail address [email protected].
3. HOW LONG DO WE RETAIN YOUR PERSONAL DATA?
Your personal data will be retained only for as long as necessary to fulfil the purposes defined in this Privacy Policy or as required by laws.
Most of your personal data will be retained during the course of your (or the company’s you represent) customer relationship with Autolevi, i.e. until your user account on the Platform is active. We may retain this data for up to 2 years after the expiry of your user account on the Platform. Some personal data may be retained after your customer relationship with us has ended, if required or allowed by applicable laws. For example, we retain accounting source documents (such as copies of vehicle rental contracts and invoices) for 7 years as of the end of the relevant financial year, as required by applicable law. We will retain personal data relating to the contract for 10 years after the termination of the contract in accordance with the maximum statutory limitation period for intentional breaches.
When your personal data is no longer required by laws or in connection with the rights or obligations of either party, we will permanently delete your personal data unless you have instructed us otherwise or we have agreed on a longer data retention period.
4. YOUR RIGHTS
You have a right to request access the personal data we process about you. To the extent permitted by law, you may access, correct, update, change or delete your personal data at any time.
If personal data is deleted upon your request, we will retain copies thereof only if this is necessary for the protection of our legitimate interests and those of third parties, to comply with orders from public authorities, for dispute resolution, for eliminating faults or ensuring the performance of contracts concluded with you. However, please note that certain personal data may be strictly necessary in order to fulfil the purposes defined in this Privacy Policy or required by laws. You may not delete such personal data.
If personal data is processed on the basis of your consent, you may withdraw your consent given to the processing of personal data at any time. Withdrawal of consent does not affect the lawfulness of any processing of personal data based on your consent prior to the withdrawal.
Subject to the conditions set out in the personal data protection legislation, in certain cases you may have the right to require restriction of processing of personal data and also to object to the processing of certain personal data.
Subject to the conditions set out in the personal data protection legislation, you have the right to data portability, i.e. the right to receive your personal data in a structured, commonly used machine-readable format and to transmit it, at your discretion, to another data controller.
We respect your right not to be subject to decisions made solely as a result of automated processing, including profiling, and any final decisions made by Autolevi are always subject to human review.
Please send any requests for exercising the abovementioned rights by e-mail to [email protected].
If you consider that we are not processing your personal data properly, you have a right to lodge a complaint with your country’s data protection authority. In Estonia, this authority is the Data Protection Inspectorate. You can find the contact details of the Data Protection Inspectorate here: www.aki.ee.
5. SECURITY
We use appropriate organisational, technical and operational security measures (including physical, electronic, and administrative) to protect personal data against loss, destruction, misuse, and unauthorised access or disclosure. For example, we only allow access to your personal data to authorised employees and contractors who need the data for performance of their tasks.
Please note that while we strive to take reasonable measures to protect the security of your personal data, no system can completely eliminate all potential security risks.
6. UPDATING THE PRIVACY POLICY
We may update this Privacy Policy from time to time. When we update this Privacy Policy, we will notify you through the Platform. The Privacy Policy was last updated on the “Last updated” date indicated in the header of the Privacy Policy.
