Personal Data Privacy Policy for QIC SafeDriver Application

 

Last Modification date: September 7, 2021

 

Below You will find Our detailed Personal Data Privacy Policy (“Privacy Policy).

Please read the Privacy Policy carefully before using the Services of the “QIC SafeDriver Application” (the "Application"). Please also note that by accessing, browsing and using the Application, You certify that You have read, understood, agreed to and ultimately accepted the Privacy Policy.

If, after having read the Privacy Policy and/or Terms, You find that for any reason You do not agree with and do not accept any of its content and provisions, You are kindly requested not to install the Application or to immediately delete it, as well as every part of it, from Your smartphone, tablet or any other electronic device You may have installed it and not to use it in any manner.

If, after reading the Privacy Policy, You still have any questions regarding the Privacy Policy or in case You need further clarifications or information, You may contact the customer service department of Qatar Insurance Company (the “Company”), by email at info@qic-insured.com.

The Company, in collaboration with OSeven Telematics Limited of 35, Ballards Lane, London, United Kingdom N3 1XW (“OSeven”), reserves the right to update / modify / amend this Privacy Policy, whenever it deems that it is necessary. To this end, the update / modification / amendment will be available to You via the Application and the Last Modification Date will be indicated under the title of the Privacy Policy, so that You will be notified thereof. The use of the Application after the Last Modification Date indicates Your acceptance of these updates / modifications / amendments. If You do not agree with any update / modification / amendment, You must delete the Application and not use it anymore.

All definitions may be found in the Terms of Use of the Application (the “Terms”).

 

 

1. Collection and processing of Your personal data

1.1       We have created this Privacy Policy for the collection and management of personal data to prove to You that Your personal data will be treated properly, with the required level of security, complying with Law No. 13 of 2016 of the State of Qatar relating to protection of personal data and, where applicable, the European Union General Data Protection Regulations (collectively referred to as “Data Protection Regulations”). The personal data We process upon Your registration to the Application (i.e., Your email) or upon the acceptance of the invitation that You have received (e.g., via Your email) to use the Application, is the minimum information required for the provision of professional services on Our part.

             Please note that the following information that We collect is provided to the Company and OSeven only with Your explicit consent, given before the installation and use of the Application and after You obtain knowledge of this Privacy Policy.

1.2       In the case You sign in with a username and password, You will also be requested to provide a password. This information will not be re-used for any purpose which does not fall within the scope of Our Services. Please note that You are solely responsible for keeping Your password and any sign in emails to Your account confidential and that You are fully responsible for any activities in Your account.

1.3       It is highlighted that the Company does not send to OSeven any of Your personal data that you may provide during Your registration to the Application and therefore Your data in the O7PLATFORM is considered pseudonymized.

1.4       The legal basis for the processing of your personal data (Email Address, Primary Data, Driving Behaviour and Vehicle Use Data, Reward Data) is the explicit consent that You provide by accepting the Application Terms of Use and Privacy Policy; whereas in case that OSeven or the Company are requested to disclose Your personal data to a public authority, the legal basis for this process is the compliance of OSeven or the Company with its legal obligations.           

1.5       The type of data that We may collect with Your consent, which is given herewith, is listed below.

 

 

2. Collection of Your Primary Data

“Primary Data”: Primary Data refers to the data recorded by the Application from the smartphone sensors or the operating system of the smartphone. Primary Data is provided to OSeven by the manufacturers and developers of the smartphone operating system (Apple: iOS, Google: Android).

The Application may collect and assess Primary Data related with driving activity (including Location data) to enable the automatic Trip recording even when the Application is closed or not in use. Specifically, the Application is activated by data received from the Android and iOS operating systems to verify if the User is in a driving status. This process is called “Driving Detection”. If the Application verifies that the User is in driving status, then the recording of Primary Data begins. Otherwise, data collection is interrupted, until the next time that the Application is activated. In case that the User is not in a driving status the data collected during “Driving Detection” is not sent to the O7PLATFORM and is finally deleted from the smartphone device. Only the Primary Data that is recorded during a Trip is sent to the O7PLATFORM.

The Primary Data that is sent to the O7PLATFORM, is stored by OSeven in servers within the European Union utilizing recognized and acknowledged technology providers (indicatively Amazon, Microsoft). The Primary Data is the following:

·         Date/Time: The Recording date/time/timestamp for Primary Data.

·         Location Data: geographic longitude, geographic latitude and altitude of the vehicle position, horizontal and vertical accuracy of the Location, vehicle movement speed, speed accuracy, vehicle movement direction.

·         Accelerometer data: Acceleration values on the three local axes of the smartphone, including and excluding the acceleration of gravity.

·         Gyroscope data: Angular velocity values on the three local axes of the smartphone.

·         Activity Data (Motion and Fitness / Activity Recognition): Data provided by Apple and Google companies related with the activity of the User as it is recognized by the smartphone operating system (indicatively but not limited to, walking, stopping, driving).

·         Values of the angles formed by the local axes of the smartphone to the North and to the horizontal plane (ground).

·         Rate of change of the angles formed by the local axes of the smartphone to the North and to the horizontal plane (ground) versus time.

·         Screen State (Android only): Data on screen activation (activated or deactivated) as an additional criterion for identifying mobile use. It is noted that the Application does not have any access to the content of the smartphone screen.

·         Smartphone device data. It is provided by Google and Apple and includes indicatively but not limited to, the manufacturer’s brand, the device model, the name and version of the operating system and the type of smartphone sensors (e.g., accelerometer, gyroscope, compass, etc.).

·         Push Notification Token Data: A unique alphanumeric code produced by Apple and Google companies, which is sent to a smartphone. This code is associated with a single and only installation of the Application. In case of uninstalling and reinstalling of the Application by the User, a new code is generated indicating the day and time that it was generated.

·         WiFi: Recording of the smartphone WiFi operation.

·         Data on the date/time of Sign In/Out to/from the Application.

·         Data on date/time of activation/deactivation of the smartphone Location Services.

·         Data on date/time of activation/deactivation of the Activity Data (Motion and Fitness / Activity Recognition).

·         Data on date/time of activation/deactivation of the Compass Calibration (iOS only).

·         Data on date/time of activation/deactivation of the smartphone device.

·         Data on date/time of activation/deactivation of the Application Recording through its settings.

·         Data on date/time of activation/deactivation of the Background Refresh (iOS only).

·         Data on date/time of activation/deactivation of the smartphone WiFi.

·         Technical information regarding the functionalities of the Application.

·         Data regarding the Power Mode/Battery settings of the smartphone device.

·         Data regarding the paired Bluetooth devices.

 

OSeven does not send any of the Primary data to the Company, i.e. the Company does not have access to Your Primary Data.

 

 

3. The purposes of collecting, storing and processing of Your data in the O7PLATFORM.

The purposes of collecting and processing of Your data (including the Primary Data and the data that is sent by the Company to OSeven for each User that do not include any personal data) in the O7PLATFORM are the following:

·         The registration and sign in of the Users in the Application, the assignment of their data in the O7PLATFORM, the calculation of the Driving Behaviour and Vehicle Use Data and the calculation of the Reward Data and to ensure the proper functioning of the Application and the O7PLATFORM for the Users.

·         To provide technical support to the Users, if and when this is requested.

·         To perform statistical analysis and to optimize the data models and algorithms (indicatively the driving behaviour models and the machine learning algorithms) in the O7PLATFORM, also improving the provided Services to the Users.

 

Specifically, regarding data which pertain to the longitude and latitude of the Location data, this is stored and kept in the O7PLATFORM indicatively for the following purposes:

·         The representation of each Trip and the risk related driving events (indicatively harsh brakes, harsh accelerations, mobile phone use while driving, speed limit violations) on a map for each Trip in the Application. This is a coaching feature that helps the Users to identify their weak points and improve their driving behaviour.

·         The visualization of road sections with frequent risky driving behaviours for each User. This is a coaching feature that helps the Users to focus on areas that they have the highest frequency of risky driving behaviours.

·         Mapping the risk of different sections of the road network as a whole and for different types of risk considering data from all the Users.

·         The determination of the status of the User (driver of the vehicle or passenger in any other vehicle) per Trip.

·         The development, evaluation and optimization of the map matching algorithms, and algorithms for the calculation of speed, course and travelled distance.

 

OSeven shall receive and retain the data of the Trips that the Users were not the driver of the vehicle for the following purposes: (i) transparency to the Users, (ii) to provide to the Users the option to access and modify their data and (iii) optimization of the reliability of the results provided to the Users.

Following the assessment of the above, the “Driving Behaviour and Vehicle Use Data” and “Reward Data” which correspond to Your actual driving behaviour are calculated by OSeven and then the score is extracted, as described herein the Personal Data Privacy Policy.

 

 

4. Extraction of “Driving Behaviour and Vehicle Use Data” and “Reward Data”

The Driving Behaviour and Vehicle Use Data is the data of the User derived from the Primary Data via processing in the O7PLATFORM and/or the Application using advanced mathematical algorithms and/or machine learning algorithms, as well as advanced driving behaviour models. Driving Behaviour and Vehicle Use Data are indicatively the following:

·         Trip start date/time.

·         Trip end date/time.

·         Number of Trips (overall and per time period - day, week, month).

·         Distance travelled (per Trip, overall and per time period - day, week, month).

·         Trip Duration (per Trip, overall and per time period - day, week, month).

·         Number of harsh brakes and intensity (per Trip, overall and per time period - day, week, month).

·         Number of harsh accelerations and intensity (per Trip, overall and per time period - day, week, month).

·         Duration of driving over the speed limit if and when the speed limit is available to OSeven by a third-party technology provider (per Trip, overall and per time period - day, week, month).

·         Average speed, exceeding the speed limit if and when it is available to OSeven by a third-party technology provider (per Trip, overall and per time period - day, week, month).

·         Mobile phone use duration while driving. Mobile phone use is determined via tracking of the movement of the device (indicatively talking, texting or any other movement of the device) (per Trip, overall and per time period - day, week, month).

·         Distance travelled in hours of increased risk (per Trip, overall and per time period - day, week, month).

·         Weather conditions during the Trip, if and when they are available to OSeven by a third-party meteorology provider.

·         Traffic load during a Trip if and when it is available to OSeven by a third-party technology provider.

·         Overall score (per Trip, overall and per time period - day, week, month).

·         Score per category. The categories are: Speeding (exceeding speed limit), Mobile phone use while driving, Braking, Acceleration (per Trip, overall and per time period - day, week, month).

·         Estimation of the transportation mode in a Trip by the O7PLATFORM and the final characterisation of the User (if applicable) per Trip.

·         Estimation if the User is the driver or a passenger in a Trip by the O7PLATFORM and the final characterisation of the User (if applicable) per Trip.

·         SafeMiles collected by the User (per Trip, overall and per time period - day, week, month).

·         Gamification Data. OSeven has developed gamification and rewarding features for the training and the motivation of the Users in order to improve their driving behaviour. The Gamification Data includes the performance of the Users related to gamification and/or rewarding features, provided that the Company has activated and/or utilized such features.

 

Score”: The driving behaviour model of OSeven provides a score from 0 (lowest) to 100 (highest) per Trip, considering the following parameters, with decreasing level of significance:

·         Driving duration over the speed limit and average speed exceedance of the speed limit if and when it is available to OSeven by a technology provider.

·         Mobile phone use while driving.

·         Harsh brakes (number and degree of intensity) and braking profile.

·         Harsh accelerations (number and degree of intensity) and accelerating profile.

·         Distance traveled in hours of increased risk.

·         Trip duration.

 

The overall Score of the User is calculated as the weighted average of the Trips’ Scores of the last twelve (12) months, where the User was the driver (according to the estimation of the machine learning algorithms of OSeven or the characterization of the User), with distance as the weighting factor.

“Reward Data”: OSeven has developed gamification and rewarding features for the training and the motivation of the Users in order to improve their driving behaviour. The Reward Data, provided that the Company has activated and/or utilized such features, includes mainly the following:

·         Rewards / Redemptions for the Users. The Rewards / Redemptions that the Users win and/or choose via the features / functionalities of the Application that are related with gamification and/or rewarding.

 

The Company has access to the Driving Behaviour and Vehicle Use Data as well as the Reward Data of the Users.

 

 

5. Time periods for the collection and processing of Your Data

5.1       The personal data that you provide during Your registration in the Application is stored in the systems of the Company.

5.2       Your Primary Data is stored in the O7PLATFORM within the European Union.

5.3       You have the option to cancel Your account by contacting the Company at the email info@qic-insured.com at any time.

             Five (5) years after the cancellation or termination or deactivation of Your account Your personal data will be anonymized in a way that it is not reversible. In this way Your data and consequently location data cannot be related in any way with You anymore.

5.4       The purposes of retaining the anonymized data in the O7PLATFORM are indicatively the following: (a) continuous improvement of the OSeven Machine Learning algorithms and the OSeven Driving Behaviour and Scoring models improving the Services provided to the Users, (b) calculation of general, aggregated and fully anonymized metrics considering all the Users, regarding the driving behaviour and road safety, that can be used for (i) the improvement of the reliability of the Services provided to the Users, (ii) the development of anonymized and statistical risk indicators which (ii.a) may be communicated to the Users, (ii.b) may be published in the OSeven webpage aiming to inform, educate and improve the driving behaviour of the public (ii.c) may be communicated to Public Authorities to contribute to the optimum use of the available resources considering road safety and the maintenance of the road network.

 

 

6. Your rights

6.1       Regarding Your right to be informed about the processing of Your personal data, please note that You may use the Application in order to receive information on the following indicative data per Trip, overall and per time period - day, week, month (for each case not all data are applicable): Trip start time and date, Trip end time and date, number of Trips, driving duration, travelled distance, travelled distance during hours of increased risk, distance and duration of speed limit exceedance, average speed exceeding the speed limit, average speed, duration of mobile phone use while driving, number and intensity of harsh brakes, number and intensity of harsh accelerations, overall score (that You may also compare with other drivers’ score in an anonymized approach) and score per category (the categories are the following: Speeding, Mobile phone use, Braking, Acceleration), determination of the User status per Trip (if the User was the driver or a passenger) and what the User ultimately characterized, determination of the vehicle type per Trip (car, mass transit, motorcycle, bicycle) and what the User ultimately characterized.

6.2       OSeven may also notify You of: a) its identity, b) the purpose of the processing, c) the recipients or categories of recipients of the data and d) of the right to access as defined in relevant legislation.

6.3       You may submit a written query to the Company at the email address info@qic-insured.com. Through the above query, You may be informed solely of Your own personal data, its origin, the purpose of its processing, the recipients or categories of recipients, the progress of processing as of the date of the previous update or notice of information, the logic of automated processing and any notification to third parties to whom the data has been communicated.

6.4       However, You should keep in mind that the access and obtaining knowledge of the automated processing, even with the assistance of an expert, may under no circumstances allow for extending this knowledge to the source code of the Application and the related algorithms.

6.5       Subject to the Data Protection Regulations, You retain all rights with respect to Your personal data as described in the applicable legislation. Indicatively:

·         Right to access Your personal data.

·         Right to rectification: You may request a correction to any incomplete, inaccurate or non-updated data of Yours.

·         Right to Erasure: You may request the erasure of Your personal data where there is no valid reason for OSeven to continue processing them.

·         Right to restrict the processing: You may request a restriction on the processing of Your personal data if it is inaccurate, has been used illegally, is no longer needed or in case You exercised the right to object.

·         Right to portability: You may request to receive a copy of Your personal data in a format easily re-usable or request the transmission of such data to other organizations.

·         Right to object to processing: In particular, the service provided to You will be performed on an automated basis. In such cases, You have the right to contact Us in order to ask to be provided with information regarding the processing of Your personal data and / or to demand that Your request be examined by an OSeven official and to obtain an explanation for the automated decision taken.

·         Right to withdraw Your consent: Your Personal Data is processed by this Application based on Your previous consent, that You may withdraw at any time. Any such withdrawal may render Us unable to keep providing You with Our services.

             To exercise any of Your rights, You may submit an email to the Company at info@qic-insured.com.

6.6       Please note that in case Your request related with the exercise of Your rights in the framework of Data Protection Regulations, is considered by the Company to be abusive or manifestly unfounded or excessive, in particular because of their repetitive nature, the Company or/and OSeven (in case that Your request has been sent by the Company to OSeven) may refuse to respond to the request.

 

7. How We share Your data with third parties

7.1       OSeven reserves the right to forward Your anonymized data to third parties, by using all suitable technological means, in order to ensure anonymity, except where the disclosure of Your identity to service providers is required for the execution of the Application’s purpose, in connection with the contract which supports its functions (e.g., technology services). Please note that We obligate all Our partners who legally have access to Your data to use Your data solely to perform legitimate tasks related only to the prompt and proper functioning of the Application and not for their own benefit.

7.2       OSeven reserves the right to transfer Your data to a parent company of OSeven, to a subsidiary of OSeven or other affiliates, joint ventures or other partner companies (collectively referred to as the "Affiliated Companies").

7.3       In the latter case, namely in the event of cross-border transfer to a recipient located in a foreign jurisdiction, We shall at all times ensure the adequate protection and the effective implementation of the basic principles of data protection under the applicable legislation. In addition, OSeven shall request from the Affiliated Companies to fully respect this Privacy Policy.

7.4       In connection with the above, Your data may also be forwarded to a company which has undertaken the financing of OSeven, which is merged with OSeven, acquires OSeven or its assets, in which case OSeven may continue to process Your personal data as set forth in this Privacy Policy and provided that the latter meets the requirements set forth by the applicable legislation.

7.5       OSeven reserves the right to transfer Your data to its consultants / subcontractors that work for the development / improvement / optimization of the Services provided by the Application and the O7PLATFORM. Please note that OSeven obligates all its consultants / subcontractors who legally have access to Your data to use Your data solely to perform legitimate tasks in compliance with the Terms and the Privacy Policy.

7.6       You should also note that the Company or/and OSeven may disclose Your personal information if required to do so by court order or by decision issued by any other public authority, to the extent permitted by law.

7.7       Finally, OSeven and the Company may forward Your data to other third parties with Your explicit consent or upon Your request.

7.8       Except as stated above, the Company and OSeven shall not sell, share, lease or exchange Your personal data, Your Primary Data, Your Driving Behaviour and Vehicle Use Data and You Reward Data, except in the cases set forth in this Privacy Policy.

7.9       OSeven reserves the right to share non-personalized information, including non-identifying information and log data, with third parties for industry analysis, demographic profiling, statistical purposes and scientific publications. Additionally, OSeven reserves the right to publish data analysis utilizing Your data, either directly or via its subsidiaries/parent companies or its scientific/research partners/consultants, provided that the published data will not include any personal data of the Users.

7.10    OSeven may use third party tracking services, to detect and analyze anonymous information of its Users. These third parties may use cookies to assist in detecting the Users’ behaviour. However, the terms of use of those cookies are not controlled by OSeven and therefore it has no liability in connection therewith.

7.11    OSeven reserves the right to disclose anonymized data collected through the use of the Application, by any means and without restrictions, indicatively to third parties (e.g., vendors) who will assist it in enhancing or providing its Application and services to third parties.

7.12    OSeven uses the following Google Firebase features to provide you with the best experience: Firebase Cloud Messaging, Firebase Crashlytics, Firebase Remote Config, Firebase Dynamic Links (if you are using iOS software).We also use the following Google Firebase features for reporting purposes: Google Analytics for Firebase (without the advertising feature).You may find information on the data collected and processed by these features here. This data may be transmitted outside the European Union and processed on Google’s globalinfrastructure to the extent that this data is collected and processed by Google Firebase.This transmission is made according to Standard Contractual Clauses, as approved by the European Commission.

 

 

8. Control of Your Data

8.1       In the event of change in Your personal data, or if You need to correct, delete inaccuracies or to modify them, You must contact the Company at info@qic-insured.com. We will respond to Your request for access, as soon as possible.

8.2       Your data (“Primary Data”, “Driving Behaviour and Vehicle Use Data” and “Reward Data”) will be stored in the database of OSeven and OSeven reserves the right to keep it stored, even if the service stops or Your account becomes inactive, in compliance with the Terms.

8.3       If You no longer wish to use Our Services or if You wish at any time to delete Your account or request that Your information should be no longer used for the provision of Our Services, You must contact the Company at info@qic-insured.com.

8.4       However, We shall maintain and use Your information as needed in order to comply with Our legal obligations, dispute resolution and enforcement of agreements.

 

 

9. Handling of Your emails

9.1       Each time You send an email, Your personal data is collected only to the extent necessary to respond to You and to send You Notifications which are relevant to the Application.

9.2       If You have any questions regarding the processing of Your email and Your data, please do not hesitate to include them in Your message.

 

 

10. Security

10.1    Your personally identifiable information, which the Company and OSeven collect, are safely stored in the databases of the Company and OSeven, that both use standard, commercially widespread security practices, such as encryption, pseudonymization and firewalls, to secure Your information.

10.2    However, as effective as state-of-the-art technology may be, no security system is, nor does it remain inaccessible. That is why, although the Company and OSeven use up-to date technology practices, the Company and OSeven cannot fully guarantee the security of the Application, O7PLATFORM or Our system, nor can OSeven guarantee that the information You provide will not be intercepted, as it is transmitted to OSeven over the Internet at Your own risk.

10.3    We advise You not to share Your username, Your password, or Your sign in emails with anyone at any time. As stated above, You are solely responsible for keeping Your password and any sign in emails to Your account confidential and You are fully responsible for any activities in Your account.

 

 

11. Contact

For any inquiries, You may email Us at info@qic-insured.com.