Privacy Policy
ARTICLE 1 – PURPOSE OF THE POLICY
This privacy policy aims to inform users of the site auto-pass.com (hereinafter "the Site") about how their personal data is collected, processed, protected, and used during their browsing or use of the services offered.
This policy has been drafted in accordance with the requirements of the General Data Protection Regulation (GDPR) No. 2016/679 and the amended Data Protection Act.
ARTICLE 2 – IDENTITY OF THE DATA CONTROLLER
The data controller is the publishing company of the site, VIASIMPLY LIMITED, a company under English law whose registered office is located at Office 18037, 182-184 High Street North, East Ham, London E6 2JA, United Kingdom, registered under number 17108668 and identified for VAT purposes under number GB518 4042 08.
The management of personal data is ensured by an authorized representative within the company. For any questions regarding your data, you can write to: assistance@autopass24.com.
ARTICLE 3 – PERSONAL DATA COLLECTED
The data collected by the Site concerns:
- Identification data: first name, last name, email address;
- Personal or professional contact details: postal address, if applicable;
- Billing and payment information: credit card data via secure provider;
- Data related to services: license plates, Cerfa forms, supporting documents provided by the user;
- History of orders and generated documents;
- Browsing data: IP address, cookies, statistics via audience measurement tools (Google Analytics or equivalent).
The Site does not collect so-called "sensitive" data within the meaning of the GDPR.
ARTICLE 4 – PURPOSES OF PROCESSING
Personal data is collected for the following purposes:
- Creation and management of the user account;
- Execution of the services offered by the Site;
- Order tracking and customer relationship management;
- Billing, accounting, and compliance with legal obligations;
- Fraud prevention and transaction security;
- Improvement of the Site and its features;
- Anonymized attendance statistics;
- Management of rights exercise requests.
The processing is based on:
- The execution of the contract (Article 6.1.b of the GDPR);
- Consent (Article 6.1.a of the GDPR) for cookies or certain optional communications;
- Compliance with a legal obligation (Article 6.1.c of the GDPR).
ARTICLE 5 – RECIPIENTS OF DATA
The personal data collected is intended for the internal services of the Service Provider. They may also be transmitted to subcontractors or service providers acting on behalf of the Site, notably:
- Secure payment providers;
- Site host (Amazon Web Services - AWS);
- Cookie management platform (CookieYes);
- Audience analysis tools;
- Customer support services and email management.
All providers are contractually obliged to ensure the confidentiality and security of personal data, in accordance with GDPR.
ARTICLE 6 – DATA RETENTION PERIOD
Personal data is retained for strictly necessary durations for the purposes pursued, in accordance with applicable legal requirements:
- Data related to the customer account: kept for the entire duration of the account activation, then archived for 5 years from the account deletion;
- Data related to billing and accounting documents: kept for 10 years in accordance with tax and accounting obligations;
- Browsing data (cookies and trackers): kept for a maximum of 13 months from their deposit;
- Connection logs and technical data: retained for 12 months for security and traceability purposes;
- Data related to requests for exercising rights: kept for a maximum of 3 years from the closure of the request.
ARTICLE 7 – SECURITY OF PERSONAL DATA
The Provider implements appropriate technical and organizational measures to ensure the security of personal data and prevent their alteration, loss, destruction, or unauthorized access.
These measures include, among others:
- Data encryption during transfer;
- Database isolation;
- The secure management of internal access;
- Regular backups;
- Security audits;
- Anonymization or pseudonymization when relevant.
In case of proven violation of personal data, the Provider commits to notify the CNIL within legal deadlines and to inform the affected individuals in cases provided for by the GDPR.
ARTICLE 8 – USER RIGHTS
In accordance with the GDPR, any person affected by data processing has the following rights:
- Right of access to personal data;
- Right to rectify inaccurate or incomplete data;
- Right to erasure in cases provided for by regulations;
- Right to restriction of processing in certain situations;
- Right to object to processing for legitimate reasons;
- Right to data portability provided in a structured and readable format;
- Right to withdraw consent at any time for processing based on that consent;
- Right to lodge a complaint with the CNIL (www.cnil.fr).
These rights can be exercised by email at the following address: assistance@autopass24.com. An identity document may be requested if necessary.
ARTICLE 9 – DATA RELATED TO MINORS
The services offered on the Site are not intended for minors and should not be used by them. No voluntary collection of personal data concerning minors is carried out.
If a parent or legal guardian finds that their child has provided personal data to the Site, they are encouraged to contact the Provider to request immediate deletion.
ARTICLE 10 – TRANSFERS OF DATA OUTSIDE THE EUROPEAN UNION
As part of the management of the Site and the execution of services, certain personal data may be transferred outside the European Union, notably to the United States, due to the use of technical service providers (hosting, emails, cookies, analytics, etc.).
These transfers are governed by standard contractual clauses approved by the European Commission or any other mechanism recognized as providing an adequate level of protection under the GDPR.
ARTICLE 11 – COOKIES AND TRACKERS
The Site uses cookies and similar technologies for:
- Facilitate navigation on the Site;
- Measure audience and improve user experience;
- Enable certain personalized features;
- Optionally suggest tailored content or services.
The management of cookie consent is ensured by the CookieYes platform, compliant with the GDPR. Upon first visit, a banner allows the user to accept, refuse, or set non-essential cookies.
Cookies strictly necessary for the operation of the Site are exempt from consent. The user can modify their preferences at any time by clicking on the "Cookie Management" link at the bottom of the page.
ARTICLE 12 – UPDATE OF THE POLICY
This policy may be modified at any time to reflect legislative, regulatory, or functional developments of the Site.
In case of a substantial update, users will be informed during their next login or by any appropriate means. The applicable version is the one published on the Site at the date of consultation.
ARTICLE 13 – CONTACT FOR PERSONAL DATA
For any questions regarding this policy or the exercise of their rights, users can contact the Provider at the following address: assistance@autopass24.com.
A response will be provided within a reasonable time frame and in accordance with GDPR requirements, usually within 30 days from the receipt of the complete request.
Last updated: September 16, 2025