High-end tuning since 2003

Data protection

Privacy Policy

1. Introduction

Upscale Msdn Co. LTD (hereafter “the Company”, “we”, “us” or “our”) is a limited liability company which operates the domain www.tuning24.org (hereafter the “Website”). The Company is incorporated under the laws of the Republic of Cyprus with Company Registration Number HE 414751 and having its registered / business office at Giannou Kranidioti 30, Orphanides Bld., Suite 2, 3rd Floor, office 301-302, 6045 Larnaca, Cyprus.

The Company is the controller of your personal data collected via the means described herein and any process of your personal data is performed in accordance with this Privacy Policy (hereafter “the Policy”) and the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) as amended from time to time (hereafter “GDPR Regulation”).   

Data Subject (hereinafter as “you,” or “your”) stands for an identified or identifiable natural person, whose personal data the Company processes in course of conducting business, regardless the personal data were obtained from this person directly or from the third parties.

Personal data means any information relating to an identifiable natural person (i.e. using information and data in order to directly or indirectly identify a specific person).

Processing means any operation(s) which is performed on personal data (or on sets of personal data) whether or not by automated means such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction.

2. Scope and Applicability

As part of the Company’s daily operations, it is necessary to collect personal data from existing and prospective clients in order to be able to provide them with our products and services. This Policy describes how the Company collects, processes, uses, maintains, stores and discloses your personal information and data. 

Any personal data the Company collects about the client will only be used for the purposes we have collected it for, or as allowed under the applicable legislation, and to perform our contractual obligations in relation to the products and services offered. This Policy covers the Company’s official corporate website www.tuning24.org, all its related sub-domains that are registered and operated by the Company as well as the payment gateways and any other software solutions used by the Company.

This Policy is applicable to the processing of personal data regardless of the form/environment that the personal data is provided (e.g. on paper, electronically, by phone or otherwise) and whether or not the Company process it by automated means of manually.

Moreover, this Policy applies to former, existing or prospective clients, applicants and visitors on the Company’s website(s) (hereafter “the client” for convenience). The Company strives to protect the privacy, confidentiality and security of all personal data obtained from our clients during the course of the business relationship and their dealings with the Company, including information obtained during their visits to the Company’s website(s).

At the Company, we treat all individual visitors that enter our corporate website(s) as well as all private individuals that represent our corporate clients (i.e. authorized representatives, proxies etc.) and all our private individual clients as Data Subjects in the sense of the GDPR Regulation.

3. Our Commitment to You

At the Company, we fully understand the importance of maintaining the confidentiality and privacy of your personal data. The Company respects your privacy and to this end, we are committed to taking all reasonable steps in order to protect and safeguard the privacy, confidentiality, security and integrity of your personal data.

 4. How do we collect your Personal Data?

In order for a natural person to become our client, (s)he must complete and submit the account opening application form. During this process, the prospective Client is requested to provide certain personal information, data and identification documents as well as acknowledge his/her willingness to share this private information with the Company for the purpose of evaluating the client’s request to open a payment account with the Company and to comply with the Laws and Regulations governing the provision of payment instruments, services and products offered by the Company.

Apart from the personal data collected during the account opening process, the Company may collect personal data in a number of ways, including but not limited to, the following:

The Company may, from time to time, request further information from you to help us improve our services & products under the Client Agreement or to comply with the applicable laws and regulations.

 5. What Personal Data do we collect?

The list of personal data that we may collect from you is not exhaustive. The list below specifies the main categories of personal data, which the Company collects and processes:

6. How do we use and process your Personal Data?

The Company will only collect, use, process, disclose, transfer and store your personal data in accordance with the GDPR Regulation, the local Cypriot legislation on data protection & practises, and the Client Agreement based on one or more of the following legal bases and purposes:

If it is necessary to use your personal data and data for any other reason which is not outlined above, then you will be duly informed (i.e. via a pop-up message, push notification, email or otherwise) and also if there are any additional terms and conditions which will apply. You will be asked to confirm whether you agree to these additional terms and conditions before we can proceed. 

Please note that you can control what and how you receive communications or information from us. If you do not wish to receive electronic communications from us (including marketing and advertising communications, promotional material, market research analysis, news, updates, newsletters etc.) then please send an email to [email protected] to unsubscribe from future correspondence and we will stop sending you this information.

Please note that even if you unsubscribe from marketing communications, you will still continue to receive communications from us that are necessary for the operation of your account.  

7. Contacting You

The Company or its affiliates, business partners, associates or other agents may, from time to time, contact clients by telephone, fax, email, post or otherwise, for the purposes of offering them further information about the Company’s products and services, or to inform them of promotional offerings, or for marketing purposes or to conduct market research.

If the client wishes to opt-out of any further contact at any time and for whatever reason, (s)he is entitled to do so by contacting the Company’s back-office department via email and requesting in writing that the client wishes no further contact in relation to the above reasons.

8. Disclosure and Transfer of your Personal Data

Any personal data or other confidential information (including recordings, documents of a confidential nature, payment details and personal details) that you provide to the Company will be treated as confidential and it will not be disclosed to any third parties, except when necessary to provide you with our services & products, fulfil our contractual obligations and conduct our business operations as described herein. 

Below are the cases under which we may disclose your personal data and why:

Entities and employees within the Company Group, third-party service providers, business partners, associates, affiliates, agents and business introducers are duly informed about the confidential nature of such information and we require that organizations to acknowledge and commit to the confidentiality of your personal data by means of contractual clauses, undertake to respect your right to privacy, safeguard your personal data and to comply with all the relevant data protections laws and this Privacy Policy. 

 9. Safeguard Measures

The Company has implemented physical, technical & organizational measures to secure and protect your personal data from unauthorized access, use or disclosure, unlawful breach or from accidental destruction, loss or damage. The personal data you provide to us is protected in many ways as follows:

While we will use all reasonable efforts to safeguard your personal data, you acknowledge that the transmission of information via the internet is not entirely secure and for this reason we cannot ensure or guarantee the confidentiality, security or integrity of any personal data transferred from you to us, or from us to you via the internet.

This Company shall not be responsible or liable (whether in civil, criminal or otherwise) under any circumstances for any amount or kind of loss or damage (including without limitation, any direct, indirect, punitive or consequential loss or damages, or any anticipated loss of profit, loss of profit, loss of opportunity, loss of data, costs and fines and/or any special or incidental damages of any kind) that may result to you or arising from or connected in any way to cyber-attacks, computer viruses, system failures or malfunctions which may occur in connection with your use of the Company’s products, services, websites, devices, mobile applications, payment channels or any other method.

 10. Storage and Retention Period of your Personal Data

Under the applicable laws and regulations (including anti-money laundering laws), the Company is required to retain all types of records containing client personal data for at least five (5) years after the termination of the business relationship between us and/or as long as one of the following criteria is valid:

However, please note that we may keep your personal data for longer than five (5) years in case for example a dispute arises between the client and the Company, or due to legal / regulatory reasons requiring us to do so. In any case, we will not keep your personal information for any longer than is required. As soon as the purpose has been fulfilled, the Company erases the data or destroys the information carriers on which the data is recorded (e.g. documents in the Company format).

Retention periods will be determined taking into account the type of information that is collected and the purpose for which it is collected, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time. When personal data is no longer necessary for the purpose for which it was collected, we will securely destroy the records.

11. Transfer of Personal Data outside the EEA

EU data protection rules apply to the European Economic Area (EEA) which includes all the EU countries and non-EU countries: Iceland, Liechtenstein and Norway. If necessary, the Company may transfer your personal data to a country outside the EEA, for storage and/or for processing by staff operating outside the EEA who work for the Company Group and/or to our suppliers, business partners, associates, affiliates, agents, business introducers or service providers who are engaged on our behalf to fulfil our contractual obligations under the Client Agreement. Moreover, personal data we collect from you may be stored or processed in a jurisdiction that is different to the country in which the specific entity you are dealing with is registered and established. Therefore, by entering into the Client Agreement with the Company and submitting your personal data, you agree to the transmittal, storing and processing of your personal data outside the EEA.

Nonetheless, when your personal data is transferred outside the EEA, the Company will take all steps reasonably necessary to ensure that the transfer is lawful, that the organization to whom your data are send provides data protection at an adequate level, or provided that receiving Company undertakes sufficient guarantees in accordance with the provisions of the GDPR regulation to ensure that your personal data are treated securely.

Where this is not possible and we are required to disclose your personal data (i.e. because we are required by law or by virtue of a court order in place) we will do this as per the applicable legal and regulatory obligations.

The Company will only send personal data outside the EU/EEA to a country, in relation to which the European Commission has not made a decision regarding the adequacy of its security level and which does not provide the corresponding guarantees, if:

12. Cookies and Links

The Company’s data collection procedures include the placement of cookies for the purpose of gathering information and data about the manner in which our clients interact with the Company’s website(s) in order to provide our clients with a better experience and present our services and products according to your needs and preferences. Cookies are small pieces of data files send from our website(s) to your browser that is stored on the client’s computer when using our website(s) and may include a unique identification number. A cookie in no way gives us access to your computer or any other information about you, other than the information you choose to share with us.

The Company uses cookies on its website(s). The Company does not link the information that it stores in cookies to any personally identifiable information that the client submits while on the Company’s website(s). The client can choose if and how a cookie will be accepted by changing his/her preferences and options in the browser. If the client chooses to disable the cookies, (s)he may still use the Company’s website(s), but (s)he will not be able to access some parts of the Company’s website(s) or fully use his/her customer account. We strongly advise you to read our Cookies Policy in order to fully understand how we use cookies and other web tracking technology via our website(s).

Moreover, it should be noted that some of the Company’s business partners, agents, associates, business introducers or affiliates also use cookies on the Company’s website(s). The Company has no access to, or control over these cookies therefore it will not be liable for misuse of loss of personal data resulting from these cookies. When you use the Company’s website(s), you may be able to link to other websites. This Privacy Policy does not apply to those other sites. The Company encourages you to read and understand the privacy policies on these other sites.

13. Monitoring and Recordings

The Company will, as required by law, monitor and record any form of communication between the Client and the Company, including but not limited to, electronic correspondence (i.e. chats/emails), video calls, fax, postage, telephone conversations, in person or otherwise, in relation to the provision of our services & products and our business relationship with you. The Client accepts such recordings as conclusive evidence of the orders, instructions, requests or conversations so recorded.

14. Your Rights regarding your Personal Data

In line with the provisions and requirements of the GDPR Regulation (679/16) on the protection of personal data, you have the following rights in relation to your personal data:

  1. Processing Restrictions: you have the right to request us to limit the processing or to stop the processing altogether of your personal data for one of the following reasons:

This will not stop us however from storing your personal data and may have an effect on the provision of our services rendered to you and/or may result in account closure.

You can submit your request to make use of the above rights to your personal data by contacting our Data Protection Officer (DPO) through email at the following address: [email protected].

15. Legal Disclaimer

The Company is not liable for the use, misuse or loss of personal data (or otherwise) on the Company’s website(s) or from the content of websites to which the Company’s website(s) links to and the Company has no access or control over the use or protection of information provided by the clients or collected by those sites. Whenever a client elects to link to a co-branded website or to a linked website, the client may be asked to provide registration or other personal data. Please note that such information is recorded by the third party and will be governed by the Privacy Policy of that third party.

The client is responsible for keeping their login credential confidential and not to disclose it to any unauthorized third party. If any person gains access to the client’s account and/or personal data, the Company will not be held responsible or liable for any damage that occurs, or any unlawful or unauthorized use of your personal data due to misuse or misplacement of your login credentials, negligent or malicious intervention (or otherwise) by you or due to your acts or omissions or by a person authorized by you (whether or to that authorization is permitted by the terms of our legal relationship with you).

16. Consent

The collection, use and storage of your personal data is based on your consent. By entering into an agreement with the Company, establishing a customer account and accessing the Company’s website(s), portals or payment gateways, you agree and consent to the collection, use and storage (for at least 5 years from the end of the business relationship) of all the personal data that you supply to the Company by the means described herein. In addition, please note that by downloading the Company’s platform(s) and allowing cookie settings in your web browser also constitutes consent of this Policy. You may revoke your consent at any time however, any personal data processed before the receipt of your revocation will not be affected.

17. Data Protection Officer (DPO)

If you have any questions regarding this Policy, wish to make a complaint or exercise any of your rights in relation to your personal data you may contact our DPO as follows:

Via email at: [email protected]

With registered post at: Upscale Msdn Co. Ltd, Data Protection, Giannou Kranidioti 30, Orphanides Bld., Suite 2, 3rd Floor, flat/office 301-302, 6045 Larnaca, Cyprus .

If you are still not satisfied after having spoken to us, or you are unhappy with the outcome of the complaint, you also have the right to lodge a complaint to the Data Protection Commissioner (which is the supervisory authority/regulator for personal data protection issues in the Republic of Cyprus).

18. Dealer Map, Location and Contact Forms

This section explains the processing that takes place when you use the interactive features of our website.

Dealer map. Our website shows an interactive map of the areas served by our dealers, built with the Leaflet library over map tiles supplied by OpenStreetMap. The map loads only once it is scrolled into view — on the home page, only after you request it — and at that moment your IP address is transmitted to the OpenStreetMap Foundation (United Kingdom), which provides the map tiles, so that the map can be shown to you. This processing is based on our legitimate interest in presenting the dealers responsible for your area (Article 6(1)(f) GDPR). The OpenStreetMap Foundation’s own privacy policy governs that transfer.

Location. If you permit it when your browser asks, the map centres on your approximate location. Your location is used only within your browser to position the map and is held temporarily in your browser’s session storage for the duration of your visit; it is not transmitted to us or stored on our servers. You may decline the browser’s location request and still use the map.

Callback requests. When you ask a dealer to call you back, we process the name, telephone number and any message you provide, together with the identifier of the dealer area you selected, in order to forward your request to the responsible dealer, who then contacts you. The legal bases are the taking of steps at your request prior to entering into a contract and our legitimate interest in putting you in touch with a dealer (Article 6(1)(b) and (f) GDPR).

Dealer applications. When you apply to become a dealer, we process the company name, contact person, country, email address, telephone number, website (where provided) and any message, in order to assess and respond to your application. The legal basis is the taking of steps at your request prior to entering into a contract (Article 6(1)(b) GDPR).

Data submitted through these forms is transmitted over an encrypted (HTTPS) connection and is retained in accordance with the retention periods set out in this Policy. To exercise your rights, or to ask us to delete a submission, please contact our Data Protection Officer as described in section 17.

19. Amendments to this Policy

The Company will review this Policy at least annually, or whenever a material change occurs in the law, or in the Company’s internal procedures/arrangements, or whenever the Company deems it necessary for any reason, and will duly notify its clients of such changes by posting an updated version of this Policy on its website(s). If however, we make material changes or significant we will notify you promptly by other means.

The Client hereby accepts that the posting of an updated Policy on the Company’s website will serve as the actual notice of the Company to its clients. The Company encourages its clients to periodically review this Policy so that they are always aware of what information the Company collects, how it uses it and to whom it may disclose it, in accordance with the provisions of this Policy.