Introduction and who we are
KINTO UK respects your privacy. Whether you deal with KINTO UK Limited as a customer, an employee of one of our customers, a consumer, a member of the general public, a partner, supplier, or staff member, you are entitled to the protection of your Personal Data and it is important to us that you always feel safe and informed about how we process your personal data.
KINTO UK is owned by KINTO Europe GmbH and is a Toyota Motor Corporation group company. It offers a complete portfolio of fleet management and funding solutions for passenger and commercial vehicles across corporate, public, not-for-profit and SME sectors. KINTO UK also offers contract hire services for individual consumers under its KINTO One brand. We provide financial products for new and used vehicles utilising Toyota Financial Services (UK) Plc to provide credit underwriting services, and some administration services, on our behalf. KINTO UK is also the flagship group mobility services provider.
In the capacity of an insurance mediator, we introduce various types of insurance when providing our salary sacrifice products to business customers.
In this Privacy Notice (‘Notice’) we describe how we collect, process, share and protect your data. We also describe why we process your Personal Data and the associated choices and rights you have with regards to your Personal Data.
This Notice applies to all processing of your Personal Data across the services we deliver at KINTO UK and all the different platforms we use to deliver those services such as online applications, websites, portals, sales and marketing activity and social media platforms. Data captured and processed if you visit a Toyota dealership (in relation to our KINTO One product) is managed separately and is described below.
We’ve taken a layered approach to inform you how we deal with your data, as we recognise it can all be a little confusing at times. Therefore, this Notice is separated into sections which provide you with more specific and concise information in a particular area. You may also receive a short version of a privacy notice when you provide us with information as a result of a specific transaction.
Our Notice is in accordance with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. Capitalised terms refer to standard terms set out in within the UK General Data Protection Regulation (GDPR).
Who is responsible for the processing of your Personal Data?
KINTO UK Limited of Building 1000, Lakeside North Harbour, Western Road, Portsmouth, PO6 3EN is a Data Controller and responsible for the processing of your data.
However, please note that we also process your data as a Data Processor, dependant on your relationship with us, on behalf of different Data Controllers, such as your employer (if you are a driver), other companies within the Toyota Group who are separate legal entities, the DVLA, authorities who process fines or take enforcement action, short rental companies (if you hire a vehicle on a temporary basis) and insurance companies. These organisations will have their own processes and procedures for handling your data and will provide you with a copy of their privacy notice.
Below is a brief summary of when we are always responsible for processing your Personal Data as Data Controllers:
- When we provide for finance for a vehicle
- When we provide risk management and driver license checking services
- When we obtain your feedback about our products and services for continuous improvement and reporting
Types of personal data we collect, process, store and use
Personal Data means any information that relates to an identified or identifiable individual. We may process, collect, use, and store Personal Data, either from you directly or about you, in a variety of ways, depending on what services we interact with you for. We will only collect and use Personal Data that is relevant to the service or product that we are providing.
The types of personal information that we collect and process are:
Identity and contact data: includes first name, maiden name, last name, title, residential address and status, billing address, delivery address, email address and telephone numbers, driving licence, passport, photographs, utility bill and other means of proving address.
Personal details: age, date of birth, gender, marital status and date of birth.
Housing characteristics: address of housing, housing type, own house or leased, length of stay at this address, rent, charges, classification of housing, valuation details, names of key holders.
Employment data: employment details including employment status, job title, duration, employment address, telephone number, previous employer details, employee number.
Vehicle data: vehicle details including make, model, colour, maintenance and repair history, vehicle registration number, V5 number, chassis number and insurance information.
Nationality: nationality or citizenship, length and / or right of residency.
Financial data: bank account and payment card details, sort code and bank statements, billing and invoice information, payment methods, tax and P11D details, ‘Benefit in Kind’ information.
Financial status: details of salary and other income, savings, money you owe, publicly available and shared credit history including County Court Judgments.
Transaction data: including information about payments to and from you and other details of products and services you have purchased from us.
Technical data: includes device identifiers such as internet protocol (IP) address, username or similar identifier, login data, browser type and version.
Other relevant people: joint product holders, beneficiaries of the product, guarantors and people acting as indemnifiers, other people who benefit from the product or service, emergency contact information/next of kin, additional drivers.
Contact with us: information and records created as a result of your contact with us such as telephone conversations, CCTV footage, postal mail, online contact, contact via app, and including information about how you use our website and apps and contact methods available for our other products and services, contact profiles such as your user name and passwords, purchases and orders made, your interests, preferences, feedback and survey responses.
Our and our partners’ products and services: information and details about your inquiry, application, purchase and use of our products and services or those of our business partners.
Marketing, communication: including information about your preferences to receive specific types of communication including marketing communication from us and any other of your communication preferences, use of media and means of communication, incl. Facebook account, Twitter account, LinkedIn account, Instagram.
Data obtained from third parties: money you owe, publicly available and shared credit history including County Court Judgments, information to check identity, current and historic financial situation including borrowings, loans and outstanding finance, information obtained from Credit Reference Agencies and Fraud Prevention Agencies.
Fraud and crime data: information about fraud or theft and related methods and media, criminal records, driving- related offences and convictions, allegations or advice of criminal activity.
Health: where relevant information about your health, for example if you are a vulnerable customer or you have medical restrictions on your driving licence.
Special categories of Personal Data
Special Categories of Personal Data include details about race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about health and genetic and biometric data. We will process Special Categories of Personal Data only where relevant and if necessary and as we may be permitted under law, in particular in the following circumstances:
- With your explicit consent.
- Where we need to carry out our legal obligations.
- Where it is needed in the public interest, or if you are a vulnerable customer, or for equal opportunities monitoring and in line with this Privacy Notice.
Less commonly, we may process this type of information where it is needed in relation to legal claims or where it is needed to protect your interests (or someone else's interests) and you are not capable of giving your consent, or where you have already made the information public.
Criminal convictions and investigation
We will collect information about criminal and fraudulent investigations and convictions where it is relevant and appropriate to do so.
We, or fraud prevention agencies, may enable law enforcement agencies to access and use your personal information including information about criminal activity to detect, investigate and prevent crime.
From other third parties
As we are often the registered keepers of our leased vehicles, we may be provided with information about you from external third parties, such as the DVLA, government enforcement agencies and insurance companies. We may also be required to provide information about you in relation to incidents or offences that have been committed when your vehicle or your company vehicle was / is in your custody.
Enforcement information: speeding, parking and other driving offence notifications are sent to us as the registered keepers of the vehicles. These notifications may contain information about you, including your vehicle registration and details of the offence itself. We may need to pass on your details to the appropriate authorities when not all information is known to them.
Driving incident information: if you are involved in an incident in your vehicle, we may be provided with information about you, and the incident itself, by insurance companies. This could be from both your employer’s insurance company, and / or any involved third party’s insurance company.
Service Providers: Some of our service providers collect your personal data directly from you. The service provider may then pass your personal data to us to enable us to manage your account.
Connected Services: Connected services and / or in-vehicle apps collect your personal data independently from us and do not pass the information gathered to us. The collection and processing of your personal data is subject to separate privacy policies that you will be asked to consent to through the connected service or in-vehicle app.
When you apply to work with us
If you apply for a job with us, your information will be shared with Toyota Financial Services (UK) Plc (TFS UK). TFS UK provide us with HR services, so it is necessary for them to process your data to facilitate job applications. We remain the Data Controller of this data and TFS UK are appointed by us to provide these services as a Data Processor.
There may be third parties involved in a job application process, such as recruitment agencies or job recruitment websites. They will have their own privacy notices and we advise you to visit their websites to check how they will use your Personal Data too. When a candidate applies for a role with KINTO UK and they are successful, we have a specific Employee Privacy Notice which we will provide to you when you join us.
Keeping your personal data accurate and up-to-date
It is important for us to maintain accurate and up-to-date records of your Personal Data. Please inform us of any changes to or errors in your Personal Data as soon as possible by contacting us using the information under the ‘Contact Us’ heading on our website. We will take reasonable steps to make sure that any inaccurate or outdated Personal Data is deleted or amended accordingly.