The following data points are collected from each vehicle tracked by Höldur ehf. through services provided by a Telematics Service Provider:-  position, speed, acceleration, impact data (location, g-force and direction of impact) and the identifier of the device in the vehicle.

This data is collected for the following reasons: -

• Detection and prevention of loss or theft of the company vehicles

• Management of insurance claims

• Identification of unauthorised vehicle movements

• Monitoring vehicle use in relation to safety and public welfare

• Management of vehicle inventory

The Telematics Service Provider uses data hosting service providers in Europe to host the information it collects, and use technical measures to secure data.

The Telematics Service Provider and EC will adhere to the following obligations under GDPR law:-

The Telematics Service Provider will only process personal data in accordance with EC’s written instructions (including when making an international transfer of personal data) unless required to do so by law.

The Telematics Service Provider will ensure that people processing the data are subject to a duty of confidence and will take appropriate measures to ensure the security of processing.

The Telematics Service Provider will only engage a sub-processor with the prior consent of the data controller and a written contract.

The Telematics Service Provider will assist EC in providing subject access and allow data subjects to exercise their right under GDPR.

The Telematics Service Provider will assist EC in meeting its GDPR obligations in relation to the security of processing, the notification of personal data breaches and data protection impact assessments.

The Telematics Service Provider will delete or return all personal data to Höldur ehf as requested at the end of the contract.

The Telematics Service Provider will submit to audits and inspections, provide Höldur ehf with whatever information it needs to ensure they are both meeting their Article 28 obligations, and tell EC if it is asked to do something infringing the GDPR or other data protection law of the EU or a member state.

This processing, for the purpose of protecting the integrity of our fleet, is based on our legitimate interests.