Privacy Policy (last update 01/09/2026)

 

If you are reading this document (“Privacy Policy”), it is because you are visiting this website and/or application, or otherwise interacting with us.

This Privacy Policy is drafted pursuant Article 13 of the EU Regulation 679/2016 (hereinafter “GDPR”) and applicable data protection law and provide you some examples of how we process personal data (“Personal Data” or “Data”). You can find definitions and more detailed explanations at the end of this Privacy Policy for the capitalized terms herein.

 

Please be aware that all marketing and customer relationship management activities are performed by Stellantis Europe S.p.A, C.so G. Agnelli 200, 10135 Turin, Italy.

They perform these activities for all companies in the Stellantis group, as an independent controller.

If you want to understand how your personal data will be processed by Stellantis Europe S.p.A. for these purposes, please refer to the privacy policy of Stellantis Europe S.p.A. directly.

1. Who we are
 
 

The Data controller of your Personal Data is:

Stellantis UK Limited, having its registered office in Pinley House, 2 Sunbeam Way, Coventry, CV3 1ND, England / Vauxhall Motors Limited, having its registered office in Pinley House, 2 Sunbeam Way, Coventry, CV3 1ND, England (“we”, “us”).

We are a member of the Stellantis group.

2. What data we collect and process
 
 

When you use this website or app or otherwise interact with us, the following personal data or categories of personal data will be processed about you:

  • Identification data such as name, surname, date of birth;
  • Contact details such as e-mail address, telephone number, address;
  • Financial data, e.g. bank data, if applicable.

4. Why we process your Data and legal basis

 

 

Your Data serves the following purposes:

a) To sell you the vehicle you have chosen to purchase, as required to perform our contractual obligations to you

b) To facilitate payment, as necessary to perform the contract we have entered into with you;

c) To perform credit checks because it is in our legitimate interests’ to do so or, based on your consent, depending on which country you are located in

 

 

 

d) To perform any activities that we are required to perform by virtue of any local regulator (financial or otherwise) as required to comply with legal obligations that we are subject to.
5. How we use your Data (method of processing)
 
 

Data collected for the purposes indicated above are processed both manually and via automated processing.

Use of Artificial Intelligence tools

Some processing activities may also be supported by Artificial Intelligence (“AI”) systems, exclusively for the purposes described in this Policy (e.g., detecting anomalies, improving our products and Services, supporting customer interactions – e.g. chatbot, analysing aggregated or pseudonymized data).

AI systems are used in accordance with the principles of applicable regulations and in line with our internal policies and procedures. AI-based processing is always subject to appropriate human oversight and does not result in fully automated decisions producing legal or similarly significant effects on you, unless permitted by law and accompanied by adequate safeguards.

6. How we may disclose your Data
 
 
 

We may disclose your Data to the following recipients and/or categories of recipients (“Recipients”):

Persons authorized by us to perform any of the data-related activities described in this document: our employees and collaborators who have undertaken an obligation of confidentiality and abide by specific rules concerning the processing of your Data;

Our Data Processors: external subjects to whom we delegate some processing activities. For example, security systems providers, data hosting providers, etc. We have signed agreements with each of our Data Processors to ensure that your Data is processed with appropriate safeguards and only under our instructions;

System administrators: our employees or those of Data Processors to whom we have delegated the management of our IT systems and are therefore able to access, modify, suspend or limit the processing of your Data. These subjects have been selected, adequately trained and their activities tracked by systems they cannot modify, as provided for by the provisions of our competent Supervisory Authority;

Third parties with whom you authorize us to share your Data: where you instruct us to share your Personal Data with specific third parties selected by you. Such recipients will process your Personal Data as autonomous Data Controllers in accordance with their own privacy notices;

Selected professionals (e.g., lawyers, accountants) when necessary to protect our rights and interest or to comply with legal obligations;

- Within the context of extraordinary transactions (merger and acquisitions) that may concern us, we may disclose your Data to third parties such as advisors, stakeholders, lawyers, accountants, for organizational purposes;

Other companies of Stellantis group, for organizational or security reasons, or when it is necessary to protect our rights and interest or to comply with legal obligation;

- Law enforcement or any other authority whose provisions are binding for us: this is the case when we have to comply with a judicial order or law or defend ourselves in legal proceedings.

7. Where your Data is located
 
 

We are a global company and our products and Services are available in multiple jurisdictions worldwide. This means that your Data may be stored, accessed, used, processed, and disclosed outside your jurisdiction, including within the European Union, the United States of America, or any other country where our Data Processors and sub-processors, or the third parties to whom we can disclose your Data, are located, or where their servers or cloud computing infrastructures may be hosted. We take steps to ensure that the processing of your Data by our Recipients is compliant with the applicable data protection laws, including EU law to which we are subject. Where required by EU data protection law, transfers of your Data to Recipients outside of the EU will be subject to adequate safeguards (such as the relevant EU standard contractual clauses for data transfers between EU and non-EU countries), and/or other legal basis according to the EU legislation. For more information about the safeguards implemented by us to protect Data transferred to third countries outside the EU, please write to us at: dataprotectionofficer@stellantis.com.

 

8. How long we retain your Data
 
 

Data processed for the purposes indicated above will be retained for the period deemed strictly necessary to fulfil such purposes. However, the Data might be stored for a longer period in case of potential and/or actual claims and resulting liabilities and/or in case of other mandatory legal retention requirement and/or storage obligations. In particular, for each purpose indicated at the paragraph 4 above are listed below:

 

Purpose

Retention Period

a) Ease the collection and correction of your Data

Same retention period as the longest retention period applicable to the other purposes described in this Privacy Policy, as this processing is ancillary to such purposes.

b) Providing our Services and related support, organizing and managing Our Events

Services: 10 years after termination of the relevant contractual relationship. Requests: until the relevant request has been fully handled and any limitation period is expired in case of complaints. Events: until all activities relating to the organization, administration and follow-up of the relevant Event have been completed.

c) Sending you promotional communications

For a maximum of 10 (ten) years from the moment the data subject has given his/her consent to the processing. This retention period has been defined also in accordance with the authorization of the Data Protection Authority.

d) Detecting anomalies and improving our Services

Data will be retained until we provide you the Services.

e) Excluding you from irrelevant promotional communications

Same retention period as marketing activities under letter c).

f) Analysing your preferences and behaviours in order to customize our Services and communications

Website: as specified in the Cookie Policy. Personalized communications: same retention period as letter c). Service improvement activities: same retention period as letter g).

g) Analysing and improving our products and Services

For the period strictly necessary to achieve these purposes and, in any event, no longer than 3 years from collection. Aggregated or anonymized data may be retained for longer periods.

h) Sharing Data with Partners for their own marketing purposes

Data are not retained by us for this purpose, unless processed for other purposes described in this Privacy Policy.

i) Complying with legal and tax obligations

For the period required by applicable laws and regulations.

j) Sending corporate and institutional communications

10 years from collection, unless the data subject objects to the processing.

k) Sending surveys related to our Services

10 years from collection, unless the data subject objects to the processing.

l) Protecting our rights and interests

For the duration of any relevant legal, regulatory or administrative proceeding and for as long as necessary to protect our rights or interests.

m) Statistical purposes

For the period strictly necessary to achieve the statistical purposes pursued and, in any event, no longer than 3 years from collection. Aggregated or anonymized statistical information may be retained for longer periods.

Once the relevant retention period/criterion has expired, your Data is erased or fully and irreversibly anonymized pursuant to our retention policy.

9.   1.   How to control your Data and manage your choices
 

At any time, you can ask to:

Access your Data (right of access): depending on your use of our Services, we will provide the Data we have about you, such as your name, age, contact detailsand preferences expressed, together with the Privacy Policy you received when you provided them; 

Exercise your right to portability of your Data (right to data portability): according to your use of our Services, we will provide you with an interoperable file containing the Data we have about you.

Correct your Data (right to rectification): for example, you can ask us to modify your e-mail address or telephone number if they are incorrect;

Limit the processing of your Data (right to restriction of processing): for example, when you think that the processing of your Data is unlawful or that processing based on our legitimate interest is not appropriate;

Delete your Data (right to erasure): for example, when you do not want to use our Services and may not want us to retain your Data any longer;

Object the processing activities (right to object);

Withdraw your consents (right to withdrawal). 

You can exercise any of the above rights or express any concern or make a complaint regarding our use of your Data directly at: https://privacyportal.stellantis.com.

At any time, you may also:

9. Complaint

You are important to us and so is protecting your personal information. We take any complaints we receive from you about our use of your personal information very seriously and request that you bring any issues to our attention. You have a statutory right to raise a complaint if you are dissatisfied about the way we have handled your personal data. If you believe that we have failed to comply with our obligations under data protection laws, you may submit your complaint by email to dataprotectionuk@stellantis.com.

We will acknowledge receipt of your complaint within 30 days. We will then investigate your concerns, which may involve seeking further information from you. When our investigation has concluded we will provide you with a written response explaining the outcome of your complaint.

If you remain dissatisfied, with our use of your personal data or our response to your complaint, then you have the right to complain the UK’s data protection authority the Information Commissioner’s Office (ICO) at: www.ico.org.uk

10. How we protect your Data
We take reasonable precautions from a physical, technological and organizational point of view to prevent the loss, misuse, or modification of Data under our control. 
11. Changes to the Privacy Policy
We reserve the right to adapt and/or change this Privacy Policy at any time. We will inform you of any substantial adaptations/changes. In any case, we have included the date of the last update at the beginning of this Privacy Policy.
12. License

 

The icons illustrated in this Policy are “Data Protection Icons” by Maastricht University European Centre on Privacy and Cybersecurity (ECPC) CC BY 4.0.

13. Definitions

Data Controller: refers to the legal person, public authority, service or other entity which, individually o jointly with others, determines the purposes and means for processing your Personal Data.

Data Processor: refers to an entity that we engage to process your Personal Data solely on behalf of the Data Controller and pursuant to its instructions.

Personal Data: means any information relating to an identified or identifiable natural person whether directly or indirectly. For example, a telephone number or IP addresses are considered personal data. For your convenience, we will collectively refer to all personal data mentioned also as “Data”.

Recipient: refers to a natural or legal person, public authority, agency or other body, to which the personal data are disclosed, whether a third party or not.