Loading AutoGo…
Please book at least 1 hour in advance— this gives our CarHosts time to prepare your vehicle.
Loading AutoGo…
Last updated: June 1, 2024
AutoGo is committed to protecting the privacy and rights of individuals in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page explains how we comply with GDPR requirements and how you can exercise your rights under the regulation.
This policy applies to all individuals located in the European Economic Area (EEA) whose personal data is processed by AutoGo.
The data controller responsible for your personal information is:
If you have any questions about how we handle your data, please contact our Data Protection Officer (DPO) at dpo@autogo.africa.
Under GDPR, we process your personal data based on the following legal grounds:
As a data subject in the EEA, you have the following rights under GDPR:
You have the right to request confirmation of whether we process your data and obtain a copy of your personal information.
You have the right to request correction of inaccurate or incomplete personal data.
Also known as the "right to be forgotten," you can request deletion of your personal data when it is no longer necessary for the purpose it was collected.
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of your data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
You have the right to object to processing based on legitimate interests, including profiling and direct marketing.
You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you.
To exercise any of your GDPR rights, please submit a request through one of the following methods:
We will respond to your request within 30 days, as required by GDPR. We may need to verify your identity before processing your request. There is no charge for exercising your rights, though we may charge a reasonable fee for repetitive or manifestly unfounded requests.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Until account deletion + 90 days | Legal obligations, dispute resolution |
| Booking Records | 6 years after booking | Tax and accounting requirements |
| Payment Information | 3 years after last transaction | Anti-fraud, financial audits |
| Communication History | 2 years | Customer service, dispute resolution |
| Usage Analytics | 2 years | Service improvement (anonymized after 6 months) |
We have Data Processing Agreements (DPAs) in place with all third-party service providers who process personal data on our behalf, including:
These agreements ensure that all processors comply with GDPR requirements and implement appropriate technical and organizational measures.
When we transfer personal data from the EEA to countries outside the EEA, we ensure appropriate safeguards are in place:
Our primary data processing infrastructure is located in the EU and Kenya. Transfers to Kenya are governed by SCCs and appropriate supplementary measures.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify:
Our incident response team follows a documented breach management procedure to contain, assess, and remediate any data security incidents.
If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so we can attempt to resolve your concerns.
For Kenya residents, you may also contact the Office of the Data Protection Commissioner (ODPC).
For all GDPR-related inquiries, please contact our Data Protection Officer:
