Privacy Policy

PRIVACY NOTICE

Use of CDK Global website and associated pages

CDK Global (UK) Limited and its subsidiaries and affiliates (hereinafter CDK or we) are committed to protecting the privacy and security of your Personal Information collected or generated in connection with your relationship with CDK (“Personal Information”). 

CDK is a Data Controller which means that we are responsible for deciding how we may collect and use personal information you provide to us either directly or through the use of our website and HTML based emails. This notice explains our practices with regard to your Personal Information and how we comply with the General Data Protection Regulation (EU) 2016/679 (GDPR).

CDK is made up of various legal entities trading in different countries. These entities are all ultimately controlled by the same entity – CDK Global, LLC.  When you provide information through our website, you will be providing it to CDK as a whole. Your information may be stored in and accessed from countries outside of the EEA whose laws provide various levels of protection for personal data, not always equivalent to the level of protection that may be provided in your own country. CDK have taken steps through the implementation of model clauses between CDK legal entities and contractual requirements with third parties to ensure an adequate level of protection.

Personal Information means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).  There are "special categories" of more sensitive personal data which require a higher level of protection, such as information about a person's health or sexual orientation. The term process used in in this Privacy Notice means any operation performed upon Personal Information, whether or not by automated means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure or dissemination, transfer, sharing and erasure or destruction.

  1. Personal Information Processed

We process your Personal Information through automated and paper-based data processing systems and have established routine processing functions (such as processing for provision of product information and provision of services). 

We will collect, store, and use the following categories of Personal Information about you:

Category

Personal Information

Personal

First name
Middle name
Last name
Title
User account or authentication data
Email address
Phone numbers

Work Contact Details

Company name
Company address
Company telephone number
Company mobile phone number
Email address
Phone numbers

Role Details

Position overview
Position details
Position, title and reporting information
Full time equivalency information



  1. Purposes For Processing Personal Information

We will only use your Personal Information when the law allows us to. Most commonly, we will use your Personal Information in the following circumstances:

  • To provide information (such as brochures requested), support and to process general enquiries you my make through our website;
  • Where we need to comply with a legal obligation;
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;


We processes your Personal Information for the following purposes:

Purposes for processing Personal Information

Marketing, Provision of product and company information and updates

Delivery of service bulletins and product information and related information to customer contacts

Legal and regulatory compliance, litigation, investigations, and risk management (including systems for storage of legal work products, documents and information);

Other legal and customary business-related information, such as making back-up copies of files for business continuity, as needed for computer system maintenance and other everyday human resource purposes;

Personal Information collected through its internal websites, including without limitation in connection with subscriptions for newsletters, downloads of materials and registration for products and services, including online and offline Personal Information pertaining to prospective, current and former customer contacts;

Data processed by CDK’s threat management platform and its related technologies and procedures that will provide advanced prevention, detection, response and intelligence capabilities to protect CDK and the employee data it processes;

Systems enabling collaboration, including document sharing;

Systems for storage and distribution of internal emails and archiving historical data;

Business operations purposes, including maintaining records related to mergers, acquisitions, reorganizations, sales, distributions, dispositions, financial management and reporting;

Statistical analysis of website traffic, including the use of Cookies.


We may be required to disclose your Personal Information in response to lawful requests by public authorities to comply with national security or law enforcement requirements.

We will only use your Personal Information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your Personal Information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your Personal Information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

  1. Cookies

What are Cookies and how are they used?

Cookies are small strings of text that web sites can send to your browser. Cookies cannot retrieve any other data from your hard drive or obtain your e-mail address. If you are simply browsing a CDK informational site, a cookie may be used to identify your browser as one that has visited the site before. The CDK website uses cookies to collect information about how our site is used and to save and remember any preferences that may have been set.

We may also make use of memory-based cookies in support of authenticating a user of certain CDK web applications. If you are a registered user of a site providing service to CDK clients (and have a user ID and password), we may use cookies so that we can provide personalized information based on preferences you have indicated while using the site.

Although you have the ability to modify your browser to either accept all cookies, notify you when a cookie is sent, or reject all cookies, it may not be possible to utilize CDK services which require registration if you reject cookies.

To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org. The following explains the different types of cookies that CDK websites use and their purpose:

Provider

Purpose

Google Analytics
Cookie name:  _utma _utmb _utmc _utmz

Used to collect information in an anonymous form about how visitors use our site including; number of visitors, where visitors have come to the site from and the pages visited.

Marketing Cookie
Cookie name: PARDOT

When you first visit a website that uses the Pardot system, a third party cookie from pardot.com is stored in your browser which tracks the pages you visit during your session. The information collected by this cookie on our website is visible only to CDK, and is not shared with any third parties including Pardot or other users of the Pardot system.

The cookie does not contain any personal information but if you choose to fill out a form on our site then we will link your personal information to the browsing information associated with the Pardot cookie on your browser.

Information collected is used to personalize our service to you (for example by choosing how we communicate with you (subject to your consent) and tailoring the content of any communications to you to include information that reflects the interest that you have shown in the content of our web pages, or by choosing offers or promotions that we think may interest you and to improve how we respond to your needs.


More Cookies Information 

Click here for an overview of privacy at Google

To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout .

  1. Other Sites

CDK sites may contain links to other sites, including those of our business partners. While we seek to link only to sites that share our high standards and respect for privacy, we are not responsible for the privacy practices employed by other sites.

  1. Disclosure to Third Parties

We may disclose your Personal Information:

  • to our affiliates for the purposes listed above,
  • to other data processors who use the data only for CDK’s purposes and under CDK’s instructions,
  • where required/permitted by law, such as with your consent,  in the event of an emergency or to comply with internal (e.g. disclosures to shareholder’s) and statutory (e.g. HMRC) reporting requirements.
  • to an acquiring organization if CDK is involved in a sale or a transfer of some or all of its business (anonymised data preceding sale). 

We may disclose your Personal Information to the categories of third parties listed above for the following purposes:

Purposes for disclosing Personal Information to third parties

Customer relationship management;

Communication including email addresses and mobile devices;

Legal and regulatory compliance, litigation, investigations, and risk management (including systems for storage of legal work products, documents and information);

Other legal and customary business-related information, such as making back-up copies of files for business continuity, as needed for computer system maintenance;

Personal Information collected through its internal websites, including in connection with subscriptions for newsletters, downloads of materials and registration for products and services, including online and offline Personal Information pertaining to prospective, current and former customers;

Data processed by CDK’s threat management platform and its related technologies and procedures that will provide advanced prevention, detection, response and intelligence capabilities to protect CDK and the employee data it processes;

Systems enabling collaboration, including document sharing;

Systems for storage and distribution of internal emails and archiving historical data;

Business operations purposes, including maintaining records related to mergers, acquisitions, reorganizations, sales, distributions, dispositions, financial management and reporting;



Our third-party service providers and other entities in the group are required to take appropriate security measures to protect your Personal Information in line with our policies. We do not allow our third-party service providers to use your Personal Information for their own purposes. We only permit them to process your personal data for specified purposes and in accordance with our instructions.

  1. Transferring Personal Information Outside The EU

Due to the global nature of our business, your Personal Information may be transferred across national borders, including to the United States. We transfer Personal Information we collect about you to those countries included in the table below. We only transfer Personal Information that is necessary for us to fulfil our obligations as an employer in order to perform our contract with you. We have stated where an adequacy decision by the European Commission in respect of each country has been provided which means that country provides an adequate level of protection for your Personal Information.

Where there is no adequacy decision, we have put in place additional measures to ensure that your Personal Information receives an adequate level of protection and is treated in a way that is consistent with and which respects EU laws on data protection.


Country receiving Personal Information

Adequacy Decision/Security Measures

United States of America

EU – US Privacy Shield. To view CDK’s certification under Privacy Shield, please visit http://www.privacyshield.gov/list.  



  1. Data Security

We have put in place measures to protect the security of your information. Third parties will only process your Personal Information on our instructions and where they have agreed to treat the information confidentially and to keep it secure.

In addition, we limit access to your Personal Information to those employees, affiliates, agents, contractors and other third parties who have a business need to know. They will only process your Personal Information on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach and will notify you and the appropriate regulator where applicable.

  1. Data Retention

We will only retain your Personal Information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements and subject to our retention policy. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances we may anonymize your Personal Information so that it can no longer be associated with you, in which case we may use such information without further notice to you. Once you are no longer a customer of the company we will retain and securely destroy your Personal Information in accordance with our data retention policy and any applicable laws and regulations.

  1. Rights of Access, correction, deletion and restriction

Under certain circumstances, by law you have the rights listed below in relation to your Personal Information. You will not usually have to pay a fee to access your Personal Information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it.

If you would like to make a data subject request please use the following contact details: privacy@cdkglobal.com

Request access to your Personal Information (commonly known as a "data subject access request"). This enables you to receive a copy of the Personal Information we hold about you and to check that we are lawfully processing it.
Your right to access your Personal Information may be limited or denied where the burden or expense of providing access would be disproportionate to the risks to your privacy in question, or when such access would:

  • compromise confidential commercial information;
  • interfere with the execution or enforcement of the law or with private causes of action including the prevention, investigation or detection of offenses or the right to a fair trial;
  • violate the legitimate rights or important interests of others;
  • breach a legal or other professional privilege or obligation;
  • prejudice employee security investigations or grievance proceedings or in connection with employee succession planning or corporate re-organizations;
  • prejudice the confidentiality necessary in monitoring, inspection or regulatory functions connected with sound management, or in future or ongoing negotiations involving CDK. 


Request correction of the Personal Information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected. Please note that you have a shared responsibility with regard to the accuracy of your Personal Information.  When updating your Personal Information, you must provide truthful, complete and accurate information.  

Request deletion of your Personal Information. This enables you to ask us to delete or remove Personal Information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Information where you have exercised your right to object to processing (see below).

Object to processingof your Personal Information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your Personal Information for direct marketing purposes.

Request the restriction of processing of your Personal Information. This enables you to ask us to suspend the processing of Personal Information about you, for example if you want us to establish its accuracy or the reason for processing it.

Request the transfer of your Personal Information to another party.

Right to withdraw consent: In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your Personal Information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact privacy@cdk.com. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

  1. Choice

If your Personal Information is:

  • to be disclosed to a third party (other than CDK’s agent acting on CDK’s behalf), or
  • to be used for a purpose that is materially different from the purpose for which it was originally collected or subsequently authorized,

CDK will inform you and give you a chance to object to such disclosure or use (opt-out).  

If such information is sensitive Personal Information, CDK will only disclose it to a third party (other than CDK’s agent acting on CDK’s behalf) or use it for a purpose that is materially different from the purpose for which it was originally collected or subsequently authorized after you have given your consent affirmatively and explicitly (opt-in).  However, your opt-in is not required in the rare occasions when the disclosure of the sensitive Personal Information is:

  • in the vital interests of you or another person;
  • necessary for the establishment of legal claims or defenses;
  • required to provide medical care or diagnosis;
  • necessary to carry out the organization’s contractual obligations, or
  • related to Personal Information that is manifestly made public by you.

  1. Complaints

CDK commits to resolving complaints about you privacy rights in a timely manner.  If you believe that your Personal Information has not been handled in accordance with the CDK Global Privacy Policy (including the Addendum), or applicable laws, you may submit a complaint by email to privacy@cdk.com

If your complaint is not satisfactorily addressed by CDK, you may file a complaint to the DPA in the country where you work for CDK.  The contact information of the DPAs may be found at http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm. CDK has committed to cooperate with EU data protection authorities (DPAs) and to comply with the advice given by such authorities with regard to your Personal Information in the context of the employment relationship. Additionally, with respect to Personal Information transferred from the EU to the U.S. pursuant to the Privacy Shield, CDK is also subject to the investigatory and enforcement powers of the United States Federal Trade Commission.

If you have any questions about CDK’s Global Privacy Policy (including the Addendum), or your privacy rights under the Privacy Shield principles or other applicable laws, you may contact your local Human Resources manager by email or by phone, or send an email to privacy@cdk.com.

  1. Changes To This Privacy Notice

We reserve the right to update this privacy notice at any time, updated versions of the notice will be published on our website.. We may also notify you in other ways from time to time about the processing of your Personal Information.

  1. Contacting your account manager

If you have any questions about this privacy notice, please contact your account manager in the first instance or alternatively by emailing privacy@cdk.com.

Last updated 7th August 2018