1. Scope

HDC Transfer protects personal data and processes it according to applicable data protection laws.

This policy explains what personal data is collected from visitors, users, and customers of HDC Transfer services (website, app, or other platforms) and for what purpose.

HDC Transfer services are not intended for minors.

2. Controller Contact Details

Controller for data processing under GDPR:

HDC Transfer

223 Link Rd. Tullamarine 3033 Victoria

Email: [info@hdctransfer.com]

3. Data Protection Officer

Data Protection Officer:

HDC Transfer

223 Link Rd. Tullamarine 3033 Victoria

Contact by email at: [info@hdctransfer.com]

4. Data Security

Technical and organizational security measures ensure protection of personal data, including TLS encryption for data transmission.
An encrypted connection is visible by a lock symbol in the browser.

Emails are generally encrypted during transport, but confidentiality cannot be fully guaranteed. For sensitive information, postal mail or PGP-encrypted emails are recommended.

5. Website Use

When visiting HDC Transfer websites, certain data (IP address, pages visited, time, browser details, referrer) is automatically collected and stored in log files to ensure technical functionality, detect issues, analyze use, and prevent misuse.

Stored logs are deleted or anonymized when no longer needed.

Legal basis: GDPR Art. 6(1)(f) (legitimate interest).

For registered users, also GDPR Art. 6(1)(b) (contract performance).

6. Cookies & Similar Technologies

Cookies, pixels, and similar methods may be used to operate the website, enhance user experience, prevent misuse, and for analytics and marketing.
Details are available in the Cookie Policy.

Consent to non-essential cookies is managed through a consent tool and can be withdrawn at any time.

Legal basis: GDPR Art. 6(1)(a) (consent) and Art. 6(1)(f) (legitimate interest for essential cookies).

7. Apps

The HDC Transfer app collects similar data as the website, along with device details (model, OS, app version).

Push notifications are only sent with device consent.

Legal basis: GDPR Art. 6(1)(a) (consent).

8. Social Media & Third-Party Integrations

HDC Transfer maintains pages on platforms like Facebook, LinkedIn, and Instagram.

These platforms handle data under their own policies.

Facebook Connect and Google Customer Match may be used for login or targeted advertising based on consent.

Legal basis: GDPR Art. 6(1)(a) (consent).

9. Registered Use & Ride Bookings

Personal data (name, contact, address, ride details, payment data) is used to manage accounts, fulfill bookings, and handle transportation with third-party providers.

Data may be transferred to countries outside the EU if necessary for the ride.

Legal basis: GDPR Art. 6(1)(b) (contract performance) and Art. 6(1)(f) (legitimate interest).

Optional data (flight number, preferences) is processed with consent under GDPR Art. 6(1)(a).

Ratings may be stored for up to 2 years and shared in anonymized form with drivers or partners.

10. Payments & Fraud Prevention

Payments are processed by certified providers.

HDC Transfer does not store full card details.

Data may be shared with fraud prevention services to prevent misuse.

Legal basis: GDPR Art. 6(1)(b), (f) and, if required, Art. 6(1)(a) (consent).

11. Communication

Contact data from inquiries (email, phone, chat, social media) is processed to handle requests and improve services.

External tools like Intercom may be used.

Legal basis: GDPR Art. 6(1)(a), (b), (f).

12. Newsletters & Marketing

Emails may be sent for marketing if there is explicit consent or existing customer relationships allow it under local laws.

Emails may contain pixels for statistics.

Consent can be withdrawn at any time via unsubscribe link or by contacting HDC Transfer.

Legal basis: GDPR Art. 6(1)(a), (f).

13. Processors & Third-Party Transfers

Third-party processors handle data on behalf of HDC Transfer under strict agreements.

Data may be transferred outside the EU with safeguards like standard contractual clauses or adequacy decisions.

14. Data Subject Rights

Under GDPR, individuals have rights to:

  • Access (Art. 15)
  • Correction (Art. 16)
  • Deletion (Art. 17)
  • Restriction (Art. 18)
  • Objection (Art. 21)
  • Portability (Art. 20)
  • Withdraw consent at any time (Art. 7(3))
  • Lodge complaints with a supervisory authority (Art. 77).

15. Automated Decisions

Automated checks may occur (e.g. fraud checks during payments).

Data subjects can request human review.

16. Data Retention

Personal data is deleted once no longer required by law or for contract purposes.

Retention may extend to meet legal obligations (e.g. tax rules).

17. Updates

This policy may be updated to reflect changes in laws, technology, or services.