Privacy Policy (last update 01/09/2026)

 

If you are reading this document (“Privacy Policy”), it is because you are visiting this website and/or application, or otherwise interacting with us.

This Privacy Policy is drafted pursuant Article 13 of the EU Regulation 679/2016 (hereinafter “GDPR”) and applicable data protection law and provide you some examples of how we process personal data (“Personal Data” or “Data”). You can find definitions and more detailed explanations at the end of this Privacy Policy for the capitalized terms herein.

Please be aware that all marketing and customer relationship management activities are performed by Stellantis Europe S.p.A, C.so G. Agnelli 200, 10135 Turin, Italy.

They perform these activities for all companies in the Stellantis group, as an independent controller.

If you want to understand how your personal data will be processed by Stellantis Europe S.p.A. for these purposes, please refer to the privacy policy of Stellantis Europe S.p.A. directly.

 
 

1. Who we are

 

The Data controller of your Personal Data is:

Stellantis UK Limited, having its registered office in Pinley House, 2 Sunbeam Way, Coventry, CV3 1ND, England / Vauxhall Motors Limited, having its registered office in Pinley House, 2 Sunbeam Way, Coventry, CV3 1ND, England (“we”, “us”).

We are a member of the Stellantis group.

 
 

2. What data we collect and process

 

When you use this website or app or otherwise interact with us, the following personal data or categories of personal data will be processed about you:

  • Identification data such as name, surname, date of birth;

  • Contact details such as e-mail address, telephone number, address;

  • Financial data, e.g. bank data, if applicable.

 

3. Why we process your Data and legal basis
 
Your Data serves the following purposes:
 

a) To sell you the vehicle you have chosen to purchase, as required to perform our contractual obligations to you

 

b) To facilitate payment, as necessary to perform the contract we have entered into with you;

 

c) To perform credit checks because it is in our legitimate interests’ to do so or, based on your consent, depending on which country you are located in

 
d) To perform any activities that we are required to perform by virtue of any local regulator (financial or otherwise) as required to comply with legal obligations that we are subject to.
 
 

4. How we use your Data (method of processing)

 

Data collected for the purposes indicated above are processed both manually and via automated processing.

Use of Artificial Intelligence tools

Some processing activities may also be supported by Artificial Intelligence (“AI”) systems, exclusively for the purposes described in this Policy (e.g., detecting anomalies, improving our products and Services, supporting customer interactions – e.g. chatbot, analysing aggregated or pseudonymized data).

AI systems are used in accordance with the principles of applicable regulations and in line with our internal policies and procedures. AI-based processing is always subject to appropriate human oversight and does not result in fully automated decisions producing legal or similarly significant effects on you, unless permitted by law and accompanied by adequate safeguards.

 
 

5. How we may disclose your Data

 

We may disclose your Data to the following recipients and/or categories of recipients (“Recipients”):

  • Persons authorized by us to perform any of the data-related activities described in this document: our employees and collaborators who have undertaken an obligation of confidentiality and abide by specific rules concerning the processing of your Data;

  • Our Data Processors: external subjects to whom we delegate some processing activities. For example, security systems providers, data hosting providers, etc. We have signed agreements with each of our Data Processors to ensure that your Data is processed with appropriate safeguards and only under our instructions;

  • System administrators: our employees or those of Data Processors to whom we have delegated the management of our IT systems and are therefore able to access, modify, suspend or limit the processing of your Data. These subjects have been selected, adequately trained and their activities tracked by systems they cannot modify, as provided for by the provisions of our competent Supervisory Authority;

  • Third parties with whom you authorize us to share your Data: where you instruct us to share your Personal Data with specific third parties selected by you. Such recipients will process your Personal Data as autonomous Data Controllers in accordance with their own privacy notices;

  • Selected professionals (e.g., lawyers, accountants) when necessary to protect our rights and interest or to comply with legal obligations;

  • Within the context of extraordinary transactions (merger and acquisitions) that may concern us, we may disclose your Data to third parties such as advisors, stakeholders, lawyers, accountants, for organizational purposes;

  • Other companies of Stellantis group, for organizational or security reasons, or when it is necessary to protect our rights and interest or to comply with legal obligation;

  • Law enforcement or any other authority whose provisions are binding for us: this is the case when we have to comply with a judicial order or law or defend ourselves in legal proceedings.

 
 
6. Where your Data is located
 
We are a global company and our products and Services are available in multiple jurisdictions worldwide. This means that your Data may be stored, accessed, used, processed, and disclosed outside your jurisdiction, including within the European Union, the United States of America, or any other country where our Data Processors and sub-processors, or the third parties to whom we can disclose your Data, are located, or where their servers or cloud computing infrastructures may be hosted. We take steps to ensure that the processing of your Data by our Recipients is compliant with the applicable data protection laws, including EU law to which we are subject. Where required by EU data protection law, transfers of your Data to Recipients outside of the EU will be subject to adequate safeguards (such as the relevant EU standard contractual clauses for data transfers between EU and non-EU countries), and/or other legal basis according to the EU legislation. For more information about the safeguards implemented by us to protect Data transferred to third countries outside the EU, please write to us at: dataprotectionofficer@stellantis.com.
 
 
7. How long we retain your Data
 
 

8. How to control your Data and manage your choices

 

At any time, you can ask to:

  • Access your Data (right of access): depending on your use of our Services, we will provide the Data we have about you, such as your name, age, contact detailsand preferences expressed, together with the Privacy Policy you received when you provided them;

  • Exercise your right to portability of your Data (right to data portability): according to your use of our Services, we will provide you with an interoperable file containing the Data we have about you.

  • Correct your Data (right to rectification): for example, you can ask us to modify your e-mail address or telephone number if they are incorrect;

  • Limit the processing of your Data (right to restriction of processing): for example, when you think that the processing of your Data is unlawful or that processing based on our legitimate interest is not appropriate;

  • Delete your Data (right to erasure): for example, when you do not want to use our Services and may not want us to retain your Data any longer;

  • Object the processing activities (right to object);

  • Withdraw your consents (right to withdrawal). 

 
You can exercise any of the above rights or express any concern or make a complaint regarding our use of your Data directly at: https://privacyportal.stellantis.com.
 

At any time, you may also:

9. Complaint
 

You are important to us and so is protecting your personal information. We take any complaints we receive from you about our use of your personal information very seriously and request that you bring any issues to our attention. You have a statutory right to raise a complaint if you are dissatisfied about the way we have handled your personal data. If you believe that we have failed to comply with our obligations under data protection laws, you may submit your complaint by email to dataprotectionuk@stellantis.com.

We will acknowledge receipt of your complaint within 30 days. We will then investigate your concerns, which may involve seeking further information from you. When our investigation has concluded we will provide you with a written response explaining the outcome of your complaint.

If you remain dissatisfied, with our use of your personal data or our response to your complaint, then you have the right to complain the UK’s data protection authority the Information Commissioner’s Office (ICO) at: www.ico.org.uk

10. How we protect your Data
 
We take reasonable precautions from a physical, technological and organizational point of view to prevent the loss, misuse, or modification of Data under our control. 
11. Changes to the Privacy Policy
 
We reserve the right to adapt and/or change this Privacy Policy at any time. We will inform you of any substantial adaptations/changes. In any case, we have included the date of the last update at the beginning of this Privacy Policy.

12. License

 

The icons illustrated in this Policy are “Data Protection Icons” by Maastricht University European Centre on Privacy and Cybersecurity (ECPC) CC BY 4.0.

13. Definitions

 

Data Controller: refers to the legal person, public authority, service or other entity which, individually o jointly with others, determines the purposes and means for processing your Personal Data.

 

Data Processor: refers to an entity that we engage to process your Personal Data solely on behalf of the Data Controller and pursuant to its instructions.

 

Personal Data: means any information relating to an identified or identifiable natural person whether directly or indirectly. For example, a telephone number or IP addresses are considered personal data. For your convenience, we will collectively refer to all personal data mentioned also as “Data”.

 

Recipient: refers to a natural or legal person, public authority, agency or other body, to which the personal data are disclosed, whether a third party or not.