BackPrivacy Policy
Client Privacy Policy
This Client Privacy Policy explains how Hemia Nao Tek Ltd., operating the BroCar service in the Republic of Vanuatu (“BroCar”, “we”, “us”), collects, uses, stores, discloses and protects personal data in connection with the BroCar services described below.
This Policy is intended to comply with the Data Protection and Privacy Act No. 13 of 2024 of the Republic of Vanuatu (the “Data Protection Act”), which commenced on 2 January 2025.
1. DATA CONTROLLER, SCOPE AND DEFINITIONS
1.1. The data controller for the processing described in this Policy is Hemia Nao Tek Ltd. A “data controller” is the natural or legal person, public authority or other body with decision-making power with respect to personal-data processing.
1.2. This Policy applies to Clients and visitors using the BroCar client application, BroCar website, ordering channels, support communications and related client-facing functionality in Vanuatu.
1.3. A “Client” is a person who places or attempts to place an Order through BroCar. A “Partner” is an independent person or entity that may accept and provide the requested transportation, delivery or other Partner Service. BroCar is not the transportation provider merely because it processes the Order.
1.4. “Personal data” means information relating directly or indirectly to an identified or identifiable natural person. “Processing” includes collection, storage, use, disclosure, making available, alteration, erasure and other operations described by the Data Protection Act.
1.5. Taxsee (Thailand) Co., Ltd. is a technology provider with authorised technical access to the BroCar platform and database. To the extent it processes personal data on behalf of Hemia Nao Tek Ltd., it acts as a data processor subject to BroCar’s instructions and applicable contractual and legal safeguards.
2. PROCESSING PRINCIPLES AND LAWFUL BASES
2.1. BroCar processes personal data lawfully, fairly and transparently; for specified and legitimate purposes; in a manner limited to what is necessary; with reasonable accuracy and security; and no longer than necessary for the relevant purpose, in accordance with sections 4 and 5 of the Data Protection Act.
2.2. Depending on the activity, BroCar relies on one or more lawful purposes recognised by section 5, including:
• consent for one or more specific purposes where consent is required;
• entering into or performing an agreement with the Client, including receiving and processing an Order;
• protecting the rights or legitimate interests of the Client or another natural person, including safety-related processing;
• compliance with a legal obligation applicable to BroCar;
• a task carried out in the public interest where applicable; or
• BroCar’s or a third party’s legitimate interests, where those interests are not overridden by the Client’s interests or fundamental rights and freedoms.
2.3. Where processing is based on consent, BroCar will seek consent in a clear manner and will allow withdrawal as required by section 8 of the Data Protection Act. Withdrawal does not make processing already lawfully carried out before withdrawal unlawful.
3. PERSONAL DATA BROCAR MAY PROCESS
3.1. Identity, account and contact data
• name or profile name;
• phone number;
• e-mail address, if provided;
• account identifier, authentication information and account settings;
• profile photograph or identity-document information only where voluntarily provided or reasonably required for verification, safety or legal compliance.
3.2. Order and service data
• pick-up/service address and destination;
• requested service category, route, timing and Order instructions;
• Order history, cancellations, service status and timestamps;
• Partner information associated with an Order;
• ratings, feedback, complaints, support requests, lost-property and dispute records.
3.3. Geolocation
BroCar may receive the Client device’s location when the Application is being used and the relevant device permission is enabled. Location may be used to identify pick-up points, show nearby service availability, calculate routes and proposed prices, support safety and investigate Order-related issues. The Client can restrict location permission through device settings, but some functions may then be unavailable or less accurate.
3.4. Payment and transaction data
Where non-cash payment is available, BroCar may process payment method, transaction amount, currency, transaction status, payment identifiers, refunds, reservations and reconciliation information. Where full card credentials are entered on a secure page controlled by an acquiring bank or payment provider, that provider processes the credentials. BroCar does not store the Client’s card security code (CVV).
3.5. Device, network and technical data
• device identifiers and operating-system/application version;
• IP address and technical logs;
• mobile-network/operator information;
• language, country and application settings;
• security, crash, diagnostic, performance and fraud-prevention signals.
3.6. Communications
BroCar may process messages, support correspondence and, where permitted by law, recordings of calls made to or through BroCar support for quality, training, safety, fraud prevention and dispute-resolution purposes.
4. SOURCES OF PERSONAL DATA
BroCar may obtain personal data directly from the Client; automatically from the Application, Website or device where a relevant feature or permission is used; from Partners involved in an Order; from payment, telecommunications or other service providers; from persons lawfully placing an Order for the Client; from competent authorities; and from other lawful sources where necessary for the purposes in this Policy.
If a Client provides personal data about another person, the Client should provide only information reasonably necessary for the Order and must have lawful authority to provide it.
5. PURPOSES OF PROCESSING
• create, authenticate, secure and maintain Client accounts;
• receive, process and make Orders available to Partners;
• provide Order status, route, arrival, communication and support functionality;
• calculate proposed prices and process or reconcile payments where enabled;
• provide customer support and resolve complaints, disputes and lost-property matters;
• verify account integrity and prevent fraud, abuse, security incidents and unlawful use;
• improve reliability, safety, service quality and functionality of the Application and Service;
• perform analytics and diagnostics reasonably necessary for operating and improving the Service;
• comply with legal, regulatory, court and government requirements;
• establish, exercise or defend legal claims;
• send operational messages necessary for Orders, accounts, support or security; and
• send marketing messages only where permitted by law and subject to the Client’s right to opt out.
6. SHARING AND RECIPIENTS
6.1. Partners. BroCar may disclose to a Partner information reasonably necessary to consider and perform an Order, such as pick-up location, destination or distance, service instructions, Client name/profile identifier and a communication method. BroCar seeks to avoid disclosing information not needed for the relevant Order.
6.2. Technology Provider. Taxsee (Thailand) Co., Ltd. has authorised technical access to the BroCar platform and database for platform operation, maintenance, support and security. To the extent it processes personal data on behalf of Hemia Nao Tek Ltd., it is required to act for authorised purposes and subject to applicable safeguards.
6.3. Service providers. BroCar may use hosting/data-centre, telecommunications, payment, analytics, security, customer-support, professional-advisory and other providers where reasonably necessary for the purposes in this Policy, subject to appropriate confidentiality and data-protection obligations.
6.4. Authorities. BroCar may disclose personal data to courts, police, PLTA, regulators, tax authorities or other competent bodies where required or permitted by Vanuatu law, or where lawfully necessary to protect rights, safety or legal claims.
6.5. Corporate transactions. If BroCar undergoes a lawful merger, restructuring, asset transfer or similar corporate transaction, relevant personal data may be disclosed to advisers and prospective or actual counterparties subject to applicable confidentiality and data-protection requirements.
6.6. BroCar does not sell Client personal data to advertisers or data brokers.
7. INTERNATIONAL STORAGE AND CROSS-BORDER ACCESS
7.1. BroCar production data is stored on servers located in Singapore. In addition, authorised technical personnel of Taxsee (Thailand) Co., Ltd. may remotely access the database from Thailand for platform operation, maintenance, support and security. Hemia Nao Tek Ltd. also has authorised access for operating the Vanuatu service.
7.2. Personal data generated or collected in Vanuatu is subject to Part 4 (sections 15–17) of the Data Protection Act. Under section 15, personal data generated or collected in Vanuatu must not be used elsewhere without the prior authorisation required by that section unless the destination country or international organisation has been prescribed as providing an appropriate level of protection.
7.3. BroCar is responsible for obtaining and maintaining any authorisation required by Part 4 for the Singapore storage and Thailand access described above. Where section 17 applies to a destination that does not ensure an appropriate level of protection, BroCar must comply with the applicable Ministerial authorisation process, conditions and safeguards.
7.4. Acceptance of this Policy alone is not treated as a substitute for governmental authorisation required by Vanuatu law. Cross-border recipients may process personal data only for authorised purposes and must apply reasonable technical, organisational and contractual safeguards.
8. CHILDREN AND OTHER VULNERABLE INDIVIDUALS
8.1. The Data Protection Act defines a child as an individual below 18 years. BroCar does not assume that a parent or guardian has consented merely because information about a child is provided.
8.2. Where BroCar processes personal data of a child or other vulnerable individual, it will do so only where permitted by section 7 of the Data Protection Act, including where valid consent is given or authorised by a parent, carer or legal representative, where processing is in the legitimate interests of the child or vulnerable individual, where required by law or public interest, or in another situation expressly permitted by section 7.
8.3. A parent or responsible adult may place an Order for a child. A Client who provides another person’s information should provide only what is necessary and have lawful authority to do so.
9. SPECIAL CATEGORIES OF PERSONAL DATA
9.1. BroCar does not routinely seek special categories of personal data for ordinary ride or delivery ordering. If special-category data becomes necessary for a specific legal, safety or other lawful purpose, it will be processed only where an exception under section 6 of the Data Protection Act applies and with safeguards appropriate to the data.
9.2. BroCar will not infer or intentionally create special-category profiles from ordinary Order behaviour merely for advertising purposes.
10. AUTOMATED PROCESSING
10.1. BroCar may use automated tools for fraud detection, safety checks, service-quality analysis, price calculation, Order handling, account security and other operational functions.
10.2. A Client may use the Feedback or support channel to submit a request concerning a decision based solely on automated processing that significantly affects the Client. A human support specialist can review the relevant information, consider the Client’s views and correct inaccurate personal data where applicable. Where section 13 of the Data Protection Act applies, BroCar will provide the safeguards required by that section.
11. RETENTION AND DELETION
11.1. BroCar keeps personal data only as long as reasonably necessary for the purposes for which it was processed, or for a longer period where necessary to comply with law, complete payment or accounting obligations, protect safety, investigate fraud, resolve a dispute, respond to an authority or establish, exercise or defend legal claims.
11.2. When personal data is no longer necessary, BroCar will delete it or retain it only in a form that prevents direct or indirect identification, in accordance with section 4(5) of the Data Protection Act.
11.3. Account deletion does not require immediate deletion of data that BroCar is legally required or lawfully entitled to retain for an unresolved Order, payment, chargeback, dispute, fraud/security investigation or legal obligation. Retained data will be limited to the relevant purpose.
12. CLIENT RIGHTS
Subject to the Data Protection Act, the Client may exercise applicable rights, including:
• access to information about processing and personal data under section 9;
• restriction of processing in the circumstances provided by section 10;
• rectification of inaccurate or incomplete personal data without delay and free of charge under section 11;
• erasure where the conditions in section 11 are met;
• objection to processing under section 12;
• withdrawal of consent where processing is based on consent;
• protection from certain solely automated decisions under section 13; and
• representation by another person where permitted under section 14.
BroCar may request reasonable information to verify the identity and authority of the requester before disclosing or changing personal data. BroCar will not impose unnecessary formalities and will respond within the timeframes and procedures required by applicable law.
13. SECURITY AND PERSONAL-DATA INCIDENTS
13.1. BroCar applies appropriate technical and organisational security measures having regard to the nature of the personal data, the purposes of processing and the relevant risks.
13.2. Access by Hemia Nao Tek Ltd., Taxsee (Thailand) Co., Ltd. and other authorised providers is limited to legitimate operational purposes and is subject to confidentiality, access-control and security requirements.
13.3. No information system can be guaranteed absolutely secure. This does not remove or transfer BroCar’s statutory obligations. BroCar will investigate personal-data incidents and make notifications required by the Data Protection Act, applicable Regulations or other binding law.
14. COOKIES, WEBSITE AND DEVICE TECHNOLOGIES
14.1. BroCar websites may use strictly necessary, functional, performance and advertising cookies or similar technologies. Non-essential technologies may be controlled through available website controls or browser settings where applicable. Disabling certain technologies may affect functionality.
14.2. BroCar may use device identifiers, logs and similar technical information for authentication, security, diagnostics, analytics and operation of the Service. Such information is treated as personal data where it relates or can reasonably be linked to an identifiable person.
15. MARKETING AND OPERATIONAL MESSAGES
15.1. Operational notifications necessary to perform Orders, maintain an account, provide support or protect security are not marketing.
15.2. Promotional communications are sent only where permitted by law. The Client may opt out of promotional e-mail, SMS, push or messaging communications using the provided unsubscribe method or by contacting BroCar. Opting out of marketing does not prevent necessary service or security messages.
16. CHANGES TO THIS POLICY
BroCar may update this Policy when processing practices, technology or law changes. The current version will be published on the legal website. BroCar may also use in-app announcements, push notifications, e-mail or another available channel to draw attention to material changes, but delivery or reading of such messages cannot be guaranteed. Where applicable law requires a specific form of notice or new consent, BroCar will comply with that requirement.
CONTACTS
Service operator / data controller in Vanuatu: Hemia Nao Tek Ltd.
E-mail: vanuatu@brocar.com
Official website: https://bro-car.com/
Legal information: https://legal.bro-car.com/
Requests concerning personal data may be submitted by e-mail. BroCar may request information reasonably necessary to verify the identity or authority of the requester before disclosing or changing personal data.
A Client may also lodge a complaint with the competent Vanuatu data-protection authority in accordance with applicable law.