PRIVACY POLICY
Action Auto Garage Limited
Effective Date: April 2026
1. Introduction
Action Auto Garage Limited ("AAG", "we", "us", or "our") is committed to protecting your personal data in accordance with the Personal Data Protection Act, 2022 (the "PDPA") of the United Republic of Tanzania and the regulations issued by the Personal Data Protection Commission (PDPC).
This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website (www.aag.co.tz), use our contact or booking forms, or engage our automotive services. By using our website or services, you acknowledge and agree to the practices described in this policy.
2. Who We Are
Action Auto Garage Limited is the authorised dealer of Toyota Tanzania Limited operating in Dodoma, Morogoro. We provide automotive services including vehicle servicing, repairs, diagnostics, paint and body work, spare parts supply, and warranty and recall services.
Data Controller: Action Auto Garage Limited
Registered Address: Dodoma, Tanzania
Email: info@action-toyota.com
Phone: +255 678 999 555
3. Personal Data We Collect
We may collect the following categories of personal data:
3.1 Information You Provide Directly
Full name and contact details (phone number, email address, physical address)
Vehicle information (make, model, year, registration number, chassis/VIN number)
Service and repair history
Insurance claim details and policy numbers (where applicable)
Corporate or fleet account information
Messages and enquiries submitted through our website contact form
3.2 Information Collected Automatically
Browser type, device information, and IP address when you visit our website
Pages visited, time spent, and other usage data
Cookies and similar tracking technologies (see Section 9)
3.3 Information from Third Parties
Toyota Tanzania Limited (for warranty, recall, and dealer-related purposes)
Insurance companies (for claims processing)
Government entities and corporate fleet managers
4. How We Use Your Data
We process your personal data for the following purposes:
To provide automotive services including repairs, servicing, diagnostics, and bodywork
To respond to your enquiries and messages submitted via our website
To manage service bookings and appointments
To process insurance claims and warranty or recall work on your behalf
To communicate with you about your vehicle, service status, and follow-up care
To comply with regulatory obligations including Tanzania Revenue Authority (TRA) invoicing, TEMESA compliance, and PDPC requirements
To improve our website, services, and customer experience
To manage our business relationships with corporate and government clients
5. Legal Basis for Processing
Under the PDPA, we process your personal data based on one or more of the following legal grounds:
Your consent (e.g. when you submit a contact form or booking request)
Performance of a contract (e.g. when we carry out vehicle repairs you have authorised)
Compliance with a legal obligation (e.g. tax invoicing, regulatory reporting)
Our legitimate business interests (e.g. improving services, maintaining records)
6. Who We Share Your Data With
We do not sell your personal data. We may share your data with the following parties only as necessary:
Toyota Tanzania Limited – for warranty claims, recall campaigns, and dealer reporting
Insurance companies – for processing approved claims
Tanzania Revenue Authority (TRA) – for fiscal compliance and tax invoicing
Government bodies (e.g. TEMESA) – as required by Tanzanian law
Service providers – trusted third parties who assist us with website hosting, IT, and business operations, bound by confidentiality obligations
NB Auto World parts and service coordination
7. How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. General guidelines include:
Service and repair records: retained for the life of the vehicle or as required by Toyota Tanzania Limited
Financial and tax records: retained in accordance with TRA requirements (typically 5 years)
Website enquiries: retained for up to 2 years after your last interaction
Insurance claim records: retained for the duration required by the relevant insurer and applicable law
After the retention period, your data will be securely deleted or anonymised.
8. How We Protect Your Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
Secure storage systems for physical and electronic records
Access controls limiting data access to authorised personnel only
Regular review of our data protection practices
Confidentiality obligations for staff handling personal data
9. Cookies and Website Tracking
Our website may use cookies and similar technologies to enhance your browsing experience. Cookies are small text files stored on your device. We may use:
Essential cookies – required for the website to function properly
Analytics cookies – to help us understand how visitors use our website
You can control cookies through your browser settings. Disabling certain cookies may affect website functionality.
10. Your Rights
Under the PDPA, you have the following rights in relation to your personal data:
Right of access – to request a copy of the personal data we hold about you
Right to rectification – to request correction of inaccurate or incomplete data
Right to erasure – to request deletion of your data where there is no compelling reason for continued processing
Right to restrict processing – to request that we limit how we use your data
Right to object – to object to processing based on legitimate interests
Right to data portability – to receive your data in a structured, commonly used format
Right to withdraw consent – at any time, without affecting the lawfulness of prior processing
To exercise any of these rights, please contact us at info@aag.co.tz or visit any of our branches.
11. Children’s Data
Our services and website are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it promptly.
12. International Data Transfers
We generally process and store your personal data within Tanzania. In the event that data needs to be transferred outside Tanzania (for example, to Toyota’s international systems), we will ensure that adequate safeguards are in place as required by the PDPA.
13. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Tanzania:
Website: www.pdpc.go.tz
Address: Personal Data Protection Commission, Dar es Salaam, Tanzania
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated version will be posted on our website with a revised effective date. We encourage you to review this policy periodically.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
Company: Action Auto Garage Limited
Email: info@action-toyota.com
Phone: +255 678 999 555
Website: www.aag.co.tz
Branches: Dodoma (Head Office), and Morogoro