Privacy Policy
Privacy Policy
This translation is provided to help our customers. The Finnish original is the legally authoritative version: https://www.truster.com/fi/ehdot/tietosuojakaytanto
Privacy Statement
The original text is written in Finnish and this is an automatic translation. If there are discrepancies between the language versions, the Finnish-language version shall be binding.
General
This privacy statement provides the information required by the EU General Data Protection Regulation about the processing of personal data to data subjects, such as the data controller's customers or personnel, as well as to the supervisory authority.
Data controller and the data controller's contact details
Truster Oy
Postal address: PL 313, 00101, Helsinki, Suomi
Visiting address: Mikonkatu 13, 00100 Helsinki, Suomi
Data controller's contact person: Data Protection Officer
Telephone number: 050 1856
Email address: [email protected]
Data Protection Officer's contact details
Truster Oy's Data Protection Officer
Truster Oy
Postal address: PL 313, 00101, Helsinki, Suomi
Email address: [email protected]
Data subjects
This is Truster Oy's customer register. The data subjects of the register are the users of the services of Truster Oy and its subsidiaries.
Purposes of processing personal data
The purposes of processing personal data are
- managing and developing the customer relationship, as well as customer service
- customer communication
- providing and developing services
- business development
- monitoring the use of products and services and ensuring quality
- direct marketing and direct advertising
- targeting of marketing and advertising
- risk management
- preventing and investigating misuse
- fulfilling obligations based on law and official regulations
- providing the account information service (AIS). The Service may offer a product in which the user connects their bank and/or payment account to the Service via a secured connection using the account information service. In this case, personal data (including transaction data and balance data) is processed in order to produce the Service, for example for accounting, reconciliation, the identification and allocation of business transactions, and reporting.
- Informing the customer's clients regarding billing readiness, service activation, and obstacles to payments.
Customer due diligence and the prevention of money laundering and terrorist financing
The data subject's customer due diligence information and personal data may be used for preventing, detecting and investigating money laundering and terrorist financing, as well as for other purposes required by anti-money-laundering legislation. The aim is customer due diligence and the prevention of money laundering, terrorist financing and misuse.
The data subject's personal data may also be used to determine whether the person is subject to the international sanctions observed by the data controller.
Legal bases for processing personal data
Truster processes personal data in order to fulfil its statutory and contractual obligations. The processing of personal data may be based on a contractual relationship or on measures preceding the conclusion of a contract, on the data controller's statutory obligation, on the data subject's consent, or on the data controller's legitimate interest. Truster processes personal data in order to fulfil its statutory and contractual obligations. The processing of personal data may be based on a contractual relationship or on measures preceding the conclusion of a contract, on the data controller's statutory obligation, on the data subject's consent, or on the data controller's legitimate interest.
Categories of personal data
Basic information
- The data subject's name, personal identity code, and account number
- The data subject's contact details, such as address, email address, telephone number
Customer due diligence information
- Information concerning customer due diligence, for example a copy of an identity document, the method of identification and the date of identification, IP address, video recording or photograph, and the date of the video recording or photograph
- Information on whether the customer is a politically exposed person, i.e. a PEP, or whether PEPs belong to their close circle
Consents
- Consents and prohibitions given by the data subject concerning the processing of personal data
Interaction data
- Information related to the data subject's contracts and services
- Information related to communication between the customer and the data controller
Tracking data
- The data subject's online behaviour and use of services is tracked, for example, by means of cookies. The collected data may include, for example, the page browsed by the user, the device model, a unique device and/or cookie identifier, the channel such as an app, mobile browser or internet browser, the browser version, IP address, session identifier, the time and duration of the session, and the screen resolution and operating system.
Location data
- The location of the data subject's device and the trip data they add to the application, such as the departure and stopping points of trips and GPS coordinates.
Account information (AIS / account information service)
- If the data subject connects their bank and/or payment account to the Service using the account information service, the following data may be processed to the extent that the account servicer provides it: basic account information (for example account number/IBAN, bank/account servicer and currency), balance data (the account balance and the time of the balance), and transaction data (the transaction date and/or booking date, amount, reference and message details, payment type, the name of the payer or payee and the account identifier to the extent that the information is available, the unique identifier of the transaction, and other data describing the transaction provided by the account servicer).
Sources and updating of personal data
The data controller collects data primarily from the data subject themselves. Personal data may also be collected when the data subject uses the services provided by the data controller, such as online services.
Within the limits permitted by law, personal data may also be collected and updated from third-party registers, such as:
- registers maintained by public authorities, such as the Digital and Population Data Services Agency, the Tax Administration, and registers kept by the Finnish Patent and Registration Office (PRH)
- data necessary for ascertaining political exposure or international financial sanctions, from parties that maintain such databases
- account information may be obtained into the service from the bank or other account servicer chosen by the data subject, via the account information service, when the data subject connects their account to the service.
Disclosure of personal data
The data subject's data may be disclosed to Truster's subsidiaries within the limits permitted by legislation, for purposes including customer service, managing the customer relationship, and marketing.
The data subject's data may be disclosed, within the limits permitted by law, to other data controllers, for example
- to authorities, such as the Tax Administration, the PRH, and enforcement, execution and supervisory authorities
- to another data controller when it is part of the service or product being produced
- in order to provide the account information service, personal data may be processed by a service provider acting on Truster's behalf. In addition, banks and other account servicers deliver account information to the service through the technical interfaces of the account information service, on the basis of the connection made by the data subject.
- The data subject's data may be disclosed to the customer's own clients to the extent necessary for transmitting payments. This disclosed data may include, for example, the necessary information on whether statutory identification has been carried out, whether the registration of the business ID (Y-tunnus) is complete, and whether there are obstacles on the account to receiving payments.
The data controller uses subcontractors and partners in producing and providing services. Your personal data may be transferred, for example, to partners, service providers and producers of IT systems for processing carried out on the data controller's behalf. Such actors may include, for example, various information systems, banks, and insurance companies. Through contractual and other arrangements, the data controller ensures that subcontractors and service providers protect the personal data being processed appropriately and in accordance with the requirements set by the data controller, observing good data processing practice.
Transfer of personal data and international data transfers
The data controller processes personal data mainly in Finland and the EEA. If the data controller transfers or discloses personal data outside the EEA, such as to the United States, it ensures an adequate level of protection for the personal data in the manner required by legislation and uses data transfer mechanisms approved by the European Commission.
Rights of the data subject
The right to receive information about the processing of personal data
The data subject has the right to receive information about the collection and processing of their personal data.
The right of access to data
The data subject has the right to obtain from the data controller confirmation as to whether it processes personal data concerning them. If the data subject's data is processed, the data controller must, upon request, provide them with a copy of the personal data being processed. If the data subject makes the request electronically, the information must be provided in a commonly used electronic format, unless the data subject requests otherwise. The data controller may charge the data subject a reasonable fee corresponding to the administrative costs arising from responding to the request if the data subject requests several copies of the data.
The right to rectify data
The data subject has the right to require the data controller to rectify inaccurate and incorrect personal data concerning them. The data subject also has the right to have incomplete personal data completed.
The right to request the erasure of data
In certain situations, the data subject has the right to have the data controller erase data concerning them. However, the data controller is not obliged to erase personal data if the processing of the data is still necessary, for example, for fulfilling the data controller's statutory obligations or for handling legal claims. If the data subject has connected their account to the service using the account information service, the account information connection can be removed in the service or by the means provided by the account servicer. Removing the connection or its expiry may affect the functionalities of the service to the extent that account information is needed to produce the service. The data subject may also, in certain situations, request the data controller to restrict the processing of personal data concerning them.
The retention period for the data or the criteria for determining the retention period
The data controller processes personal data for the duration of the contractual and customer relationship. Personal data is retained for a maximum of 5 years from the most recent customer transaction. After the retention period ends, the data is erased or anonymised in accordance with the deletion process followed by the data controller. The data controller processes personal data for the duration of the contractual and customer relationship. Personal data is retained for a maximum of 10 years from the most recent customer transaction. After the retention period ends, the data is erased or anonymised in accordance with the deletion process followed by the data controller.
Protection of the data
The data controller has in place appropriate technical, organisational and administrative security procedures with which it protects all data in its possession against loss, misuse, unauthorised access, disclosure, alteration and destruction.
The data controller has protected the data appropriately by technical and organisational means. The following means, among others, are used in protecting the register:
- protection of hardware and files
- identification of users
- access rights
- logging of access events
- guidance and supervision of processing