Privacy Policy
Privacy Policy
Privacy Notice
The original text is written in Finnish, and this is a machine translation. If there are discrepancies between language versions, the Finnish version prevails.
General
This privacy notice provides the information required under the EU General Data Protection Regulation regarding the processing of personal data to data subjects, such as the controller's customers or staff, as well as to the supervisory authority.
Controller and controller's contact details
Truster Oy
Postal address: PO Box 313, 00101 Helsinki, Finland
Visiting address: Mikonkatu 13, 00100 Helsinki, Finland
Controller's contact person: Data Protection Officer
Phone number: 050 1856
Email address: [email protected]
Data Protection Officer's contact details
Truster Oy's Data Protection Officer
Truster Oy
Postal address: PO Box 313, 00101 Helsinki, Finland
Email address: [email protected]
Data subjects
This is Truster Oy's customer register. The data subjects in the register are users of the services provided by Truster Oy and its subsidiaries.
Purposes of processing personal data
The purposes for which personal data is processed include:
- managing and developing the customer relationship, and customer service
- customer communications
- providing and developing services
- business development
- monitoring the use of products and services and ensuring quality
- direct marketing and direct advertising
- targeting of marketing and advertising
- risk management
- preventing and investigating misuse
- fulfilling obligations based on law and regulatory requirements
- providing account information services (AIS). The Service may offer a product in which the user links their bank and/or payment account to the Service via a secure connection through an account information service. In this case, personal data (including account transaction data and balance information) is processed to provide the Service, for example for bookkeeping, reconciliation, identifying and matching transactions, and reporting.
- Informing the customer's clients about invoicing readiness, service activation, and payment obstacles.
Customer due diligence and prevention of money laundering and terrorist financing
The data subject's customer due diligence information and personal data may be used to prevent, detect, and investigate money laundering and terrorist financing, as well as for other purposes required by anti-money laundering legislation. The aim is to know the customer and to prevent money laundering, terrorist financing, and misuse.
The data subject's personal data may also be used to determine whether the person is subject to international sanctions that the controller complies with.
Legal bases for processing personal data
Truster processes personal data in order to fulfil its statutory and contractual obligations. The processing of personal data may be based on a contractual relationship or measures taken prior to entering into a contract, the controller's statutory obligation, the data subject's consent, or the controller's legitimate interest. Truster processes personal data in order to fulfil its statutory and contractual obligations. The processing of personal data may be based on a contractual relationship or measures taken prior to entering into a contract, the controller's statutory obligation, the data subject's consent, or the controller's legitimate interest.
Categories of personal data
Basic information
- The data subject's name, personal identity code, and account number
- The data subject's contact details, such as address, email address, and phone number
Customer due diligence information
- Information related to customer due diligence, for example a copy of an identity document, method and date of identification, IP address, video recording or photograph and its date
- Information on whether the customer is a politically exposed person (PEP), or whether a PEP belongs to their close circle
Consents
- Consents and prohibitions given by the data subject regarding the processing of personal data
Transaction information
- Information related to the data subject's contracts and services
- Information related to communications between the customer and the controller
Tracking information
- The data subject's online behaviour and use of the services is tracked, for example, using cookies. Data collected may include, for example, pages browsed, device model, unique device and/or cookie identifier, channel (such as app, mobile browser, or web browser), browser version, IP address, session identifier, session time and duration, and screen resolution and operating system.
Location information
- The location of the data subject's device, as well as trip information added to the app, such as trip start and stop points and GPS coordinates.
Account information (AIS / account information service)
- If the data subject links their bank and/or payment account to the Service via an account information service, the following data may be processed, to the extent provided by the account holder: basic account information (for example account number/IBAN, bank/account holder, and currency), balance information (account balance and the time of the balance), and transaction information (transaction date and/or booking date, amount, reference and message details, payment type, payer's or payee's name and account identifier where available, a unique transaction identifier, and other transaction details provided by the account holder).
Sources of personal data and updating of data
The controller primarily collects data from the data subject. Personal data may also be collected when the data subject uses services provided by the controller, such as online services.
To the extent permitted by law, personal data may also be collected and updated from third-party registers, such as:
- registers maintained by authorities, such as the Digital and Population Data Services Agency, the Finnish Tax Administration (Vero), and registers maintained by the Finnish Patent and Registration Office (PRH)
- information necessary for determining political influence or international financial sanctions, obtained from parties maintaining such databases
- account information may be received from the bank or other account holder chosen by the data subject via the account information service, when the data subject links their account to the Service.
Disclosure of personal data
The data subject's data may be disclosed to Truster's subsidiaries within the limits permitted by law, for purposes such as customer service, managing the customer relationship, and marketing.
The data subject's data may be disclosed, within the limits permitted by law, to other controllers, for example:
- to authorities, such as the Finnish Tax Administration (Vero), the Finnish Patent and Registration Office (PRH), and enforcement, execution, and supervisory authorities
- to another controller when this forms part of the service or product being provided
- personal data may be processed on Truster's behalf by a service provider in order to deliver the account information service. In addition, banks and other account holders provide account data to the Service through the technical interfaces of the account information service, based on the connection made by the data subject.
- The data subject's data may be disclosed to the customer's own clients to the extent necessary to process payments. This disclosed information may include, for example, necessary information on whether statutory identification has been completed, whether the Business ID (Y-tunnus) registration is complete, and whether there are any obstacles to receiving payments on the account.
The controller uses subcontractors and partners to produce and provide its services. Your personal data may be transferred, for example, to partners, service providers, and IT system providers for processing on the controller's behalf. Such parties may include various information systems, banks, and insurance companies. The controller ensures, through contractual and other arrangements, that subcontractors and service providers protect the personal data being processed appropriately and in accordance with the controller's requirements, following good data processing practice.
Transfer of personal data and international data transfers
The controller processes personal data primarily in Finland and the EEA. If the controller transfers or discloses personal data outside the EEA, for example to the United States, it ensures an adequate level of protection for the personal data as required by law and uses data transfer mechanisms approved by the European Commission.
Rights of the data subject
Right to information about the processing of personal data
The data subject has the right to receive information about the collection and processing of their personal data.
Right of access to data
The data subject has the right to obtain confirmation from the controller as to whether their personal data is being processed. If the data subject's data is being processed, the controller must, upon request, provide them with a copy of the personal data being processed. If the data subject makes the request electronically, the information must be provided in a commonly used electronic format, unless the data subject requests otherwise. The controller may charge the data subject a reasonable fee based on administrative costs if the data subject requests additional copies of the data.
Right to rectification
The data subject has the right to require the controller to rectify inaccurate and incorrect personal data concerning them. The data subject also has the right to have incomplete personal data completed.
Right to request erasure of data
In certain situations, the data subject has the right to have the controller erase data concerning them. However, the controller is not obliged to erase personal data if processing is still necessary, for example to fulfil the controller's statutory obligations or to handle legal claims. If the data subject has linked their account to the Service via the account information service, the account connection can be removed within the Service or through means offered by the account holder. Removing the connection, or its expiry, may affect the Service's functionality to the extent that account data is needed to provide the Service. In certain situations, the data subject may also request that the controller restrict the processing of their personal data.
Data retention period or criteria for determining it
The controller processes personal data for the duration of the contractual and customer relationship. Personal data is retained for a maximum of 5 years from the most recent customer transaction. After the retention period ends, the data is erased or anonymised in accordance with the controller's deletion process. The controller processes personal data for the duration of the contractual and customer relationship. Personal data is retained for a maximum of 10 years from the most recent customer transaction. After the retention period ends, the data is erased or anonymised in accordance with the controller's deletion process.
Data protection measures
The controller has appropriate technical, organisational, and administrative security measures in place to protect all data in its possession from loss, misuse, unauthorised access, disclosure, alteration, and destruction.
The controller has appropriately protected the data both technically and organisationally. The following measures, among others, are used to protect the register:
- protection of hardware and files
- user authentication
- access rights
- logging of usage events
- instructions and supervision of processing