Tietosuojakäytäntö

Privacy Policy

This translation is provided to help our customers. The original Finnish version is the legally binding one: https://www.truster.com/fi/ehdot/tietosuojakaytanto

Data Protection Notice

The original text is written in Finnish and this is a machine translation. If there are discrepancies between the language versions, the Finnish version prevails.

General

This data protection notice provides data subjects, such as the data controller's customers or personnel, as well as the supervisory authority, with the information on the processing of personal data required under the EU General Data Protection Regulation.

Data controller and data controller's contact details

Truster Oy

Postal address: PL 313, 00101, Helsinki, Finland

Visiting address: Mikonkatu 13, 00100 Helsinki, Finland

Data controller's contact person: Data Protection Officer

Phone number: 050 1856

Email address: [email protected]

Data Protection Officer's contact details

Truster Oy's Data Protection Officer

Truster Oy

Postal address: PL 313, 00101, Helsinki, Finland

Email address: [email protected]

Data subjects

This concerns Truster Oy's customer register. Data subjects in the register are the users of the services provided by Truster Oy and its subsidiaries.

Purpose of processing personal data

The purposes of processing personal data are

  • managing and developing the customer relationship, as well as customer service
  • customer communications
  • provision and development of services
  • development of business operations
  • monitoring the use of products and services, and quality assurance
  • direct marketing and direct advertising
  • targeting of marketing and advertising
  • risk management
  • prevention and investigation of misuse
  • fulfilling obligations based on law and regulatory requirements
  • provision of the account information service (AIS). The Service may offer a product where the user connects their bank and/or payment account to the Service via a secure connection using the account information service. In such cases, personal data (including account transaction data and balance information) is processed in order to provide the Service, for example for bookkeeping, reconciliation, identification and matching of business events, and reporting.
  • Informing the customer's principal about invoicing readiness, activation of the service and payment obstacles.

Customer due diligence and prevention of money laundering and terrorist financing

The data subject's customer due diligence data and personal data may be used to prevent, detect and investigate money laundering and terrorist financing, as well as for other purposes required by anti-money-laundering legislation. The aim is customer due diligence and the prevention of money laundering, terrorist financing and misuse.

The data subject's personal data may also be used to determine whether the person is subject to international sanctions that the data controller complies with.

Truster processes personal data in order to fulfil its statutory and contractual obligations. The processing of personal data may be based on a contractual relationship or measures preceding the conclusion of a contract, on the data controller's statutory obligation, on the data subject's consent, or on the data controller's legitimate interest. Truster processes personal data in order to fulfil its statutory and contractual obligations. The processing of personal data may be based on a contractual relationship or measures preceding the conclusion of a contract, on the data controller's statutory obligation, on the data subject's consent, or on the data controller's legitimate interest.

Categories of personal data

Basic information

  • The data subject's name, personal identity code and account number
  • The data subject's contact details, such as address, email address, phone number

Customer due diligence data

  • Customer due diligence information, such as a copy of an identity document, the method and date of identification, IP address, video recording or photograph, and the date of the video recording or photograph
  • Information on whether the customer is a politically exposed person (PEP), or whether any of the customer's close associates are PEPs

Consents

  • Consents and prohibitions given by the data subject regarding the processing of personal data

Case information

  • Information relating to the data subject's contracts and services
  • Information relating to communications between the customer and the data controller

Tracking data

  • The data subject's online behaviour and use of the services are tracked, for example using cookies. Information collected may include, for example, the pages the user has visited, the device model, a unique device and/or cookie identifier, the channel (such as application, mobile browser or internet browser), the browser version, IP address, session identifier, the time and duration of the session, and screen resolution and operating system.

Location data

  • The location of the data subject's device, as well as travel information added in the application, such as trip start and end locations and GPS coordinates.

Account information (AIS/account information service)

  • If the data subject connects their bank and/or payment account to the Service using the account information service, the following information may be processed, to the extent provided by the account holder: basic account information (such as account number/IBAN, bank/account holder and currency), balance information (the account's balance and the time of the balance), and account transaction data (the transaction date and/or booking date, amount, reference and message details, payment type, the name and account identifier of the payer or payee to the extent available, the transaction's unique identifier, and other information describing the transaction provided by the account holder).

Sources of personal data and how it is updated

The data controller collects data primarily from the data subject directly. Personal data may also be collected when the data subject uses services provided by the data controller, such as web services.

Within the limits permitted by law, personal data may also be collected and updated from third-party registers, such as:

  • registers maintained by authorities, such as the Digital and Population Data Services Agency, the Finnish Tax Administration, and registers maintained by the Finnish Patent and Registration Office (PRH)
  • information needed to determine political influence or international financial sanctions, from providers who maintain such databases
  • account information may be obtained by the service from the bank or other account holder chosen by the data subject, via the account information service, when the data subject connects their account to the service.

Disclosure of personal data

Within the limits permitted by law, the data subject's information may be disclosed to Truster's subsidiaries, for purposes such as customer service, managing the customer relationship, and marketing.

Within the limits permitted by law, the data subject's information may be disclosed to other data controllers, for example

  • to authorities, such as the Finnish Tax Administration, the Finnish Patent and Registration Office (PRH), and the enforcement, execution and supervisory authorities
  • to another data controller when this forms part of the service or product being provided
  • to provide the account information service, personal data may be processed by a service provider acting on Truster's behalf. In addition, banks and other account holders provide account information to the service via the account information service's technical interface, based on the connection made by the data subject.
  • The data subject's information may be disclosed to the customer's own principal to the extent necessary to facilitate payments. This disclosed information may, for example, include necessary details on whether the statutory identification has been carried out, whether registration of the Business ID (Y-tunnus) has been completed, and whether there are any obstacles on the account to receiving payments.

The data controller uses subcontractors and partners in the production and provision of its services. Your personal data may, for example, be transferred to partners, service providers and IT system suppliers for processing carried out on behalf of the data controller. Such parties may include, for example, various information systems, banks and insurance companies. The data controller ensures, through agreements and other arrangements, that subcontractors and service providers protect the personal data processed in an appropriate manner and in accordance with the requirements set by the data controller, observing good data processing practice.

Transfer of personal data and international data transfers

The data controller processes personal data mainly in Finland and within the EEA. If the data controller transfers or discloses personal data outside the EEA, for example to the United States, it ensures an adequate level of protection for the personal data as required by law and uses transfer mechanisms approved by the European Commission.

Data subject's rights

Right to information about the processing of personal data

The data subject has the right to obtain information about the collection and processing of their personal data.

Right of access to data

The data subject has the right to obtain confirmation from the data controller as to whether personal data concerning the data subject is being processed. If the data subject's data is being processed, the data controller shall, upon request, provide a copy of the personal data being processed. If the data subject makes the request electronically, the information shall be provided in a commonly used electronic format, unless the data subject requests otherwise. The data controller may charge the data subject a reasonable fee, based on the administrative costs of responding to the request, if the data subject requests further copies of the data.

Right to rectification of data

The data subject has the right to require the data controller to rectify inaccurate or incorrect personal data concerning the data subject. The data subject also has the right to complete incomplete personal data.

Right to request erasure of data

In certain situations, the data subject has the right to have the data controller erase data concerning the data subject. However, the data controller is not obliged to erase personal data if the processing of the data is still necessary, for example to fulfil the data controller's statutory obligations or to handle legal claims. If the data subject has connected their account to the service using the account information service, the account information connection can be removed in the service or through the methods offered by the account holder. Removing or terminating the connection may affect the functions of the service to the extent that account information is needed to provide the service. In certain situations, the data subject may also request that the data controller restrict the processing of personal data concerning the data subject.

Data retention period or the criteria used to determine it

The data controller processes personal data for the duration of the contractual and customer relationship. Personal data is retained for a maximum of 5 years from the most recent customer event. After the retention period has expired, the data is deleted or anonymised in accordance with the data controller's deletion process. The data controller processes personal data for the duration of the contractual and customer relationship. Personal data is retained for a maximum of 10 years from the most recent customer event. After the retention period has expired, the data is deleted or anonymised in accordance with the data controller's deletion process.

Protection of data

The data controller has appropriate technical, organisational and administrative security procedures in place to protect all data in its possession from loss, misuse, unauthorised use, disclosure, alteration and destruction.

The data controller has protected the data appropriately, both technically and organisationally. Methods used to protect the register include, among others:

  • protection of equipment and files
  • user identification
  • user access rights
  • logging of usage events
  • instructions for and monitoring of processing