Privacy Notice
1 General
This Privacy Notice contains information required by the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act for data subjects such as the controller’s customers and employees, and for the supervisory authority.
2 Controller and its contact information
OP Palvelut Oy (services company)
Postal address: P.O. Box 308, FI-00013 OP POHJOLA, FINLAND
Street address: Gebhardinaukio 1, 00510 HELSINKI
Controller’s contact person: Markus Sarja
Phone: 0203 355455
Email address: asiakaspalvelu@op-kevytyrittaja.fi
3 Data Protection Officer's contact information
OP Pohjola Data Protection Officer
OP Pohjola
Postal address: P.O. Box 308, FI-0013 OP POHJOLA, FINLAND
Email: dataprotection@op.fi
4 Name of the personal data file and data subjects
Customer data file for the OP Light Entrepreneur service
The data subjects in the data file are the OP Light Entrepreneur service's users.
5 Purposes of personal data processing and legal basis for processing
5.1 Purposes of processing
The purposes of use of personal data include the following:
- customer service and customer relationship management and development, including customer communications
- provision, development and quality assurance of services
- business development such as improving invoicing, automation of accounting and settlement of customer taxes
- monitoring and analysis of service use and customer segmentation, for example, in order for the controller to be able to offer personalised service content to the users
- opinion polls and market surveys
- direct marketing
- targeted marketing and advertising
- fulfilling statutory obligations and any other official rules and regulations
- risk management
- ensuring the security of services and investigating abuses
- training purposes.
Automated decision-making and profiling
The controller uses automated processing during the implementation of the OP Light Entrepreneur service. Based on automated processing, it is determined whether the data subject fulfils the criteria set for opening and using the service. The controller ensures that a negative decision (refusal to open the service) based on automated decision-making can be submitted for review and solution through a manual process.
Sanctions monitoring
The data subject’s personal data may be used to investigate whether the person is subject to international sanctions applied by the controller. Further information about OP Pohjola's sanctions compliance is primarily available in the terms and conditions of the acquired product or service.
5.2 Legal bases for processing
The table below describes the legal bases for processing personal data contained in the data file, and provides examples of processing performed on each basis.
| Legal basis | Example |
|---|---|
| Contractual relationship or actions preceding the conclusion of a contract | Actions based on a contract or the conclusion of a contract. OP Palvelut Oy submits reports to the authorities such as the Tax Administration on behalf of the entrepreneur based on the contract. |
| Consent | Direct marketing through electronic channels is usually based on the consent of the data subject. In addition, service development and customer satisfaction are measured with customer satisfaction surveys and actual marketing communications related to the service. Consent will be requested separately for them. |
| Legal obligation |
For example, anti-money laundering and counter-terrorist financing legislation. |
| Legitimate interests of the controller or a third party |
Personal data may be disclosed to the other personal data files of OP Pohjola based on legitimate interests. Direct marketing and business development can be based on legitimate interest. In most cases, the controller’s legitimate interests are based on the customer relationship or a similar relationship between the controller and the data subject. The controller also ensures that processing is proportionate to the data subject’s benefits and meets their reasonable expectations. |
6 Categories of personal data
| Category | Data content |
|---|---|
| Basic details | The data subject’s name, personal ID code and contact details such as address, email address and phone number |
| Customer relationship information | Information that uniquely identifies and classifies the customer, such as tax information |
| KYC/CDD information | Statutory KYC information such as the information required to identify the customer and determine their financial status and political exposure |
| Consents | Any consents given or withheld by the data subject concerning personal data processing |
| Contract and product information | Information about the agreement between the controller and the entity represented by the data subject Information about the products and services obtained by the data subject |
| Customer activity data | Tasks and transactions related to customer relationship management |
| Background information | For example, details of the data subject's financial status |
| Behavioural information (incl. information collected using cookies and other such technologies) | Tracking of the data subject's online behaviour and use of services using cookies, for example. The collected information may include a website browsed by the user, the device model, unique device and/or cookie ID, a channel such as an application, mobile browser or web browser, a browser version, IP address, session ID, session time and duration, and the display resolution and operating system. |
| Recordings and content of messages | Messages in various formats, in which the data subject is a party |
7 Recipients and recipient groups of personal data
Any personal data obtained may be used within OP Pohjola as permitted by the law, such as to clarify the validity of insurance cover included in Pohjola Insurance's OP Light Entrepreneur Without Business ID service. Data is disclosed to Ilmarinen Mutual Pension Insurance Company for the provision of the YEL pension insurance service ordered separately by the customer. Data is disclosed to Intercom, Inc for the provision of a chat service on the customer's initiative on the op-kevytyrittaja.fi website.
In addition, personal data may be disclosed, within the limits permitted by law, for example:
- to the authorities such as the Finnish Tax Administration and the Finnish Patent and Registration Office.
8 Transfer of personal data
The controller has suppliers which process personal data for its account. The controller concludes appropriate agreements on personal data processing with all such suppliers.
The controller’s suppliers provide the controller with information system services, for example. Some of the controller’s suppliers are other OP Pohjola entities.
8.1 International transfers of data
The controller uses subcontractors for data processing, and data may be transferred outside the EU or EEA. When data is transferred outside the EU or EEA, the transfer is done using the European Commission’s standard contractual clauses or another transfer mechanism in accordance with legislation. Further details on international transfers of personal data and standard contractual clauses are available from OP's website at op.fi/dataprotection.
Some of the controller's subcontractors are other OP Pohjola entities. They provide the controller with items such as IT and other support services.
9 Personal data retention period or criteria for determining the period
Personal data may be processed within the validity of the customer relationship. The customer relationship is determined by valid terms and conditions. Once the customer relationship has ended, the data is erased or anonymised after the period defined in the valid Accounting Act (currently 6 years) in accordance with the erasure processes followed by the controller.
After the customer relationship has terminated, the controller may process personal data for direct marketing purposes or business development in accordance with applicable legislation.
For potential customers, only the email address is stored. This retention period can be up to six months unless the person requests the removal of their email address before then.
10 Personal data sources and updates
Personal data is primarily collected from the data subjects themselves. Personal data may also be collected when the data subject uses certain services of the controller, such as online services.
Personal data may also be collected and updated within the limits permitted by law from the personal data files of third parties, including the following:
- Digital and Population Data Services Agency
- personal data files maintained by other authorities such as the Finnish Tax Administration, and the Finnish Patent and Registration Office
- credit data file controllers
- parties that maintain databases with information that is necessary to identify parties subject to international sanctions followed by the controller
- other customer data files of OP Pohjola entities.
11 Data subject’s rights
Data subjects have the right to receive the controller’s confirmation of whether their personal data will be processed or not, or whether they have already been processed.
If the controller processes a data subject’s personal data, the data subject has the right to receive the information in this document and a copy of the personal data being processed or already processed.
The controller may charge a reasonable administrative fee for any additional copies requested by the data subject. If the data subject submits a request electronically and has not requested any other form of delivery, the data will be delivered in a commonly used electronic format, provided that the data can be delivered in a secure manner.
Data subjects also have the right to request the controller to rectify or erase their personal data and prohibit the processing of their personal data for direct marketing purposes.
Since the adoption of the GDPR, data subjects also have, in certain circumstances, the right to request the controller to restrict the processing of their personal data or to otherwise object to processing. In addition, under the GDPR, data subjects may request that the data they have provided themselves be transferred in a machine-readable format.
All requests mentioned herein must be submitted to the abovementioned contact person of the controller.
If a data subject considers that their personal data are not being processed legally, they have the right to file a complaint with the competent supervisory authority.
12 Right to revoke consent
If the controller processes a data subject’s personal data based on consent, the data subject has the right to cancel such consent. The cancellation of consent does not affect the lawfulness of processing performed on the basis of said consent prior to its withdrawal. However, such cancellation may affect the usability and functionalities of the controller’s services.
13 Protection methods regarding the data file
The controller is committed to processing personal data securely and in a manner that fulfils the requirements of applicable laws. The controller has carefully assessed the risks that may be associated with the processing and taken the necessary measures to manage these risks.
The controller has taken appropriate technical and organisational measures to protect the data. The data file is protected by the following means, for example:
- protection of hardware and files
- access control
- user identity verification
- access rights
- user logs
- processing guidelines and supervision.
The controller also requires that its suppliers and other partners engage in appropriate protection of any personal data they process.