We have a range of rental homes in Vantaa. Take a look at the apartments and fill in an application.
Would you like to book a parking space or a sauna session? Have you left your keys at home? Please get in touch with us.
VAV is a rental housing group founded in 1986 that enables a good and high-quality life in Vantaa.
We provide service around the clock, every day of the year.
Privacy Notice for the VAV Group’s user management and log registers.
Data controllers
The data controllers are the landlords of the properties owned by the VAV Group companies listed below, each in respect of their own tenants; hereinafter referred to as “VAV” or “Data Controller”.
VAV Yhtymä Oy (business ID 0640915-7) and its subsidiaries listed below
Contact details for data protection matters
email: tietosuoja@vav.fi
Address: VAV Yhtymä Oy, Data Protection, Veturikuja 7, 01300 Vantaa
The Data Controller’s information and communication systems utilise access rights management to control access to and use of the systems. The register stores data on data subjects, i.e. system users, who include the Data Controller’s employees, as well as employees of customers, subcontractors and other organisations to whom the Data Controller has granted access rights to the Data Controller’s systems.
The user management register contains information on the access rights granted to the systems, their duration and their scope. It contains the following personal data:
Log files contain event data from the systems: time, event, author, access rights used to perform the event, source of the event (where it was performed, where the change data originated), target of the event (which data or system the action was directed at), status of the event. For example:
In addition, the user management and logging system processes and collects personal data of users of the access rights and log register, e.g. the level of access to the logging system (how the user in question can view, edit and/or delete logs), the log data viewed, edited and deleted by the user, as well as the timestamps and identification data relating to these actions.
The purpose of the Register is to ensure the continuity and information security of the Data Controller’s services and operations, as well as to prevent and minimise any damage or harm caused to the Data Controller, users and other parties, and
With regard to information systems containing personal data, the basis for processing is the data controller’s statutory obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 of the EU General Data Protection Regulation and Section 6 of the Data Protection Act).
With regard to user management and the processing of log data in electronic communications information systems, the maintenance of the register is based on Chapters 17 and 33 of the Act on Electronic Communications Services.
With regard to information systems concerning the selection of tenants for state-subsidised rental housing, the processing is based on the statutory obligation of a private entity performing a public administrative task to manage access rights to information systems and to collect log data (Sections 16–17 of the Act on Information Management in Public Administration).
With regard to other information systems, the basis for processing is a legitimate interest based on the ownership, control and use of the data and information systems (Article 6(1)(f) of the EU General Data Protection Regulation).
Data for the user management register is routinely collected from the data subject themselves when they apply for access rights and in connection with the creation of access rights, from the controller’s human resources management system or from the data subject’s employer. The primary source of data stored in the log register is the data subject themselves, as well as the information systems whose events are recorded in the logs.
The data controller shall not disclose data to external parties without the data subject’s consent, unless this is necessary for the prevention and investigation of misconduct by the police and other investigative authorities, for the handling of legal claims (e.g. to legal advisers and courts), or to fulfil the data controller’s statutory obligations.
The Data Controller uses subcontractors for the processing of personal data in accordance with this policy. In such cases, personal data may be transferred to subcontractors to the extent necessary for the subcontractor to perform its services. Subcontractors process personal data on behalf of and for the account of the Data Controller in accordance with its instructions. Subcontractors are bound by agreements entered into with the Data Controller regarding the processing of personal data, including provisions on confidentiality and data security. An up-to-date list of the subcontractors used by the Data Controller in the processing of stored data.
If, in exceptional circumstances, personal data is processed in other countries, VAV ensures an adequate level of data protection by agreeing to the transfer using standard contractual clauses approved by the European Commission.
Only those persons who require the data to carry out their work duties are authorised to access it.
The data is protected by personal usernames and passwords. Access to and processing rights for the data are granted on the basis of work duties. Staff and subcontractors processing the data are bound by confidentiality and data security obligations. The protection of electronically stored data is based on access control, technical protection of databases and servers, monitoring of their use through the collection of log data, physical security of premises, access control, firewalls and other data communication security measures, as well as data backups.
Staff are briefed and trained on the processing of personal data through regularly organised data protection and information security training sessions.
Personal data is retained for as long as is necessary for the purpose for which it was collected. As a general rule, data is retained for as long as the data subject has access rights to the information system and for a reasonable period after such access rights have expired.
In practice, the majority of personal data may be required, for example, to investigate data protection breaches or data leaks; for this reason, the data is retained at least until the limitation periods for criminal and civil claims, as well as any related legal proceedings, have expired. The limitation periods for bringing legal actions and prosecutions vary between two and five years for data protection offences and infringements, as well as for any resulting claims for damages. According to Section 145 of the Act on Electronic Communications Services, event data must be retained for two years from the date of recording.
Data subjects have the following rights under the General Data Protection Regulation:
If the data subject has provided their personal data to the data controller and the processing is based on consent or a contract, they have the right to receive this data in a structured, commonly used and machine-readable format and the right to transfer the data to another controller in accordance with applicable legislation.
Where the processing of personal data is based on a legitimate interest, the data subject has the right to object to the processing of their data on grounds relating to their particular personal situation. When making such a request, the data subject must specify the particular situation on which their objection is based.
In situations specified by law, the data subject may request that the processing of their personal data be restricted, for example by suspending it in whole or in part, where the data subject considers that there is uncertainty regarding the accuracy of the data or its processing.
A request to access or restrict data may be made via the data request form available on the VAV website. A request to rectify data may be made the OmaVAV service or via the data request form on the website.
Data subjects have the right to lodge a complaint regarding the processing of personal data with the Data Protection Commissioner.