We have a range of rental homes in Vantaa. Take a look at the apartments and fill in an application.
Would you like to book a parking space or a sauna session? Have you left your keys at home? Please get in touch with us.
VAV is a rental housing group founded in 1986 that enables a good and high-quality life in Vantaa.
We provide service around the clock, every day of the year.
Data controllers
VAV Yhtymä Oy (company registration number 0640915-7) and its subsidiaries listed below, hereinafter referred to as the “data controller”
Contact details for data protection matters
Enquiries to the data controller’s data protection officer and regarding all data protection matters may be sent using the following contact details:
email: tietosuoja@vav.fi
Address: VAV Yhtymä Oy, Data Protection Matters, Veturikuja 7, 01300 Vantaa
The Data Controller uses an electronic locking and access control system in its properties. Keys to the properties are issued to and used by the Data Controller’s employees, the residents of the properties, and cleaning and property maintenance staff. The following information on data subjects – that is, individuals to whom the Data Controller has granted access rights – is stored in the locking and access control register:
The data controller has a legitimate interest, based on the ownership and management of the properties (Article 6(1)(f) of the EU General Data Protection Regulation), in processing the personal data in the register for the following purposes:
The data required for granting access rights is obtained from the data subject themselves, from the Data Controller’s HR system, or from the data subject’s employer if they are employed by an external organisation. The data controller determines the data subject’s access rights, and the access control system generates an access card or key number or other identifier and an alarm code.
Access event data is collected from the use of access cards. For example, information on keys and their access rights is stored in a smart lock. The smart key number and the time of use are transmitted to the lock when the key is used. Lock-specific key event data is automatically transferred from some locks and readers to the database and can, if necessary, be read using a separate reading device.
The Data Controller will not disclose data to external parties without the Data Subject’s consent, unless this is necessary for the prevention and investigation of misconduct by the police and other investigative authorities, for the purpose of handling legal claims, e.g. to legal advisers and courts, or to fulfil the Data Controller’s statutory obligations.
The Controller uses subcontractors in the processing of personal data in accordance with this notice. In such cases, personal data may be transferred to subcontractors to the extent necessary for the subcontractor to perform its services. Subcontractors process personal data on behalf of and for the account of the Data Controller in accordance with its instructions. Subcontractors are bound by agreements concluded with the Data Controller regarding the processing of personal data, including terms relating to confidentiality and data security.
The Data Controller uses the following subcontractors for the processing of personal data:
Personal data will not be transferred outside the EU/EEA.
Only those persons who require the data to carry out their work duties are authorised to access it.
The data is protected by personal usernames and passwords. Access to and processing rights for the data are granted on the basis of job duties. Staff and subcontractors processing the data are bound by confidentiality and data security obligations. The protection of electronically stored data is based on access control, technical protection of databases and servers, monitoring of their use through the collection of log data, physical security of premises, access control, firewalls and other data communication security measures, as well as data backup.
Staff are briefed and trained on the processing of personal data through regularly organised data protection and information security training sessions.
Personal data is retained for as long as necessary to fulfil the purpose of access control, but for no longer than one year from the date of recording, so that the Data Controller can investigate any incidents of damage or property offences that may have occurred on the premises. For example, a lock in the iLOQ system records approximately the last 500 instances of the door being opened and automatically deletes old log data to make way for new entries. Under normal use, the lock’s event log data is retained for an average of approximately 2–3 months from the date the log event was recorded.
Log event data is retained in the system for 90 days.
The data required for granting access rights, as well as the access rights and identifiers themselves, are deleted once it is no longer necessary for the data subject to access the data controller’s premises, for example, following the termination of a tenancy, rental agreement or employment contract.
Data may be retained beyond the aforementioned retention periods for as long as it is required as evidence for claiming compensation, to comply with a statutory obligation, or to establish, exercise or defend a legal claim, that is, until the legal proceedings in the matter have been concluded, for example by a final and binding judgement.
The data subject has the following rights under the General Data Protection Regulation:
The customer has the right to access their personal data held in the register by submitting a request for access using the information request form available on the data controller’s website.
Data subjects have the right to request the rectification or erasure of data that is inaccurate, out of date, unnecessary or unlawful.
Data subjects also have the right to withdraw their previously given consent to the processing of their personal data at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal of consent.
If the data subject has provided their personal data to the data controller and the processing is based on consent or a contract, they have the right to receive this data in a structured, commonly used and machine-readable format and the right to transfer the data to another controller in accordance with applicable legislation.
Where the basis for the processing of personal data is a legitimate interest, the data subject has the right to object to the processing of their data on grounds relating to their particular personal circumstances. When making such a request, the data subject must specify the particular circumstances on which their objection is based.
In situations specified by law, the data subject may request that the processing of their personal data be restricted, for example, that it be suspended in whole or in part, where the data subject believes there is uncertainty regarding the accuracy of the data or its processing.
Requests must be submitted in person, by post or by email using the contact details provided in paragraph 1. Where necessary, the data controller may ask the data subject to clarify their request in writing and to prove their identity.
The data subject has the right to lodge a complaint regarding the processing of personal data with the Data Protection Commissioner.