Privacy Notice for the Locking and Access Control Register

1. Contact details of the data controller for data protection matters

Data controllers

VAV Yhtymä Oy (company registration number 0640915-7) and its subsidiaries listed below, hereinafter referred to as the “data controller”

Contact details for data protection matters

Enquiries to the data controller’s data protection officer and regarding all data protection matters may be sent using the following contact details:

email: tietosuoja@vav.fi

Address: VAV Yhtymä Oy, Data Protection Matters, Veturikuja 7, 01300 Vantaa

2. Data subjects and the content of the register

The Data Controller uses an electronic locking and access control system in its properties. Keys to the properties are issued to and used by the Data Controller’s employees, the residents of the properties, and cleaning and property maintenance staff. The following information on data subjects – that is, individuals to whom the Data Controller has granted access rights – is stored in the locking and access control register:

  1. information required for granting access rights, e.g. name, contact details, company; access rights and identifiers, e.g. access card or access control key number or mobile identifier, access rights group and any alarm code
  2. access events, i.e. door, date and time.

3. Legal bases and purposes for the processing of personal data

The data controller has a legitimate interest, based on the ownership and management of the properties (Article 6(1)(f) of the EU General Data Protection Regulation), in processing the personal data in the register for the following purposes:

  1. Management of the use of the data controller’s premises
  2. Preventing unauthorised access to the data controller’s properties
  3. Ensuring and safeguarding the security of the Data Controller’s premises, the property located therein and the persons moving within them
  4. Preventing vandalism and criminal offences, as well as investigating and documenting offences that have already occurred and situations that endanger property and safety.

4. Sources of data

The data required for granting access rights is obtained from the data subject themselves, from the Data Controller’s HR system, or from the data subject’s employer if they are employed by an external organisation. The data controller determines the data subject’s access rights, and the access control system generates an access card or key number or other identifier and an alarm code.

Access event data is collected from the use of access cards. For example, information on keys and their access rights is stored in a smart lock. The smart key number and the time of use are transmitted to the lock when the key is used. Lock-specific key event data is automatically transferred from some locks and readers to the database and can, if necessary, be read using a separate reading device.

5. To whom is the data disclosed or transferred?

The Data Controller will not disclose data to external parties without the Data Subject’s consent, unless this is necessary for the prevention and investigation of misconduct by the police and other investigative authorities, for the purpose of handling legal claims, e.g. to legal advisers and courts, or to fulfil the Data Controller’s statutory obligations.

The Controller uses subcontractors in the processing of personal data in accordance with this notice. In such cases, personal data may be transferred to subcontractors to the extent necessary for the subcontractor to perform its services. Subcontractors process personal data on behalf of and for the account of the Data Controller in accordance with its instructions. Subcontractors are bound by agreements concluded with the Data Controller regarding the processing of personal data, including terms relating to confidentiality and data security.

The Data Controller uses the following subcontractors for the processing of personal data:

  • Certego Oy
  • iLOQ Oy: technical support and maintenance of the locking and access control system.

Personal data will not be transferred outside the EU/EEA.

6. Principles governing the protection of the register and the retention period for data

Only those persons who require the data to carry out their work duties are authorised to access it.

The data is protected by personal usernames and passwords. Access to and processing rights for the data are granted on the basis of job duties. Staff and subcontractors processing the data are bound by confidentiality and data security obligations. The protection of electronically stored data is based on access control, technical protection of databases and servers, monitoring of their use through the collection of log data, physical security of premises, access control, firewalls and other data communication security measures, as well as data backup.

Staff are briefed and trained on the processing of personal data through regularly organised data protection and information security training sessions.

Personal data is retained for as long as necessary to fulfil the purpose of access control, but for no longer than one year from the date of recording, so that the Data Controller can investigate any incidents of damage or property offences that may have occurred on the premises. For example, a lock in the iLOQ system records approximately the last 500 instances of the door being opened and automatically deletes old log data to make way for new entries. Under normal use, the lock’s event log data is retained for an average of approximately 2–3 months from the date the log event was recorded.

Log event data is retained in the system for 90 days.

The data required for granting access rights, as well as the access rights and identifiers themselves, are deleted once it is no longer necessary for the data subject to access the data controller’s premises, for example, following the termination of a tenancy, rental agreement or employment contract.

Data may be retained beyond the aforementioned retention periods for as long as it is required as evidence for claiming compensation, to comply with a statutory obligation, or to establish, exercise or defend a legal claim, that is, until the legal proceedings in the matter have been concluded, for example by a final and binding judgement.

7. The data subject’s rights to access, rectification and other rights

The data subject has the following rights under the General Data Protection Regulation:

The customer has the right to access their personal data held in the register by submitting a request for access using the information request form available on the data controller’s website.

Data subjects have the right to request the rectification or erasure of data that is inaccurate, out of date, unnecessary or unlawful.

Data subjects also have the right to withdraw their previously given consent to the processing of their personal data at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal of consent.

If the data subject has provided their personal data to the data controller and the processing is based on consent or a contract, they have the right to receive this data in a structured, commonly used and machine-readable format and the right to transfer the data to another controller in accordance with applicable legislation.

Where the basis for the processing of personal data is a legitimate interest, the data subject has the right to object to the processing of their data on grounds relating to their particular personal circumstances. When making such a request, the data subject must specify the particular circumstances on which their objection is based.

In situations specified by law, the data subject may request that the processing of their personal data be restricted, for example, that it be suspended in whole or in part, where the data subject believes there is uncertainty regarding the accuracy of the data or its processing.

Requests must be submitted in person, by post or by email using the contact details provided in paragraph 1. Where necessary, the data controller may ask the data subject to clarify their request in writing and to prove their identity.

The data subject has the right to lodge a complaint regarding the processing of personal data with the Data Protection Commissioner.