Privacy notice for the corporate customer, supplier and partner register

1. Contact details of the data controller for data protection matters

Data controllers

The data controllers are the housing companies owned by the VAV Group companies listed below, each in respect of their own residents’ register; hereinafter referred to as the “Data Controller” or “VAV”.

VAV Yhtymä Oy (business ID 0640915-7) and its subsidiaries listed below,

  • VAV Asunnot Oy
  • VAV Palvelukodit Oy
  • VAV Hoiva-asunnot Oy

Contact details for data protection matters 

Data protection

email: tietosuoja@vav.fi

Address: VAV Yhtymä Oy, Data Protection, Veturikuja 7, 01300 Vantaa

2. Data subjects and the content of the register

The register contains the following personal data on decision-makers, contact persons and representatives (‘data subjects’) of the controller’s current and potential customers, suppliers or partner companies and organisations (‘Company’):

2.1 Basic details

Name, title or profession, position or role within the Organisation, Organisation details, work-related contact details (postal and visiting addresses, email address, telephone number), preferred method of contact

2.2 Data for verifying, identifying and distinguishing the data subject

2.3 Data on the data subject’s eligibility

In connection with the data controller’s procurement activities, details of the data subjects employed by the supplier regarding their education, experience, qualifications and suitability, date of birth and, where necessary, personal identification number; information required by public procurement legislation, e.g. information on the checking and content of criminal record extracts; information on European Union and UN sanctions concerning the company or the data subject; a confidentiality undertaking for tasks requiring a high degree of reliability; information concerning access and entry rights;

2.4 Background information

Information concerning roles and positions in business or public office, and other information provided by the data subject; participation in events, consents, prohibitions and restrictions regarding the processing of personal data;

2.5. Usage data relating to the data controller’s electronic services or information systems:

for example, access rights, usernames and passwords, other possible identification details, usage history and log data recorded in connection with the use of information systems; information on subscribers to the data controller’s newsletter and contact details for sending partnership-related communications.

Information relating to the company does not constitute personal data.

Communication and documents between the data controller and the Company (e.g. enquiries, emails, online forms, feedback, chat conversations, call recordings, requests for information, requests for quotations, quotations, orders and contracts carried out by the data subject on behalf of the Company, as well as the data subject’s details contained therein, do not constitute personal data but rather information describing the Company, and are not subject to data protection legislation.

3. Legal bases and purposes for the processing of personal data

The data controller processes the personal data of data subjects on the following legal bases and for the following purposes:

  1. in accordance with the legitimate interests arising from the customer, supplier or other relationship between the data controller and the Companies: establishing, managing, maintaining and developing the customer or other relationship between the data controller and the Company; the planning and development of business operations and services; the organisation of events and communication based on the relationship between the Company and the data controller;
  2. fulfilling the data controller’s statutory obligations, e.g. checking the criminal record details of data subjects employed by the supplier in procurements exceeding the EU thresholds, and assessing the reliability, competence and suitability of data subjects in accordance with the data controller’s legitimate interests; detecting, preventing and investigating fraud, money laundering and other crimes and misconduct, and complying with obligations to impose sanctions;
  3. processing of data collected through the use of cookies, advertising identifiers or other similar technical tracking methods in connection with the data controller’s online and mobile services, for the purposes specified in the data subject’s consent to the use of cookies. See further details on the use of cookies.

4. Where data is collected from

Data in the register is routinely collected from the data subject themselves in connection with the use of services and the website, when filling in a contact request or other form, when entering into a contract, or in connection with other personal, electronic or telephone communications, or when participating in events. In addition, personal data may be collected and updated from open and public information concerning companies that the Company or its representatives have published, for example, on the internet and from generally available sources of information, such as company websites, the Trade Register, postal operators and directory enquiry services (e.g. Suomen Asiakastieto Oy, Fonecta Oy, Posti Oy).

The personal data of registered individuals acting as the Supplier’s representatives (e.g. eligibility details) is generally obtained from the supplying Company. Data for verifying, identifying and distinguishing the data subject is obtained from banks and other providers of electronic signature and identification services. Criminal record information is always obtained from the individual themselves. Information regarding European Union and UN sanctions affecting a Company or a data subject is obtained from the authorities and organisations that maintain sanctions lists.

5. To whom data is disclosed or transferred

The data controller may disclose data from the register to companies belonging to the same group as the data controller and to business partners where this is necessary to fulfil the purposes of the register.

Data will not be disclosed to external parties without the data subject’s consent, except where this is necessary to fulfil the data controller’s statutory obligations, in connection with legal proceedings, at the request of public authorities, or as part of business arrangements.

The data controller uses the services of external subcontractors, for example, for data maintenance, conducting satisfaction and other surveys, managing cookie consents; for ICT tasks, the provision of electronic communication services and operational management.

Subcontractors process personal data on behalf of and for the account of the data controller in accordance with the data controller’s instructions and only to the extent necessary for the subcontractor to perform its tasks. Subcontractors are bound by agreements concluded with the data controller regarding the processing of personal data, including provisions on confidentiality and data security.

VAV and its subcontractors may process personal data within the EU/EEA and in countries whose level of data protection has been recognised as adequate by the European Commission.

If, in exceptional circumstances, personal data is processed in other countries, VAV will ensure an adequate level of data protection by agreeing to the transfer under the Standard Contractual Clauses approved by the European Commission, which can be found at: https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en

Third parties monitoring internet and mobile services on behalf of the data controller may also collect data via cookies for their own use in accordance with their own terms and conditions. They are solely responsible for their own cookies and for the data they collect for their own use.

6. Processing of personal data relating to the Data Controller’s social media users

The Data Controller’s website utilises social media features (i.e. social media plugins), such as Facebook buttons, which link to the Data Controller’s social media pages.

Social media services share users’ data with the data controller in accordance with their privacy policies and the consent given by users, e.g. comments and links relating to the data controller’s websites shared by the user on social media, as well as information contained in the user’s public profile. The data controller processes personal data obtained via its social media pages on the basis of a legitimate interest solely for the data controller’s own purposes, such as informing users about new products, services or offers, organising competitions and prize draws, receiving feedback, purchasing advertising on social media platforms, measuring the reach of pages or adverts, or providing customer service on community pages. The data controller does not process data outside of social media, nor is the data shared by social media platforms combined with the data controller’s other data or registers without the user’s consent.

Community plugins are the responsibility of the company providing them. They are primarily responsible for compliance with data protection legislation, data security and the implementation of the data subject’s rights within the service. The data controller acts as a joint controller with Facebook in respect of the data of users of the data controller’s community pages. You can familiarise yourself with social media privacy policies and information regarding joint controllership, and manage your privacy settings on a service-by-service basis:

Facebook and Instagram / Meta

7. Principles governing the protection of the register and data retention periods

Only those individuals who require the data to carry out their work duties are authorised to access it. Manual records are stored in locked premises commensurate with the data’s security level. Staff and subcontractors processing the data are bound by confidentiality obligations. The security of electronically stored data is based on access control, technical protection of databases and servers, physical security of premises, access control, communication security and data backup.

The original criminal record extract is not stored, but a record of the criminal record check is retained. If a data subject submits a criminal record extract to the data controller with their consent, it is destroyed immediately after processing.

A confidentiality undertaking provided by the data subject to the data controller is retained for 10 years following the expiry of the confidentiality period specified in the undertaking.

Usage data for electronic services collected via cookies is deleted in accordance with the time limits specified in the cookie consents.

The basic and background data of the data subject described in section 2 shall be retained permanently for communication and marketing purposes related to the data controller’s field of activity, within the limits permitted by law, unless the data subject has objected to the processing of such data.  The data controller regularly assesses the necessity of retaining personal data and, in addition, takes reasonable measures to ensure that no personal data of data subjects is retained in the register that is incompatible with the purposes of processing, outdated or inaccurate personal data.

Other personal data relating to a data subject’s customer, supplier or other relationship with the Data Controller and the Company shall be erased upon termination of the relationship or once the Data Controller has been informed that the data subject is no longer employed by the Company.

8. Rights of access, rectification and other rights of the data subject

The data subject has the right to access the personal data stored in the personal data register concerning them and to request the rectification or erasure of any data that is inaccurate, out of date, unnecessary or unlawful.

The data subject also has the right at any time to withdraw their previously given consent to the processing of their personal data. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal of consent.

If the data subject has provided their personal data to the data controller and the processing is based on consent or a contract, they have the right to receive this data in a structured, commonly used and machine-readable format, and the right to transfer the data to another data controller in accordance with applicable legislation.

Where the basis for the processing of personal data is a legitimate interest, the data subject has the right to object to the processing of their data on grounds relating to their particular personal circumstances. When making such a request, the data subject must specify the particular circumstances on which the objection is based.

In situations specified by law, the data subject may request that the processing of their personal data be restricted, for example, by suspending it in whole or in part, where the data subject considers there to be uncertainty regarding the accuracy of the data or its processing.

A request to access or restrict data may be made via the data request form on the VAV website. A request to rectify data may be made the OmaVAV service or via the data request form on the website.

Data subjects have the right to lodge a complaint regarding the processing of their personal data with the Data Protection Commissioner.