
Privacy Policy
treco Oy
Combined privacy policy and information document in accordance with the Data Protection Act and the European Union's General Data Protection Regulation (2016/679/EU).
REGISTRAR
treco Oy
Otakaari 5, 02150 Espoo
Contact person for data protection matters
Nikodemus Nousiainen
044 971 3271
info@treco.fi
Postal Address: Otakaari 5, 02150 Espoo
NAME AND CONTENTS OF THE REGISTER
treco Oy's customer register ("Customer Register").
LEGAL BASIS FOR PROCESSING PERSONAL DATA / WHY DO WE COLLECT YOUR DATA?
1.1 General information about processing personal data
Insofar as the Customer Register contains personal data, its processing complies with the Data Protection Act and other applicable laws, regulations, provisions, and official guidelines concerning the processing of personal data. Personal data refers to information that can be linked to a specific person. This document describes in more detail the procedures for collecting, processing, and disclosing personal data, as well as the rights of the customer, i.e., the data subject.
1.2 Purpose of collecting personal data
a) Contractual, customer, or other comparable relationship
The purpose of the customer register is the controller's
contractual or customer relationship with the client (e.g., seller or landlord);
a relationship related to the performance of an assignment with the client's counterparty (e.g., buyer or tenant);
a contractual relationship with the user of an assessment assignment or other expert service.
The controller may also collect data, for example, from persons present at apartment viewings in order to prevent crimes or misconduct, monitoring and investigating them, or by other means to determine the interests of potential customers or to establish a subsequent customer relationship/provide services and for marketing purposes.
The persons referred to in point a) above are referred to as Customers in this statement.
b) Legislation concerning real estate agencies, including the Act on Real Estate Agencies and Rental Housing Agencies (1075/2000) and the Act on Real Estate and Rental Housing Agencies (1074/2000) and the handling of assignments based on them, as well as the clarification of the Customer's own searches, require the storage, use, and retention of the information mentioned in the section "Customer register data content" below. The agency must, among other things, keep an assignment log in which the personal, property, and event information related to each assignment, together with the relevant documents, are stored ("Assignment Log").
c) Statutory supervision of money laundering
In accordance with Chapter 3, Section 3 of the Act on the Prevention of Money Laundering and Terrorist Financing (444/2017, hereinafter referred to as the "Money Laundering Act"), customer identification data and other personal data required by law shall be stored stored and may be used for the prevention, detection, and investigation of money laundering and terrorist financing, as well as for the investigation of money laundering and terrorist financing and the crime by which the property or proceeds of crime subject to money laundering or terrorist financing have been obtained. Customer identification data or other personal data obtained solely for the purpose of preventing and detecting money laundering and terrorist financing shall not be used for any purpose incompatible with those purposes.
d) Storage of data based on consent
Insofar as the right to register based on the above-mentioned laws or circumstances is exceeded, or there is no other legal basis, the Customer will be asked for separate consent to the storage, processing and retention of personal data. Assignment data is also used for contractual relationships related to assessment and other expert services and is stored in the same way as the Assignment Log.
1.3 Purpose of use of data
The data in the customer register may be used for the following main purposes:
-
managing and developing customer relationships
-
producing, providing, developing, improving and protecting services
-
invoicing, collection and verification of customer transactions
-
targeting advertising
-
analysis and statistics related to services
-
customer communications, marketing and advertising
-
protecting and securing the rights and/or property of the controller and other persons and entities related to the assignments
-
property
-
fulfilment of the controller's legal obligations, and
-
other similar purposes.
1.4 Consequences of not providing information
If the controller does not receive the information referred to in sections 1.2 a), b) and c), it will not be possible to establish or continue a customer relationship, enter into any other agreement or participate in legal proceedings with the customer. If sufficient information to identify a visitor is not obtained during a property viewing, that person may not be allowed to attend the viewing.
CUSTOMER REGISTER DATA CONTENT / WHAT DATA DO WE COLLECT?
The assignment log and its appendices contain or may contain data belonging to the following categories:
-
Basic customer data, such as full name, address, language
-
personal identification number and, if applicable, company identification number of the person acting on their own behalf or on behalf of the company for reliable identification
-
information related to invoicing and collection
-
information related to the customer relationship and contractual relationship, such as services offered to the customer, date of use,
-
purchase offer, its acceptance, date of rental or sales agreement and information, property details, brokerage commission,
-
service seller information and other similar information
-
permission and prohibition information, such as direct marketing permissions and prohibitions
-
interests and other information provided by the Customer
-
other service event information
-
complaints and their processing information
-
tenant credit information and other financial information for assessing the ability to pay rent
The following customer-related information is or may be processed in the register data concerning the supervision of the Money Laundering Act:
-
name, date of birth, and personal identification number
-
representative's name, date of birth, and personal identification number
-
legal entity's full name, registration number, date of registration, and registration authority
-
full names, dates of birth, and nationalities of the members of the legal entity's board of directors or equivalent decision-making body
-
legal entity's field of activity
-
name, date of birth, and personal identification number of the beneficial owners
-
name, document number, or other identifying information of the document used for identity verification and the issuer, or a copy of the document, or, if the customer has been identified remotely, information on the procedure or sources used for verification
-
information on the customer's activities, the nature and scope of their business, their financial position, the reasons for using the transaction or service, and information on the origin of funds, as well as other necessary information obtained for customer identification purposes as referred to in Section 4(1) of the Money Laundering Act
-
information related to determining the origin of funds in accordance with section 4(3) of the Money Laundering Act, and necessary information obtained in order to fulfill the enhanced customer due diligence requirements related to politically influential persons in accordance with section 13
-
in the case of a foreign Customer who does not have a Finnish personal identity number, information on the Customer's nationality and travel document details
DATA RETENTION PERIOD
The data in the assignment log shall be retained for ten (10) years after the end of the assignment.
Data subject to the Money Laundering Act is stored for five (5) years, unless further storage of the data is necessary for criminal investigations, pending legal proceedings, or to safeguard the rights of the data controller or its employees. The necessity of further storage of data and documents shall be reviewed no later than three (3) years after the previous review of the necessity of storage (Act on the Prevention of Money Laundering and Terrorist Financing, 444/2017, Section 4).
Other personal data will be deleted once there is no longer a need to retain it. If the collection and retention of personal data is based solely on the Customer's consent, the personal data will be deleted at the Customer's request.
REGULAR SOURCES OF INFORMATION / WHERE IS THE INFORMATION COLLECTED FROM?
Personal data is collected from the Customer themselves in connection with the assignment agreement, purchase or rental offer and other events related to the assignment, the fulfillment of the obligation to obtain consent and the preparation of documents, when using the services of the data controller in other ways, or otherwise directly from the Customer, for example, during apartment and property viewings. Personal data may also be collected and updated from, for example, property management companies, the population register, other official registers, and credit registers.
Consent-based data is collected directly from the Customer or, with their consent, from registers or sources maintained by authorities or third parties.
DISCLOSURE OF DATA / TO WHOM CAN DATA BE DISCLOSED?
The controller may disclose personal data within the limits permitted and required by applicable law, as well as for the purpose of implementing an agreement between the parties or when there is a relevant connection. Personal data may be disclosed, for example, to the Regional State Administrative Agency and other authorities, to the banks of the parties to the transaction in connection with the transaction, and to the property manager and the National Land Survey of Finland at various stages of the assignment.
Data is not regularly transferred outside the European Union or the European Economic Area. However, data may be transferred or disclosed outside the European Union or the European Economic Area in accordance with the law if the data is transferred to a country where the European Commission has determined that the level of data protection is adequate, or if an adequate level of data protection can be guaranteed through contractual arrangements. Transfers outside the EU may also take place temporarily in connection with the use of various cloud services, such as OneDrive, iCloud, or Dropbox.
Data is disclosed to authorities in cases required by law.
The purchase price and other information about the object of the transaction are also disclosed to the Central Federation of Finnish Real Estate Agencies (KVKL), where the information is stored in the KVKL price monitoring service (HSP) used by real estate agents to the extent required by the service. Information from the HSP may be further disclosed to HSP customers. The privacy policy for this service can be found at http://www.hintaseurantapalvelu.fi/tietosuoja.
In connection with the outsourcing of the controller's data management, personal data may also be processed by the controller's subcontractors, but only on behalf of the controller. Such subcontractors may include, for example, providers of real estate brokerage and marketing systems, as well as entities that maintain apartment sales advertisement portals.
REGISTRY PROTECTION PRINCIPLES / HOW DO WE PROTECT YOUR PERSONAL DATA?
Access to the registry requires a user ID granted by the main user of the customer registry. The main user also determines the level of access granted to other users. Only those employees of the data controller and subcontractors who need the information to perform their work-related tasks have access to the data.
The data is collected in service databases that are protected by firewalls, passwords, and other technical means. The databases are located in locked and guarded premises, and only certain predefined persons have access to the data.
Insofar as personal data is processed on behalf of the controller by its subcontractor, the agreements between the controller and the subcontractor ensure that appropriate safeguards are in place and that the processing of personal data complies with the requirements of data protection legislation.
CUSTOMER RIGHTS / HOW CAN I ENSURE THAT THE PROCESSING IS LAWFUL?
1. Inspection, access, and transfer of data
The customer has the right to check what information concerning them has been stored in the customer register. The customer must submit a request for inspection to the controller in writing, signed by hand or in a similarly certified document, or by email.
Notwithstanding the above, the Customer does not have the right to check data obtained for the purpose of fulfilling the reporting or notification obligation laid down in the Money Laundering Act (Section 4:3 of the Money Laundering Act). However, the Data Protection Ombudsman may, at the Customer's request, inspect the lawfulness of the processing of such information.
The controller shall provide the Customer with the above information within 30 days of the request for inspection.
The Customer has the right to have the customer data they have provided transferred to a third party in a structured and commonly used machine-readable format. However, the controller shall retain the transferred data in accordance with this privacy policy.
2. Correction of incorrect information
The customer has the right to correct information stored in the personal data register concerning him/her insofar as it is incorrect. 9.3 Objection to or restriction of data processing and deletion of data
The customer has the right to object to the processing of data concerning him or her for the purposes of direct advertising, distance selling, and other direct marketing, as well as market and opinion surveys and for the development of the controller's business, and to restrict the processing of data concerning them, as well as the right to have personal data concerning them that has already been stored for the aforementioned purposes deleted, even if there are grounds for processing the data otherwise.
3. Withdrawal of consent
If the data in the register is based on the consent given by the Customer, the consent can be withdrawn at any time by notifying the controller's representative mentioned in this statement. Upon request, all data that does not need to be retained or cannot be retained on the basis of the law or other grounds mentioned in this privacy statement will be deleted.
4. Procedure for exercising rights
Requests for inspection, correction, or other requests can be made by contacting the controller's customer service using the contact details provided in this statement.
5. Disputes
The customer has the right to refer the matter to the Data Protection Ombudsman if the controller does not comply with the customer's request for correction or other request.
PROFILING AND AUTOMATED DECISION-MAKING
The controller does not profile the customer on the basis of personal data or use automated decision-making.