Data protection notice regarding VR FleetCare’s customer information

1. Controller

VR FleetCare
Business ID: 2945253-7

Radiokatu 3
PO Box 488
FI-00101 Helsinki, Finland
tel. +358 29 4343

(VR Kunnossapito Oy)
(VR FleetCare Ltd)
(VR Underhåll AB)

2. Data Protection Officer and contact information

VR Group’s Data Protection Officer Tanja Kalliojärvi
VR FleetCare’s data protection contact person Juha Ohvo

Data and contact requests to VR FleetCare: tietosuoja.kunnossapito@vr.fi

3. For which purposes do we use your personal data?

Data about the contact persons of VR FleetCare’s partners is processed for the following purposes:

  • Managing cooperation and related contact requests
  • Creating statistics on, reporting on and planning VR’s own operations
  • VR’s sales and marketing

The processing of personal data about partners’ contact persons is based on:

A contract: We process the contact persons’ personal data to put into effect a contract to which the partner is a party.

A legal obligation: We process the customer’s personal data in order to fulfil our statutory obligations, such as those stipulated by the provisions for the retention of information in the Accounting Act and the special requirements laid down in the Rail Transport Act.

A legitimate interest: The processing of the personal data of a partner’s contact person may be based on the legitimate interest of the data controller when the data is used to manage and develop the customer relationship or to prevent and investigate irregularities.

4. Sources of data

Data about partners’ contact persons is collected from a company acting as a partner or from the persons themselves.

5. Data subjects and the categories of personal data

Basic information that is registered about the contact persons of VR FleetCare’s customers:

  • Customer basic information, such as name and company
  • Customer contact information, such as first name, last name, email address, telephone number, fax number and mailing address

6. Processors of personal data

We use external parties to support the processing of personal data, including the maintenance and development of IT systems. These service providers process personal data commissioned by us and on our behalf. The data processing is in compliance with the current legislation and is always carried out in accordance with this data protection notice. This is ensured, among other things, through contracts between the organisations.

Without statutory grounds, we will not disclose customer data to parties outside VR FleetCare or parties other than those participating in the production of VR FleetCare’s services.

7. Transfer or disclosure of data outside the EU or the EEA

Data will not be disclosed outside the EU or the European Economic Area or outside countries which the European Commission considers having an adequate level of data protection, unless the adequate level of data protection has been ensured with contracts or in another manner required by law.

8. Data retention period

In data retention, the controller follows its statutory obligations. The practices of the retention of the personal data of partners’ contact persons depend on the grounds for the processing of the data.

9. Our customers’ rights

As a partner’s contact person, you have the right to access your personal data processed by VR FleetCare. You can exercise your rights by sending email to the following address: tietosuoja.kunnossapito@vr.fi. You will receive a response to your request no later than one month after sending the request.

Below, we have listed the general rights of data subjects:

1. Right to access data

A data subject has the right to obtain confirmation whether their personal data has been processed by VR FleetCare and to receive a copy of their personal data.

2. Right to rectification

A data subject has the right to request VR FleetCare rectifies inaccurate and erroneous data about them. The erroneous nature of data is to be decided on a case-by-case basis by resolving whether the data is erroneous from the viewpoint of its processing (unnecessary, incomplete, outdated).

3. Right to erasure (“right to be forgotten”)

A data subject has the right to request VR FleetCare to erase their personal data. Requests will be handled on a case-by-case basis and data that VR FleetCare has a legislation-based obligation or right to store will not be erased.

4. Right to restriction of processing

A data subject has a right in certain special situations stipulated by the regulation to request the restriction of the processing of their personal data.

5. Right to object

A data subject has the right to object to the processing of their personal data if the processing is based on the controller’s legitimate interest or if personal data is processed for direct marketing purposes.

6. Right to data portability

A data subject has the right to request their personal data in machine-readable file format. This right concerns data that is in electronic format and whose processing is based on consent or the performance of a contract.

7. Right to withdraw consent

In situations in which the processing of the data subject’s personal data is based on consent, the data subject has the right to withdraw their consent. After the consent is withdrawn, the consent-based processing in question will be discontinued.

8. Right to lodge a complaint with an authority

We seek to resolve any disputes primarily directly with data subjects. If a customer finds that we have not processed personal data as stipulated by law, the customer may lodge a complaint with a data protection authority.

10. Principles of data protection

The data security of VR FleetCare’s personal data processing as well as personal data confidentiality, integrity and accessibility are ensured with appropriate technical and organisational measures in accordance with VR-Group Ltd’s data security principles. Personal data is protected against unauthorised access and illegal or accidental processing. Personal data is processed only by persons specifically appointed by VR FleetCare to such tasks. We provide data protection training and guidance to our employees who process customer data.