| 1 | Introduction |
| 1.1 | The purpose of this Privacy Policy is to explain how and why we at Autorola Group process your personal data in connection with the use of our services. We recommend that you read this policy carefully. We are happy to assist you if you have any questions regarding your data protection. You can contact us by email at: customercenter@autorola.fi.
Your personal data is protected by law when you use our services. We comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) of the European Parliament and of the Council. This regulation ensures strong rights regarding your personal data and defines uniform rules for the processing and movement of such data.
We recommend reviewing this policy regularly, as we update it from time to time. The most up-to-date version is always available on this page. |
| 2 | What personal data do we collect? |
| 2.1 | We collect different types of personal data depending on which of our services you use and how you interact with us. However, across all Autorola services, we only collect standard data necessary for providing the service.
Personal data you provide to us When you register as a user of Autorola services, you enter into an agreement under which Autorola may use your contact details to verify your identity and provide its services.
Data collected from registered users - Name
- Phone number
- Email address
- IP address
- Age and gender
- For business users, we also collect billing and payment information as well as vehicle-related data
- Data obtained via cookies (such as location data or information about how the site is used). More details are available on our Cookies page
Data collected from website visitors - Pages visited
- Vehicles viewed
- Searches and favorites
- IP address and browser information
- Data obtained via cookies (such as location data or information about site usage). More details are available on our Cookies page
Data collected from customer service users - Information related to support requests and contact details
We also collect data related to the use of our services, which may include personal data. Payment and billing data are used exclusively for processing payments and delivering our products and services.
Sensitive personal data We do not collect sensitive personal data. Please do not send us such data unless we have specifically requested it based on legal requirements. |
| 3 | How do we collect your personal data? |
| 3.1 | We collect data when you use our website or services. Some data is provided by you, while some is collected automatically during use.
Cookies We use cookies to collect data. Cookies are small files stored in your browser when you use our website. Some cookies are deleted when your session ends, while others remain longer to facilitate site usage (e.g., remembering session information).
Cookies are used to collect information such as IP address, browser settings, and usage patterns. Location data can also be derived from IP addresses. Certain cookies track user activity on our website, applications, and services to enable personalized advertising both on this and other websites.
For more information on managing or disabling cookies, please see our Cookies page. |
| 4 | How do we use your personal data? |
| 4.1 | We use your personal data for the following purposes: - To provide and deliver our services.
- To respond to your inquiries.
- For customer communication (such as service updates and notifications).
- For marketing and advertising our services, including communications you have consented to (such as newsletters).
- To analyze and improve our website and services.
Additionally, we use your personal data to: - Analyze user experience.
- Recommend relevant vehicles.
- Optimize sales and service processes.
- Identify potential buyers.
|
| 4.2 | Legal basis for processing personal data Consent - We process data based on your consent, for example when you subscribe to newsletters, request information, or order services.
Performance of a contract - We may collect and process your personal data when necessary to provide our services or fulfill contractual obligations. We may also process limited amounts of personal data to develop and test our services when necessary.
Legal obligations - We may collect and process data to comply with legal obligations.
Legitimate interest - We may process data based on legitimate interest to improve marketing and sales activities and enhance service quality, ensuring that our interests do not override your rights.
|
| 4.3 | Sharing of personal data In certain cases, we share personal data collected through Autorola services with third parties. Such situations include buying or selling vehicles or goods, payment defaults, refunds, and official requests related to criminal investigations.
Recipients may include: - Auditors
- Buyers of vehicles or goods you sell
- Sellers of vehicles or goods you purchase
- Our bank
- Debt collection agencies
- Enforcement authorities
- Digital contract signature service providers
- Authorities
- Website maintenance and network partners
- Data backup providers
- SMS service providers
- Parking facilities where vehicles or goods are collected or delivered
- Transport companies handling your vehicles
- Third-party systems
- Logging services
Purchasing As transactions require identification, Autorola shares necessary personal data between buyer and seller as part of the agreement entered into when registering. Some transactions are conducted through intermediaries, in which case personal data may not be shared directly. After auctions, Autorola may contact buyers and sellers to finalize transactions.
Autorola is legally required to report imports and exports to INTRASTAT and may provide required personal data. Autorola must also deregister vehicles before export and provide relevant data to authorities.
Transfers to third countries We transfer your contact details outside the EU when you buy or sell vehicles or goods outside the EU.
Autorola uses the European Commission's Standard Contractual Clauses to ensure appropriate data protection where no adequacy decision exists under GDPR Article 45(3).
Service providers may only use your personal data to deliver contracted services.
Misuse Autorola Group maintains a register of users who have committed serious misuse, such as payment default or fraud.
We aim to maintain a professional service and ensure professional conduct by both buyers and sellers.
If laws are violated or legal claims arise, we may share necessary data (including personal data) with: Data may also be required for audits and shared with: |
| 4.4 | Data retention We retain personal data as follows:
User accounts: - 1 year from last login or 5 years from last transaction.
Customer service: - Up to 2 years after resolution.
Billing and payment data: Misuse: Data is deleted or anonymized after the retention period. |
| 5 | Your rights regarding personal data |
| 5.1 | If you reside in the EU/EEA, you have the right to: - Access your personal data.
- Request correction of inaccurate data.
- Request deletion of your data unless retention is legally required.
- Restrict or object to processing.
- Transfer your data to another system.
- Withdraw your consent.
To exercise your rights, contact: gdpr@autorola.com. |
| 6 | Protection of personal data |
| 6.1 | We take appropriate measures to protect your personal data from accidental or unlawful destruction, loss, alteration, or unauthorized access or disclosure. However, no system is completely secure.
Security measures include: - Encryption during data transmission.
- Encryption in data centers.
- Access restricted to necessary personnel only.
- Employee GDPR and security training.
- Confidentiality agreements for employees with access to personal data.
- Ensuring subcontractors meet data protection requirements. Service providers may not use or share your data for any purpose other than delivering contracted services.
|
| 7 | Contact us |
| 7.1 | If you have questions or wish to exercise your rights, contact us:
Data Controller:
AUTOROLA Oy Keilaranta 10E, 6th floor 02150 Espoo Email: customercenter@autorola.fi
Supervisory Authority in Finland:
Office of the Data Protection Ombudsman Lintulahdenkuja 4 00500 Helsinki Phone: +358 29 566 6700 Email: tietosuoja@om.fi
|