Skip to content
Home

Privacy

his page describes how Autoklinikka-yhtiöt Oy processes the personal data of the persons in its registers.

Register details

Controller

Autoklinikka-yhtiöt Oy, Harkkokuja 2, 01510 Vantaa, asiakaspalvelu@autoklinikka.fi, 020 7737 437

Purposes of processing

Damage repair

Autoklinikka processes personal data for the purposes of managing repair transactions and assessing the need for or cost of the repair. The processing is based on an agreement between Autoklinikka and the data subject or the preparation thereof. The management of repair transactions for companies and organisations is related to the performance of an agreement between Autoklinikka and the organisation, where the processing is based on a legitimate interest. We process vehicle owner and possessor data as part of the management of a repair transaction based on our legitimate interest related to an agreement or the management of the repair transaction. We process invoicing information as part of the management of the repair transaction. Invoicing and other voucher information becomes part of our statutory accounting records.

We collect and receive feedback on the use of our services. We process the personal data we receive in connection with customer feedback for business development or to respond to feedback. In addition, we process data in connection with customer service, for example, when the processing is related to responding to an enquiry. To the extent that the processing of feedback and customer service are not related to the management of the repair, they are part of Autoklinikka’s legitimate interest in conducting its business operations. Processing data enables us to serve our customers in accordance with our service promise and to improve our practices.

When you order a Tesla spare part, we will share your identification and contact information and vehicle details with Tesla (privacy policy). Tesla will send you a survey on the collision repair when the work is completed.

Maintenance services

We process your personal data to assess the need for and cost of maintenance services and to carry out maintenance services. The processing is primarily based on an agreement between Autoklinikka and the data subject or the preparation thereof. We also provide our services on the basis of our legitimate interest.

In connection with maintenance services, personal data may also be collected from the centralised customer information systems of the importers of the brands that we represent, such as K-Auto Oy, Veho Group Oy Ab, Helkama-Auto Oy, Toyota Auto Finland Oy, Auto-Bon Oy, Nordic Automotive Services Oy and Hyundai Motor Finland Oy.

If you have provided your details at a maintenance location, online or in any other way in connection with maintenance or other service, your personal data may be transferred to the car importer. As a result, you may receive an electronic customer satisfaction survey, which is carried out by an external service provider on behalf of the importer. The feedback we receive from customer satisfaction surveys helps us develop our services and business operations. One-off surveys may also be carried out by the importer. Personal data related to the car and the customer relationship, including customer satisfaction data, may also be transferred to the car manufacturer on the basis of a legitimate interest.

Electronic services, marketing, customer acquisition and recruitment

The technical implementation of our online services requires the processing of electronic identification data. We measure the use of our online services for statistical purposes and carry out electronic marketing based on the usage and visitor data of our online services. The provision of online services, the compilation of statistics and electronic marketing are part of Autoklinikka’s legitimate interest in conducting and developing its business operations. Our online services make it easier and quicker for customers to do business with us and enable them to contact us at a time that suits them. The information we process for statistical purposes concerning our online services enables us to analyse and thereby develop our business operations and improve our service level. The information we process for electronic marketing purposes allows us to provide information about the services we offer through our electronic channels and to direct customers to our online service. A data subject may also give separate consent to marketing when contacting us in connection with a repair transaction.

Marketing and advertising based on the user and usage data of the online services is based on the consent of the data subject. For more information about how to withdraw consent and how to use cookies, please visit our cookie information page.

Our website includes a Google Maps functionality. Google processes personal data as an independent controller in accordance with its privacy policy and the terms and conditions of its map functionality. The service on our website allows the user to find the nearest Autoklinikka location based on the approximate location provided by the user or the exact location shared by their terminal device. The transmission and processing of the exact location is based on the user’s consent, which they provide when allowing their terminal device to transmit their location data to our online service. The location is transmitted to Google in a format that does not identify the user. The user can withdraw their consent in the settings of their terminal device.

We process the personal data of potential corporate and organisational customers and other partners for the preparation of agreements.

The processing of data about decision-makers at organisations and corporate customers is part of Autoklinikka’s marketing and communication activities. We also provide representatives of companies and organisations with information about news and current affairs related to our operations. Marketing and the provision of information to companies and organisations and their representatives falls within the scope of Autoklinikka’s legitimate interests related to its business operations. The information we process for organisational and corporate marketing purposes is used to acquire new customers and make additional sales. The information we process for communication purposes is used to keep our organisational and corporate customers informed about changes and reforms in our operations.

We organise a variety of events, where the participants’ personal data is processed for the purposes of organising the event on the basis of an agreement, our legitimate interest or the consent of the participant, depending on the event. Participant information and photographs or videos taken at events may be published and transferred to third parties for communication purposes on the basis of our legitimate interest.

We also organise various sweepstakes and contests, in which case the personal data of the participants is processed for the purpose of the sweepstake or contest based on the participant’s consent.

We process job applications submitted to us for a vacancy in order to prepare a possible employment contract. The data of a person who has submitted an open job application to Autoklinikka is processed on the basis of their consent.

Statutory obligations and the prevention of abuse

We process data to ensure the security of data processing and the implementation of the rights of the data subject as required by the General Data Protection Regulation. If a person in our register wishes to exercise their rights, this requires identification. Information about the data subject wishing to exercise their rights is stored so that we can demonstrate, if necessary, that the data subjects’ rights have been respected.

We process personal data where necessary to identify, prevent or investigate any abuse of our services. The processing is based on the legitimate interest of Autoklinikka. By preventing the abuse of our services, we are able to focus our resources on serving our customers in line with our service promise.

Automated decision-making and profiling

We do not use automated decision-making or profiling in the processing of personal data.

Personal data that we process

We process the following personal data:

  • Identification and contact details
  • Membership of a partner benefits programme
  • Information about the person’s position in the company
  • Details of the vehicle to be repaired or serviced, photographs of the vehicle and details of the repair or maintenance services
  • Insurance and invoicing information
  • Customer feedback and other reviews of Autoklinikka’s services
  • Messages sent to us, such as feedback and chat service messages
  • Information provided for recruitment purposes
  • Electronic identification data, information about the features of the terminal device and information about the use of Autoklinikka’s online services
  • Target group and interest-related data concerning the user of the online services, based on separate consent
  • Location of the terminal device
  • Information about the exercise of data subjects’ rights
  • Video recordings from surveillance cameras at our locations, and the time and place of recording

When you are doing business with us, we may ask you to provide proof of your identity by presenting your ID card. The information is only used to identify you. Your personal identify code, for example, will not be stored.

We obtain the personal data we process from the data subjects themselves or from companies or organisations used by the data subject, such as an insurance company, a finance company that owns the vehicle, a towing company or a car dealer. We also receive information about the data subject’s use of online services. Where necessary, we will seek information from public sources, such as websites, telephone enquiry services or Traficom’s vehicle registers. For marketing and communication, we also use external registers and data collected in surveys and studies.

The provision of the information marked as mandatory on online forms or agreements is a prerequisite for entering into an agreement. Additional information may also be required for performing a repair. In connection with the management of a repair transaction, it is possible to provide additional contact information that enables us to contact the data subject. If the contact information is not a prerequisite for an agreement, the processing is based on the data subject’s consent.

Data storage periods

We observe the following maximum storage periods unless otherwise required by law:

  • We will store the data processed in the course of the repair transaction for a period of five years, in accordance with the maximum warranty period we grant.
  • For maintenance services, personal data is stored for the duration of the customer relationship or for as long as required by an agreement or law.
  • We keep records of the exercise of data subjects’ rights for two years.
  • We keep invoicing data and other accounting material for the period required by the Accounting Act.
  • We store job applications and recruitment data for six months after the end of the recruitment.
  • For analytics and marketing services, we store personal data for 38 months or the minimum period permitted by the partners we use, if longer than 38 months.
  • In terms of the provision of information, we store the data for the duration of the communication activities.
  • The data of the companies and organisations we use for marketing and sales purposes is stored for the time necessary to enable sales and cooperation, up to 4 years after the last contact.

In other cases, we store personal data for one year.

Recipients of personal data

Personal data is processed by Autoklinikka’s employees whose duties require the processing of data, such as customer service staff, repair shop supervisors, and administrative and sales staff. To the extent necessary for the purposes of the processing, we disclose or transfer personal data to our partners as follows.

Damage repair

  • Our partner repair shops whose repair services are used by the data subject
  • Courtesy car service providers if the data subject needs a courtesy car
  • Other service partners for whose services the data subject contacts us
  • Subcontractors and suppliers related to the repair
  • Vehicle importers or manufacturers
  • Credit service providers to whom we disclose information only at the request of the data subject
  • Communication service providers when you contact us via chat or when we communicate with you about your repair
  • Online service providers
  • Information system providers related to vehicle repair
  • Suppliers of accounting and invoicing systems and auditors
  • Insurance companies
  • Traficom, if the details of the registered vehicle are retrieved from the vehicle register on the basis of the registration number.

Maintenance services

  • Service providers related to maintenance
  • Vehicle importers or manufacturers
  • External service providers used by vehicle importers for customer satisfaction surveys
  • Online service providers
  • Providers of information systems related to vehicle repair
  • Suppliers of accounting and invoicing systems and auditors
  • Traficom, if the details of the registered vehicle are retrieved from the vehicle register on the basis of the registration number

Electronic services, marketing, customer acquisition and recruitment

  • Analytics, marketing and advertising partners such as Google, Facebook, Leadoo and Hotjar
  • Communication service providers
  • Online service providers
  • Marketing-related information system providers

Other purposes of processing

  • Online service providers
  • System providers
  • Other processors of personal data used by Autoklinikka

In addition to the partners mentioned above, we will disclose information to the authorities if required by law.

The recipients of personal data are subject to obligations under the General Data Protection Regulation to support the exercise of the data subjects’ rights and ensure the security of processing. Data will not be transferred outside the EU to third countries unless the recipients have taken the appropriate security measures required for the transfer.

Security of processing

Autoklinikka processes personal data in accordance with the General Data Protection Regulation. The communication connections used for online services are encrypted. The systems used to process personal data require identification of the user or physical access to the processing system. Physical material containing personal data is appropriately disposed of by using a data protection container, for example, and documents containing personal data are not kept visible to other customers.

The processing of personal data is limited to those persons whose duties require the processing of personal data. The staff of Autoklinikka are instructed in accordance with the General Data Protection Regulation. When using external processors, Autoklinikka and the processors enter into a personal data processing agreement, which obligates the external processors to ensure the security of their processing operations.

Rights of the data subject

If you would like more information about the processing of your personal data, rectification, erasure or restriction of processing, please send your request by email to asiakaspalvelu@autoklinikka.fi or in writing, signed and addressed to Autoklinikka-yhtiöt Oy, Harkkokuja 2, 01510 Vantaa. Identification is required to exercise a request concerning your personal data, so please provide sufficient personal details (for example, a copy of your driving licence or ID card) with your request. Autoklinikka has the right to ask the person in question for additional information to verify their identity, if necessary. The rights of the persons in our register are described in more detail below. You can also find more information about data subjects’ rights at Tietosuoja.fi.

Right of access to data

Any person in our register has the right to receive information about the processing of their personal data, the right to request access to their data and the right to receive information about the processing of their personal data in accordance with this privacy policy.

Right to rectification

Any person in our register has the right to request the rectification of inaccurate or incorrect personal data. They also have the right to have incomplete personal data completed, taking the purpose of the processing into account.

Right to erasure

Any person in our register has the right to have their personal data erased if one of the following grounds applies:

  1. The personal data is no longer needed for the purposes for which it was processed
  2. The person withdraws their consent, if the processing was based on consent and there is no other ground for the processing
  3. The person objects to the processing on the basis of a legitimate interest and there is no overriding ground for the processing
  4. The data subject objects to the processing of their data for direct marketing purposes
  5. The personal data has been unlawfully processed
  6. The personal data must be erased to comply with a legal obligation applicable to the controller

Right to restriction of processing

Any person in our register has the right to restrict processing in the following situations:

  1. The person contests the accuracy of the data, in which case the processing is restricted for the time needed to verify the data
  2. The processing of the data is unlawful and the data subject opposes the erasure of the data and requests the restriction of the use of the data
  3. Autoklinikka no longer needs the personal data, but the data subject needs it to support a legal claim
  4. The person has objected to processing on the basis of a legitimate interest, in which case the processing is restricted for the time needed to assess the interests involved

Right to object

Any person in our register has the right to prohibit direct marketing at any time – that is, to object to processing – if their personal data is processed for direct marketing purposes.

Any person in our register also has the right to object to the processing of their data on grounds related to their particular situation if the processing is based on a legitimate interest. The processing of personal data may be continued only if there is a compelling legitimate ground which overrides the interests, rights and freedoms of the data subject or if it is necessary for the establishment, exercise or defence of legal claims.

Right to data portability

Any person in our register has the right to receive in electronic format the personal data concerning them that

  • they have provided to the controller,
  • the processing of which is based on consent or on an agreement, and
  • if the processing is carried out automatically.

Right to withdraw consent

If the processing is based on the consent of the data subject, they have the right to withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out before the withdrawal. If no other way of withdrawing consent is provided, please send a notice of withdrawal of consent by email to asiakaspalvelu@autoklinikka.fi or in writing to Autoklinikka-yhtiöt Oy, Harkkokuja 2, 01510 Vantaa.

Right to lodge a complaint with the supervisory authority

Any person in our register has the right to lodge a complaint with the supervisory authority if they consider that the processing of the data concerning them infringes the General Data Protection Regulation. The complaint must be lodged in the EU Member State where the person has their permanent place of residence or work, or where the alleged infringement took place.