1. General

This privacy policy (hereinafter the “policy”) explains how AutoLoop Oy (“Autoloop”) collects and processes personal data, the legal basis on which the data is collected, the purposes for which it is used, and to whom the data may be disclosed. In our operations, we comply with the EU General Data Protection Regulation (2016/679) and all other data protection legislation related to the processing of personal data.

Personal data means any information relating to a natural person (“data subject”) from which they can be directly or indirectly identified, as defined in data protection legislation. Data from which a data subject cannot be directly or indirectly identified is not considered personal data.

This privacy policy applies to all activities conducted with members of Autoloop’s producer community, contractual partners, and other cooperating partners. The privacy policy applies to the processing of personal data of Autoloop’s producer community members, contractual partners, representatives of other cooperating entities, as well as consumers using Autoloop’s website.

2. Data Controller and Controller’s Contact Person

The data controller in accordance with applicable data protection law is AutoLoop Oy.

Controller’s contact details:
AutoLoop Oy
Ateneuminkuja 2 C, 10th floor, 00100 Helsinki
Business ID: 3506448-5

Controller’s contact person:
Juha Kenraali
[email protected]
Tel: 040 772 2026

3. Legal Basis and Purpose of Processing Personal Data

We collect and process only the personal data that is necessary for conducting Autoloop’s operations and managing member affairs.

The legal basis for processing is a contract, consent, or a legitimate interest related to the management of a membership or other cooperative relationship. Additionally, the processing of personal data is based on statutory obligations, such as accounting requirements.

Personal data is processed for purposes including, but not limited to:

4. Categories of Processed Personal Data

Data is collected from the users themselves, for example, by email, by phone, or through Autoloop’s website. Additionally, any previously provided information that may exist about the user is utilized.

The data to be stored in the register includes the person’s name, position, company/organization, business ID, and contact details (phone, email, address).

Necessary cookies for website visitors are processed based on separate consent or legitimate interest. Cookies that collect user data are not used.

5. Retention of Personal Data

Personal data is retained only for as long as is necessary to fulfill the purposes defined in this policy, or if the data controller has a statutory obligation to do so.

Personal data is deleted when its retention is no longer necessary by law or for the fulfillment of the rights or obligations of either party.

6. Disclosure of Personal Data and Data Processing Entities

The data controller may transfer the processing of personal data to external service providers or subcontractors. Appropriate processing of personal data that meets the requirements of data protection legislation is ensured through agreements between the parties.

The following entities, separate from the data controller, act as data processors:

Based on consent, the contact and billing information of companies joining as members of the producer community is disclosed to the lead-acid battery producer community Akkukierrätys Pb Oy and the tire producer community Suomen Rengaskierrätys Oy for the implementation of producer responsibility for these product groups.

Additionally, in special cases, personal data may be disclosed to authorities based on a statutory obligation or right.

7. Rights of the Data Subject

Data subjects have, among others, the following rights guaranteed by data protection legislation:

8. Data Security and Potential Data Breaches

We implement appropriate measures to protect personal data against loss, destruction, misuse, and unauthorized access or disclosure. Access to personal data is restricted only to individuals who need it to perform their work duties.

In the event of a potential personal data breach, data subjects will be notified without delay as required by data protection legislation.

9. Right to Lodge a Complaint with a Supervisory Authority

The data subject has the right to lodge a complaint with a supervisory authority if they consider that their personal data has been processed in violation of data protection legislation. In Finland, the competent supervisory authority is the Office of the Data Protection Ombudsman.

10. Changes to the Privacy Policy

We make changes and updates to this policy as necessary. The need for updates may arise, for example, from the development of our services or changes in data protection legislation.

The latest, up-to-date version of the policy can always be found on our website.

11. Further Information

Further information regarding this policy and the processing of data subjects’ personal data can be obtained upon request from the contact person named in Section 2 of this policy.