Privacy Policy

How we collect, use, and protect your personal data

Last updated: April 2026 | Version: 1.0

Table of Contents

Part 1 — Identity & Contact

1. Controller Identity (Rekisterinpitäjä)

Data Controller / Rekisterinpitäjä:

Autoydin

Data Protection Contact: Our data protection officer at the same email address above.

2. What Personal Data We Collect and Why

We collect and process personal data in the following situations:

A. Enquiries & Contact Forms

Data: Name, email, phone number, message content.

Purpose: To respond to your enquiry.

Legal basis: Legitimate interest (Art. 6(1)(f)) — responding to a direct enquiry is a legitimate purpose.

Retention: 6 months from last contact, then deleted.

B. WhatsApp Communications

Data: Your phone number, message content, any images/video you send.

Purpose: To conduct vehicle presentations and manage purchase discussions.

Legal basis: Contractual necessity (Art. 6(1)(b)) or legitimate interest.

Retention: 12 months after last communication. WhatsApp messages are also subject to Meta's own privacy policy — we recommend you review it at whatsapp.com/legal.

Note: WhatsApp is operated by Meta (US company). Data may be transferred outside the EEA under Standard Contractual Clauses.

C. Vehicle Purchase Transactions

Data: Full name, address, date of birth, ID document details (for anti-money-laundering verification), payment information, vehicle registration details.

Purpose: To fulfil the sales contract and comply with Finnish accounting and anti-money-laundering obligations.

Legal basis: Contract performance (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).

Retention: 10 years — required by Finnish Accounting Act (Kirjanpitolaki 1336/1997).

D. Sourcing Service Clients

Data: Name, contact details, budget, car preferences, bank/financing details if provided.

Purpose: To carry out the sourcing service agreement.

Legal basis: Contract performance (Art. 6(1)(b)).

Retention: Duration of agreement + 12 months.

E. Marketing (only with consent)

Data: Name, email address.

Purpose: To send newsletters or vehicle availability updates.

Legal basis: Consent (Art. 6(1)(a)). You may withdraw consent at any time.

Retention: Until you unsubscribe. We delete within 30 days of unsubscribe request.

Part 2 — Third Parties & Transfers

3. Recipients of Your Data

We share your personal data only with the following parties, and only to the extent necessary:

  • Financing partners: If you apply for financing, we share your contact details and vehicle interest with our partner. They are an independent data controller.
  • Extended warranty provider: Receives vehicle and contact details to issue and manage warranty contracts.
  • Vehicle inspection companies: We may share a vehicle's details (not buyer's personal data) with inspection providers.
  • Accounting software / bookkeeping service: Transactional data is processed by our service provider acting as our data processor under a GDPR-compliant processing agreement.
  • WhatsApp / Meta: Communications via WhatsApp are processed by Meta Platforms Ireland Ltd under their own terms.
  • Finnish tax authority (Verohallinto): Transaction records are reported as required by Finnish law.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

4. International Data Transfers

Some of our service providers are based outside the European Economic Area (EEA). Specifically:

  • WhatsApp (Meta Platforms, USA): Messages sent via WhatsApp may be processed on servers outside the EEA. Meta relies on Standard Contractual Clauses (SCCs) approved by the European Commission for these transfers. See Meta's privacy policy for details.

Where data is transferred outside the EEA, we ensure appropriate safeguards are in place under GDPR Article 46.

Part 3 — Your Rights

5. Your Data Subject Rights (8 Rights)

Under GDPR and the Finnish Data Protection Act (Tietosuojalaki 1050/2018), you have the following rights:

1. Right of Access

You may request a copy of all personal data we hold about you.

2. Right to Rectification

You may ask us to correct inaccurate data.

3. Right to Erasure

You may request deletion of your data where there is no legal obligation requiring us to retain it. Note: We cannot delete accounting records required by the Finnish Accounting Act for 10 years.

4. Right to Restrict Processing

You may request we limit how we use your data while a dispute is resolved.

5. Right to Data Portability

You may receive your data in a machine-readable format.

6. Right to Object

You may object to processing based on legitimate interest (e.g., direct marketing).

7. Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time without penalty. Withdrawal does not affect processing that already took place.

8. Right to Lodge a Complaint

You have the right to complain to the Finnish Data Protection Ombudsman (tietosuoja.fi): PO Box 800, 00531 Helsinki.

To exercise any of these rights, contact us at privacy@autoydin.fi. We will respond within 30 days.

6. Cookies & Compliance

Our website uses cookies. Cookies are small text files stored on your device.

You can manage your preferences at any time. Withdrawing consent does not affect cookies already set. To delete existing cookies, use your browser settings.

7. Policy Updates & Version Control

This Privacy Policy was last updated: April 2026. Version: 1.0.

We may update this policy when our practices change or when required by law. For material changes, we will notify you by email (if you have provided one) at least 14 days before the change takes effect. The current version is always available at autoydin.fi/privacy.

Previous versions are available on request by emailing privacy@autoydin.fi.

Questions About This Privacy Policy?

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:

Email: privacy@autoydin.fi

Phone: +358 10 200 2970

Address: Gerbyntie 16, 65230 Vaasa, Finland

We take your privacy seriously and are committed to transparency and compliance with all applicable data protection laws.

Ready to find your car?

Let's start a conversation. Message me on WhatsApp or browse available cars.