Privacy Notice

  1. BACKGROUND
  2. IDENTITY AND CONTACT DETAILS OF THE CONTROLLER 
    • Processing for which Edenred Finland acts as a controller
    • Contact requests
  3. PROCESSING PURPOSES
  4. RIGHTS OF USERS
    • Introduction
    • Access
    • Rectification
    • Erasure
    • Right to restriction of processing
    • Notification obligation regarding rectification or erasure of personal data or restriction of processing
    • Right to data portability
    • Right to object
    • Automated individual decision-making, including profiling

1. Background

Version 2.1, date of publication September 1st, 2021

Edenred Finland attaches great importance to the protection of personal data it processes in the course of its activities. This privacy notice applies to the processing of personal data carried out by Edenred Finland as a controller.

Processing means all operations applied to data that directly or indirectly helps identify a natural person, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

This Privacy Notice is intended to provide the data subjects with the information required by the applicable regulations and in particular by Regulation (EU)2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or “GDPR”).

2. Identity and contact details of the controller – contact details of the data protection officer

Processing for which Edenred Finland acts as controller

Edenred Finland Oy, a limited liability company whose registered office is located at Elimäenkatu 15, 00510 Helsinki, Finland and registered under the Business ID 1057825-2 (hereinafter “Edenred Finland”) is responsible for the processing of personal data as part of its activities as described in the privacy notices linked above or described below.

Contact requests

Requests for correcting information should be first solved in the application related to benefit usage or by request to the employer contact person. If this is not possible, Customer Care should be contacted. Contact forms are available to Users via the Help & Support FAQ accessible on the Edenred Website.

Requests relating to the exercise of the other rights referred to in section ‘rights of users’ of this privacy notice, the User should contact Edenred Finland here.

Contact details of the Data Controller

Edenred Finland Oy
Elimäenkatu 15, 00510 Helsinki, Finland
Online request form: https://privacyportal-de.onetrust.com/webform/[…]
Tel.: +358 9 7594 2848

3. Processing purposes

Security of Edenred Finland’s services and related IT systems

Purpose and legal basis

Edenred Finland processes the personal data of Users in order to guarantee the security of their personal data and more specifically for the purpose of prevention, detection, and circumvention of faults and fraud. To the extent necessary, Edenred Finland processes personal data in connection with encryption/decryption, logging, troubleshooting, backup, change, and problem management in systems and in cases of potential IT incidents.

This processing is necessary in order to fulfill Edenred Finland’s legitimate interests in ensuring the security of Edenred Finland’s services and related IT systems.

Data source
The personal data concerned are collected by Edenred Finland when the Users provide personal data to Edenred Finland directly or (as the case may be with regard to the Beneficiaries) when the employer companies provides personal data on Beneficiaries of the Solution.

Categories of data processed

The personal data communicated by the companies granting the Solution concerning the beneficiaries thereof, as the case may be:

  • Identification information: last name, first name, social security number
  • Professional information: company name
  • Contact information: postal address, email address, phone number
  • Data relating to the Solution associated with a Beneficiary of the Solution: benefit and load parameters like start date, end date, amounts, frequency, quantity, face value, validity period, and point of distribution/delivery

The personal data communicated directly by the Users, that is, as the case may be:

  • Identification information: last name, first name
  • Professional information: company name, role in the company
  • Contact information: postal address, email address, phone number
  • Data relating to the Solution: load parameters like requested amounts or frequency
  • Electronic identification data: IP addresses, cookies
  • Data relating to transactions made using the Solution
  • Data relating to the behavior and habits of Users when using Edenred Finland’s websites, platforms, and applications
  • Data relating to incidents that may occur while using Edenred Finland’s cards, websites, platforms, and applications

Data recipients
The personal data are exclusively intended for:

  • The individuals and organizations in direct contact with Edenred Finland requiring the data to guarantee the security of the personal data of Users
  • The Users
  • The authorities that require such data

Personal data will not be shared with third parties.

The processors of Edenred Finland include as the case may be:

  • For the hosting of information systems: DXC TECHNOLOGY FRANCE SAS, a French company whose registered office is located at 92400 Courbevoie (France), Place des Corolles, Tour Carpe Diem CS40075, RCS Nanterre 315 268 664, Siret 315 268 664 00143
  • For the issuing of Edenred Cards, the management of personal accounts/wallets, and for the authorization of transactions: PREPAY TECHNOLOGIES Ltd, an English company whose registered office is located at London W2 6HY (United Kingdom), Sheldon Square 3, Company Number 04008083, FCA Reference Number 900010
  • For personalization and delivery of Edenred Cards: THALES DIS DENMARK A/S, a Danish company whose registered office is located at 2750 Ballerup (Denmark), Borupvang 1B, CVR 16882194
  • For the management of paper vouchers: HANSAPRINT OY, a Finnish company whose registered office is located at 20100 Turku (Finland), Kauppiaskatu 5, Business ID 1023181-4
  • For services communications: LIANA TECHNOLOGIES OY, a Finnish company whose registered office is located at 90100 Oulu (Finland), Kansankatu 53, Business ID 2854471-2
  • For the Virtual Customer Service “Ella”: FRONT AI OY, a Finnish company whose registered office is located at 00180 Helsinki (Finland), Lapinlahdenkatu 16, Business ID 2990106-4
  • For application development and support: EDENRED SA, a French company whose registered office is located at 92130 Issy-les-Moulineaux (France), Boulevard Garibaldi 14-16, Be Issy building, RCS Nanterre 493 322 978, Siret 493 322 978 00021
  • For application development and support: PGS SOFTWARE SA, a Polish company whose registered office is located at 50-086 Wrocław (Poland), ul. Sucha 3, Registration number 0000304562
  • For application development and support: BEL SOLUTIONS OY, a Finnish company whose registered office is located at PO Box 59, 02601 Espoo (Finland), Business ID 1906872-6
  • For application development and support: FENIX SOLUTIONS OY, a Finnish company whose registered office is located at 20520 Turku (Finland), Lemminkäisenkatu 59, Business ID 2273220-2
  • For external security audits: F-SECURE CYBER SECURITY SERVICES OY, a Finnish company whose registered office is located at 00180 Helsinki (Finland), Tammasaarenkatu 7, Business ID 2088487-8

Data transfer outside the EU/EEA

Edenred Finland ensures that your personal data will not be transferred outside the European Union in the absence of an adequacy decision by the European Commission or without establishing appropriate and adequate safeguards ensuring the security and protection of your personal data.

Decision based exclusively on automated processing, including profiling

The processing does not involve any decision based exclusively on automated processing, including profiling, which would produce legal effects or similarly significant effects.

Retention period
Personal data are retained, and access to these data is limited, for a period of 5 or 7 years, depending on the applicable limitation period and, in the event of legal proceedings brought during this period, until all legal remedies have been exhausted.

Personal data included in Edenred Finland’s logs are stored for a maximum period of 2 years following the logging event.

Statistics

Purpose and legal basis
Edenred Finland processes the personal data of Users for research and statistical purposes, including the collection of visitor statistics on Edenred's Website.

The processing is necessary for Edenred Finland’s legitimate interests in compiling statistics and improving the quality of its services to the Users. The collection of visitor statistics on the Edenred Website takes place through statistical cookies and the placement of cookies on the User’s device is based on consent as required by applicable legislation. More information on the use of cookies is available in the cookie setting which can be accessed through the Edenred Website.

Data source

The personal data concerned are collected from the Users in connection with the use of the Solution.

Categories of data processed

The personal data collected from the employer companies granting the

The solution, include, as the case may be:

  • Identification information: last name, first name
  • Professional information: company name
  • Contact information: postal address, email address, phone number
  • Data relating to the Solution associated with a Beneficiary of the Solution: benefit and load parameters like start date, end date, amounts, frequency, quantity, face value, validity period, and point of distribution/delivery
  • The personal data collected directly from the Users, include, as the case may be
  • Identification information: last name, first name
  • Professional information: company name, role in the company
  • Contact information: postal address, email address, phone number
  • Data relating to the Solution: load parameters like requested amounts or frequency
  • Data relating to transactions made using the Solution
  • Data relating to the behavior and habits of Users when using Edenred Finland’s platforms and applications
  • Data relating to incidents that may occur while using Edenred Finland’s cards, platforms, and applications

Data recipients

The personal data are exclusively intended for:

  • Edenred Finland requires the data for research and statistical purposes;

Data transfers outside the EU/EEA

Edenred Finland ensures that your personal data will not be transferred outside the European Union in the absence of an adequacy decision by the European Commission or without establishing appropriate and adequate safeguards ensuring the security and protection of your personal data.

Decisions based exclusively on automated processing, including profiling
The processing does not involve any decision based exclusively on automated processing, including profiling, which would produce legal effects or similarly significant effects.

Retention period
Personal data are processed for the period necessary to compile statistics and deleted after the relevant statistics have been analyzed. Reports and statistics on an aggregated level that do not contain any personal data are stored until further notice.

4. Right of users

Introduction

Edenred Finland will always comply with Users’ requests in accordance with this section unless it can demonstrate that it is unable to identify the User concerned.

The identification of the User may in particular be carried out by means of a copy of an identity document or other safe means decided by Edenred Finland.

As soon as possible and at the latest within one month from the receipt of the request, Edenred Finland provides the User exercising one or more of the rights referred to below, with information on the measures taken following the request. The one-month period can be extended by two months, given the complexity and the number of requests. In the latter case, Edenred Finland informs the User of the extension and the reasons justifying it.

When the User makes his request in electronic form, the information is provided by Edenred Finland electronically where possible unless the User requests otherwise.

If Edenred Finland does not respond to the User’s request, it shall promptly inform the User, at the latest within one month from receipt of the request of the reasons for this refusal and the possibility for the User to lodge a complaint with the Data Protection Authority and to file a judicial recourse.

The requests under Article V shall be free of charge except where a User’s requests are manifestly unfounded or excessive, in particular, because of their repetitive nature. In the latter case, Edenred Finland may require the payment of reasonable fees that take into account the administrative costs related to these requests or refuse to act on them.
Where Edenred Finland has reasonable doubts concerning the identity of the User making the request, it may request the provision of additional information necessary to confirm the identity of the data subject.
The User has the right to lodge a complaint with the data protection authority. In Finland, the relevant data protection authority is the Office of the Data Protection Ombudsman: https://tietosuoja.fi

Access

The User has the right to obtain from Edenred Finland confirmation as to whether or not the personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:

  • The purposes of the processing
  • The categories of personal data concerned
  • The recipients or categories of recipients to whom the personal data
    have been or will be disclosed, in particular recipients outside the European Economic Area or in international organizations
  • Where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period
  • The existence of the right to request from Edenred Finland rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing
  • The right to lodge a complaint with the data protection authority
  • The existence, as the case may be, of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject
  • Where the personal data are not collected from the data subject, any available information as to their source

Where the personal data are transferred to a country outside the European Economic Area or to an international organization, the User shall have the right to be informed of the appropriate safeguards relating to the transfer.

The User has the right to obtain, free of charge, from Edenred Finland a copy of the personal data being processed. This right, however, may not affect the rights and freedoms of others, including the trade secrets of Edenred Finland or its intellectual property rights.

Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.

Edenred Finland may require the payment of reasonable fees based on the administrative costs, fixed at 25 EUR, for any additional copies requested by the data subject.

Rectification

The User shall have the right to obtain, free of charge, from Edenred Finland the rectification of inaccurate personal data concerning him or her, without any undue delay.

Taking into account the purposes of the processing, the User shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Erasure

The User shall have the right to obtain from Edenred Finland the erasure of personal data concerning him or her without undue delay and Edenred Finland shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

  • The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed
  • The User withdraws consent on which the processing is based and where there is no other legal ground for the processing
  • The User objects to the processing pursuant hereto
  • The personal data have been unlawfully processed
  • The personal data must be erased for compliance with a legal obligation to which Edenred Finland is subject
  • Personal data have been collected in relation to the offer of information society services to children

Where Edenred Finland has made the personal data public and is obliged in accordance with the above to erase the personal data, Edenred Finland, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the User has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

The User’s right to erase personal data shall not apply to the extent that processing is necessary:

  • For exercising the right of freedom of expression and information
  • For compliance with a legal obligation that requires processing to which Edenred Finland is subject
  • Establishment, exercise, or defence of legal claims
  • For statistical purposes in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing

Right to restriction of processing

The User shall have the right to obtain from Edenred Finland restriction of processing where one of the following applies:

  • The accuracy of the personal data is contested by the User, for a period enabling Edenred Finland to verify the accuracy of the personal data
  • The processing is unlawful, and the User opposes the erasure of the personal data and requests the restriction of their use instead
  • Edenred Finland no longer needs personal data for the purposes of processing, but they are required by the User for the establishment, exercise, or defense of legal claims
  • The User has objected to processing based on Edenred Finland’s legitimate interests pending the verification of whether these interests override those of the User

Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the User’s consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.

A User who has obtained restriction of processing shall be informed by Edenred Finland before the restriction of processing is lifted.

Notification obligation regarding rectification or erasure of personal data or restriction of processing

Edenred Finland shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance herewith to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. Edenred Finland shall inform the data subject about those recipients if the data subject requests it.

Right to data portability

Subject to the rights and freedoms of third parties, the Users shall have the right to receive the personal data concerning them, which they have provided to Edenred Finland, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance from Edenred Finland, where:

  • The processing is based on consent, or on a contract
  • The processing is performed using automated means

In exercising his or her right to data portability, the User shall have the right to have the personal data transmitted directly from Edenred Finland to another controller, where technically feasible.

The exercise of the right to portability of personal data is without prejudice to the provisions on the right to erasure.

Right to object

Where personal data are processed for direct marketing purposes, the User shall have the right to object at any time to the processing of personal data concerning him for such marketing, which includes profiling to the extent that it is related to such direct marketing.

When the User objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

The User shall have the right to object, on grounds relating to his specific situation, at any time to the processing of personal data concerning him which is based on legitimate interests pursued by Edenred Finland.

Edenred Finland shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the User or for the establishment, exercise, or defense of legal claims.

Automated individual decision-making, including profiling

The User shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or similarly significantly affects him, except when the decision:

  • Is authorized by the regulations to which Edenred Finland is subject and which also lays down suitable measures to safeguard the User’s rights and freedoms and legitimate interests; or
  • Is necessary for entering into, or performing, a contract between the User and Edenred Finland; or
  • Is based on the explicit consent of the User

In the last two cases, Edenred Finland shall implement suitable measures to safeguard the User’s rights and freedoms, at least the right to obtain human intervention on the part of Edenred Finland, to express his point of view and to dispute the decision.