Privacy Policy seloste

Privacy policy of the user register

1. The controller

This privacy notice is available in several languages. In the event of a difference of interpretation between the language versions, the Finnish version shall prevail.

DuuniOnline Oy (Y-tunnus: 3020384-5)
Volttikatu 5
70150 KUOPIO

The data subject should contact PalkkaOnline's customer service for all questions related to the processing of personal data and the exercise of data subjects' rights.

PalkkaOnline's customer service e-mail address: or by post:

DuuniOnline Oy
Volttikatu 5
70150 KUOPIO

2. Purpose and legal grounds for processing personal data

Personal data are processed for the following purposes:

  • Service provision, customer relationship management, administration and customer communication.
  • Maintenance of user data
  • Execution of tasks authorised by users, such as sending invoices and receiving payment from the customer, payment of wages, insurance management and collection.
  • Surveys, such as customer satisfaction surveys
  • Performing statutory and regulatory obligations, such as handling tax matters
  • Business and service development, statistics, analysis and data security
  • Risk management
  • Detection of irregularities
  • Marketing
  • Profiling of users and decisions based on automated processing of personal data, such as targeted provision of additional services.

The processing of personal data is based on contract, consent, a legal obligation or a legitimate interest of PalkkaOnline. Legitimate interests include intra-group data transfers, data processed for data security purposes, investigation of misconduct and direct marketing.

3. Personal data processed

The personal data processed may include:

  • Name
  • Contact details (telephone number and e-mail address)
  • Age
  • Gender
  • Occupation
  • Personal identification number
  • Nationality and work permit details if applicable
  • Tax information
  • Enforcement information, if any
  • Information relating to payment of wages
  • Client-related information, such as information on mandates authorised by the client
  • Necessary identification and technical usage data related to the customer relationship, such as customer service call logs, cookies and log data, location data related to mileage reimbursements
  • A copy of the identity document, if applicable
  • Documents required to verify professional qualifications, e.g. certificates and attestations
  • Criminal record to check the criminal background of those working with children. Only the production of the extract and its identifying information will be recorded in the data file. The extract is not stored permanently.
  • Customer ratings of the service provided with the user's consent

4. Regular data sources

As a rule, we collect personal data from the data subject when registering for and using the service. Data may also be collected from the customer. Personal data is also collected and updated from the authorities providing the personal data services.

5. Disclosure of data

Personal data is disclosed to service providers who process personal data on behalf of PalkkaOnline in accordance with the confidentiality and data protection obligations of the contract.

Personal data may also be disclosed to the extent permitted and required by applicable law, for example to public authorities entitled to receive the data. In addition, personal data may be disclosed to other companies within the group for the purposes described in this report and for the marketing of their products and services, as well as for administrative purposes, such as the processing of data in a centralised information system.

6. Retention period of personal data

Personal data will be kept for as long as processing is necessary for the purposes for which the collected personal data are used, up to a maximum of 10 years from the last time the data subject used the data, unless the data subject has withdrawn any consent he or she may have given. Personal data may be kept for a longer period if this is necessary to comply with an obligation imposed by law or other source of authority, such as accounting law.

7. Protection of the register

The register is kept in a secure system accessible only to the controller and to technical administrators authorised by the controller.

8. Rights of the data subject

The data subject has the right to request access to personal data concerning him or her, the right to request rectification, restriction of processing or erasure of personal data and the right to object to the processing of his or her personal data. The data subject also has the right to receive the personal data concerning him or her in a commonly used, machine-readable format and the right to transmit such data to another controller. Where technically feasible, the data subject has the right to have the personal data transmitted directly from one controller to another.

9. Right to lodge a complaint with a supervisory authority

The data subject has the right to lodge a complaint with the competent supervisory authority if DuuniOnline Oy has not complied with the applicable data protection legislation.