Privacy policy
We commit to keeping your personal information safe. In this privacy policy, we explain what information about you we collect and why, how we store or disclose it, and what your rights are.
General
In this privacy policy, we describe how Taksikuutio Oy ("Taksikuutio," "we," or "data controller") processes the personal data of users of the Kaista service (www.kaista.fi, the "Service"). The privacy policy applies to the processing of personal data collected in connection with the use of the Service. The Service enables companies or organizations to acquire and manage taxi ride permits, distributing them for use by selected individuals such as employees, collaborators, or customers.
We adhere to applicable data protection legislation in all personal data processing. Data protection legislation refers to the current data protection laws, including the General Data Protection Regulation of the European Union (2016/679) and the Finnish Data Protection Act (5.12.2018/1050). Terms related to data protection that are not defined in this privacy policy are interpreted by data protection legislation.
Our Service and website may contain links to external websites and services operated by other organizations. This privacy policy does not apply to their use, so we encourage you to review their respective privacy policies separately.
"Personal data" refers to all information concerning natural persons ("data subjects") by which a person can be directly or indirectly identified, as specified in the data protection regulation.
This privacy policy was published on January 5, 2024.
Data controller and person responsible for data protection
Data controller
Taksikuutio Oy
Business Id 0645272-9
PL 50, Nuijamiestentie 7
00401 Helsinki
Phone: +358 (0) 207 756 822
Email: asiakaspalvelu@taksikuutio.fi
Contact person responsible for data protection
Jouni Mutanen
Email: jouni.mutanen@taksikuutio.fi
Phone: +358 20 775 6806
What personal data do we process, why, and how?
The purposes (and legal bases) for processing personal data are as follows:
- Providing the Service (contractual relationship or its preparation, legitimate interest)
- Administration, protection, and maintenance of the Service, as well as development (legitimate interest)
- Customer service and communication, e.g., Service-related notifications, informing about changes to the Service, requesting feedback on the Service, and customer satisfaction surveys (legitimate interest, consent, contractual relationship)
- Marketing, including market research, other marketing promotions, and analytics, as well as generating statistics and measuring marketing effectiveness (legitimate interest)
- Direct marketing, including electronic direct marketing and telemarketing, as well as planning advertising and marketing, measuring effectiveness, and combining and updating personal data for direct marketing purposes (the data controller may use personal data to tailor its offerings and provide relevant content - this includes recommendations or tailored content and tailored ads on its and third-party services) (legitimate interest, consent)
- Management of customer and partnership relationships, as well as cooperation with subcontractors and service providers (legitimate interest, contractual relationship, or its preparation)
- Using data analytics to develop the website, services, marketing, customer relationships, and experiences (legitimate interest, consent)
- Tracking user traffic on our website and other services (consent)
- Invoicing, credit decisions, and debt collection (legitimate interest)
- Internal reporting and other administrative actions (compliance with legal obligations)
- Handling complaints and managing litigation and official proceedings (compliance with legal obligations)
- Preventing and investigating misuse, as well as ensuring security (legitimate interest)
- Managing and protecting our business and website, including troubleshooting, data analysis, testing, and system maintenance (legitimate interest)
- Fulfilling other legal obligations (e.g., accounting and taxation-related actions) and reporting obligations (legal obligation)
When processing personal data based on legitimate interests, we assess the benefits and potential risks to the data subject, and we have assessed that the rights and interests of the data subjects do not override the legitimate interest. Upon request, we provide additional information about the processing of personal data based on legitimate interests.
The following personal data of Service users are processed:
- User related information:
-
- First and last name
- Phone number
- Address
- Email address
- User-inputted data for the Service:
-
- Departure address
- Destination address
- Details related to taxi rides:
-
- Travel date
- Payment time
- Distance of the ride
- Cost of the ride
- Addresses
- Travel restrictions
- Additional notes by the user
- Other user data:
-
- Customer service and contact information provided by the customer
- Customer satisfaction information (e.g., feedback and complaints), comments on the data controller's services, and other information obtained with customer consent
- Data related to Service usage (e.g., details about the use, ordering, and cancellation of trips)
- Customer payment method and payment behavior information, along with billing details
- Direct marketing consents and opt-outs (e.g., removal from the newsletter mailing list)
- Business or organization-related information::
-
- Basic details like name, marketing name, business ID, and contact details (address, phone number, email address)
- Service provider related info:
-
- Basic details like name, marketing name, business ID, contact details (address, phone number, email address), license number
- Taxi Association membership number
- Technical information related to the Service:
-
- Data collected during website use, such as usernames, passwords, identification-related details
We collect personal data directly from the data subject, for example, during transactions when the data subject uses our Services either personally or on behalf of an organization, or when the data subject visits our website. We may also receive personal data about the data subject from the company or organization using the Service.
When the data subject uses our website, we may automatically collect technical information and usage data related to the data subject's devices, browsing, and browsing behavior. We collect such information using cookies and similar technologies. We use cookies only if the data subject has given consent to their use unless they are technically necessary for the functioning of the website. For more information about cookies, refer to the website's cookie banner.
We do not engage in automated decision-making or profiling that would have legal or similar effects on data subjects by Article 22 of the General Data Protection Regulation.
After the purpose of use has ended, personal data is deleted or anonymized within a reasonable time.
Generally, we follow the following criteria for the retention and deletion of personal data:
- Personal data is processed for as long as the Customer uses the Service and for one year thereafter. Upon request, we provide additional information about the practices related to the retention of personal data.
Upon request, we provide additional information about our practices regarding the retention of personal data.
We ensure that the necessary agreements regarding data protection are in place with the parties we use for the processing of personal data.
The company or organization using the Service has access to information regarding the trips it has ordered.
In addition to the above, the data controller may disclose personal data for the following purposes:
- To taxi companies to order and execute the requested service;
- For the collection of payments, it may, for example, transfer or sell unpaid invoices to third-party debt collection services;
- The data controller may share personal data in the context of a corporate merger or other business arrangement, or when the Service is transferred to another service provider. The data controller may share personal data based on a court or similar order;
- To third parties in situations required by legislation or authorities, or to investigate misconduct and ensure security. In addition, personal data may need to be disclosed in the context of legal proceedings or similar legal processes;
- If the data controller is involved in a merger, business acquisition, or other corporate transaction, personal data may be disclosed to the parties involved in the transaction or to entities assisting in the transaction.
When personal data is transferred to a third party, i.e., another data controller, the data protection practices of that organization are then applied.
On our website and in our Service, cookies may be set, and data may be collected or transferred to third parties. We ask you to review our cookie policy and cookie settings on our website for information about these third parties and the purposes for which data is collected. We only use non-essential cookies if the data subject has given their consent.
Upon request, we provide additional information about the recipients of personal data.
The data controller aims to keep personal data within the European Economic Area (EEA) and the European Union, but this may not always be possible. If data is transferred outside the European Union or the EEA, the data controller ensures an adequate level of protection for personal data. This may include agreements on data processing matters by data protection laws, such as using European Commission-approved standard contractual clauses or relying on the European Commission's adequacy decision regarding the level of data protection.
Upon request, we provide additional information regarding the transfer of personal data and the protection mechanisms used.
Security and protecting personal information are of utmost importance to us. We employ appropriate technical and organizational measures to safeguard personal data. We also ensure the fault tolerance of our systems and the ability to recover data. Access to personal information is restricted to authorized parties only. Parties handling personal data are bound by confidentiality obligations regarding the processing of personal information.
What are your rights related to privacy protection?
Individuals have rights regarding their data by data protection legislation. The application of these rights in each specific situation depends on the purpose and context of the personal data processing.
- Right to access personal data: Individuals have the right to confirm whether their data is being processed and to obtain additional information about the processing, as per data protection legislation. Individuals have the right to receive a copy of their data.
- Right to rectify personal data: Individuals have the right, with certain restrictions, to request the correction or deletion of inaccurate or incomplete information.
- Right to erasure of personal data: Individuals have the right, by data protection legislation, to request the deletion of their data. We will comply with the request unless there are legal or other applicable exceptions that require us to retain the data.
- Right to restrict processing: Individuals have the right, by data protection legislation, to request the restriction of processing in certain situations.
- Right to data portability: Individuals have the right to request the transfer of their data to another controller. This right generally applies to data provided by the individual in a structured, machine-readable format, processed based on consent or a contract, and/or processed automatically.
- Right to object processing: Individuals have the right, by data protection legislation, to object to the processing of personal data based on legitimate interests, including profiling. We may refuse the request if the processing is necessary for the compelling and legitimate interests of the controller or a third party. However, individuals always have the right to object to the processing of personal data for direct marketing purposes and related profiling.
- Right to withdraw consent: If the processing of personal data is based on the individual's consent, they have the right to withdraw that consent at any time. Withdrawal of consent does not affect processing performed before the withdrawal.
We hope that you stay in touch with us if you have any questions regarding the processing of your data. You can submit a request related to data subject rights by mail or email using the contact details mentioned in this privacy policy. The requester's identity may be verified before processing the request. We aim to respond to the request within a reasonable time and, in principle, within one month from the submission of the request and verification of identity. If the request cannot be fulfilled, a separate notification of refusal will be provided.
The data subject has the right to complain to the competent data protection authority if they believe that their data has been processed in violation of data protection legislation. You can find the contact information for the Finnish Data Protection Authority at www.tietosuoja.fi.
Changes to the privacy policy
Changes may be made to this privacy policy from time to time. Changes may also be based on alterations in data protection legislation. Therefore, we encourage regular checking of the privacy policy for any updates. The latest version is available on our website.