Privacy

Privacy Policy

This policy explains how Garage Corporation Oy (Autonavaimet) processes personal data under the EU General Data Protection Regulation (GDPR). Updated 6.9.2026.

1. Controller and contact

Data controller

Garage Corporation Oy ("Autonavaimet", "we"), business ID 2600117-5.

  • Locations: Sahaajankatu 23, 00880 Helsinki and Lokomonkatu 11, 33900 Tampere, Finland.
  • Email for privacy matters: info@autonavaimet.fi.

We have not appointed a Data Protection Officer, as the statutory criteria for one are not met. Please direct privacy enquiries to the email above.

2. What data we collect

Customer and vehicle data

Depending on the service you use, we process:

  • Contact details: name, email, phone and, where needed, address.
  • Vehicle data: registration number, make and model, and vehicle identification number (VIN).
  • Job data: fault description, work performed, parts used, odometer reading and any photos of the vehicle.
  • Identity verification for key services:
    • type and number of an identity document and the customer's signature on the work order.
    • This is collected to prevent misuse and vehicle theft, since making and programming keys could enable unauthorised use of the vehicle.
  • Order and payment data: orders, invoices, receipts and payment status. We do not store card numbers – card payments are handled by Stripe.
  • Business customer data: company name, business ID, billing details and contact persons.
  • Communications: booking and contact requests, and chat/email correspondence with us.

Automatically collected data

  • Logs and security: IP address, activity log and sign-in data to prevent misuse and ensure security.
  • Cookies and analytics: website usage data, only with your consent (see section 7).

3. Purposes and legal bases

Purposes and lawful bases

  • Providing the service (contract, GDPR Art. 6(1)(b)):
    • booking, performing the work, handing over the vehicle, invoicing and customer service.
  • Legal obligations (GDPR Art. 6(1)(c)):
    • retention of accounting records as required by law and consumer-protection obligations.
  • Legitimate interest (GDPR Art. 6(1)(f)):
    • preventing misuse and vehicle theft (incl. identity verification for key services), security and logging, and service development.
  • Consent (GDPR Art. 6(1)(a)):
    • optional analytics/marketing cookies and any direct marketing. Consent can be withdrawn at any time.

We use the data only for the purposes for which it was collected, or compatible purposes.

4. Disclosures and processors

Service providers acting on our behalf

We do not sell personal data. We use trusted processors that handle data only on our behalf and instructions:

  • Railway – application and database hosting (EU region).
  • Cloudflare R2 – file and image storage.
  • Stripe – card payment processing.
  • PostNord – webshop deliveries and tracking.
  • Resend – email delivery (e.g. booking confirmations and receipts).
  • Twilio – SMS delivery (e.g. booking reminders).
  • Procountor – invoicing and accounting.
  • Google – website analytics and staff sign-in (analytics only with consent).
  • Anthropic – AI answers for the website chat assistant.

We may also disclose data to authorities where required by law.

Transfers outside the EU

Some processors (such as Stripe, Google and Anthropic) may process data outside the EU/EEA, e.g. in the United States. Such transfers rely on the European Commission's Standard Contractual Clauses (SCCs) or another safeguard permitted by the GDPR. We aim to keep core data (application and database) within the EU.

5. Retention

Retention periods

  • Accounting records (invoices, receipts): as required by accounting law, generally six (6) years from the end of the financial year.
  • Work orders and key-service identity data: as long as necessary to prevent misuse and to resolve any liability questions, after which the data is deleted or anonymised.
  • Customer and booking data: for the duration of the customer relationship and a reasonable period afterwards.
  • Data based on marketing consent: until consent is withdrawn.
  • Sales history migrated from our previous system (receipts and invoice lines before September 2026): six (6) years from the end of the financial year, after which it is deleted automatically.

When data is no longer needed it is securely deleted or anonymised.

6. Your rights

Rights of the data subject

You have the right to:

  • access your data and receive a copy of it,
  • request correction of inaccurate data,
  • request erasure ("right to be forgotten") where no statutory retention obligation applies,
  • request restriction of, or object to, processing,
  • receive the data you provided in a machine-readable format (portability),
  • withdraw consent at any time where processing is based on consent.

To exercise your rights, contact info@autonavaimet.fi. We will verify your identity before acting on a request. If you believe we process your data unlawfully, you may lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).

7. Cookies

Use of cookies

We use strictly necessary cookies required for the site to work (e.g. session and language choice). These do not require consent.

Analytics and marketing cookies are used only with your consent. You can accept or reject them in the cookie notice on the site and change your choice later. Without consent, analytics is not enabled.

8. Security and changes

Protecting the data

We protect data with appropriate technical and organisational measures: access is restricted and requires authentication, traffic is encrypted, and system actions are logged. We take regular database backups.

Changes to this policy

We may update this policy as the service or legislation changes. The current version is always available on this page, and we will notify separately of material changes where appropriate.