last updated 1st October 2023
PRIVACY POLICY
- What personal data we collect about you;
- How we use your personal data and on which basis;
- Who we share your personal data with;
- International transfers of your personal data;
- For how long we retain your personal data;
- What actions we have taken to keep your data secure;
- What are your rights as a data subject and how you may exercise them;
- How you can contact us in case of questions related to this privacy policy.
3Step IT Oy Business ID 2161942-7 Mechelininkatu 1A 00180 Helsinki Registered in Finland |
3 Step IT A/S Business ID 26106427 Vandtårnsvej 62 2860 Søborg Registered in Denmark |
3 Step IT AS Business ID 878703812 Wergelandsveien 7 0167 Oslo Registered in Norway |
3 Step IT Sweden AB Business ID 556488-0218 Box 1556 581 15 Linköping Registered in Sweden |
3Step IT OÜ Business ID 10731756 Narva mnt 7d Tallinn 10117 Registered in Estonia |
3 Step IT Trading AB Business ID 559267-1738 Drottninggatan 19 582 25 Linköping Registered in Sweden |
AddPro Finans AB Business ID 556861-4357 Box 1566 581 52 Linköping Registered in Sweden |
3 Step IT SIA Business ID 40003717838 Vilandes iela 3 LV-1010 Riga Registered in Latvia |
UAB 3Step IT Business ID 300059934 Vito Gerulaičio g. 10-101 Vilnius Registered in Lithuania |
3 Step IT Services Limited Business ID 13762523 100 Liverpool Street EC2M 2AT London Registered in United Kingdom |
Purpose of processing |
Legal basis |
Personal data |
To fulfil regulations and legal requirements relating to: • anti-money laundering and counter-financing of terrorism, including Know Your Customer (KYC) obligations; • international financial sanctions and embargoes • export control obligations set forth in relevant international and national export control regulations • other mandatory legal requirements such as accounting |
Legal obligation The legitimate interest of the data controller when financial sanctions are imposed by UK and the United States which 3stepIT has contractually undertaken to comply with |
• Name, date of birth, city of birth, nationality, personal identity number, address, other information included in ID copy, information included in possible proof of address • PEP-status and details of such PEP-status Data subject categories may include following: • Customer or representatives of the customer (authorised signatories or employees of customer without signatory status), possible beneficial owners of the customer, next-of-kin and close business associates of PEP-persons |
To market our products and services (e.g. sending newsletters), communicate with you and develop our customer relationships To develop our products and services |
Legitimate interest of the data controller |
• Name, title, address and contact information of the customer or contact persons, representatives and/or decision-makers of the customer • Data from your interactions with us, including meetings, emails and other communication or correspondence with us • Data relating to your habits and preferences, such as participation in our marketing events, potential co-development projects and areas of interest • Other personal data relating to data subject’s attendance to 3stepIT’s marketing or other events and general information of data subject’s areas of interest • Usage data including information used to connect to our products and data created from use of our products • Data from public sources, e.g. job title from LinkedIn |
To provide the service portal to the customers |
Legitimate interest of the data controller |
• Usernames and log data (e.g., account credentials provided to customers, data relating to logins) |
To provide and deliver our products and services to you |
Performance of a contract |
• Name, title, address and contact information of the customer or contact persons, representatives and/or decision-makers of the customer • Identification information related to your role as authorized representative or beneficial owner of our customer entity (e.g., full name, identity (e.g., ID card or other personal ID, passport information, etc.), nationality, place and date of birth, gender, photograph) |
To manage and develop the supplier relationship, such as business partner management To manage contracts |
Legitimate interest of the data controller Performance of a contract |
• Name, title, address and contact information of the supplier or contact persons • Correspondence and other information relating to the maintenance of the supplier relationship |
- Contact persons or other representatives of our customers or customer prospects;
- Ultimate beneficial owners of our customers and their next of kins, significant owners;
- Users of our products and services;
- Participants to our webinars and events;
- Contact persons or other representatives of our suppliers.
- Our customers;
- Our business partners;
- Public sources (e.g., company registers, LinkedIn, company websites, press);
- Third parties such as data brokers or databases (e.g., databases used in marketing, KYC or sanction screening).
Purpose of processing |
Legal basis |
Personal data |
To improve the website performance, functionalities, and user experience and to analyse the website traffic |
Consent prior placing other than strictly necessary cookies Legitimate interest of the controller when retrieving the data through the cookies |
• Information about your device (IP address, technical specifications and uniquely identifying data) • Other personal data retrieved via cookies, such as site pages visited, links, buttons and other items clicked, date, time, number and duration of visits |
To target ads |
Consent prior placing other than strictly necessary cookies Legitimate interest of the controller when retrieving the data through the cookie |
• Information about your device (IP address, technical specifications and uniquely identifying data) • Other personal data retrieved via cookies, such as site pages visited, links, buttons and other items clicked, date, time, number and duration of visits • Data from your interactions with us, including visits to our internet websites or social media pages (connection and tracking data such as cookies, IP address), meetings, emails and other communication or correspondence with us |
To communicate with you (e.g., sending newsletters and information on products and services) |
Legitimate interests of the data controller Consent of the data subject prior to sending electronic direct marketing where applicable |
• Information about your device (IP address, technical specifications and uniquely identifying data) • Other personal data retrieved via cookies, such as site pages visited, links, buttons and other items clicked, date, time, number and duration of visits • Data from your interactions with us, including visits to our internet websites or social media pages (connection and tracking data such as cookies, IP address), meetings, emails and other communication or correspondence with us |
- Service providers which perform services on our behalf (e.g., IT services, logistics, marketing, telecommunication, advisory and consulting);
- Our commercial partners, including our financing partners;
- Authorities or other public bodies if we are required by law to disclose such data;
- KYC: In connection with assigning concluded lease agreements to its refinancing partners, 3stepIT transfers personal data to the selected refinancing partner, who process personal data as data controller in accordance with its own privacy policy. 3stepIT will deliver a copy of the refinancing partner’s privacy policy upon request.
- Certain regulated professionals such as lawyers or auditors when needed under specific circumstances (litigation, audit, etc.) as well as to actual or proposed purchaser of the companies or businesses of the 3stepIT.
- If 3stepIT is involved in a corporate transaction personal data may be disclosed to third parties in relation to such transaction in accordance with the applicable data protection laws.
- Requirements set forth in applicable laws and regulations; and
- Other requirements related to the purpose of the processing in question, e.g., operational requirements, such as proper account maintenance and management, security reasons, or responding to legal claims or regulatory requests.
Rights of the data subject |
|
Right of access to your data |
You can obtain information relating to the processing of your personal data and request a copy of such personal data. If you make your request electronically and have not requested another form of delivery, the data will be provided in the commonly used electronic format. |
Right to rectify your data |
Where you consider that your personal data is inaccurate or incomplete, you can request that such personal data is modified accordingly. |
Right to have your data erased |
You can require the deletion of your personal data, to the extent permitted by law. However, a request to delete personal data cannot be implemented if the personal data is stored, for example, to comply with a legal obligation. |
Right to restrict the processing of your data |
In certain cases, you have the right to request the restriction of the processing of your data. |
Right to object to the processing of your data |
You can object to the processing of your personal data, on grounds relating to your situation. You have the right to object to the processing of your personal data for direct marketing purposes, which includes profiling related to such direct marketing. 3stepIT may refuse a request if the processing is necessary for the legitimate interests of 3stepIT or a third party. |
Right to withdraw your consent |
Where you have given your consent for the processing of your personal data, you have the right to withdraw your consent at any time. With every newsletter, we provide a way for you to request to revoke your consent at any time when you do not wish to subscribe to and receive our newsletters anymore. |
Right to transfer data from one system to another |
Where legally applicable, you have the right to have the personal data you have provided to us to be returned to you or, where technically feasible, transferred to a third party. To the extent that we process your data on a contractual basis and the processing is carried out automatically, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format and the right to transfer that data to another controller. |
Right to lodge a complaint with a supervisory authority |
You have the right to lodge a complaint with the competent supervisory authority if you consider that data protection legislation has not been respected in the processing of your personal data. |