Privacy Policy
Epassi Finland Oy, Epassi Sweden AB and Epassi Clearing Oy
1. GENERAL INFORMATION
Epassi Finland Oy, Epassi Sweden AB, and Epassi Clearing Oy (together “Epassi” or “we” in all grammatical forms) respect your privacy and aim to maintain the protection of personal data of individuals using Epassi’s services. This Privacy Policy describes how Epassi processes personal data, including what types of personal data are collected, the purposes for which personal data is used, and to whom personal data may be disclosed.
This Privacy Policy applies when you use Epassi’s services, including services intended for Epassi end-users and our websites.
It also applies in other situations listed in section 3 below, for example when we communicate about our services or manage customer relationships with our clients’ contact persons.
Personal data refers to any information relating to a natural person (“data subject”) that can identify the person directly or indirectly. Terms such as personal data, data subject, and controller are defined in the General Data Protection Regulation ((EU) 2016/679, “GDPR”), which applies to all processing of personal data by Epassi. Epassi complies with the GDPR and other applicable national data protection laws (“data protection legislation”) in all personal data processing.
Our services may also include links to external websites and services to which this Privacy Policy does not apply. These websites or services are operated by other organizations that Epassi does not control and therefore Epassi is not responsible for their processing of personal data. For this reason, we encourage you to review the applicable privacy policies of those websites or services.
2. JOINT CONTROLLERS AND CONTACT INFORMATION
Joint Controller: Epassi Finland Oy
Business ID: 3220764-7
Address: Porkkalankatu 22 A, 00180 Helsinki, Finland
Email: dataprivacy@epassi.com
Representative of the joint controller: Data Protection Officer – Taika Pöntinen
Joint Controller: Epassi Sweden AB
Business ID: 556617-0030
Address: Storgatan 31, 461 30 Trollhättan, Sweden
Email: dataprivacy@epassi.com
Representative of the joint controller: Data Protection Officer – Taika Pöntinen
Joint Controller: Epassi Clearing Oy
Business ID: 2872241-9
Address: Porkkalankatu 22 A, 00180 Helsinki, Finland
Email: dataprivacy@epassi.com
Representative of the joint controller: Data Protection Officer – Taika Pöntinen
3. PURPOSES, TYPE OF DATA, LEGAL BASES AND RETENTION TIMES FOR PROCESSING
Epassi processes only personal data that is relevant and necessary to fulfill the purposes defined in this Privacy Policy. Personal data is processed separately from other Epassi systems and is not combined with other processing purposes. Below, you will find tables listing the purposes of processing identified by Epassi, the categories of personal data involved, a description of the processing and retention periods, and the applicable legal basis under the GDPR.
3.1 Epassi Service for End-Users
Epassi processes personal data for the following purposes related to providing its service:
|
Purpose |
Categories of Personal Data |
Description and Retention |
Legal Basis (GDPR Art. 6) |
|
3.1.1 Providing the Epassi Service |
|
We process personal data to provide the Epassi platform as a service to the end-user. This includes platform access and login, as well as execution of payment transactions. Data is retained according to the agreement between Epassi and the end-user. |
|
|
3.1.2 Identifying End-Users for Payment Services
|
|
Personal data is processed to identify end-users, complete user profiles, and perform the necessary KYC (Know Your Customer) process so that Epassi can fulfill its legal obligations and provide end-user services.
|
|
|
3.1.3 Execution of Epassi Payment Transactions and Instruments
|
|
Personal data is processed for the distribution, use, maintenance, and development of Epassi’s specific and general payment instruments, as well as for financial data, application usage data, and other technical background information. Personal data is retained for as long as the end-user uses Epassi services and for up to two years thereafter. |
|
|
3.1.4 Reporting on Used Benefits |
|
Personal data is processed to report benefit usage to employer clients for payroll purposes, salary deductions, taxation, and invoicing.
|
|
|
3.1.5 Communication Related to EpassiBIKE Service
|
|
Personal data is processed to implement the EpassiBIKE service. Epassi communicates with financing partners regarding bike activation and usage, and with potential buyers regarding bike collection.
|
|
|
3.1.6 Customer Support
|
|
Personal data is processed to manage support cases and provide phone support.
|
|
|
3.1.7 Receipt Handling (Sweden)
|
|
If you use Epassi Sweden AB’s receipt management service, you can consent to automatic receipt processing using Epassi’s AI solution. The AI analyzes the entire receipt content against your granted benefits. Decisions regarding the reimbursement of the receipt and benefit are based solely on the personal data you provided in the receipt.
|
|
|
3.1.8 Service Development and Analytics
|
|
Epassi uses service usage data to analyze functionalities and improve the service. Analysis helps us develop the service according to your needs and preferences. Epassi strives to process personal data as minimally as possible relative to the purpose and legitimate interest.
|
|
|
3.1.9 Epassi Savings
|
|
Epassi offers the Epassi Savings add on service to its end users. Through the Epassi Savings service, end users gain access to offers from Epassi’s partners.
|
|
3.2 Other functions of Epassi Service
|
3.2.1 Identification of Merchant Customers
|
|
Personal data is processed to collect and store the necessary KYC (Know Your Customer) information and risk classifications for identifying Epassi’s merchant customers in order to fulfill our legal obligations.
|
|
|
3.2.2 Communication with Employer and Merchant Customers
|
|
Personal data is processed to enable communication with contact persons of Epassi’s employer and merchant customers. |
|
|
3.2.3 Account Management for Employer and Merchant Customers
|
|
Personal data is processed to implement employer and merchant portals. |
|
|
3.2.4 Processing of Personal Data of a Sole Trader
|
|
Some merchant customers using Epassi’s service may operate as sole traders, in which case information related to their business may constitute personal data in a different way than for other merchant customers. Epassi processes such merchant customers’ data to fulfill the purpose of the merchant agreement and service agreement, as well as to comply with its own legal obligations. Since a sole trader is considered a data subject under data protection legislation, any data subject requests regarding this information may be limited to their merchant status only. Data is retained for the duration of the agreement and in accordance with each of Epassi’s legal obligations.
|
|
3.3 Other data processing conducted by Epassi
|
3.3.1 Accessibility Feedback
|
|
If you provide us with accessibility feedback via Epassi’s accessibility feedback form, we process the categories of personal data you include in your feedback to address it.
|
|
|
3.3.2 Website, Web Analytics, and Cookies
|
|
Personal data is processed to develop Epassi’s services using web analytics and cookies, as well as to manage our website and fulfill user requests.
|
|
|
3.3.3 Marketing to Employer Customer Contact Persons
|
|
Personal data of employer customer contact persons may be used for marketing Epassi’s services and/or the services of its partners.
|
|
|
3.3.4 Marketing of the Epassi Platform and Other Marketing
|
|
Epassi sends marketing communications to end-users related to their use of Epassi services.
|
|
Epassi uses tools that leverage artificial intelligence (AI), including large language models and machine learning models, in the delivery of its services. However, Epassi’s use of AI is strictly limited by contractual agreements, technical restrictions, and internal policies to ensure that personal data is never disclosed to AI models in a way that would compromise data protection, such as by training the AI. The use of these tools and applications within Epassi does not affect or hinder the exercise of data subject rights. You always have the option to refuse the processing of your personal data by AI by notifying Epassi as described in section 9, “Data Subject Rights.”
4. Sources of Personal Data
Personal data is primarily collected directly from data subjects, for example, during registration for our services, while using them, or during the customer relationship.
Personal data concerning end-users is also collected from the end-user’s employer in connection with services provided jointly by the employer and Epassi under their service agreement. This data is collected to register the end-user as an Epassi consumer customer by creating a personal account and to report the use of employment benefits to the employer for tax purposes.
Personal data received from employers is used solely to identify the end-user for service access, and data about the end-user’s service usage is disclosed to the employer only to the extent necessary to provide benefits or as otherwise agreed for benefit tracking.
In connection with Epassi’s legal obligations regarding payment instruments and customer due diligence, Epassi may update and supplement related data from private and public sources.
5. Disclosure, Transfer, and Recipients of Personal Data
Personal data may be disclosed, as necessary for the purposes described in this Privacy Policy, to the following third parties:
- Epassi merchants for financial and payment-related purposes during service use.
- Financial service providers or other service providers for financing products included in Epassi’s offering.
- Employer customers as described in section 4 “Sources of Personal Data.”
- Epassi’s service providers, such as web service providers, to the extent necessary to deliver the Epassi service.
- Epassi group companies under agreed data processing agreements, where they perform parts of the Epassi service or its support functions.
Epassi may also share personal data in connection with a potential merger, sale of assets, financing, or transfer of all or part of its business, and similar arrangements.
Personal data may be disclosed to third parties if required by applicable data protection regulations or an order from a competent authority, and for investigating misuse of products or services, as well as ensuring the security and usability of Epassi’s products and services.
To provide agreed services, the following Epassi data processors also process personal data. A list of processors and other recipients includes:
- Amazon Web Services (support tool)
- APSIS International AB (marketing tool)
- BitBot Oy (support tool for EpassiBIKE)
- Contentsquare SAS (analytics software)
- Cellip AB (support tool)
- Databricks (support tool)
- Epassi Finland Oy (IT operations)
- Fortnox AB (financial management tool)
- Freshworks Inc. (support tool)
- HeadQ Oy (digital commerce platform)
- Google LLC (Google Analytics, Google Ads, Google Translation)
- Hetzner Online GmbH (web hosting)
- HubSpot, Inc. (CRM tool)
- InExchange Factorum AB (e-invoicing)
- Kund-o AB (case management support tool)
- Lime Technologies AB (CRM tool for Swedish employer and merchant contacts, Sweden only)
- Mainloop AB (IT development)
- Microsoft Corporation (business tools)
- Oneflow AB (digital contract platform)
- Oura Health Oy (marketing partner)
- Parvus Vulpes Oy (platform tool)
- Sharpspring (marketing tool)
- Shopify (EpassiBIKE platform)
o Lightward Inc. (Shopify functionality tool)
o HulkApps Inc. (Shopify functionality tool)
o Instacollect Inc. (Shopify functionality tool)
- Signicat AS (identity verification service)
- Svea Bank AB and affiliates or Tukirahoitus Oy (EpassiBIKE financing partner)
- Telavox AB (support tool)
- Telia Finland Oyj (strong authentication)
- Tradedoubler AB (marketing tool)
- Visma Solutions Oy (Netvisor and customer due diligence)
- RevQore (Hubspot consulting)
- Kaks.io (Hubspot consulting)
- Vainu.io (Business information service)
6. Transfers Outside the EU/EEA
Some third parties and their services used by Epassi for personal data processing may operate outside the European Union (EU) or European Economic Area (EEA), meaning personal data may be transferred outside these regions. If personal data is transferred outside the EU/EEA, such transfers are subject to the following legal safeguards:
• Transfers are made to a country for which the European Commission has issued an adequacy decision regarding minimum data protection standards;
• Transfers are carried out using the European Commission’s standard contractual clauses or other appropriate safeguards approved by a competent data protection authority.
When transferring data to third countries, Epassi implements appropriate safeguards, including additional protective measures where necessary, or other methods approved by the European Commission or competent data protection authority to maintain data protection in accordance with the GDPR.
Recipients that may transfer personal data outside the EU/EEA include:
• Shopify, Inc. (EpassiBIKE end-user data)
o Lightward Inc.
o HulkApps Inc.
o Instacollect Inc.
7. Security measures
Ensuring the confidentiality, integrity, and availability of personal data is important to Epassi. Epassi’s security management system is based on legal, regulatory, and contractual requirements. The Epassi service and IT systems are certified according to the ISO27001 information security standard. The security management system consists of appropriate technical, administrative, and organizational measures to protect personal data from unauthorized access, disclosure, destruction, and processing.
Administrative and organizational measures:
• Epassi services are implemented and personal data stored in two separate EU-based data centers certified to internationally recognized security standards
• Role-based access control
• Technical segregation of personal data
• Supplier and system monitoring in accordance with ISO27001
Technical measures:
• Firewalls
• Backups
• Access control
• Technical monitoring of processing and errors
• Secure encryption techniques
• Encrypted network connections (HTTPS)
All parties involved in personal data processing are bound by contractual confidentiality obligations. We also require our service providers to use appropriate methods to protect personal data.
8. Use of Cookies and Similar Technologies
Epassi’s website uses cookies.
Details of the use of cookies and similar technologies are documented in Epassi’s Cookie Policy, which explains how and for what purposes Epassi uses each cookie.
9. Data subject’s rights
When we process your personal data, you have certain rights under applicable data protection legislation. Each right applicable to the purposes listed in section 3 is described below, along with instructions for exercising these rights:
Right of access and right to review data
You have the right to obtain confirmation of whether your personal data is being processed and to access your data in written or electronic form upon request.
Right to rectification and erasure
You have the right to request correction of inaccurate personal data and the right to request deletion of your personal data. Epassi must delete personal data where there is no legal basis for processing (e.g., withdrawal of consent).
Right to data portability
You have the right to receive personal data you have provided to Epassi in a structured, commonly used, machine-readable format and to transfer that data to another controller.
Right to restriction of processing
You have the right to restrict processing where there is no longer a legal basis for processing but data must be retained for other legitimate purposes. In cases where data suspected to be inaccurate cannot be corrected or deleted, or where a deletion request is unclear, Epassi will restrict access to the data.
Right to object to processing
You have the right to object to processing based on Epassi’s legitimate interest or for direct marketing unless Epassi demonstrates compelling legitimate grounds for processing.
Right to withdraw consent
Where processing is based on consent, you have the right to withdraw consent at any time by notifying Epassi.
Right to lodge a complaint with a supervisory authority
If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent data protection authority.
In Finland: Data Protection Ombudsman (http://www.tietosuoja.fi)
In Sweden: Swedish Authority for Privacy Protection (https://www.imy.se/)
Exercising your rights
Requests must be made in writing or electronically and sent to the address specified in section 1. Please clearly specify your request and related personal data to facilitate resolution. Include your name, phone number, email address, username, and details of the products or services used.
Epassi will verify your identity before fulfilling the request and providing data. Responses will be provided within a reasonable time, typically within one month of the request and identity verification.
If your request cannot be fulfilled, Epassi will inform you in writing. Epassi may refuse requests (such as deletion) based on legal obligations or rights, including service-related requirements. Epassi may charge a reasonable fee if requests are particularly burdensome or manifestly unfounded.
Contact us if you have questions about our privacy practices or wish to exercise your rights.
10. Changes to the Privacy policy
Epassi may update this Privacy Policy by posting changes on its website and/or through other appropriate means. Data subjects are strongly encouraged to review the Privacy Policy on our website regularly.
If you object to any changes, you must discontinue use of the services and may request deletion of your personal data unless applicable law requires retention. Unless otherwise stated, the current Privacy Policy applies to all personal data we process.
This Privacy Policy was published on 21 October 2021 (version 1.0).
Version history available upon request.
Version history
|
Version number |
Change description |
Date |
|
1.0 |
Document created |
|
|
2.0 |
Document updated |
25.2.2022 |
|
2.1 |
Document updated |
17.3.2022 |
|
2.2 |
Document updated (EpassiBIKE) |
21.6.2022 |
|
2.3 |
Document updated |
3.5.2023 |
|
2.4 |
Document updated |
21.11.2023 |
|
2.5 |
Document updated |
19.12.2023 |
|
2.6 |
Document updated |
15.3.2024 |
|
2.7 |
Document updated |
12.9.2024 |
|
2.8. |
Document updated |
25.6.2025 |
|
2.9. |
Document updated |
18.7.2025 |
|
3.0. |
Document updated |
15.1.2026 |
|
3.1. |
Document updated |
20.2.2026 |
|
3.2. |
Document updated |
25.3.2026 |
|
3.3. |
Document updated |
20.4.2026 |