Skip to content
English

Privacy Policy

Epassi Finland Oy, Epassi Sweden AB and Epassi Clearing Oy

 

1. GENERAL INFORMATION

Epassi Finland Oy, Epassi Sweden AB, and Epassi Clearing Oy (together “Epassi” or “we” in all grammatical forms) respect your privacy and aim to maintain the protection of personal data of individuals using Epassi’s services. This Privacy Policy describes how Epassi processes personal data, including what types of personal data are collected, the purposes for which personal data is used, and to whom personal data may be disclosed.

This Privacy Policy applies when you use Epassi’s services, including services intended for Epassi end-users and our websites.
It also applies in other situations listed in section 3 below, for example when we communicate about our services or manage customer relationships with our clients’ contact persons.

Personal data refers to any information relating to a natural person (“data subject”) that can identify the person directly or indirectly. Terms such as personal data, data subject, and controller are defined in the General Data Protection Regulation ((EU) 2016/679, “GDPR”), which applies to all processing of personal data by Epassi. Epassi complies with the GDPR and other applicable national data protection laws (“data protection legislation”) in all personal data processing.

Our services may also include links to external websites and services to which this Privacy Policy does not apply. These websites or services are operated by other organizations that Epassi does not control and therefore Epassi is not responsible for their processing of personal data. For this reason, we encourage you to review the applicable privacy policies of those websites or services.

2. JOINT CONTROLLERS AND CONTACT INFORMATION

Joint Controller: Epassi Finland Oy
Business ID: 3220764-7
Address: Porkkalankatu 22 A, 00180 Helsinki, Finland
Email: dataprivacy@epassi.com
Representative of the joint controller: Data Protection Officer – Taika Pöntinen

Joint Controller: Epassi Sweden AB
Business ID: 556617-0030
Address: Storgatan 31, 461 30 Trollhättan, Sweden
Email: dataprivacy@epassi.com
Representative of the joint controller: Data Protection Officer – Taika Pöntinen

Joint Controller: Epassi Clearing Oy
Business ID: 2872241-9
Address: Porkkalankatu 22 A, 00180 Helsinki, Finland
Email: dataprivacy@epassi.com
Representative of the joint controller: Data Protection Officer – Taika Pöntinen

 

3. PURPOSES, TYPE OF DATA, LEGAL BASES AND RETENTION TIMES FOR PROCESSING

Epassi processes only personal data that is relevant and necessary to fulfill the purposes defined in this Privacy Policy. Personal data is processed separately from other Epassi systems and is not combined with other processing purposes. Below, you will find tables listing the purposes of processing identified by Epassi, the categories of personal data involved, a description of the processing and retention periods, and the applicable legal basis under the GDPR.

3.1 Epassi Service for End-Users

Epassi processes personal data for the following purposes related to providing its service:

Purpose

Categories of Personal Data

Description and Retention

Legal Basis (GDPR Art. 6)

3.1.1 Providing the Epassi Service

  • Name
  • Personal identity code
  • Phone number
  • Postal address
  • Email address
  • Amount and type of employee benefit
  • Payment transactions and history
  • Service usage history

We process personal data to provide the Epassi platform as a service to the end-user. This includes platform access and login, as well as execution of payment transactions. Data is retained according to the agreement between Epassi and the end-user.

  • Contract

3.1.2 Identifying End-Users for Payment Services

 

  • Name
  • Nationality
  • Date of birth
  • Personal identity code
  • Home address
  • Occupation
  • Political exposure
  • Details of the identity document used for verification or, if the person is remotely identified, details of the methods or sources used for verification

 

Personal data is processed to identify end-users, complete user profiles, and perform the necessary KYC (Know Your Customer) process so that Epassi can fulfill its legal obligations and provide end-user services.
Personal data is retained for as long as the end-user uses Epassi services and for up to five years after termination. Epassi may process personal data for a longer period if there are pending inquiries related to the end-user or if mandatory national legislation requires it.

 

  • Legal obligation

 

3.1.3 Execution of Epassi Payment Transactions and Instruments

 

  • Name
  • Company (employer)
  • Transaction details
  • Purchase history
  • Usage logs
  • User device
  • Email address
  • Phone number
  • Postal code
  • Account balances
  • Personal data provided by the data subject

 

Personal data is processed for the distribution, use, maintenance, and development of Epassi’s specific and general payment instruments, as well as for financial data, application usage data, and other technical background information.

Personal data is retained for as long as the end-user uses Epassi services and for up to two years thereafter.
Financial and transaction-related data is retained for ten years from the date of creation as required by law.

  • Contract
  • Legitimate interest (service maintenance and development)
  • Legal obligation (Retention of payment information)

 

3.1.4 Reporting on Used Benefits

  • Granted benefit amount
  • Used benefit amount
  • Employee name, email address, and other identifiers if necessary
  • Top ten merchants most favored by employees
  • Benefit category
  • At employer’s request: individual benefit usage data (amount in SEK and location) (Sweden)

 

Personal data is processed to report benefit usage to employer clients for payroll purposes, salary deductions, taxation, and invoicing.
Personal data is retained for as long as the end-user uses Epassi services or as required by law in relation to fraud/misuse cases (10 years for transaction data).

 

  • Contract
  • Legitimate interest (fraud and misuse prevention)

 

3.1.5 Communication Related to EpassiBIKE Service

 

  • Name
  • Email address
  • Phone number
  • Address
  • Personal identity code of guarantor (if agreed)

 

Personal data is processed to implement the EpassiBIKE service. Epassi communicates with financing partners regarding bike activation and usage, and with potential buyers regarding bike collection.
Personal data is processed/retained for as long as the end-user uses the EpassiBIKE service.

 

  • Contract

 

3.1.6 Customer Support

 

  • Contact details of the party initiating the support case
  • Contact details of the person managing the case
  • Information provided in text fields
  • Log file details
  • Phone number

 

Personal data is processed to manage support cases and provide phone support.
Personal data is retained for up to two years after the resolution of the support case.

 

  • Legitimate interest

 

3.1.7 Receipt Handling (Sweden)

 

  • Data contained in receipts
  • Employee benefit details

 

If you use Epassi Sweden AB’s receipt management service, you can consent to automatic receipt processing using Epassi’s AI solution. The AI analyzes the entire receipt content against your granted benefits. Decisions regarding the reimbursement of the receipt and benefit are based solely on the personal data you provided in the receipt.
You will always be informed of the decision, its content, and its basis.
You have the right to request a human review of the decision through the system. We process the information contained in receipts in order to assess the eligibility of the receipts for reimbursement, to translate the text, to make decisions, and to store the supporting documents.

 

  • Consent
  • Legitimate interest

 

3.1.8 Service Development and Analytics

 

  • Data generated from end-user service usage

 

Epassi uses service usage data to analyze functionalities and improve the service. Analysis helps us develop the service according to your needs and preferences. Epassi strives to process personal data as minimally as possible relative to the purpose and legitimate interest.
Data is retained for up to two years or until the data category is deleted earlier.

 

  • Legitimate interest

3.1.9 Epassi Savings

 

  • Name
  • Email address
  • Data generated from the use of the Epassi Service

 

Epassi offers the Epassi Savings add on service to its end users. Through the Epassi Savings service, end users gain access to offers from Epassi’s partners.


In accordance with the Terms of Use of the Epassi Service, within the Epassi Savings service Epassi acts as the service provider and as the controller of personal data to the extent that Epassi implements the service, meaning that the use of partners’ offers may result in the processing of personal data and controller responsibility by those partners. You should always review the privacy notice of Epassi’s partner when using the partner’s offer.


Data is stored for as long as the end user uses the Epassi Savings service.

 

3.2 Other functions of Epassi Service

3.2.1 Identification of Merchant Customers

 

  • Date of birth
  • Personal identity code
  • Nationality
  • PEP status (Politically Exposed Person) of board members, CEO, and individuals owning more than 25% of the company

 

Personal data is processed to collect and store the necessary KYC (Know Your Customer) information and risk classifications for identifying Epassi’s merchant customers in order to fulfill our legal obligations.
Personal data is retained for as long as the end-user uses Epassi services and generally for up to five years after the termination of service use. Epassi may process personal data for a longer period if there are pending consumer-related inquiries or if mandatory legislation requires it.

 

  • Legal obligation

 

3.2.2 Communication with Employer and Merchant Customers

 

  • Name
  • Email address
  • Phone number

Personal data is processed to enable communication with contact persons of Epassi’s employer and merchant customers.
Personal data is processed/retained for as long as the contact person is identified as representing the company.

  • Legitimate interest

3.2.3 Account Management for Employer and Merchant Customers

 

  • Contact details and account information of employer and merchant customer representatives

Personal data is processed to implement employer and merchant portals.
Personal data is processed for as long as the agreement between the employer or merchant customer and Epassi remains in force.

  • Sopimus

3.2.4 Processing of Personal Data of a Sole Trader

 

  • The same categories of personal data as listed above in section 3.2, as applicable to the situation.

 

Some merchant customers using Epassi’s service may operate as sole traders, in which case information related to their business may constitute personal data in a different way than for other merchant customers.

Epassi processes such merchant customers’ data to fulfill the purpose of the merchant agreement and service agreement, as well as to comply with its own legal obligations.

Since a sole trader is considered a data subject under data protection legislation, any data subject requests regarding this information may be limited to their merchant status only.

Data is retained for the duration of the agreement and in accordance with each of Epassi’s legal obligations.

 

  • Contract
  • Legal obligation

3.3 Other data processing conducted by Epassi

3.3.1 Accessibility Feedback

 

  • As specified in the accessibility statement

 

If you provide us with accessibility feedback via Epassi’s accessibility feedback form, we process the categories of personal data you include in your feedback to address it.
Data is retained for three years from the response to each feedback submission.

 

  • Legal obligation

3.3.2 Website, Web Analytics, and Cookies

 

  • Categories of personal data defined in the cookie policy

 

Personal data is processed to develop Epassi’s services using web analytics and cookies, as well as to manage our website and fulfill user requests.
For more detailed information on what personal data is processed through web analytics and cookies, and instructions on how you can manage cookie-based processing, please refer to Epassi’s cookie policy.

 

  • Consent
  • Legitimate interest

3.3.3 Marketing to Employer Customer Contact Persons

 

  • Name
  • Email address
  • Phone number

 

Personal data of employer customer contact persons may be used for marketing Epassi’s services and/or the services of its partners.
Personal data is processed for the duration of the marketing campaign and up to two (2) years thereafter, or until the data subject withdraws consent for processing.

 

  • Legitimate interest

3.3.4 Marketing of the Epassi Platform and Other Marketing

 

  • Contact details related to service use
  • Log data and other analytics
  • Location data (with consent)

 

Epassi sends marketing communications to end-users related to their use of Epassi services.
Marketing is carried out based on both consent and legitimate interest.
Marketing based on legitimate interest applies only to marketing related to an existing customer relationship and is not targeted beyond that relationship.
End-users can also give consent for targeted and location-based marketing, such as presenting nearby offers and electronic direct marketing. You can manage your marketing consent using the consent management tool.
Personal data is retained for as long as your consent remains valid, and if processing is based on legitimate interest, for as long as you remain an Epassi customer or until the relevant data category is deleted earlier.

 

  • Consent
  • Legitimate interest

Epassi uses tools that leverage artificial intelligence (AI), including large language models and machine learning models, in the delivery of its services. However, Epassi’s use of AI is strictly limited by contractual agreements, technical restrictions, and internal policies to ensure that personal data is never disclosed to AI models in a way that would compromise data protection, such as by training the AI. The use of these tools and applications within Epassi does not affect or hinder the exercise of data subject rights. You always have the option to refuse the processing of your personal data by AI by notifying Epassi as described in section 9, “Data Subject Rights.”

4. Sources of Personal Data

Personal data is primarily collected directly from data subjects, for example, during registration for our services, while using them, or during the customer relationship.

Personal data concerning end-users is also collected from the end-user’s employer in connection with services provided jointly by the employer and Epassi under their service agreement. This data is collected to register the end-user as an Epassi consumer customer by creating a personal account and to report the use of employment benefits to the employer for tax purposes.

Personal data received from employers is used solely to identify the end-user for service access, and data about the end-user’s service usage is disclosed to the employer only to the extent necessary to provide benefits or as otherwise agreed for benefit tracking.

In connection with Epassi’s legal obligations regarding payment instruments and customer due diligence, Epassi may update and supplement related data from private and public sources.

5. Disclosure, Transfer, and Recipients of Personal Data

Personal data may be disclosed, as necessary for the purposes described in this Privacy Policy, to the following third parties:

  • Epassi merchants for financial and payment-related purposes during service use.
  • Financial service providers or other service providers for financing products included in Epassi’s offering.
  • Employer customers as described in section 4 “Sources of Personal Data.”
  • Epassi’s service providers, such as web service providers, to the extent necessary to deliver the Epassi service.
  • Epassi group companies under agreed data processing agreements, where they perform parts of the Epassi service or its support functions.

Epassi may also share personal data in connection with a potential merger, sale of assets, financing, or transfer of all or part of its business, and similar arrangements.

Personal data may be disclosed to third parties if required by applicable data protection regulations or an order from a competent authority, and for investigating misuse of products or services, as well as ensuring the security and usability of Epassi’s products and services.

To provide agreed services, the following Epassi data processors also process personal data. A list of processors and other recipients includes:

  • Amazon Web Services (support tool)
  • APSIS International AB (marketing tool)
  • BitBot Oy (support tool for EpassiBIKE)
  • Contentsquare SAS (analytics software)
  • Cellip AB (support tool)
  • Databricks (support tool)
  • Epassi Finland Oy (IT operations)
  • Fortnox AB (financial management tool)
  • Freshworks Inc. (support tool)
  • HeadQ Oy (digital commerce platform)
  • Google LLC (Google Analytics, Google Ads, Google Translation)
  • Hetzner Online GmbH (web hosting)
  • HubSpot, Inc. (CRM tool)
  • InExchange Factorum AB (e-invoicing)
  • Kund-o AB (case management support tool)
  • Lime Technologies AB (CRM tool for Swedish employer and merchant contacts, Sweden only)
  • Mainloop AB (IT development)
  • Microsoft Corporation (business tools)
  • Oneflow AB (digital contract platform)
  • Oura Health Oy (marketing partner)
  • Parvus Vulpes Oy (platform tool)
  • Sharpspring (marketing tool)
  • Shopify (EpassiBIKE platform)

o Lightward Inc. (Shopify functionality tool)

o HulkApps Inc. (Shopify functionality tool)

o Instacollect Inc. (Shopify functionality tool)

  • Signicat AS (identity verification service)
  • Svea Bank AB and affiliates or Tukirahoitus Oy (EpassiBIKE financing partner)
  • Telavox AB (support tool)
  • Telia Finland Oyj (strong authentication)
  • Tradedoubler AB (marketing tool)
  • Visma Solutions Oy (Netvisor and customer due diligence)
  • RevQore (Hubspot consulting)
  • Kaks.io (Hubspot consulting)
  • Vainu.io (Business information service)

 

6. Transfers Outside the EU/EEA

Some third parties and their services used by Epassi for personal data processing may operate outside the European Union (EU) or European Economic Area (EEA), meaning personal data may be transferred outside these regions. If personal data is transferred outside the EU/EEA, such transfers are subject to the following legal safeguards:
• Transfers are made to a country for which the European Commission has issued an adequacy decision regarding minimum data protection standards;
• Transfers are carried out using the European Commission’s standard contractual clauses or other appropriate safeguards approved by a competent data protection authority.

When transferring data to third countries, Epassi implements appropriate safeguards, including additional protective measures where necessary, or other methods approved by the European Commission or competent data protection authority to maintain data protection in accordance with the GDPR.

Recipients that may transfer personal data outside the EU/EEA include:
• Shopify, Inc. (EpassiBIKE end-user data)
o Lightward Inc.
o HulkApps Inc.
o Instacollect Inc.

7. Security measures

Ensuring the confidentiality, integrity, and availability of personal data is important to Epassi. Epassi’s security management system is based on legal, regulatory, and contractual requirements. The Epassi service and IT systems are certified according to the ISO27001 information security standard. The security management system consists of appropriate technical, administrative, and organizational measures to protect personal data from unauthorized access, disclosure, destruction, and processing.

Administrative and organizational measures:
• Epassi services are implemented and personal data stored in two separate EU-based data centers certified to internationally recognized security standards
• Role-based access control
• Technical segregation of personal data
• Supplier and system monitoring in accordance with ISO27001

Technical measures:
• Firewalls
• Backups
• Access control
• Technical monitoring of processing and errors
• Secure encryption techniques
• Encrypted network connections (HTTPS)

All parties involved in personal data processing are bound by contractual confidentiality obligations. We also require our service providers to use appropriate methods to protect personal data.

8. Use of Cookies and Similar Technologies

Epassi’s website uses cookies.
Details of the use of cookies and similar technologies are documented in Epassi’s Cookie Policy, which explains how and for what purposes Epassi uses each cookie.

9. Data subject’s rights

When we process your personal data, you have certain rights under applicable data protection legislation. Each right applicable to the purposes listed in section 3 is described below, along with instructions for exercising these rights:

Right of access and right to review data
You have the right to obtain confirmation of whether your personal data is being processed and to access your data in written or electronic form upon request.

Right to rectification and erasure
You have the right to request correction of inaccurate personal data and the right to request deletion of your personal data. Epassi must delete personal data where there is no legal basis for processing (e.g., withdrawal of consent).

Right to data portability
You have the right to receive personal data you have provided to Epassi in a structured, commonly used, machine-readable format and to transfer that data to another controller.

Right to restriction of processing
You have the right to restrict processing where there is no longer a legal basis for processing but data must be retained for other legitimate purposes. In cases where data suspected to be inaccurate cannot be corrected or deleted, or where a deletion request is unclear, Epassi will restrict access to the data.

Right to object to processing
You have the right to object to processing based on Epassi’s legitimate interest or for direct marketing unless Epassi demonstrates compelling legitimate grounds for processing.

Right to withdraw consent
Where processing is based on consent, you have the right to withdraw consent at any time by notifying Epassi.

Right to lodge a complaint with a supervisory authority
If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent data protection authority.
In Finland: Data Protection Ombudsman (http://www.tietosuoja.fi)
In Sweden: Swedish Authority for Privacy Protection (https://www.imy.se/)

Exercising your rights
Requests must be made in writing or electronically and sent to the address specified in section 1. Please clearly specify your request and related personal data to facilitate resolution. Include your name, phone number, email address, username, and details of the products or services used.
Epassi will verify your identity before fulfilling the request and providing data. Responses will be provided within a reasonable time, typically within one month of the request and identity verification.
If your request cannot be fulfilled, Epassi will inform you in writing. Epassi may refuse requests (such as deletion) based on legal obligations or rights, including service-related requirements. Epassi may charge a reasonable fee if requests are particularly burdensome or manifestly unfounded.

Contact us if you have questions about our privacy practices or wish to exercise your rights.

10. Changes to the Privacy policy

Epassi may update this Privacy Policy by posting changes on its website and/or through other appropriate means. Data subjects are strongly encouraged to review the Privacy Policy on our website regularly.
If you object to any changes, you must discontinue use of the services and may request deletion of your personal data unless applicable law requires retention. Unless otherwise stated, the current Privacy Policy applies to all personal data we process.

This Privacy Policy was published on 21 October 2021 (version 1.0).
Version history available upon request.

Version history

Version number

Change description

Date

1.0

Document created

 

2.0

Document updated

25.2.2022

2.1

Document updated

17.3.2022

2.2

Document updated (EpassiBIKE)

21.6.2022

2.3

Document updated

3.5.2023

2.4

Document updated

21.11.2023

2.5

Document updated

19.12.2023

2.6

Document updated

15.3.2024

2.7

Document updated

12.9.2024

2.8.

Document updated

25.6.2025

2.9.

Document updated

18.7.2025

3.0.

Document updated

15.1.2026

3.1.

Document updated

20.2.2026

3.2.

Document updated

25.3.2026

3.3.

Document updated

20.4.2026