Skip to content

Customer and stakeholder register pivacy notice and cookie policy

Trevian Asset Management Oy – Customer and stakeholder register pivacy notice and cookie policy

Privacy notice in accordance with the European Union General Data Protection Regulation (GDPR) This privacy notice explains how Trevian Asset Management Oy processes personal data of customers, cooperation partners and other stakeholders.
The notice describes:
– what personal data we collect
– for what purposes and on what legal bases personal data is processed
– where personal data is obtained from and to whom it may be disclosed
– how long personal data is retained and how it is protected
– how the data subject’s rights are exercised.

1. Controller
Trevian Asset Management Oy
Business ID 2507543-9
Erottajankatu 2, 3rd floor
00120 Helsinki
Email: tietosuoja@trevian.fi
Telephone: +358 10 581 3830

Hereinafter “Trevian”.

In matters concerning data protection, you may contact Trevian by email at tietosuoja@trevian.fi.

2. Name of the register

Customer and stakeholder register

3. Purposes and legal bases of processing personal data

Personal data is processed for the following purposes:
– managing customer, cooperation and stakeholder relationships
– communication and contact
– developing services, business operations and the website
– organising events
– marketing and direct marketing
– handling customer feedback and contacts
– business analysis, reporting and statistics
– contract management
– fulfilling statutory obligations and preparing, presenting or defending legal claims.

Depending on the situation, the processing of personal data is based on:
– Trevian’s legitimate interest, such as maintaining customer and stakeholder relationships, developing business operations, communication and B2B marketing
– the data subject’s consent, where consent is the appropriate legal basis
– the performance of a contract or steps taken prior to entering into a contract
– compliance with a statutory obligation of the controller.

Personal data may be used to segment contact persons and to target marketing communications. Profiling is not used as a basis for decisions based solely on automated processing that would have legal effects concerning the data subject or similarly significant effects.

4. Data content of the register

The register may contain the following personal data:

– first and last name
– employer organisation
– job title, position, role or area of responsibility
– department, office, address and country
– email address and telephone number
– customer feedback, contacts and other communication
– information relating to customer, cooperation and contractual relationships and basic contract information
– information on participation in events
– marketing consents, objections and other preferences
– information on website use, such as browsing, search, device and log data, where processing is permitted
– data update dates and other information necessary for the purposes of the register
– descriptive identifiers such as “tenant” or “service provider”.

5. Regular sources of data

Personal data is collected:
– from the data subject, for example by email, online form, telephone or in connection with meetings
– during the customer, cooperation or contractual relationship
– in connection with events
– through the website and cookie settings
– from public sources such as company websites, the trade register and professional online services
– from cooperation partners related to properties and assignments managed by Trevian where there is a lawful basis for disclosure and processing.

6. Recipients and disclosures of personal data

Personal data is processed by Trevian personnel who need the data to perform their work duties. Data may also be made available to service providers acting on behalf of Trevian, including:
– providers of IT, cloud, information security and maintenance services
– providers of customer relationship management, communication, marketing and analytics services
– providers of website and event services
– other service providers participating in Trevian’s assignments.

Service providers process personal data on behalf of Trevian in accordance with written agreements and Trevian’s instructions.

Personal data may also be disclosed:

– to authorities and other parties where required by legislation or a competent authority
– in connection with a corporate transaction, business transfer or change of service provider to the extent necessary to carry out the arrangement and ensure continuity of operations
– to protect Trevian’s or a third party’s rights or to prepare, present or defend a legal claim where there is a lawful basis for the disclosure.

7. Transfers of data outside the EU or EEA
Personal data is primarily processed within the European Union or the European Economic Area. However, some of the service providers used by Trevian may process personal data outside the EU or EEA.

Where personal data is transferred outside the EU or EEA, Trevian ensures the lawfulness of the transfer by using an applicable transfer basis under the GDPR and the necessary safeguards. These may include an adequacy decision by the European Commission, standard contractual clauses approved by the European Commission and, where necessary, supplementary safeguards or another transfer mechanism permitted by law.

8. Retention of data
Personal data is retained only for as long as necessary to fulfil the purposes described in this notice or to comply with statutory obligations.

Customer and stakeholder data is generally retained for the duration of the customer, contractual or cooperation relationship and thereafter for as long as necessary to handle any legal claims or comply with legal obligations. Marketing data is retained for as long as there is a lawful basis for processing it or until the data subject objects to direct marketing. Information concerning a marketing objection may be retained to ensure compliance with the objection.

The need for retention is assessed regularly. Unnecessary data is deleted or anonymised.

9. Protection of personal data
Trevian protects personal data by appropriate technical and organisational measures. These include access rights management, personal user IDs, appropriate authentication and encryption solutions, backups, logging, information security updates, and personnel instructions and training.

Access to personal data is restricted to persons who need the data to perform their work duties.

10. Rights of the data subject

Under applicable data protection legislation, the data subject has the right to:

– receive information on the processing of their personal data and access their personal data
– request rectification of inaccurate or incomplete data
– request erasure of personal data where the conditions for erasure are met
– request restriction of processing
– object to processing based on legitimate interest on grounds relating to their particular situation
– object to processing for direct marketing purposes at any time
– receive the data they have provided in a structured, commonly used and machine-readable format and transmit it to another controller where the conditions for the right are met
– withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal
– lodge a complaint with the competent supervisory authority.

The exercise of rights is not absolute in all situations. The applicability of a right depends, among other things, on the legal basis for processing personal data.

Requests concerning rights may be sent by email to tietosuoja@trevian.fi. Trevian may request additional information to verify the identity of the data subject. Requests will be responded to within the time limits required by data protection legislation.

11. Right to lodge a complaint
If the data subject considers that their personal data has been processed in breach of data protection legislation, they have the right to lodge a complaint with the competent supervisory authority.

Office of the Data Protection Ombudsman
PO Box 800
00531 Helsinki
Telephone exchange: 029 566 6700
Website: tietosuoja.fi

TREVIAN.FI COOKIE POLICY

1. What are cookies?
Cookies are small text files stored on the user’s device when using a website. Cookies also include similar technologies that allow information to be stored on or read from the user’s device.

Cookies can be used to ensure the functioning of the website, remember the user’s choices, analyse website use and carry out marketing in accordance with the user’s preferences.

2. Cookie categories
Necessary cookies
Necessary cookies are required for the technical functioning of the website, information security and functions explicitly requested by the user. They may be used without separate consent.

Functional cookies
Functional cookies enable additional features and remembering choices made by the user. They are used on the basis of the user’s consent unless they are necessary to provide a service requested by the user.

Analytics cookies
Analytics cookies collect information on website use, such as visit numbers and pages used. The information is used to analyse and develop the website. Analytics cookies are used on the basis of the user’s consent.

Marketing and social media cookies
Marketing and social media cookies may be used to measure the effectiveness of marketing, target content and advertising, and enable third-party content and functions. They are used on the basis of the user’s consent.

3. Accepting and managing cookies
Cookies other than necessary cookies are set or used only after the user has given consent in the cookie settings. The user may accept or reject cookie categories and change or withdraw consent at any time in the website’s cookie settings.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Restricting cookies may affect the functioning of some website features.

4. Cookie information
The cookies used on the website should be listed in the cookie settings or cookie list, including at least the cookie name, service provider, purpose, validity period and cookie category. The list is updated to reflect the cookies and similar technologies actually used on the website.

5. Processing of personal data related to cookies
If the data collected through cookies or similar technologies constitutes personal data, the principles of this privacy notice apply to its processing. Third-party service providers may process data in accordance with their own privacy policies.

SOCIAL MEDIA PAGES MAINTAINED BY TREVIAN

Trevian maintains pages on, among others, LinkedIn, Facebook, Instagram and YouTube. When a user follows Trevian’s page, comments on a post, sends a message or otherwise interacts with the page, Trevian may process the user’s public profile information and information related to the interaction.

The data is processed for communication, informing users about services and events, handling feedback and contacts, marketing, and assessing the effectiveness of communication and marketing. The processing is based on Trevian’s legitimate interest or, where necessary, consent.

Social media service providers also process personal data for their own purposes in accordance with their own privacy policies. Trevian and the service provider may be joint controllers for certain page statistics in accordance with the service-specific terms. The data subject may exercise their rights by contacting Trevian or the relevant service provider.

Updating the privacy notice
Trevian may update this privacy notice and cookie policy, for example due to changes in legislation, authority guidance, services, systems or the processing of personal data. The current version is published on Trevian’s website.

Privacy Notice and Cookie Policy | Updated 13 August 2026