Hyppää sisältöön

Privacy Policy of Whistleblower Channel

Trevian Asset Management Oy – Privacy Policy of the Ethical Channel i.e., Whistleblower Channel.

Privacy notice in accordance with the European Union General Data Protection Regulation (GDPR)

This privacy notice explains how Trevian Asset Management Oy processes personal data in connection with the ethics reporting channel, also known as the Whistleblower Channel.

1. Controller
Trevian Asset Management Oy
Business ID 2507543-9
Erottajankatu 2, 3rd floor
00120 Helsinki
Email: tietosuoja@trevian.fi
Telephone: +358 10 581 3830
Hereinafter “Trevian”.

Contact person for matters concerning the register:
Kim Särs, Chief Compliance Officer

2. Name of the register
Ethics reporting channel, also known as the Whistleblower Channel (hereinafter the “reporting channel”).

3. Purposes and legal bases of processing personal data
Personal data is processed to receive reports submitted through the reporting channel, assess the accuracy of the reports, carry out necessary investigations and follow-up measures, and document the handling of reports.

The purpose of the reporting channel is to enable the safe and confidential reporting of suspected acts and omissions that violate the law, internal rules or ethical principles, and to prevent, detect and investigate misconduct.

Depending on the situation, the legal basis for processing is:
– compliance with Trevian’s statutory obligations, particularly when processing reports that fall within the scope of the Finnish Whistleblower Protection Act
– Trevian’s legitimate interest in investigating and preventing conduct that violates the law, internal rules or ethical principles, insofar as the processing is not based on a statutory obligation
– the establishment, exercise or defence of legal claims.

Submitting a report does not require the reporting person to disclose their identity. If the reporting person provides personal data, it will be processed for the purposes described in this notice.

4. Personal data processed
The following data may be processed in the reporting channel:

– the reporting person’s name, contact details and position, if provided by the reporting person
– the name, position, contact details and other identifying information of the person concerned by the report or other persons involved in the matter
– the content of the report, a description of the events, the time and place, and documents or other material related to the report
– information on the suspected act or omission and information obtained during the investigation
– information on the handling of the report, communications, investigative measures, conclusions and follow-up measures
– user and log data relating to the persons handling the report, such as user ID and time of processing
– technical log and information security data relating to the reporting channel, depending on how the service is implemented.

A report may contain special categories of personal data or personal data relating to criminal convictions and offences. Such data is processed only where necessary to investigate the matter and where there is a lawful basis under applicable legislation. Personal data that is clearly irrelevant to the handling of the report will be deleted without undue delay.

5. Sources of personal data
Personal data is primarily obtained from the reporting person and from material submitted with the report. During the investigation, information may also be obtained from the person concerned by the report, other parties involved, witnesses, Trevian’s systems and documents, service providers, authorities and other lawful sources to the extent necessary to investigate the matter.

6. Recipients and disclosures of personal data
Reports are handled only by persons specifically appointed by Trevian who are authorised to perform the task and bound by confidentiality. In accordance with Trevian’s current internal guidelines, the reports are handled by the designated Compliance Team.

The technical service provider for the reporting channel is Suomen Tunnistetieto Oy, which processes personal data on behalf of Trevian in accordance with a written agreement and Trevian’s instructions.

Personal data may be disclosed only to the extent necessary and lawful, for example:
– to competent authorities, courts or pre-trial investigation authorities
– to external legal advisers, auditors or other experts for the purpose of investigating the matter
– to other parties where disclosure is required by law or necessary for the establishment, exercise or defence of legal claims.

The identity of the reporting person and the person concerned by the report, as well as other information that directly or indirectly reveals their identity, is protected in accordance with the Finnish Whistleblower Protection Act and other applicable legislation.

7. Transfers of data outside the EU or EEA
Personal data is primarily processed within the European Union or the European Economic Area. If personal data is transferred outside the EU or EEA, Trevian ensures the lawfulness of the transfer by using an applicable transfer basis under the GDPR and the necessary safeguards, such as an adequacy decision by the European Commission, standard contractual clauses approved by the European Commission and, where necessary, supplementary safeguards.

8. Protection, confidentiality and security of personal data
Reports and related personal data are processed confidentially. Access to the data is restricted to persons appointed to handle reports. Access rights are personal and role-based.

The data is protected by appropriate technical and organisational measures, including access rights management, authentication, encryption, logging, backups, information security updates and instructions for persons processing the data. Persons processing personal data are bound by confidentiality.

The identity of the reporting person will not be disclosed without the reporting person’s explicit consent to anyone other than authorised persons responsible for receiving reports and carrying out follow-up measures, unless disclosure is required by a necessary and proportionate obligation imposed by law. If the identity must be disclosed by law, the reporting person will be informed in advance and provided with a written explanation of the reasons for disclosure, unless such information would jeopardise the related investigation or legal proceedings.

9. Retention period
The report and related personal data will be deleted five (5) years after the report was received, unless continued retention is necessary for the exercise of rights or fulfilment of obligations laid down in the Finnish Whistleblower Protection Act or other legislation, or for the establishment, exercise or defence of legal claims.

Personal data that is clearly irrelevant to the handling of the report will be deleted without undue delay. The need for retention is assessed during the handling of the matter and after it has been concluded.

10. Informing data subjects
The reporting person is provided with information on the processing of personal data when submitting the report. The person concerned by the report and other persons whose data is processed will be provided with the information required by the GDPR at an appropriate stage.

Providing this information may be postponed or restricted if doing so would jeopardise the investigation of the report, the preservation of evidence, the protection of the reporting person’s identity or the rights of other persons, or where there is another lawful basis for the restriction.

11. Rights of the data subject
Under applicable data protection legislation, the data subject has the right to:

– receive information on the processing of their personal data and access their personal data
– request rectification of inaccurate or incomplete data
– request erasure of personal data where the conditions for erasure are met
– request restriction of processing
– object to processing based on legitimate interest on grounds relating to their particular situation
– lodge a complaint with the competent supervisory authority.

These rights are not absolute in all situations. They may be restricted under the Finnish Whistleblower Protection Act, the Finnish Data Protection Act or other applicable legislation, for example to safeguard the investigation of the report, protect the identity of the reporting person or protect the rights of other persons. The right to data portability generally does not apply where processing is not based on consent or a contract.

Requests concerning the exercise of rights may be sent by email to tietosuoja@trevian.fi. Trevian may request additional information to verify the identity of the data subject. Requests will be responded to within the time limits required by data protection legislation.

12. Automated decision-making
No decisions based solely on automated processing that would have legal effects concerning the data subject or similarly significant effects are made in connection with the handling of reports.

13. Right to lodge a complaint
If the data subject considers that their personal data has been processed in breach of data protection legislation, they have the right to lodge a complaint with the competent supervisory authority.

Office of the Data Protection Ombudsman
PO Box 800
00531 Helsinki
Telephone exchange: 029 566 6700
Website: tietosuoja.fi

14. Applicable legislation and updates to this privacy notice
The processing of personal data is governed in particular by:
– the General Data Protection Regulation (EU) 2016/679
– the Finnish Data Protection Act (1050/2018)
– the Finnish Act on the Protection of Persons Reporting Infringements of European Union and National Law (1171/2022), also known as the Whistleblower Protection Act
– the Finnish Act on the Protection of Privacy in Working Life (759/2004), where applicable
– other legislation applicable from time to time to the handling of reports and the protection of personal data.

Trevian may update this privacy notice, for example due to changes in legislation, authority guidance, the reporting channel, service providers or processing practices. The current version is published on Trevian’s website or made available in connection with the reporting channel.

Whistleblower Channel Privacy Notice | Updated 13 August 2026