Skip to content

Privacy Policy

Trevian Asset Management Oy – Privacy Policy

This Privacy Policy defines the objectives, responsibilities, and organization of data protection at Trevian Asset Management Oy. The policy serves as the foundation for procedures and guidelines that ensure the lawful and responsible processing of personal data as part of the company’s operations.

Data protection is closely linked to information security, which is governed by a separate Information Security Policy. Trust, transparency, and responsibility guide the processing of personal data across all company processes.

1. Purpose of the Privacy Policy
The purpose of this policy is to define the principles and operating practices by which personal data is processed in a lawful, secure, and ethical manner. Data protection is an integral part of risk management and responsible business conduct.

Processing is based on a clear purpose, only necessary data is collected, and the rights of data subjects are implemented transparently.

2. Principles of Personal Data Protection
Personal data is processed for predefined and justified purposes. Processing is lawful and transparent, and data is retained only for as long as required by its intended purpose. The accuracy and timeliness of data are ensured, and data subjects have the right to be informed about the processing of their data and to exercise their statutory rights.

Practical application:

Purpose limitation and data minimization: only essential data is collected; data is
deleted once the legal basis no longer exists.

Accuracy and timeliness: data is updated from reliable sources and corrected upon
request.

Transparency and rights: clear information is provided, and access, rectification, and
erasure are enabled.

3. Ensuring Data Protection
Ensuring data protection is based on a risk-based approach, where the processing of personal data is assessed as part of planning and continuous risk management. The results of these assessments guide technical and organizational safeguards.

Contracts are used to ensure that personal data protection and the rights of data subjects are also upheld when using external service providers. Personnel competence is developed through onboarding, training, and up-to-date instructions.

4. Double Materiality in Data Protection
Data protection is included in the company’s double materiality assessment as part of its sustainability and risk management framework. The assessment examines both the significance of data protection from the perspectives of business continuity, regulation, and reputation, as well as the impacts of personal data processing on data subjects and stakeholders. The results guide prioritization, resourcing, and development and are linked to target setting, monitoring, and reporting.

5. Procedure in the Event of a Data Protection Breach
Data security incidents are prevented and managed in accordance with a unified operating model. Every employee has a duty to report observed or suspected breaches without delay. Incidents are investigated without undue delay, documented, and assessed in relation to risks. Notifications to authorities and/or data subjects are made where required by law.

Data protection breach handling process:

1. Detection and reporting: immediately in accordance with instructions.

2. Assessment and containment: impact and scope assessment, immediate protective
measures.

3. Notifications and documentation: statutory notifications and internal reporting.

4. Follow-up actions: corrective measures and incorporation of lessons learned into
guidance and training.

    6. Responsibilities and Organization
    Senior management is responsible for defining the principles of data protection and ensuring that data protection is integrated into the company’s risk management.

    The Compliance Team acts as the coordinating and steering body for data protection, ensures compliance with obligations, maintains documentation and policies, monitors risks, and reports to management.

    Business management is responsible for the processing of personal data within their respective areas and for practical implementation, including regarding stakeholders.

    Each employee complies with this policy and maintains their data protection competence in accordance with their role.

    7. Review and Approval
    This policy is reviewed regularly and updated based on changes in the operating environment, legislation, the results of the double materiality assessment, and risk developments. Updates are the responsibility of the Compliance Team.

    Approved by the Board of Directors of Trevian Asset Management Oy on 23 February 2026.