Privacy Notice
Avara’s General Privacy Notice
Updated 1.12.2023
Avara specializes in residential investment, asset management, and property management. More information about us can be found on our website at: https://www.avara.fi/en/company
In this Privacy Notice, we explain how we process your personal data when you are a housing applicant, a tenant, or a resident of a property owned or managed by us. This Privacy Notice also describes how we process your information when you visit our website or use our services online.
Please note that when processing personal data related to tenant relationships and the management of the rental properties, we act as joint controllers with the owners of the properties. You can find the property owner's information in your rent agreement. In this Privacy Notice, "we" refers to Avara and the property owners.
Your personal data is primarily processed for various purposes related to housing applications, tenancy customer relationships, and housing-related purposes. Additionally, we process your personal data for various marketing purposes as described in this Privacy Notice.
In some rental properties, recording surveillance cameras and electronic access control and locking systems are also used to enhance the safety of the living environment.
If you have any questions regarding how we handle your personal data or the shared responsibilities and joint controllership with the property owners, or if you wish to exercise your rights protected by data protection laws, feel free to reach out to us using the contact details provided below.
1. Contact point for Avara and Property owners
Avara Oy
Bulevardi 7
00120 Helsinki
tietosuoja@avara.fi
2. Processed Personal Data, Processing Purposes and Legal Basis
In this section, we describe how we process your personal data when you are our housing applicant or tenant customer when you use our website or digital services, or when you act as a rent payer. In certain rental properties where video surveillance is employed, we also process your personal data when you visit our rental premises.
Right to Object: When your personal data is processed based on legitimate interests, you can object to the processing based on your personal situation. Learn more in section 7.
Examples of processed data types |
Purposes of processing |
Legal basis for processing |
Housing applicant's basic information, such as name, contact information and citizenship, social security number. |
Processing rental apartment applications. Housing offers. |
The processing of personal data is mainly based on the use of Avara's services and preparation of rental agreement. In addition, we process data based on our legitimate interests related to the customer or similar relationship, the good rental brokerage practice, and the good rental practice, as well as the organization and development of our business operations. |
ARA apartment applicant's basic information, such as name, contact information, nationality, and social security number. |
Resident selection and reporting of ARA (The Housing Finance and Development Centre of Finland) apartments. |
The processing of personal data is mainly based on the regulation regarding the selection of residents of state-subsidized rental apartments and the official instructions that specify it. |
Tenant’s basic information, such as name, contact information. |
Rental brokerage and rental relationship management. |
Statutory obligations related to the regulation of rental apartment brokerages and the rental of residential apartments. |
OmaAvara is Avara's digital service for apartment applicants and residents, where you can manage your apartment applications and information related to rental brokerage and rental relationships. |
Use, maintenance, and development of the OmaAvara service. |
The processing of personal data is mainly based on using Avara's services. |
Customer service requests and related customer engagement history, contact details, communication, and related technical identifiers. |
Customer service. |
Legitimate interest related to the customer or similar relationship, the good rental brokerage practices, and the good rental practices, as well as the organization and development of the business operations. |
Resident list, residents' names, apartment number, start and end dates of the tenancy. |
Maintaining the resident list. |
Legitimate interest related to safe housing. |
Information related to surveys, such as e-mail address of the survey recipient and survey responses. |
Resident, apartment applicant and customer surveys. |
Legitimate interest related to the customer or similar relationship and the organization and development of the business operations. |
Resident's name and contact information. |
Service, maintenance, and upkeep of apartments and properties. |
Legitimate interests related to the customer or similar relationship, the good brokerage practice and the good rental practice, and the organization and development of the business operations. |
Information related to key management, such as tenant's name, address, start and end dates of tenancy, key returns. |
Management of apartment keys. |
Legitimate interests related to the customer or similar relationship, the good rental practice, and safe housing. |
Legitimate interests related to the customer or similar relationship, the good rental practice, and safe housing. |
Resident gifts. |
Legitimate interests related to the customer or similar relationship, and development of the business operations.. |
Information related to resident meetings, such as invitation lists, resident meeting participants and minutes. |
Residential democracy in ARA apartment properties. |
Statutory obligations related to the state-subsidized rental apartments. |
Information related to knowing the customer obligations. This information is obtained through the strong authentication processes within the OmaAvara service or alternatively through our customer service. |
Customer due diligence to prevent money laundering and the financing of terrorism, and compliance with official regulations regarding sanctions and asset freezing. |
Legal obligations related to customer due diligence, preventing money laundering and the financing of terrorism, including duties related to compliance with sanctions and asset freezing. |
Information related to the management of parking spaces, such as name, address, parking space information. |
Management of car and other parking spaces. |
Legitimate interests related to the organization of business and housing services. |
Information about the apartment, such as address, apartment number and square footage. |
Energy management and energy efficiency monitoring. |
Legitimate interests related to energy management and energy efficiency. |
Information related to invoicing, payments, and rental deposit management. |
Billing services and rent payment. |
The processing of personal data is mainly based on the use of Avara's services and the tenant relationship. |
Information related to invoicing, payments, and rental deposit management. |
Property management and property secretarial services. |
Legitimate interest related to the customer or similar relationship, the good rental brokerage practices, and the good rental practices, as well as the organization and development of the business operations. |
Information related to marketing and communication, such as contact information, interests, reactions, direct marketing permissions and prohibitions. |
Marketing and communication. |
Legitimate interests related to the customer or similar relationship and the business development. |
Housing applicant’s and resident's basic information, such as name, social security number and contact information. Information related to financial management and accounting.
|
Complying with and demonstrating compliance with legal obligations, preventing, and investigating abuses or disturbances, monitoring and defending rights. |
Statutory obligations based on the regulation regarding rental apartment brokerages and the rental of residential apartments. |
Video recording and recording time. |
Recording camera surveillance. |
Legitimate interests related to safe housing. |
Information related to the use of the website: technical identifiers such as IP address, time stamp, device identifier, session identifier. See in more detail, section 9. the use of cookies in our online services |
Maintaining and developing websites and digital services. |
Legitimate interests to maintain and improve the stability and functionality of our website and digital services. |
Resident's name and contact information, information related to the accident and damages. |
Managing damage incidents. |
Legitimate interests related to safe housing. |
Resident's name and contact information, |
Booking calendars for common areas (laundry and sauna). |
Legitimate interests related to the organization of housing services. |
3. Automatic Decision-Making and Profiling
We've streamlined the rental decision process in our "Rent Now" service. Additionally, we employ automated decision-making in our rental process when you submit a housing application to us. Automated decision-making means that decisions are made without human involvement in the decision-making process. With our "Rent Now" service, you can instantly secure the apartment you desire and move in on its availability or completion date. When you submit a housing application, automation ensures that your application is processed quickly, and you receive a housing offer as soon as possible.
Evaluated Information and Data Sources
Using the "Rent Now" service and logging into OmaAvara requires strong authentication with online banking credentials or mobile ID. Through authentication, we obtain your name, social security number, and nationality. Reliably verified identity, along with meeting other criteria, enables us to make a rental decision. The decision is based on your authentication data, credit information reflecting your financial capacity, and your age. Additionally, you must be registered in the Finnish population information system.
When you use our 'Rent Now' service or submit a rental application to us, your credit information is checked through Lowell Suomi Oy's credit decision service, using data from Suomen Asiakastieto Oy's credit information system, to facilitate the signing of the rental agreement. The automated decision service undergoes regular testing to ensure its functionality.
Logic of Automatic Processing
Through the credit decision service, we receive a automatic rental decision recommendation. Based on this information, we can better manage risks associated with rental operations.
In the "Rent Now" service, you will receive a negative response if you have a credit default entry or if you are under 18 years of age. If there are disruptions in your credit information or you are underage, renting an apartment through the "Rent Now" service is not possible. In such cases, you can still submit a housing application to us.
Similarly, for housing applications, we cannot automatically offer you the apartment you applied for if you are underage or have credit issues.
In these situations, our rental team will process your application, verifying the accuracy of the information, and assessing your situation on a case-by-case basis.
4. Sources of data
We primarily collect your personal data directly from you through the housing application, rental agreement, OmaAvara service, and our customer service. Additionally, we receive information from our partners, such as details related to apartment maintenance, billing, electronic signatures, or key handovers. While using strong authentication, we obtain your name and social security number from the Digital and population data services agency's population information system. For the implementation of energy efficiency, apartment-specific temperature and humidity data are measured with sensors.
When you submit a housing application or use the "Rent Now" service, your credit information is checked from the credit information register of Suomen Asiakastieto Oy. Our rental experts also use credit inquiries through Alma Talent Tietopalvelu.
5. Data retention
Personal data is processed only for as long as necessary to fulfill the purposes mentioned above. We delete unnecessary and outdated personal data when there are no longer grounds for data retention.
As required by the Real Estate Agencies and Rental Agents Act (2000/1075), Avara must maintain a diary of received assignments. The rental agency must keep the assignment diary, assignment agreements with attachments, tender documents, brochures, and other documents related to the assignment for five years after the assignment's completion.
Additionally, the Good Rental Brokerage Practice and the Good Rental Practice require consideration of the liability limitation period for compensation. The liability for damages expires after 10 years. We do not retain any information beyond ten years from the termination of the brokerage mandate agreement between the property owner and Avara.
6. Recipients of personal data and data transfers outside the European Economic Area (EEA)
In our operations, we engage external entities apart from Avara or the property owners who process data only within the boundaries we establish and for the purposes outlined in this Privacy Notice. We enter into appropriate data processing agreements with our partners, where they commit to handling personal data securely and confidentially.
Your personal data can be disclosed to the following recipients
- To companies belonging to the Avara Group
- To various IT and data center service providers
- To the energy management system supplier
- To the supplier of the electronic information board, resident application, and common space booking calendars
- To our real estate management and property maintenance partners
- To our billing and collection service partners
- To our marketing partners
- To electricity and data network suppliers
- To contractors and brokers
- To security and lock services
- To the authorities
- To other third parties, such as home appliance suppliers.
- To facilitate the exchange of keys, we may provide your contact information (name, email, phone number) to the new tenant when your rental agreement ends, unless you object to the disclosure. We will contact you separately in these situations.
We mainly process your personal data in systems and data centers situated within the European Union. However, some of our partners or the services they offer may be based outside the European Economic Area (EEA), resulting in the transfer of your personal data beyond the EEA. This transfer may occur, for instance, when the IT system or cloud service used for processing personal data is situated outside the EEA or on a server provided by a U.S. service provider.
In situations where personal data is transferred outside the EEA, we implement protective measures to ensure the high level of personal data protection required by European data protection laws is maintained even after the transfer. Protective measures include, among others, a decision by the European Commission regarding the adequacy of data protection and ensuring that the recipient of personal data is committed to the required safeguards, such as the EU-US Data Privacy Framework. Additionally, we may require the use of standard contractual clauses approved by the European Commission as part of agreements binding our partners. In addition to these, we demand compliance with appropriate technical and administrative safeguards.
7. Your rights as a data subject
The General Data Protection Regulation grants you several rights as a data subject related to processing of your personal data.
However, we would like to point out that these rights ensured by the law are not absolute. For example, we cannot delete personal data related to your tenancy in a situation where you have a valid rental agreement with us.
You can ask us to exercise your rights mentioned below by sending your request to the address mentioned in section 1 of this Privacy Notice.
The right of access to personal data. You have the right to receive confirmation on whether we process personal data relating to you. You have the right to access and ask for a copy of any such personal data. We may ask you to specify your request, when necessary, for example regarding to the details of the provision of information.
Right to rectification. You have the right to request the rectification of incorrect, incomplete, or outdated personal data relating to you.
Right to data erasure. In some situations, you have the right to request erasure of your personal data from our data systems. We will comply with your request, if there is no legitimate reason to retain the data, such as a legal obligation to continue processing the personal data.
Right to object and right to restrict the processing of your personal data. Based on a specific personal reason, you have the right to object to the processing of personal data. However, this does not mean the general right to oppose all processing, but is limited, for example, to situations where the processing is based on legitimate interest of ours or a third party. We have the right to continue to process your personal data if we have a compelling reason to do so. Such a reason may be, for example, a continuous threat or investigation of crime or abuse.
In addition, you may at any time object to the processing of your personal data for direct marketing purposes.
You also have the right to request a restriction on the processing of your personal data, for example in situations where you dispute the accuracy of your personal data.
Right to data portability. You have the right to receive your personal data from us in a structured, commonly used format so that you may transfer your personal data to another controller, provided that the processing of your personal data is based on consent or a contract between you and Avara.
Right to lodge a complaint. If the processing of your personal data is in breach of applicable legislation, you have the right to lodge a complaint with the national supervisory authority. You can lodge the complaint with a competent supervisory authority. In Finland, this is the Data Protection Ombudsman, and the complaint must be lodged in accordance with instructions provided by the Office of the Data Protection Ombudsman. Please see https://tietosuoja.fi/en/home for more information.
8. How we keep your personal data safe?
Access management. The processing of personal data is only permitted to designated, authorized persons whose duties require it. Personal data can only be accessed with appropriate access rights.
Agreements. Persons processing personal data have signed appropriate confidentiality commitments or are otherwise subject to an obligation of confidentiality. Our data processing partners have committed to take appropriate measures to ensure the security of personal data.
Staff training and guidance. We have provided comprehensive data protection training and guidance for all our personnel. We have issued binding written instructions and regulations to our employees regarding the processing of personal data, data security and data protection, which the employees have committed to comply with.
Technical measures. Personal data and systems are protected e.g. with firewalls. In addition, we monitor the processing of personal data and automatically detect anomalies. The data is stored on a server located in a locked premises where passing is restricted by access control and monitored by recording camera surveillance. Necessary physical copies of personal information will be kept in a locked premises. We regularly review the processing of personal data and the systems and equipment used for processing activities, and assess the risks associated with the processing, for example, when introducing new technology.
9. Use of cookies in our online services
We use cookies and similar technologies in our online services. A cookie is a small text file that is sent to and stored on a user's computer, enabling the webmaster to identify visitors who visit the site frequently, to make it easier for visitors to log in to the site, and to compile aggregate information about visitors.
Cookies can be used to improve the content of pages and provide customers with personalized content. Cookies do not harm users' computers or files and may be necessary for the proper functioning of some of the pages maintained and services provided.
Functional cookies
Functional cookies are used to store information that is relevant to the functionality of the website and cannot be switched off. Functional cookies include e.g. saving the cookie consent selection so that you are not asked for this information again.
The website uses the following third-party functional cookies:
• HubSpot
• CookieBot (Enables cookie consent across websites)
Analytics and advertising cookies
This site uses a variety of analytics cookies to help evaluate how users use the online service. The cookie stores data about how you use the web service (including your IP address). The cookie data is sent to and stored on third-party servers. The data may be located outside the EU.
With the help of advertising cookies, this same analytical information is used to target and personalize advertising.
The site uses the following third-party analytics and advertising cookies:
• Google
• HotJar
• Facebook
• HubSpot
• LinkedIn
Change your cookie preferences
10. Modification of this Privacy Notice
The ways in which your personal data is processed may change as our business develops and thus this Privacy Notice may change. You will always find the up-to-date version of this Privacy Notice on this website.