Privacy Policy
Last updated: April 4, 2026
This Privacy Policy explains how ToCar processes personal data in connection with the service in accordance with GDPR and applicable Finnish law.
1. Controller and Scope
ToCar is controller for personal data related to account administration, billing, security, and customer support of our own service operations. For customer business data uploaded into the service, customers are generally controllers and ToCar acts as processor as described in the DPA.
2. Data We Process
Data may include account and contact details, organization and workshop information, user authentication and audit events, communications metadata, support records, billing records, and service usage telemetry necessary for operation, legal compliance, and security.
3. Purposes and Legal Bases
We process data to provide and secure the service, manage accounts and subscriptions, process payments, provide support, fulfill legal obligations, and improve service quality. Legal bases include performance of contract, compliance with legal obligations, and legitimate interests. Where required by law, processing is based on consent.
4. Data Retention
Data is retained only for as long as necessary for the purposes described above. Retention periods are based on contractual needs, legal requirements (including accounting and tax obligations), and security needs. After the retention period, data is deleted or anonymized unless continued storage is required by law.
5. Data Sharing and Subprocessors
We do not sell personal data. We may share data with service providers and subprocessors required to operate the service (for example hosting, communications, and support tooling) under contractual safeguards, including data processing terms where required.
6. International Transfers
Where personal data is transferred outside the EEA, we apply appropriate safeguards under GDPR Chapter V, such as adequacy decisions or the European Commission's Standard Contractual Clauses, supplemented where required.
7. Security Measures
We apply administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, and loss. Security controls are continuously reviewed and updated based on risk.
8. Data Subject Rights
Depending on the circumstances, you may have rights to access, rectify, erase, restrict, or object to processing, and to data portability. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman or another competent supervisory authority in the EU/EEA. ToCar does not carry out automated decision-making that produces legal or similarly significant effects on data subjects within the meaning of Article 22 of Regulation (EU) 2016/679 (GDPR).
9. How to Exercise Rights
Rights requests can be submitted via support@tocar.fi. We may request additional information to verify identity before fulfilling a request. We respond within the timelines required by GDPR and applicable law.
10. Personal Data Breaches
If we become aware of a personal data breach affecting customer-controlled data, we will notify the relevant customer controller without undue delay as required by GDPR and the DPA. If we are controller, we will notify supervisory authorities and data subjects where legally required.
11. Children's Data
The service is intended for business users and is not directed to children. We do not knowingly collect children's personal data for our own purposes.
12. Changes to this Policy
We may update this Privacy Policy when necessary due to legal, operational, or product changes. Material updates will be communicated through appropriate channels.
13. Contact
Privacy requests, DPA questions, and data protection inquiries can be sent to support@tocar.fi.