Back to registration

Privacy Policy

Last updated: April 4, 2026

This Privacy Policy explains how ToCar processes personal data in connection with the service in accordance with GDPR and applicable Finnish law.

1. Controller and Scope

ToCar is controller for personal data related to account administration, billing, security, and customer support of our own service operations. For customer business data uploaded into the service, customers are generally controllers and ToCar acts as processor as described in the DPA.

2. Data We Process

Data may include account and contact details, organization and workshop information, user authentication and audit events, communications metadata, support records, billing records, and service usage telemetry necessary for operation, legal compliance, and security.

3. Purposes and Legal Bases

We process data to provide and secure the service, manage accounts and subscriptions, process payments, provide support, fulfill legal obligations, and improve service quality. Legal bases include performance of contract, compliance with legal obligations, and legitimate interests. Where required by law, processing is based on consent.

4. Data Retention

Data is retained only for as long as necessary for the purposes described above. Retention periods are based on contractual needs, legal requirements (including accounting and tax obligations), and security needs. After the retention period, data is deleted or anonymized unless continued storage is required by law.

5. Data Sharing and Subprocessors

We do not sell personal data. We may share data with service providers and subprocessors required to operate the service (for example hosting, communications, and support tooling) under contractual safeguards, including data processing terms where required.

6. International Transfers

Where personal data is transferred outside the EEA, we apply appropriate safeguards under GDPR Chapter V, such as adequacy decisions or the European Commission's Standard Contractual Clauses, supplemented where required.

7. Security Measures

We apply administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, and loss. Security controls are continuously reviewed and updated based on risk.

8. Data Subject Rights

Depending on the circumstances, you may have rights to access, rectify, erase, restrict, or object to processing, and to data portability. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman or another competent supervisory authority in the EU/EEA. ToCar does not carry out automated decision-making that produces legal or similarly significant effects on data subjects within the meaning of Article 22 of Regulation (EU) 2016/679 (GDPR).

9. How to Exercise Rights

Rights requests can be submitted via support@tocar.fi. We may request additional information to verify identity before fulfilling a request. We respond within the timelines required by GDPR and applicable law.

10. Personal Data Breaches

If we become aware of a personal data breach affecting customer-controlled data, we will notify the relevant customer controller without undue delay as required by GDPR and the DPA. If we are controller, we will notify supervisory authorities and data subjects where legally required.

11. Children's Data

The service is intended for business users and is not directed to children. We do not knowingly collect children's personal data for our own purposes.

12. Changes to this Policy

We may update this Privacy Policy when necessary due to legal, operational, or product changes. Material updates will be communicated through appropriate channels.

13. Contact

Privacy requests, DPA questions, and data protection inquiries can be sent to support@tocar.fi.