Part I – Privacy Policy
Koll's Privacy Policy
Data controller
Koll Group Oy
Joensuunkatu 7
24100 Salo
Finland
- Business ID
- 3410913-5
- Data protection matters
- hannu.nissinen@koll.to
- Version
- 2.0
- Effective from
- 28 July 2026
- Applicable data protection law
- The EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act
- Supervisory authority
- Office of the Data Protection Ombudsman (tietosuoja.fi)
In brief: Koll Group Oy processes personal data as an independent controller when it determines the purposes and means of processing. When Koll transmits its business customer's contacts, calls, SmartCards, messages, or CRM integration data on that customer's instructions, the business customer is generally the controller and Koll is the processor.
This privacy policy describes how Koll Group Oy ("Koll") processes personal data as an independent controller in the Koll app, Koll's business portals and websites, and in its customer, sales, support and security activities.
1. Scope of this policy
This policy applies in particular to:
- users, administrators and contact persons of business customers;
- recipients of a call, SmartCard, RCS, SMS or other message transmitted via Koll, to the extent Koll processes data for its own purposes;
- users of the websites, business portals and support services;
- sales, partner, supplier and event contact persons; and
- persons who contact Koll or report misuse.
User accounts in the Koll service are intended for users authorised by organisations. The Service is not intended as a general consumer account service or a service directed at children.
When Koll processes recipient, contact, message or integration data defined by a business customer solely on that customer's behalf, the processing is subject to the customer's own privacy information and the Data Processing Agreement (DPA) between the customer and Koll.
2. Data controller and contact details
Data controller: Koll Group Oy, Business ID 3410913-5, Joensuunkatu 7, 24100 Salo, Finland.
Email for data protection matters: hannu.nissinen@koll.to. Company website: www.koll.to.
Questions about data protection and requests to exercise data subject rights can be sent to the email address above. Koll may ask for reasonable additional information to verify the requester's identity and the subject of the request.
3. Koll's roles in the processing of personal data
| Role | Situation |
|---|---|
| Controller | Koll determines the purpose and essential means of processing, for example regarding its own user accounts, contract and billing data, security logs, abuse prevention, support, website, and its own marketing. |
| Processor | Koll processes, according to a business customer's instructions, the customer's CRM contacts, recipients, reasons for calling, SmartCard and message content, replies, call outcomes, and other data necessary to provide the Service. |
| Third-party channels | A telecom operator, SMS or RCS provider, WhatsApp, or other channel may, depending on the situation, act as a processor for Koll or the customer, or as an independent controller for its own statutory and service-specific obligations. |
The same technical event may involve processing in different roles. For example, the content of a SmartCard may be transmitted on the customer's behalf, while Koll may process limited delivery, security and abuse-related data as an independent controller.
4. Data processed and sources of data
Business user and administrator data: name, job role, organisation, work email, work phone number, username, access rights, language, profile and brand information, authentication and verification data, and settings chosen by the user.
Contract, customer relationship and billing data: company name, Business ID or other company identifier, contact persons, order and contract data, service package, billing and payment data, payment receipts, and communications related to the customer relationship.
Call, SmartCard, message and usage data: the caller's and recipient's phone numbers and names where available, company identity, reason for calling, SmartCard content and image, message and chat content, the recipient's reactions and replies, timestamps, delivery and read status, call direction, duration, answer status, call outcome, reminders, and other service data entered by the user. This data is processed only to the extent the relevant feature is in use.
Contact and integration data: contacts from the user's device, based on operating-system-level permission granted by the user, and contacts, identifiers, roles, phone numbers, reasons for calling and call outcomes transmitted from the customer's CRM, CCaaS, authentication or other integrated system. Koll does not require an entire address book or CRM dataset if a feature can be implemented with a narrower set of data.
Technical, security and diagnostic data: IP address, device and browser type, operating system, application version, session and device identifiers, login and access events, error and performance data, delivery logs, abuse reports, blocks, failed logins, and other logs necessary for the security and functioning of the Service.
Support, sales and marketing data: contact requests, support tickets and their attachments, feedback, demo and meeting data, event participation, marketing preferences, and other information voluntarily provided to Koll.
Data is obtained:
- from the data subject themselves;
- from the business customer, its administrator, or employer;
- from the user's device and its operating system, in accordance with permissions granted by the user;
- from the customer's chosen CRM or other integration;
- from the other party to a call or message and the communications channel used;
- from an app store, payment provider, or other service provider, to the extent required by the service; and
- from public business and professional information sources for B2B communications.
5. Purposes and legal bases of processing
| Purpose | Legal basis | Key data |
|---|---|---|
| Managing user accounts and organisations | Legitimate interest; contract, if the user is a party to the agreement | Profile, organisation, role, authentication and access data |
| Providing the Service and customer support | Contract and legitimate interest | Usage, contact, support, contract and technical data |
| Customer-directed communications | The customer determines the legal basis; Koll acts as processor | Contacts, phone numbers, reasons for calling, SmartCards, messages, replies and outcomes |
| Security, fraud and abuse prevention | Legitimate interest; statutory obligation where applicable | Authentication, log, device, delivery, blocking and reporting data |
| Billing, accounting and contract management | Statutory obligation and legitimate interest | Company, contact person, order, invoice and payment data |
| Service development and quality monitoring | Legitimate interest; consent where device-level tracking requires it | Aggregated, diagnostic, error and usage data |
| B2B sales and marketing | Legitimate interest and, where applicable, consent | Professional contact details, interests, and marketing preferences |
| Legal claims and regulatory obligations | Legitimate interest and statutory obligation | Contract, event, security and communications data necessary case by case |
Koll's legitimate interests include providing a secure and reliable communications service, managing business customer relationships, improving the quality and usability of the Service, combating fraud and misuse, ensuring information security, protecting its business, and relevant B2B communications. Koll assesses the necessity of processing and its impact on data subjects' rights when relying on legitimate interest.
6. Mandatory nature of data and access permissions
Data needed to set up an organisation and user account, authentication, service security and billing is mandatory. Without it, a user account or the agreed service may not be able to be provided.
Use of a profile picture, additional brand information, device contact data, optional integrations, and non-essential analytics is voluntary unless the customer organisation has chosen to make the feature part of its own workflow. Device permissions can be managed in the device's settings. Removing a permission may prevent the related feature from functioning.
7. Recipients of data and service providers
Koll may disclose or grant access to data, only to the extent necessary, to the following parties:
- Koll's authorised personnel and group companies to the extent required by their duties;
- providers of cloud, database, storage, authentication, email, support, billing, accounting, analytics and security services;
- telecom operators and SMS, RCS, WhatsApp and other communications channels, in order to transmit information related to a message or call;
- CRM, CCaaS, identity and other integration services deployed by the customer;
- professional advisers, auditors and insurers, subject to confidentiality obligations;
- public authorities, courts and other parties, where required by law or a binding order; and
- parties to a corporate transaction, with necessary safeguards.
Koll does not sell personal data. An up-to-date list of material processors of personal data, processing locations and transfer mechanisms is available from Koll on request. Integrations and communications channels deployed by the customer itself may also process data in accordance with their own terms and privacy policies.
8. Transfers outside the EEA
Koll aims to use processing and storage solutions located within the European Economic Area. However, data may be transferred or made remotely accessible outside the EEA if required by a service provider, communications channel, the customer's integration, or an international support function.
A transfer is based, depending on the situation, on a European Commission adequacy decision, a valid certification under the EU–US Data Privacy Framework, standard contractual clauses approved by the European Commission, or another basis permitted by applicable data protection law. Koll assesses the circumstances of the transfer where necessary and applies supplementary technical or organisational safeguards.
Further information on the applicable transfer mechanism and available safeguards can be requested from Koll's data protection contact.
9. Data retention
| Data category | Retention principle |
|---|---|
| User account and access rights | For the duration of the active customer relationship and user account. Data is normally deleted or anonymised within 90 days of the account or agreement ending, unless longer retention is necessary. |
| Contract and customer relationship data | For the duration of the customer relationship and thereafter for the time necessary to handle legal claims, complaints and contractual liabilities, normally up to three years, unless a longer statutory period applies. |
| Invoicing and accounting records | For the period required by accounting legislation, generally at least six years from the end of the relevant financial year. |
| Support and customer communications | Normally up to 24 months after the matter is closed, unless the communication relates to a contract, complaint, security incident, or legal claim. |
| Security and technical logs | Normally up to 12 months. Data relating to a security or abuse incident may be retained for the time necessary to investigate the matter and handle legal claims. |
| Marketing data | Until the data subject objects to processing or withdraws consent. Opt-out or suppression list data may be retained to ensure the opt-out is honoured. |
| Content processed on the customer's behalf | In accordance with the customer's instructions, service settings and the DPA. After termination of the agreement, data is deleted from active systems normally within 90 days at the latest; backups are removed in the normal rotation cycle. |
If data is needed to comply with a statutory obligation, investigate a security incident, or establish, exercise or defend a legal claim, it may be retained for a period limited to that purpose. Once the retention period ends, the data is deleted or anonymised.
10. Information security and personal data breaches
Koll implements technical and organisational safeguards appropriate to the risk of processing. Measures may include, among others, role-based access management, strong authentication for relevant administrative functions, encryption of data in transit, logging, backups, vulnerability and incident management, staff instructions, and risk-based assessment of service providers.
If a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, Koll will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. In a high-risk situation, Koll will also notify data subjects as required by law. When acting as a processor, Koll will notify the customer of a personal data breach without undue delay.
11. Data subject rights
Subject to applicable data protection law and the conditions set out therein, a data subject may have the right to:
- obtain confirmation as to whether their personal data is being processed, and to access that data;
- request rectification of inaccurate or incomplete data;
- request erasure of data or restriction of processing;
- object to processing based on legitimate interest on grounds relating to their particular situation;
- object to the processing of personal data for direct marketing at any time;
- receive certain data they have provided themselves in a structured, commonly used and machine-readable format, where processing is based on consent or a contract and is automated;
- withdraw consent as easily as it was given, without affecting the lawfulness of processing carried out before withdrawal; and
- lodge a complaint with the competent data protection authority.
These rights are not absolute. Koll may, for example, retain data where processing is required by law or where the data is necessary to establish, exercise or defend a legal claim.
If a request concerns data Koll processes on behalf of a business customer, Koll may forward the request to that business customer or direct the data subject to it. The customer acting as controller is responsible for handling the request.
12. Automated decision-making and profiling
Koll does not make decisions concerning a data subject based solely on automated processing that would have legal effects or similarly significant effects on them. The Service may use automated rules to detect fraud, security or abuse risk. Material restrictive measures may be referred for human review where appropriate in the circumstances.
13. Minors
User accounts in the Koll service are intended for users authorised by organisations, and the Service is not directed at children. If Koll becomes aware that an account has been created for a child without appropriate authorisation, or that a child's data has been processed unnecessarily, Koll will take reasonable steps to restrict the account and delete the data, unless there is a statutory basis for retention.
15. Changes and supervisory authority
Koll may update this policy if the service, the processing of personal data, or legislation changes. The up-to-date version is published on Koll's website. Material changes will be notified in an appropriate manner, for example within the Service or by email.
A data subject has the right to lodge a complaint, in particular in the EU or EEA country of their habitual residence or place of work, or where the alleged infringement took place.
Finnish supervisory authority: Office of the Data Protection Ombudsman, P.O. Box 800, FI-00531 Helsinki, Finland. Switchboard +358 29 566 6700, www.tietosuoja.fi.
This version is dated 28 July 2026.