Part II – You received a call or message via Koll

Privacy Information for Recipients

Data controller

Koll Group Oy

Joensuunkatu 7

24100 Salo

Finland

Business ID
3410913-5
Data protection matters
hannu.nissinen@koll.to
Version
2.0
Effective from
28 July 2026
Applicable data protection law
The EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act
Supervisory authority
Office of the Data Protection Ombudsman (tietosuoja.fi)

Summary: the company that contacted you is generally responsible for the purpose and content of that contact. Koll transmits the company's name, the caller's details, the reason for calling, and the SmartCard or message, and in doing so generally acts as the company's processor of personal data.

This page is intended for you if you have received a call, SmartCard, RCS, SMS or other message via Koll.

1. Why you received a Koll message or call

A company or its representative uses the Koll service to tell you, before contacting you, who is contacting you and why. The information may be displayed in the Koll app or transmitted, for example, via an SMS, RCS or WhatsApp channel as a SmartCard or other message.

2. Who is responsible for your personal data

The company that made contact is normally the controller, as it determines the purpose, recipient, content and legal basis of the contact. The company's name appears in the call, SmartCard or message. You can find more information about its processing in that company's own privacy policy.

Koll Group Oy normally acts as that company's processor of personal data when it transmits information according to the company's instructions. Koll acts to a limited extent as controller for its own security, abuse-prevention, logging and statutory obligations.

3. What data is processed

The following may be processed in connection with the contact:

  • your name and phone number, if known to the caller or its organisation;
  • the caller's name, company, phone number and company profile;
  • the reason for calling, the SmartCard's content, image, and other information transmitted by the company;
  • your messages, replies and reactions, if you use a reply or chat feature;
  • timestamps, delivery, read and answer status, call direction, duration and outcome; and
  • limited technical and security data, such as an IP address, device or browser information, and abuse reports.

Data is obtained from the company that made contact, from the caller, from its CRM or contact system, from you yourself, and from the communications channel used.

4. What the data is used for

The company uses the data for its stated purpose of contact and is responsible for the lawfulness of that processing. Koll uses and transmits data according to the company's instructions to deliver the call, SmartCard or message, transmit replies, verify delivery, implement the integration, and provide technical support for the Service.

As an independent controller, Koll may process limited event and security data to protect the Service, prevent fraud and harassment, investigate misuse, and handle legal claims. This processing is based on Koll's legitimate interest and, where necessary, a statutory obligation.

5. Communications channels and data transfers

Data may be transmitted to a telecom operator and an SMS, RCS, WhatsApp or other chosen communications channel. The channel's provider may process data in accordance with its own terms and privacy policy. Not all channels offer the same level of encryption, confidentiality or delivery assurance.

If processing or remote access takes place outside the EEA, an applicable transfer mechanism is used, such as an adequacy decision, DPF certification, or standard contractual clauses.

6. Retention period

The company that made contact determines the retention period for contact, call and message data processed on its behalf. Koll deletes data in accordance with the customer's instructions and the DPA. After termination of the agreement, data is normally deleted from active systems within 90 days, unless law, a security incident, or a legal claim requires a limited longer retention period.

Koll's own security and abuse logs are normally retained for up to 12 months, unless investigating a specific matter requires longer retention.

7. Your rights and contact information

If you want to know why you were contacted, object to the contact, or exercise your rights relating to the content of the contact and the choice of recipient, please contact primarily the company named in the message or SmartCard. It acts as the controller for that processing.

You can report misuse of the Koll service, or ask about Koll's own processing, at hannu.nissinen@koll.to. Where necessary, Koll will forward a request concerning data processed on a customer's behalf to the company acting as controller.

Koll Group Oy, Joensuunkatu 7, 24100 Salo, Finland. Supervisory authority in Finland: Office of the Data Protection Ombudsman, www.tietosuoja.fi.