Sisällys
- 1. This notice in brief
- 2. Controller and contact details
- 3. Whose personal data we process
- 4. Which channel you are in and who is responsible for what
- 5. What data we process and where it comes from
- 6. Purposes of processing and legal bases
- 7. Processing of the personal identity code
- 8. Processing of credit information
- 9. Customer due diligence, PEP status and sanctions
- 10. Special categories of personal data and criminal offence data
- 11. Is providing data mandatory
- 12. To whom we disclose data
- 13. Transfers outside the EU and the EEA
- 14. Automated decision-making and profiling
- 15. Use of artificial intelligence in the service
- 16. How long we retain data
- 17. Information security
- 18. Your rights
- 19. Cookies and web tracking
- 20. Marketing and advertising
- 21. Changes to this notice
- 22. Contact
1. This notice in brief
This notice explains what personal data Rahoo Oy ("Rahoo", "we") processes, for what purposes and on what legal basis, to whom we disclose data and what rights you have. It is an information document under Articles 13 and 14 GDPR.
1.1 What Rahoo’s service does
Rahoo’s financing application service is available on websites, in software, on platforms and marketplaces and in other services offered by Rahoo’s partners. The purpose of the service is to speed up applying for business financing: you complete one application and we forward it to our financing partners — banks and finance companies — which may make you an offer of financing. The financing products and financing partners available vary depending on the partner service through which you apply.
1.2 What Rahoo is not
This delimitation is essential for understanding who is responsible for what:
- Rahoo is not a credit institution or a financial institution and does not grant credit for its own account.
- Rahoo does not make the credit decision. The financing decision is always made by the financing partner on its own criteria.
- Rahoo is not a party to the financing agreement. If you accept an offer, the agreement is concluded between you and/or the company you represent and the financing partner.
- Rahoo gives no guarantees as to offers of financing and makes no commitments on behalf of its financing partners.
1.3 Using the service is not consent
Using the service is not in itself consent to the processing of personal data within the meaning of the GDPR. We process personal data on the legal bases described in section 6 below. Where processing is based on consent — in practice marketing communications and non-essential cookies — we ask for consent separately, and you may withdraw it at any time.
1.4 Where this notice applies
This notice is available on Rahoo’s website and in all of Rahoo’s financing application processes, regardless of the channel through which you apply. It describes Rahoo’s own processing in every channel.
This notice does not replace the notices of other parties. The partner in whose service you are dealing and the financing partner that processes your application each have their own privacy notice covering their own processing.
The channel affects who collects your data and when you receive this notice. The channels are described in section 4.
2. Controller and contact details
Enquiries concerning data protection and requests to exercise data subject rights: asiakaspalvelu@rahoo.fi.
3. Whose personal data we process
We process data relating to the following groups of people:
- The person making the financing application — usually a representative of the company or a private trader.
- The officers of the company applying for financing — members of the board, the managing director and other persons entitled to sign for the company.
- The beneficial owners of the company — where the financing partner must establish them in order to meet its customer due diligence obligations.
- Guarantors and providers of collateral — where the financing requires a personal guarantee or a third-party pledge.
- Contact persons of partners and financing partners.
- Users of Rahoo’s system employed by a financing partner. Employees of a financing partner who log in to Rahoo’s financing partner view to handle applications forwarded to them. We process their user ID, name, work email address, role and usage log.
- Users of our website and service — as regards cookies and log data. This also covers partner services in which Rahoo’s application form is embedded (see section 4.3).
4. Which channel you are in and who is responsible for what
4.1 Four ways to apply for financing
There are four ways to apply for financing. The way you deal with us affects who collects your data and when you receive this notice. In every channel, Rahoo is the controller from the moment the data is with Rahoo.
| Channel | Who collects the data | What this means for you | |
|---|---|---|---|
| A | You complete the financing application on the partner’s own form, and the partner sends the application to Rahoo through an interface | The partner. Rahoo has no form and no cookies of its own in the partner’s service | The partner’s own privacy notice covers the collection. Rahoo is the controller from the moment it receives the application, and informs you by means of this notice. See section 4.4 |
| B | You complete Rahoo’s application form embedded in the partner’s service | Rahoo, on the partner’s site | Rahoo and the partner are joint controllers as regards the collection and transfer. See section 4.3 |
| C | You complete the application on Rahoo’s own website, to which the partner has directed you | Rahoo, on its own site | Rahoo is the sole controller. The partner is told the status of your application so that it can manage its customer relationship with you |
| D | You complete the application on Rahoo’s own website, having arrived there through Rahoo’s own channels | Rahoo, on its own site | Rahoo is the sole controller. No partner is involved |
4.2 Three parties and their responsibilities
An application for financing typically involves three parties. Each of them is a controller in its own right for its own processing:
| Party | Role | Responsible for |
|---|---|---|
| The partner in whose service the application begins | Independent controller in its own service | Your customer relationship with the partner and the partner’s own service. In channel A, also the collection of the application. The partner has its own privacy notice. |
| Rahoo Oy | Controller for the processing described in this notice | Receiving the application, supplementing the data, pre-screening, forwarding the application to financing partners and tracking the status of the application. |
| Financing partner (bank or finance company) | Independent controller from the moment the application is transferred to it | Assessing creditworthiness, the credit decision, customer due diligence and the financing agreement. The financing partner has its own privacy notice. |
When we forward your application to a financing partner, this is a disclosure to an independent controller — not processing on our behalf. From that moment on, the financing partner is itself responsible for processing your data and informs you by means of its own notice.
4.3 Joint controllership in a partner’s service (channel B)
Where Rahoo’s application process is embedded in a partner’s service, Rahoo’s code runs on the partner’s domain and stores on your device an identifier that is essential for the application to work, so that data about you is transferred to Rahoo before you submit the application. At this stage of collection and transfer, Rahoo and the partner are joint controllers within the meaning of Article 26 GDPR. Joint responsibility covers this stage only; after it, each party is independently responsible for its own processing.
In an embedded process, Rahoo’s component sets only essential cookies, which do not require consent, unless consent for others is obtained from the partner’s consent management. The list of cookies is in section 19.
The arrangement is identical in substance with every partner. Its essence is as follows:
| Obligation | Who is responsible |
|---|---|
| Obtaining consent for non-essential cookies | The partner, in its own service. Consent is obtained by the party in whose service the storage takes place |
| Rahoo’s essential cookies, and ensuring that no others are set without consent | Rahoo |
| The partner’s own cookies and their management | The partner alone |
| Informing about the collection of data in the partner’s service | The partner, and Rahoo by means of this notice |
| All processing once the data is with Rahoo | Rahoo alone |
| The partner’s own service, analytics and marketing | The partner alone |
| Responding to data subject requests | Rahoo is the primary point of contact for requests concerning application data and coordinates the response. You may nonetheless address your request to either party; the parties forward requests to each other within five business days |
| Point of contact for you | For Rahoo, asiakaspalvelu@rahoo.fi. The partner’s point of contact is set out in the partner’s own privacy notice and on our joint controllers page |
You may exercise your rights against either party irrespective of this arrangement (Article 26(3) GDPR).
The partner to which the arrangement applies in your case is the partner in whose service you complete the application. An up-to-date list of the partners with which the arrangement is in force is available at www.rahoo.fi/yhteisrekisterinpitaja.
No joint controllership arises in channels A, C and D: in channel A Rahoo has no code of its own in the partner’s service, and in channels C and D you deal with Rahoo on its own site.
4.4 When an application reaches us from a partner’s system (channel A)
In channel A we have not collected your data from you but have received it from the partner. Article 14 GDPR applies to this situation.
You receive this notice while completing the application. The partner presents it, or a link to it, on its own application form before you submit the application, and you accept it at the same time. Where you already have the information, we do not send it to you again (Article 14(5)(a) GDPR).
In all other respects this channel works in the same way as the others:
- We tell you where the data came from. The source is the partner in whose service you completed the application (Article 14(2)(f) GDPR).
- Your rights are the same as if you had completed the application directly with us. See section 18.
- If for any reason you have not received this notice with the application, you will receive it from us within one month at the latest of our having obtained your data — or, if we contact you before that, at the latest at the time of the first contact (Article 14(3) GDPR).
The partner is responsible for having a legal basis for disclosing the application to Rahoo and for having told you about the disclosure beforehand.
5. What data we process and where it comes from
We collect personal data only to the extent necessary to provide and develop the service (data minimisation, Article 5(1)(c) GDPR).
5.1 From you
| Category of data | Examples |
|---|---|
| Financing need | Amount applied for, loan period, purpose of the financing |
| Identifying data of the applicant | Name, personal identity code, contact details, position in the company |
| Financial data of the applicant | Income, expenses, assets, liabilities — where the financing partner requires personal liability or a guarantee |
| Company data | Name, business ID, industry, contact details |
| Financial data of the company | Financial statements, accounting extracts, key figures, trade receivables |
| Background data | Occupation and education to the extent required by the financing partner |
| Consents | Marketing permission, cookie consent |
5.2 From the partner
- The complete financing application, where you have completed it on the partner’s own form (channel A). In that case the source of the data is that partner, and we tell you so in accordance with section 4.4.
- The object of the financing, for example the product or invoice being financed.
- Data based on customer history, for example purchase or invoicing history.
- Detailed financial data of the company, for example financial statements and accounting extracts.
5.3 From registers maintained by public authorities
The sources are the Finnish Patent and Registration Office and the Business Information System (YTJ), the Finnish Tax Administration and the transport register of the Finnish Transport and Communications Agency Traficom.
We retrieve this data through the service of Datatriever Oy (business ID 3274195-4), which compiles it from public authority registers. Datatriever acts as a technical intermediary; the original sources are the registers named above.
- Official company data: name, business ID, officers, industry and financial statement data, and information on ownership structure and beneficial owners in so far as it is available from the register.
- Registrations and tax debt data: the prepayment register, the register of parties liable for VAT, the employer register and the tax debt register.
- Vehicle and equipment data, where the financing concerns a vehicle or other registrable equipment.
The applicant’s verified personal data is obtained from strong electronic identification.
5.4 From credit reference agencies and identification services
- From strong electronic identification: verified personal data such as name and personal identity code.
- From credit reference agencies — Dun & Bradstreet and Suomen Asiakastieto — payment default entries, payment behaviour data and creditworthiness assessments concerning the company applying for financing. The processing of this data is described in more detail in section 8.
- From sanctions and PEP list services: information on whether a person appears on international sanctions lists or is a politically exposed person. See section 9.
5.5 From financing partners
- The stage and outcome of the processing of the application.
- The financing offer made to the applicant and its terms, such as amount, loan period, interest rate, fees and validity period. Rahoo passes the offer on to the applicant.
- The terms of any financing granted, such as amount, loan period and interest rate.
- Whether a financing agreement has arisen as a result of the application, including where the financing is arranged using a financing product other than the one the application concerned. This covers only the financing need arising from the application.
5.6 From cookies and log data
- Device, operating system and browser.
- IP address and approximate location.
- Online behaviour in our service and on the application form on partners’ sites: pages, clicks, form completion stages.
Identifier used to continue an application (`vc`). When you start an application, a cookie containing a randomly generated identifier is stored in your browser. Its only function is to recognise your application in progress if you leave the page and come back. The identifier does not in itself contain your name or contact details, but it can be used to link them to you, and we therefore process it as personal data.
The identifier is not used for advertising, visitor tracking or linking visits on different days. It is valid for 4 hours. Because the storage is essential in order to provide the service you have requested, it does not require consent (section 205(2) of the Act on Electronic Communications Services). The basis for the processing is the taking of steps prior to entering into a contract (Article 6(1)(b) GDPR).
Cookies and consent are described in more detail in section 19.
6. Purposes of processing and legal bases
Every processing operation has a legal basis under Article 6 GDPR. The bases are not alternatives to one another: the same data may be processed on a different basis for a different purpose.
| Purpose | What we do | Legal basis |
|---|---|---|
| Processing and forwarding the financing application | Receiving the application, supplementing the data from public sources, pre-screening and forwarding the application to financing partners | Contract or steps taken prior to entering into a contract (Article 6(1)(b)). Where the applicant is not itself a party to the contract but represents a company: legitimate interests (Article 6(1)(f)) |
| Verifying the applicant and the right of representation | Strong electronic identification, checking the right to sign for the company in the Trade Register | Contract (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)): the right to be certain with whom we are dealing |
| Preliminary assessment of creditworthiness | Obtaining and using credit information concerning the company applying for financing in order to direct the application. Rahoo does not obtain personal credit information concerning the applicant as a private individual | Steps taken prior to entering into a contract (Article 6(1)(b)). In addition, the conditions in section 19 of the Credit Information Act, see section 8 |
| Preventing misuse and fraud | Cross-checking applications, detecting anomalies | Legitimate interests (Article 6(1)(f)): protecting Rahoo, its financing partners and its customers against fraudulent activity |
| Collecting customer due diligence data for the financing partner | Establishing beneficial owners, PEP status and sanctions list matches | Steps taken prior to entering into a contract (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)). See section 9 |
| Calculating and invoicing the intermediary fee | Matching drawdown and status information received from the financing partner to the application, and calculating and invoicing the fee from the financing partner | Legitimate interests (Article 6(1)(f)): Rahoo’s right to receive its intermediary fee and to substantiate the basis for it. As regards the retention of invoicing material, a legal obligation (Article 6(1)(c)), the Finnish Accounting Act (1336/1997). The financing partner discloses drawdown and status information only with the applicant’s consent, see section 5.5 |
| Customer service and communication | Answering questions, informing you of the status of the application | Contract (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)) |
| Developing the service and analytics | Analysing use, investigating errors, statistics compiled primarily from aggregated or anonymised data | Legitimate interests (Article 6(1)(f)): ensuring and developing the functioning and security of the service |
| Handling legal claims | Complaints, disputes, questions of liability | Legitimate interests (Article 6(1)(f)): the establishment, exercise or defence of legal claims |
| Accounting and statutory reporting | Retaining vouchers and accounting material | Legal obligation (Article 6(1)(c)), the Finnish Accounting Act (1336/1997) |
| Direct marketing and marketing communications | Newsletters, offers and benefits, and targeted advertising on third-party platforms | Consent (Article 6(1)(a)). See section 20 |
| Cookies and web tracking | Non-essential cookies: analytics and marketing | Consent (section 205 of the Act on Electronic Communications Services (917/2014)) and consent (Article 6(1)(a)). Essential cookies: legitimate interests (Article 6(1)(f)) |
Processing based on legitimate interests. Where processing is based on legitimate interests, we have carried out a balancing test assessing the relationship between our interests and your rights. You may request the outcome of the balancing test from asiakaspalvelu@rahoo.fi. You always have the right to object to processing based on legitimate interests (see section 18).
7. Processing of the personal identity code
We process the personal identity code because unambiguous identification of the applicant is necessary when applying for financing and for the financing partner’s credit decision. Under section 29(2) of the Finnish Data Protection Act (1050/2018), the personal identity code may be processed for the unambiguous identification of the data subject in, among other things, the granting of credit and the collection of debts, and in credit institution and credit reference activities.
We also observe the restrictions in the same section:
- We do not enter the personal identity code unnecessarily in documents (section 29(4)).
- We do not use the personal identity code alone, or the combination of the personal identity code and a name, to verify identity (section 29(5), in force since 1 January 2024). Identification is carried out by means of strong electronic identification.
8. Processing of credit information
In addition to the GDPR, the processing of credit information is governed by the Finnish Credit Information Act (527/2007). Rahoo may obtain credit information concerning the company applying for financing, but does not do so for every application. The credit reference agencies we use are Dun & Bradstreet and Suomen Asiakastieto.
8.1 What credit information we process
We process credit information concerning the company applying for financing, such as payment default entries, payment behaviour data and creditworthiness assessments. This data is necessary in order for us to direct the application to those financing partners whose basic requirements it may meet.
Rahoo does not obtain personal credit information. We do not make a credit information enquiry about you as a private individual or as a guarantor. If a financing partner needs personal credit information for its credit decision, it obtains that information itself and is responsible for it as a controller in its own right.
8.2 Prior information and a negative decision
The obligations under section 19(5) and (6) of the Credit Information Act — to provide information before personal credit information is obtained and to give notice in connection with a negative decision — are directed at the party that obtains the information. Since Rahoo does not obtain personal credit information, these obligations rest with the financing partner.
If an assessment of your creditworthiness has been made solely by automated means, you have the right under section 16 of the Credit Information Act to require the assessment to be carried out again. Address the request to the financing partner that made the assessment. Rahoo’s own pre-screening is described in section 14.
9. Customer due diligence, PEP status and sanctions
Granting financing requires the financing partner to meet its obligations under the Finnish Act on Preventing Money Laundering and Terrorist Financing (444/2017). The financing partner is responsible for customer due diligence as regards its own obligations. In so far as data the financing partner needs for that purpose is collected or forwarded in the application process, it may consist of the following:
- The company’s beneficial owners and ownership structure.
- Whether the applicant or a beneficial owner is a politically exposed person (PEP) or a family member or close associate of such a person. PEP status is defined in Chapter 1, section 4(11)–(13) of the Act on Preventing Money Laundering, and the related enhanced due diligence obligation is laid down in Chapter 3, section 13.
- Sanctions list matches and information on the origin of funds.
Legal basis. Rahoo is not an obliged entity within the meaning of Chapter 1, section 2 of the Act on Preventing Money Laundering: Rahoo does not grant credit, is not a party to the financing agreement and does not handle client funds. As regards Rahoo, the processing under this section is therefore based on steps taken prior to entering into a contract (Article 6(1)(b)) and on legitimate interests (Article 6(1)(f)): a financing application cannot be forwarded to a financing partner without the data the financing partner is required by law to have. As regards the financing partner, the basis for processing is a legal obligation (Article 6(1)(c)).
10. Special categories of personal data and criminal offence data
We do not collect or request special categories of personal data within the meaning of Article 9 GDPR — such as health data, political opinions, religious beliefs, trade union membership or biometric identifiers.
If you provide such data on your own initiative in the attachments to an application, we delete it as soon as reasonably practicable and do not forward it to financing partners.
We process data relating to criminal convictions and offences (Article 10 GDPR) only where there is a basis for doing so under section 7 of the Data Protection Act. Information on a business prohibition is not criminal offence data but company data obtained from a public register.
11. Is providing data mandatory
Providing data is not a statutory obligation, but it is a condition for using the service. The data marked as mandatory on the application form is necessary in order for the application to be processed and forwarded to a financing partner. If you do not provide that data, we cannot process your application.
Marketing consent and acceptance of non-essential cookies are voluntary. Not giving them has no effect on applying for financing.
12. To whom we disclose data
| Recipient | What we disclose | Why |
|---|---|---|
| Financing partners — banks and finance companies:Aktia, BusinessCredit, CapitalBox, Corona Capital, Fundu, Qred, Saldo Bank, Säästöpankki Helsinki, Svea Bank and Vauraus.Up-to-date list: www.rahoo.fi/kumppanipankit | The content of the financing application and the data needed to process it | So that the financing partner can assess the application and make an offer. The financing partner may use the data for processing the application and for the customer relationship that follows from it, as well as for meeting its own statutory obligations, such as customer due diligence and record retention, and for responding to legal claims. In these respects the financing partner is an independent controller and cannot waive obligations laid down by law. Which financing partners an application is forwarded to is determined by the service you use and by the pre-screening. |
| The partner in whose service you completed the application | The status of the application and the amount applied for and any amount granted, the loan period, the financing product and the pricing of the financing | So that the partner can manage its customer relationship with you |
| Service providers and subcontractors:Amazon Web Services (server environment, Stockholm)Google Workspace (email and files)Zapier (integrations built by partners and users themselves to third-party systems)Twilio SendGrid (sending email)Telavox (telephone and communications service)Datatriever Oy, Finland (retrieval of company data from public authority registers)Sentry (error monitoring on Rahoo’s own domains) | Only what providing the service requires | Software, cloud and storage services. A data processing agreement under Article 28 GDPR has been concluded with each of them |
| Providers of strong electronic identification: Telia Finland Oyj | The data needed for identification | Verifying identity and the accuracy of the data provided, and preventing misuse |
| Credit reference agencies: Dun & Bradstreet and Suomen Asiakastieto | Identifying data for the purpose of making the enquiry | Assessing solvency and creditworthiness within the limits permitted by the Credit Information Act (see section 8) |
| Public authorities and courts | Only what the law or a decision of an authority requires | Meeting statutory obligations and responding to legal claims |
| Advertising platforms and advertising services:Meta, Google Ads, LinkedIn and other comparable advertising and measurement platforms | Only on the basis of your consent: audience identifiers and event data | Targeted marketing and measuring the effectiveness of advertising. See sections 19 and 20. |
We do not sell personal data.
13. Transfers outside the EU and the EEA
Our servers and the primary storage of data are within the EU (Amazon Web Services, Stockholm). Some of the services we use are, however, United States services, in which case personal data may be transferred outside the EU and the EEA.
| Recipient | What is transferred | Country | Basis for transfer |
|---|---|---|---|
| Google LLC (Google Workspace) | Email and files that may contain application data | United States | EU–US Data Privacy Framework adequacy decision (EU) 2023/1795 |
| Zapier, Inc. | Application and contact data transferred in integrations built by partners and users themselves | United States | EU–US Data Privacy Framework adequacy decision (EU) 2023/1795 |
| Twilio SendGrid | Email recipient data and message content | United States | Standard contractual clauses (Article 46(2)(c) GDPR) and a transfer impact assessment |
| Functional Software, Inc. (Sentry) | Technical data on error situations on Rahoo’s own domains: the error message, browser and device data and the IP address. No transfer in respect of an application completed on a partner’s domain | United States | EU–US Data Privacy Framework adequacy decision (EU) 2023/1795. In addition, standard contractual clauses (Article 46(2)(c) GDPR) are incorporated into the data processing agreement as a fallback mechanism |
| Telavox AB | Contact details in the telephone and communications service | Sweden | No transfer outside the EEA in the basic service. In additional services a transfer is possible under standard contractual clauses |
| Amazon Web Services | No regular transfer: the server environment is in Stockholm | EU | No transfer. Access by support staff from outside the EU is restricted in the data processing agreement |
We use the following safeguards for transfers:
- An adequacy decision (Article 45 GDPR), where the recipient is certified under the EU–US Data Privacy Framework.
- Standard contractual clauses (Article 46(2)(c) GDPR), where an adequacy decision cannot be applied.
- A transfer impact assessment and supplementary safeguards, such as encryption in transit and at rest and access control.
- Data minimisation: we do not transfer personal identity codes or credit information by email or in integrations where this can be avoided.
You may request a copy of the safeguards used from asiakaspalvelu@rahoo.fi.
14. Automated decision-making and profiling
14.1 What automated decision-making means
Automated decision-making means a decision based solely on automated processing of personal data, without human assessment, which produces legal effects concerning you or similarly significantly affects you.
14.2 How we use it and on what basis an application is directed
When you apply for financing, your application is automatically compared against the basic requirements set by our financing partners. If an application does not meet a financing partner’s basic requirements, it is not forwarded to that financing partner. This screening is not a credit decision but a matching exercise: the application is forwarded to those financing partners from which an offer is possible at all.
The following data is taken into account in the comparison:
| Category of data | Examples of what is looked at |
|---|---|
| Age and operating history of the company | Date of registration, number of completed financial periods |
| Size of the company | Turnover, balance sheet, number of employees |
| Payment behaviour | Payment default entries, payment delays, tax debt |
| Industry | Industry classification and any industry restrictions applied by the financing partner |
| Financing applied for | Amount, loan period and financing product in relation to the financing partner’s product range |
| Purpose of the financing | For example working capital, equipment purchase or invoice financing |
| Collateral | The collateral offered and its nature, and any personal guarantee |
| Financing product | The product applied for in relation to the products the financing partner offers |
We do not publish financing-partner-specific thresholds, because they are the financing partners’ trade secrets and they change. You may always ask us for a more detailed explanation of why your application did not proceed to a particular financing partner.
14.3 Legal basis
Under Article 22(2) GDPR, solely automated decision-making is permitted on three grounds only: it is necessary for entering into or performing a contract, it is authorised by Union or Member State law, or it is based on explicit consent.
Rahoo’s pre-screening is based on Article 22(2)(a) GDPR: it is necessary in order for a financing application to be processed and forwarded to a financing partner.
14.4 Your rights
Under Article 22(3) GDPR you have the right:
- to require that the decision be made by a natural person, that is, that your application be processed manually;
- to express your own point of view;
- to contest the decision and to obtain an explanation of how it was reached.
In addition, under section 16 of the Credit Information Act you have the right to require a new assessment if an assessment of your creditworthiness has been made solely by automated means.
Exercise your rights by sending a request to asiakaspalvelu@rahoo.fi. We will reply within one month of receiving the request at the latest. If the request is complex, we may extend the period by up to two further months and will inform you of this within one month (Article 12(3) GDPR).
14.5 Financing partners’ own decision-making
Financing partners make their own credit decisions independently and may use their own automated systems in doing so. Rahoo is not responsible for those systems. Ask the financing partner directly for more information on how automated decision-making has been applied to your application.
15. Use of artificial intelligence in the service
15.1 How we may use artificial intelligence
We may use artificial intelligence in the service to assist, for example, in reading attachments to applications, structuring financial data and in customer service. In using artificial intelligence we observe the following principles:
- We make it clear when you are dealing with artificial intelligence — for example in an AI-assisted chat service (Article 50 of the EU Artificial Intelligence Act (EU) 2024/1689, applicable from 2 August 2026).
- We update this notice before taking into use any new AI-assisted use that affects the processing of your personal data.
- If we use artificial intelligence in a way falling within the high-risk systems of the Artificial Intelligence Act — in practice the assessment of the creditworthiness of a natural person — we inform you expressly that you are subject to the use of a high-risk artificial intelligence system (Article 26(11)).
- On request you receive a clear and meaningful explanation of the role of the artificial intelligence system in the decision-making and of the main elements of the decision (Article 86).
- The use of artificial intelligence does not extend the amount of data collected and does not change the legal bases described in this notice. The rights set out in section 14.4 remain unchanged.
15.2 Financing partners’ use of artificial intelligence
Financing partners make their credit decisions independently and may use artificial intelligence in doing so. Rahoo has no information on whether an individual financing partner uses artificial intelligence or how it does so. If you wish to know, ask the financing partner directly. If a financing partner’s system is a high-risk system within the meaning of the Artificial Intelligence Act, the financing partner is obliged to tell you about its use and to give you an explanation of the decision.
16. How long we retain data
We retain personal data only for as long as is necessary for the purpose for which it was collected, or for as long as the law requires.
| Data | Maximum retention period | Basis |
|---|---|---|
| A page load or an interrupted session in which you answered no questions | IP address 30 days. After that the data is deleted or rendered non-identifiable | Information security and the prevention of misuse (legitimate interests). There is no basis for retaining the rest of the content without consent |
| An interrupted application in which you answered some of the questions | 6 months from the last action | Continuing the application and customer service. Data minimisation (Article 5(1)(e) GDPR) |
| An application that does not lead to financing | 12 months from the resolution of the application | Handling complaints, preventing misuse and renewing the application |
| Credit information and creditworthiness assessments | 12 months from obtaining the data. Deleted earlier once the application has been resolved and no financing arises | Purpose limitation (section 19 of the Credit Information Act) and data minimisation |
| Verification log for an application forwarded to a financing partner: application identifier, timestamps, channel, IP address at the time of sending, the result of identification, the company’s business ID, the version of the terms of use accepted and the timestamps and text versions of the consents given. In addition, the applicant’s name, email address and telephone number as hashes, from which the data cannot be read as such | 5 years from the forwarding of the application | Legitimate interests: responding to legal claims, demonstrating to the financing partner when and from where an application was received, and preventing and detecting misuse. The financing partner needs this information in order to meet its own statutory obligations. The hashes are used solely to identify whether the same party has applied for financing repeatedly. The version of the terms and the consent timestamps are retained in order to meet the accountability obligation (Article 5(2)) and to demonstrate what the applicant accepted |
| An application that led to financing and the related communications | 3 years from the end of Rahoo’s intermediary assignment. In special situations no more than 10 years | The Finnish Act on Limitations (728/2003), sections 4 and 7. Rahoo is not a party to the financing agreement, so the period runs from the end of Rahoo’s own assignment, not from the end of the financing agreement. See the clarification after this table |
| Accounting vouchers and correspondence concerning business transactions | 6 years from the end of the year in which the financial period ended | The Finnish Accounting Act (1336/1997), Chapter 2, section 10(2) |
| Financial statements and accounting records | 10 years from the end of the financial period | Accounting Act, Chapter 2, section 10(1) |
| Identifier used to continue an application (`vc`) on your device | 4 hours | Essential in order to provide the service you have requested (section 205(2) of the Act on Electronic Communications Services). Does not require consent. See section 19 |
| Marketing tracking identifiers and the data collected with them | 25 months | Consent |
| Marketing permissions and consent management | For the period of validity of the consent and 2 years from its withdrawal | Accountability (Article 5(2) GDPR) |
When Rahoo’s intermediary assignment ends. Rahoo intermediates financing and is not a party to the financing agreement. The retention period therefore runs from the end of Rahoo’s own assignment. The intermediary assignment is deemed to have ended when the last of the following has occurred:
- the financing partner’s decision or offer has been forwarded to you, or the application has otherwise been resolved;
- the related communication between you and Rahoo has ended.
In practice the retention period begins when the last of these events has been recorded in Rahoo’s system. This is an event known to Rahoo and capable of being verified.
Limits of the right to erasure. Where we have a statutory obligation to retain data, we cannot delete it at your request. Where there is no statutory obligation, we assess separately whether the data is needed for the establishment, exercise or defence of a legal claim.
An obligation to retain data is not a right to use it: even where we must retain data, we may not use it for any purpose other than the one for which the retention obligation exists.
Deletion means deletion. When the retention period ends, the data is either deleted or irreversibly rendered non-identifiable. Marking a record as deleted is not deletion.
Backups. When data is deleted from the live system, it may remain in backups until the backup is replaced — at most seven days from deletion. We do not use data held in a backup for any other purpose, and if a backup is ever restored, the deletions are carried out again.
17. Information security
We protect personal data by the technical and organisational measures required by Article 32 GDPR:
- encrypted data traffic and encryption of data at rest;
- a server environment within the EU (Amazon Web Services, Stockholm);
- role-based access control and the principle of least privilege — access to data only for those who need it in their duties;
- logging and monitoring of anomalies;
- confidentiality undertakings by personnel;
- assessment of subcontractors and data processing agreements under Article 28 GDPR;
If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (Article 34 GDPR). We will notify the supervisory authority of a breach within 72 hours (Article 33 GDPR).
18. Your rights
| Right | What it means |
|---|---|
| Access to data (Article 15) | You may ask whether we process your data and obtain a copy of it |
| Rectification (Article 16) | You may ask for inaccurate or incomplete data to be corrected or completed |
| Erasure (Article 17) | You may ask for your data to be deleted where there is no longer a basis for processing it. The right does not extend to data we are required by law to retain |
| Restriction of processing (Article 18) | You may ask for processing to be restricted, for example where you contest the accuracy of the data |
| Data portability (Article 20) | You may receive the data you have provided in a structured, commonly used and machine-readable format and transmit it to another controller. The right concerns automated processing based on consent or on a contract |
| Objection to processing (Article 21) | You may object to processing based on legitimate interests on grounds relating to your particular situation. Objection to direct marketing is absolute: we always stop it, with no reasons required |
| Withdrawal of consent (Article 7(3)) | You may withdraw a consent you have given at any time. Withdrawal does not affect the lawfulness of processing carried out before it, nor your use of the service |
| Rights relating to automated decision-making (Article 22) | See section 14.4 |
| Lodging a complaint with the supervisory authority (Article 77) | See below |
18.1 How to exercise your rights
Send your request to asiakaspalvelu@rahoo.fi. We may ask you to verify your identity if we cannot otherwise reliably identify you. We will reply within one month at the latest; in complex cases we may extend the period by up to two further months and will inform you of this within one month. Handling requests is free of charge unless a request is manifestly unfounded or excessive.
If you completed the application in a partner’s service (channel A or B), you may also address your request to the partner. See sections 4.3 and 4.4.
18.2 Complaint to the Data Protection Ombudsman
If you consider that we process your personal data unlawfully, you may lodge a complaint with the Office of the Data Protection Ombudsman. We hope you will contact us first.
19. Cookies and web tracking
A cookie is a small file stored on your device when you use the service. The use of cookies is governed by section 205 of the Finnish Act on Electronic Communications Services (917/2014).
In the application process we use essential cookies only. An essential cookie is one without which the service you have requested does not work. Storing it does not require consent (section 205(2) of the Act on Electronic Communications Services).
Consent. If we take into use cookies other than essential ones, they will require your consent. Consent is not requested in this notice but separately, before anything is stored, and rejecting will be as easy as accepting. We will update this section before doing so.
We use the following cookies in the service. The list is updated whenever the cookies in use change.
| Cookie | Set by | Purpose | Validity | Consent |
|---|---|---|---|---|
| `vc` | Rahoo | Continuing an interrupted application: recognises your application in progress if you leave the page and come back. Not used for advertising or visitor tracking | 4 hours | Not required |
| `XSRF-TOKEN` | Rahoo | Security: protects the form against request forgery | For the session | Not required |
| `rahoo_session` | Rahoo | Maintaining the server session while the application is completed | 2 hours | Not required |
Your browser may hold older cookies from an earlier period. If you have used the service before, cookies may have been stored in your browser that the service no longer sets, reads or uses to send data. They disappear on their own when they expire, and you can also remove them yourself in your browser settings.
The same identifier may also travel as a parameter in the web address. When you move from the preliminary enquiry to the application proper, or return to your application from a link you received by email, the identifier is passed in the address. This serves the same purpose of continuing the application as the cookie does.
Do not share the return link you received by email. The link opens your application without separate authentication, so that continuing the application is effortless.
Differences between channels. In channel B, where Rahoo’s application form is embedded in a partner’s service, Rahoo’s component sets only the essential cookies listed above. If Rahoo were to take non-essential cookies into use there, consent would be obtained by the partner on its own site, because the storage takes place in the partner’s service (see section 4.3). In channel A, Rahoo sets no cookies at all in the partner’s service — only the partner’s own cookies are used there, and the partner is responsible for them. In channels C and D you deal with Rahoo on its own site, and the cookies there are the same essential ones.
The partner is responsible for its own cookies and for the consent relating to them. They appear in the partner’s own cookie list, not here.
The storing of cookies on a device is supervised by the Finnish Transport and Communications Agency Traficom. The processing of personal data collected by means of cookies is supervised by the Office of the Data Protection Ombudsman.
20. Marketing and advertising
- Offers of financing relating to an application are not direct marketing but part of the service you have requested. They are based on a contract and on steps taken prior to entering into a contract.
- Newsletters and other marketing communications are sent only with your separate consent. You may withdraw your consent at any time using the link in every message or by writing to asiakaspalvelu@rahoo.fi. Withdrawal has no effect on your use of the service.
- Targeted advertising on third-party platforms. If you give consent to marketing cookies, we may share identifiers and event data with advertising platforms so that we can target advertising and measure its effectiveness.
Rahoo and an advertising platform may be joint controllers within the meaning of Article 26 GDPR in so far as data is collected on Rahoo’s site and transferred to the platform. The essence of the arrangement corresponds to that described in section 4.3: Rahoo obtains consent and provides information, the platform is responsible for its own processing, and you may exercise your rights against either party.
21. Changes to this notice
We develop our service continuously, so we may update this notice. The current version is always available on our website. We will inform you of material changes by email or in the service before the change takes effect.
| Version | Date | Main changes |
|---|---|---|
| 3.1 | 18 September 2026 | Section 5.5 extended to cover financing arising from the application where it is arranged using a different financing product. Section 12 clarified as to what data is disclosed to the partner. Section 12 clarified as regards the financing partner’s right to use the data for its own statutory obligations and for legal claims. The provider of strong electronic identification and the role of Zapier named (sections 12 and 13). Collateral and the financing product added to the pre-screening data categories in section 14.2. The maximum period for backups specified as seven days in section 16 |
| 3.0 | 17 September 2026 | Added the drawdown and status information received from the financing partner to the sources of data (section 5.5) and the calculation of the intermediary fee as a separate purpose of processing (section 6). Corrected the reference to personal credit information in section 6 so that it corresponds to section 8: Rahoo obtains credit information only about the company applying for financing. Added users of Rahoo’s system employed by a financing partner as a category of data subjects (section 3). Added the version of the terms of use accepted and the timestamps and text versions of consents to the verification log (section 16) |
| 2.9 | 8 September 2026 | Sections 12 and 13 on recipients and third-country transfers updated to correspond to the services in use. Section 19 on cookies rewritten to correspond to how the service actually works: the cookie list has been brought up to date and the validity of the identifier used to continue an application has been shortened from 13 months to 4 hours and limited to a single purpose. Added a note that the same identifier may travel as a parameter in the web address, and a warning against sharing the return link. Section 4.3 clarified: responsibility for cookies is itemised, and Rahoo is named as the primary point of contact for data subject requests. The retention table in section 16 aligned with section 19 |
| 2.8 | 26 August 2026 | Comprehensive revision: legal bases clarified, the processing of the personal identity code and of credit information separated out, the PEP assessment replacing an incorrect reference to political connections, the legal basis and rights relating to automated decision-making corrected to accord with Article 22, joint controllership on partner sites described, a section on the use of artificial intelligence added, retention periods clarified, information security and the right to data portability added, cookie consent corrected, recipients and third-country transfers named. Version 2.2 added the visitor identifier and the retention periods for interrupted sessions. Version 2.3 added the channel-specific description of roles and the information required by Article 14. Version 2.4 clarified the visitor identifier, the maximum retention periods, the recipients and the fact that Rahoo does not obtain personal credit information. Version 2.5 added the verification log, a section on backups and a reference to financing partners’ use of the system. Version 2.6 clarified the information provided in channel A and the way source data is retrieved. Version 2.7 added the cookie-by-cookie list. Version 2.8 corrected the starting point of the retention period for an application that led to financing: the period runs from the end of Rahoo’s intermediary assignment, because Rahoo does not learn when the financing agreement ends |
| 1.0 | 19 October 2025 | First version |
22. Contact
Questions about this notice, data protection and data subject rights: asiakaspalvelu@rahoo.fi.