TAVEX DATA PROTECTION TERMS

The controller of personal data is Tavex OY (Tavex), Finnish registry code 1053069-7, registered office address Fabianinkatu 14, 00100 Helsinki, Finland, email tavex@tavex.fi.

  1. Definitions

Data Subject means a natural person whose personal data is processed.

Personal Data means any information through which a specific natural person can be directly or indirectly identified.

Processing of Personal Data means any operation or set of operations performed on personal data, including collection, recording, registration, storage, alteration, organisation, enabling access, transfer, use, anonymisation and erasure. The operations may or may not be carried out by automated means.

Customer means any natural person who uses, has used or has expressed a wish to use the Services offered by Tavex.

Tavex Group means the Estonian parent company Tavex Group AS together with its subsidiaries.

Services means all services, including consultations, the purchase and sale of products and currencies, the booking of the purchase price or unit price of products or of a currency exchange rate, which Tavex provides to the Customer at its branches, on the website www.tavex.fi, by telephone, email, social networks or any other channel, as well as in connection with the services and products of partners.

Controller means a person who processes personal data, or on whose instructions personal data is processed, and who determines the purposes and means of the processing of personal data.

Recipient means any natural or legal person, including a public authority or other body, to whom personal data is disclosed.

Processor means any person who processes personal data on behalf of and under the instructions of the Controller.

  1. General provisions

2.1. These terms for the processing of personal data (the Terms) describe how Tavex processes personal data.

2.2. Terms for the processing of personal data may also be included in other documents or forms. More detailed terms by categories of Data Subjects are provided in the following sections of these Terms.

2.3. Tavex has the right to involve third parties (Processors) in the processing of personal data. In such cases, Tavex takes all necessary measures to ensure that such processors process personal data in accordance with Tavex’s instructions and applicable law, including by requiring the implementation of appropriate security measures.

2.4. Tavex may amend these Terms unilaterally. The current version of the Terms is always available on Tavex’s website. At the Customer’s request, a Tavex representative will print the Data Protection Terms for the Customer at a Tavex branch.

  1. Rights of the Data Subject

3.1. The Data Subject may exercise the following rights in relation to their personal data:

3.1.1. to know whether Tavex processes their personal data and, if so, to obtain an overview of the data being processed;

3.1.2. to request rectification of inaccurate or incomplete data;

3.1.3. to request erasure of personal data;

3.1.4. to request restriction of the processing of personal data;

3.1.5. to request that data be provided in a structured, commonly used electronic format for the transfer of data to a third party;

3.1.6. to object to the processing of personal data based on legitimate interest and to the processing of personal data for direct marketing purposes;

3.1.7. to withdraw consent given for the processing of personal data.

3.2. The above rights are not absolute, and the detailed conditions for, or restrictions on, exercising those rights may arise from the General Data Protection Regulation of the European Union or other laws applicable to Tavex (including applicable Anti Money Laundering Regulation).

3.3. To exercise the rights, a written request must be submitted to Tavex at Tavex’s offices or by email to tavex@tavex.fi. The request must state the Data Subject’s name, date of birth and which right the Data Subject wishes to exercise.

3.4. Before resolving a request, Tavex may ask the Data Subject for additional information in order to verify the Data Subject’s identity or to identify the data that is the subject of the request.

3.5. The Data Subject’s request will be responded to no later than within one month of submission of the request. Depending on the volume or complexity of the request or inquiry, Tavex may extend the time limit set out in the previous sentence by two months.

3.6. If the Data Subject considers that the processing of their personal data by Tavex infringes their statutory rights and/or interests, the Data Subject may lodge a complaint with the Office of the Data Protection Ombudsman in Finland or apply to a court to protect their rights.

  1. Processing of Customer data

4.1. Tavex, as a financial institution, is required to process the Customer’s personal data when providing the Service. Therefore, in certain cases, the processing of personal data is a prerequisite for providing the Service as a requirement arising from the Act on Preventing Money Laundering and Terrorist Financing. If the processing of personal data is necessary for compliance with a legal obligation, Tavex cannot provide the Service if the personal data is not provided.

4.2. Tavex also processes the Customer’s personal data to prepare and provide the Services requested by Customers, to protect Tavex’s property and rights, and to ensure security.

4.3. Tavex obtains personal data when the Customer provides the data. In addition, in the course of providing the Service, Tavex collects data about the Customer from public sources and public registers.

4.4. The legal basis for the processing of Customer data is primarily the performance of a contract and compliance with legal obligations.

4.5. Tavex processes personal data on the basis of legitimate interest when organising video surveillance, responding to Customer calls and in e-commerce transactions in order to protect Tavex’s rights and property interests and prevent fraud, and where the Customer has clearly expressed a wish to be notified of the arrival of a product or a change in price.

4.6. Tavex uses profiling and automated decision-making to fulfil obligations related to the prevention of money laundering. If the Customer’s risk rating exceeds Tavex’s risk appetite, Tavex may refuse to provide the Service. If the Customer’s risk rating calculated by an automated decision would result in refusal to provide the Service, the result of the risk rating is always reviewed by a Tavex employee.

4.7. Tavex generally does not share the Customer’s personal data with third parties, except where this is necessary for the provision of the Service or for compliance with a legal obligation. The categories of persons with whom sharing of data may be necessary are:

4.7.1. companies belonging to Tavex Group;

4.7.2. persons connected with the provision of the Service and performance of the contract;

4.7.3. public authorities and officials who have a statutory right to request the transfer of personal data;

4.7.4. legal advisers and audit firms.

4.8. Tavex does not transfer data to a third country or to an international organisation, except where this is strictly necessary for the provision of the Service, for example if the Customer orders delivery of a product to a third country.

4.9. Tavex retains personal data for the period provided by law. Under the Act on Preventing Money Laundering and Terrorist Financing, the retention period for personal data processed to fulfil anti-money laundering obligations is 5 years from the execution of the transaction or the end of the business relationship. The retention period for data necessary to comply with accounting requirements is 7 years from the end of the year in which the transaction was carried out.

  1. Processing of personal data of newsletter subscribers

5.1. Tavex processes the personal data of newsletter subscribers in order to send newsletters to persons who wish to receive them.

5.2. Tavex processes newsletter subscribers’ data for sending newsletters on the basis of consent, and providing the data is a prerequisite for sending the newsletter.

5.3. Tavex obtains the personal data from the newsletter subscriber.

5.4. In addition, Tavex processes usage data of newsletter subscribers on the basis of legitimate interest for the purpose of carrying out marketing analysis in order to provide newsletter subscribers with better content and experience.

5.5. A newsletter subscriber may withdraw consent at any time by using the “unsubscribe” link at the end of the newsletter or by submitting a written request to Tavex by email or post.

5.6. Tavex processes personal data until the newsletter subscriber expresses a wish to unsubscribe from the newsletter, i.e. until withdrawal of consent.

5.7. Tavex does not share newsletter subscribers’ data with third parties.

  1. Processing of data of persons on sanctions lists and politically exposed persons lists

6.1. Tavex is a financial institution within the meaning of the Act on Preventing Money Laundering and Terrorist Financing and is subject to obligations under the Act on the Fulfilment of Certain Obligations of Finland as a Member of the United Nations and of the European Union. Therefore, when carrying out transactions, Tavex must identify whether the Customer is subject to an international sanction or has the status of a politically exposed person.

6.2. Tavex processes the data of sanctioned persons and politically exposed persons for compliance with a legal obligation.

6.3. The sources of personal data are public sources and registers.

6.4. Tavex does not separately notify Data Subjects included on international sanctions lists and politically exposed persons lists of the processing of their data, because Tavex’s processing of the data arises from a legal obligation, the Data Subjects are presumed to be aware of processing of the data by financial institutions, and notifying the Data Subjects would require the processing of additional data, which would require unreasonable efforts from Tavex.

6.5. Personal data is processed until 12 months after the person is removed from a sanctions list or loses the status of a politically exposed person.

  1. Processing of personal data in the context of video surveillance

7.1. Tavex uses video surveillance as part of security measures at its branches. The operating areas of surveillance cameras are marked with the relevant information signs.

7.2. The personal data processed by Tavex in the context of video surveillance are the Data Subject’s image, location and timestamp.

7.3. Tavex carries out video surveillance on the basis of legitimate interest to ensure the security of Tavex’s employees, premises and property, to protect its legal claims and interests, and to detect and prevent unlawful activity.

7.4. Video recordings are retained for up to 3 years.

7.5. Tavex does not transfer personal data to third parties, except where a third party submits a request to Tavex for the release of a video recording and Tavex is satisfied that there is a legal basis for releasing the data, for example a police request in criminal proceedings.

7.6. If the Data Subject wishes to exercise data protection rights in relation to personal data processed as camera recordings, the Data Subject must specify, together with their request, the date and time period of the camera recording.

  1. Processing of personal data of website visitors

8.1. If a website visitor creates a Tavex-ID user account, Tavex processes the personal data provided by the website user.

8.2. The data is processed for the provision of the Tavex-ID service.

8.3. The data is processed until the Tavex-ID user expresses a wish to delete their user account.

8.4. Tavex does not transfer personal data to third parties.

8.5. If a website visitor places an order via the website, the rules on processing Customer data also apply to the processing of their personal data.

8.6. Tavex uses cookies on its website. The cookies used and information about them are specified in Tavex’s Cookie Policy, which is available on the website www.tavex.fi.

This version of the Terms is effective as of 26 May 2026.