Carbit

Privacy Policy

This page contains Carbit Oy’s privacy policy and information about how personal data is processed.

Controller

Carbit Oy
Business ID: 3601351-6
Sienitie 34, 00760 Helsinki
carbitoy@gmail.com
+358 44 986 4688

Carbit Oy has not appointed a separate Data Protection Officer.


Purposes and Legal Bases for Processing Personal Data

Vehicle Repair and Maintenance Services

Carbit Oy processes personal data to provide vehicle repair and maintenance services, including assessing repair needs, preparing cost estimates, performing work, maintaining service history, and managing customer relationships. Data is also used to ensure quality and to handle warranty and complaint situations.

Legal bases:

  • contract or pre-contractual measures
  • legitimate interest (customer relationship management, service development, and business operations)

Owner and holder information of the vehicle is processed to provide the service. Billing data is processed as part of the service and to fulfill accounting and taxation obligations.


Customer Service and Communication

Personal data is processed to provide customer service, communicate with customers (e.g., bookings, work progress updates, completion notifications), and to improve services.

Legal bases:

  • contract
  • legitimate interest (improving customer experience)

Billing, Accounting and Legal Obligations

Personal data is processed for invoicing, payment monitoring, accounting, taxation, and for handling potential legal claims, debt collection, and disputes.

Legal bases:

  • legal obligation
  • legitimate interest

Fraud and Misuse Prevention

Personal data may be processed to prevent and investigate fraud and misuse.

Legal basis:

  • legitimate interest

Digital Services, Analytics and Marketing

We process data related to the use of our online services to provide services, perform analytics, develop services, and for marketing purposes.

Legal bases for marketing:

  • legitimate interest (direct marketing to existing customers)
  • consent (new customers and electronic direct marketing)

We use cookies and similar technologies. Analytics and marketing cookies are based on the user’s consent. More detailed information is provided in a separate cookie policy.


Recruitment

We process personal data of job applicants for recruitment purposes.

Data is retained for a maximum of 12 months after the end of the recruitment process unless the data subject consents to longer retention.


Legal Obligations

We process personal data to comply with legal obligations and to prevent and investigate misuse.


Automated Decision-Making

Carbit Oy does not use automated decision-making or profiling.


Categories of Personal Data

We process the following categories of personal data:

  • name and contact details
  • vehicle data (e.g., registration number, service history)
  • billing and payment information
  • customer communications and feedback
  • website usage and identification data
  • location data (only with consent)

Sources of Data

Data is obtained from:

  • the data subject
  • partners (e.g., insurance companies)
  • public registers (e.g., Traficom)

Data Retention

Personal data is retained only as long as necessary to fulfill the purposes of processing and to comply with applicable laws.

When determining retention periods, we consider, among other things:

  • duration of the customer relationship
  • responsibilities related to vehicle repair and maintenance (such as complaints and warranties)
  • statutory accounting obligations
  • potential legal claims

Marketing data is retained until the data subject withdraws consent or the data is no longer needed for marketing purposes.

Personal data is deleted or anonymized when no longer needed.


Recipients of Personal Data

Data may be disclosed to:

  • subcontractors and service providers
  • vehicle manufacturers and importers
  • insurance companies
  • IT and system providers
  • authorities when required by law

Data processors process personal data only in accordance with Carbit Oy’s instructions.


Transfers Outside the EU/EEA

Personal data may be transferred outside the EU/EEA (e.g., analytics services).

Transfers are carried out in accordance with GDPR using:

  • standard contractual clauses (SCC) approved by the European Commission
  • or other lawful safeguards

Data Security

Personal data is protected by technical and organizational measures such as:

  • access control
  • encrypted connections
  • protection of information systems

Rights of the Data Subject

The data subject has the right to:

  • access their data
  • rectify data
  • erase data
  • restrict processing
  • object to processing
  • data portability
  • withdraw consent
  • lodge a complaint with a supervisory authority

Supervisory authority in Finland:
Office of the Data Protection Ombudsman


Contact

For data protection matters:
carbitoy@gmail.com

Requests require identity verification.


Updated: 4.5.2026