Privacy Notice for Partners and Visitors at Municipality Finance

Updated: 20.8.2026

Who is the data controller?

Municipality Finance Plc (”MuniFin”)
Business ID 1701683-4

Who can be contacted about this privacy notice?

Municipality Finance Plc / Legal
legal@munifin.fi
Jaakonkatu 3 A / P.O. Box 744
FI-00101 Helsinki, Finland

Whose personal data do we process?

This privacy notice applies to the following data subjects:

  • Contact persons of investors and banks and investment firms acting as counterparties in funding and investment activities
  • Contact persons, beneficial owners and board members of other parties acting as partners of MuniFin, such as service providers
  • Representatives and contact persons of authorities
  • Individuals visiting MuniFin’s premises

On what basis and for what purposes do we process personal data?

MuniFin processes personal data in accordance with the legal bases and purposes described below.

Legal obligations

Examples of legal obligations requiring the processing of personal data:

  • Accounting regulations
  • Sanctions screening
  • Obligations related to securities markets and investment services legislation
  • Maintaining and improving the security of information systems

Legitimate interest

Examples of processing of personal data based on legitimate interest:

  • Sales and marketing activities, including direct marketing. MuniFin offers and markets its products to existing and potential partners to promote its business activities.
  • Fulfilling contractual obligations
  • Maintaining partner relationships, including organising events
  • Maintaining and improving the security of information systems
  • Visitor data and video surveillance. MuniFin’s legitimate interest is to ensure the security of its physical premises.

Consent

MuniFin may also process personal data based on consent, for example in connection with sales and marketing activities and maintaining partner relationships. When we request your consent, we will provide more detailed information about the processing.

What personal data do we process?

The following categories of personal data may be collected about data subjects:

  • Identification and contact details: name, phone number, email address, position, represented organisation
  • Sanctions-related information
  • Other information necessary for maintaining the partner relationship, such as related events and tasks
  • Additional data stored by MuniFin, such as connections to other target groups and regular mailing preferences, for example for sending newsletters
  • Visitor data and video surveillance on MuniFin’s premises

Personal data may be obtained from the following sources:

  • Information provided by the data subject
  • Information collected by MuniFin, such as requests for proposals, contracts and partner websites
  • Registers maintained by authorities, such as the Finnish Trade Register
  • Commercial information providers, such as Suomen Asiakastieto

Phone and meeting recordings

MuniFin may record calls to fulfil its obligations related to investment services legislation, to confirm assignments and for internal control and risk management purposes. Access to recordings is governed by strict internal instructions, and recordings may be accessed only by designated persons who are authorised to do so based on their work duties. Recordings may be disclosed to authorities where required by law. Recordings are retained for five years, or for seven years at the request of an authority, after which they are deleted.

Teams meetings may be recorded to confirm assignments and to prepare meeting minutes. Recordings are retained only for as long as necessary to fulfil the purpose for which they were recorded.

Information about recording is provided in connection with the call or meeting, or in the meeting invitation.

Video surveillance

MuniFin’s premises are monitored by video surveillance to protect property, assets and individuals, and to prevent and investigate possible security incidents or crimes. Video recordings capture images, the time of recording and the location. Surveillance areas are marked with signs. Viewing of recordings is governed by strict internal instructions. Only designated personnel with job-related authorisation can view recordings. Recordings may be disclosed to authorities (e.g., the police) when required by law.

Video surveillance data are retained for a maximum of 90 days.

Processing of photographs and other communications material

MuniFin may process photographs, videos and other communications material taken at events and marketing campaigns in the company’s internal and external communications. The material may be used, for example, on MuniFin’s website, internal communication channels, social media channels and in other communications and marketing materials.

The material may be used for communications and marketing purposes for a maximum of five (5) years from the date it was produced, unless the data subject exercises their rights as described below.

After the five-year period, the material may be retained as part of documenting MuniFin’s history, but it will not be used in new marketing or communications material unless there is an applicable legal basis for such processing.

How long do we retain personal data?

MuniFin retains personal data for as long as necessary for the purpose for which the personal data were collected and processed, or for as long as applicable regulations require. Personal data are also retained for as long as needed to perform contractual obligations and to meet statutory retention requirements.

Detailed retention periods are as follows:

  • Personal data related to contracts are retained for 10 years after the end of the contract.
  • Phone recordings are retained for five years.
  • Other data are retained for the duration of the contractual relationship, unless the purpose for which the personal data were collected ends earlier, in which case the data will be deleted once no longer needed (e.g., data collected for events).
  • Visitor data are deleted six months after the visit.
  • Video surveillance data are retained for a maximum of 90 days.

To whom may we disclose personal data?

Data may be disclosed, on a regular basis or where required or permitted by law, to:

  • Authorities
  • IT service providers and other contractual partners, where necessary for the purpose of the contract

When disclosing personal data, MuniFin ensures compliance with applicable legal requirements, including confidentiality obligations applicable to MuniFin.

Do we transfer data outside the EU or the European Economic Area?

When using IT service providers or other contractual partners, MuniFin may transfer data outside the European Union (EU) or the European Economic Area (EEA). Data will not be transferred outside the EU, the EEA, or countries recognised by the European Commission as providing an adequate level of data protection, unless adequate safeguards for data protection have been ensured through contractual arrangements or in another manner required by data protection legislation.

How do we store and protect personal data, and how do we notify data breaches?

Manual materials
Manual material is printed only when necessary and stored in locked premises. Access is granted only to authorised persons. Paper printouts are destroyed after use.

Digitally stored data
Personal data are kept confidential. The use of personal data within MuniFin’s organisation is governed by internal instructions, and access is restricted so that only those employees who need the data for their work tasks are authorised to use it. MuniFin requires all IT service providers it engages to ensure confidentiality, maintain appropriate information security, and comply with the principles of data protection legislation.

Notification of data breaches
In the event of a personal data breach, the data subject will be notified without undue delay in accordance with Article 34 of the EU General Data Protection Regulation, if the breach is likely to result in a high risk to the rights and freedoms of the data subject.

What rights does the data subject have?

The data subject has the following rights regarding the processing of their personal data:

  • Right of access – The data subject has the right to know whether the controller processes personal data concerning them and, if so, to access such data. However, this right may be restricted on the basis of legislation, to protect the privacy of other individuals, and to protect MuniFin’s internal materials and trade secrets.
  • Right to rectification – The data subject has the right to request the correction or completion of inaccurate, incorrect or incomplete personal data concerning them, unless restricted by legislation.
  • Right to erasure- In the following situations, the data subject has the right to request the deletion of their personal data:
    • The data are processed unlawfully.
    • The processing is based solely on the data subject’s consent and the data subject withdraws their consent.
    • There is no justified reason for continuing the processing.
    • The data subject objects to the processing of data for direct marketing purposes.
  • Right to restriction of processing – In certain circumstances, the data subject may request that the processing of their personal data be restricted, for example when the accuracy of the data is contested.
  • Right to object to the processing of personal data based on legitimate interest – The data subject may object to the processing of personal data where the processing is based on the controller’s legitimate interest or where the data are processed for direct marketing purposes.
  • Right to data portability – The data subject has the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit those data to another controller when the processing is based on consent or contract and is carried out by automated means.
  • Right to withdraw consent – Where the processing of personal data is based on consent, the data subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
  • Right to lodge a complaint with a supervisory authority – The data subject has the right to lodge a complaint with the Data Protection Ombudsman if they consider that their personal data have been processed in violation of data protection legislation.
  • Exercising rights – The data subject may exercise their rights by contacting the controller. Contact details for matters related to this privacy notice are provided at the beginning of the notice. More information about these rights and how to exercise them: Rights of the data subject | Data Protection Ombudsman’s Office