This Privacy Notice is a guide to our use of the personal information we have about you.
Hoist Finance AB (publ) (HFAB) is the Controller of the data we hold about you in relation to processing activities mentioned in the table below. Your account is owned by HFAB, but all matters related to debt collection, debt administration and exercising the rights of the lender in relation to your account is managed by one of our partners, who is a separate Controller for processing of your data related to debt collection. All communication with you will be managed by the partner in question, including but not limited to complaints handling, delivery of notices, accepting and managing written correspondence relevant to your debt. To find out more about how our partners process your personal data, please refer to their websites for more information.
HFAB uses your information only for the purposes of debt administration and processes associated with servicing credit. We will use the data in accordance with General Data Protection Regulation (GDPR), Swedish Data Protection Act 2018 and good debt collection practice to gather and update documentation necessary for compliance with applicable laws such as Anti Money Laundering Law, Swedish tax laws, Accounting laws etc.
In order to pursue the above purposes and to act lawfully, transparently and fairly, we process the following types of information, always under strict controls, such as encryption, internal access rights, and audits to keep your information safe:
Type of information |
Reason for processing |
Legal basis for processing |
How long we keep your information for |
---|---|---|---|
Contact and account information, such as your name, home address, date of birth, national identification number, phone number and details of previous communication with us, emails, and letters. | We process this data to be able to contact you, keep records of any previous conversations or correspondence, and in general keep a full and up to date picture of your circumstances and your dealings with us. This is necessary to handle your case fairly and in your best interests. | The legal basis for processing this information is the original credit agreement to which you are a party, legitimate interest or legal obligation which we need to fulfil. Once your account has been closed, we will hold your data to satisfy relevant regulations such as, Anti Money Laundering, Tax laws, Accounting laws etc. | 5 years (AML), 7 years (Tax), 7 years + days left in the calendar year (Accounting) from the moment the account is closed but, in any case, no longer than 10 years (for AML legal requirements), at which point it will be deleted/irreversibly anonymized. |
Payment information, such as your bank account number, transaction history, financial data etc. | To be able to provide Accounting, AML and Tax reports to relevant authorities and to fulfil our legal requirements. We also process this data in order to be able to create Analytical and Performance reports which are used to improve process how we deal with our customers and to educate our employees. |
We initially receive the information from the previous owner of the claim as part of its sale and transfer to us.
We may also obtain information from third parties in order to increase the accuracy of the information we hold and/or to gain a better understanding of your circumstances. These third parties are credit reference agencies, public government records, and other organisations which provide services to improve the quality of the data we hold about you.
We do not disclose your information except in the following limited circumstances:
We may also share your personal data with carefully vetted organisations, who must comply with our strict contractual security and privacy requirements and follow our guidelines, for the following purposes:
Finally, we may also disclose your personal information to third parties:
Your information will generally be kept within the EU/EEA or in countries deemed by the European Commission to have an adequate level of protection; only for limited purposes and temporarily may data be transferred to other countries. This is in particular where we need 24/7 technical support to maintain our IT infrastructure, and where the support teams of our service providers are located outside the EU/EEA.
In all cases, however, we have technical, organisational, and contractual protections in place to keep the information safe and to ensure an adequate level of protection. Contractually, transfers outside the EU/EEA to countries without an adequacy decision by the European Commission will be based on standard data protection clauses adopted by the European Commission.
We have put in place appropriate technical and security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we only give access to your personal data to employees, contractors and other third parties who have a business relation with us on a need-to-know basis. They will only process your personal data on our specific instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable authority of a suspected breach where we are legally required to do so.
We regularly review this Privacy Notice. We will notify you of any substantial updates that affect you 2 weeks in advance. Minor changes to the policy, such as making it clearer, will be implemented without directly notifying you.
This privacy notice was last updated: 24 June 2024.
If you have questions, comments or want to exercise any of your rights, please contact us at contact@hoistfinance.se, our Data Protection Officer at dpo@hoistfinance.com or send mail to our postal address Hoist Finance AB (publ), Dataskyddsombud, Box 7848, SE-111 21 Stockholm, Sweden. You can also file a complaint to the Swedish Authority for Privacy Protection (IMY) via email: imy@imy.se, or their postal address: Integritetsskyddsmyndigheten, Box 8114, SE-104 20 Stockholm, Sweden.