Privacy Policy

Last updated: October 1, 2026

This privacy policy explains how ToCar Oy processes personal data. It is organised by data subject group (A–F), and each group's table states the purpose of processing, the data processed, the legal basis and the retention period. Article references refer to the General Data Protection Regulation of the European Union (EU), Regulation (EU) 2016/679, hereinafter the GDPR.

1. Controller

The controller is ToCar Oy (business ID 3636957-1), Uutistie 7, 01770 Vantaa, Finland.

Requests and questions about data protection can be sent to support@tocar.fi.

2. Whose data we process and in which role

ToCar Oy is the controller for the personal data of groups A–F described in sections 3–8 below. These include, for example, the data of workshop account owners, workshop employee users, people who submit a demo request and website visitors.

In this policy, "workshop" means a business that has registered as a customer of the service. For the data a workshop stores in the service about its own customers, vehicles and work orders, the workshop is the controller and ToCar Oy is the processor. That processing is governed by the data processing agreement (/data-processing-agreement).

If a workshop processes your data, please contact that workshop. A request sent to us by mistake is forwarded to the right workshop, and we tell you that it has been forwarded.

3. A. Account owners and billing contacts

This group consists of the people who register a workshop for the service or administer the workshop's account, and the workshop's billing contacts.

Purpose Data Legal basis Retention period
Creating and administering the user account and providing the service to the workshop Name, email address, phone number, user role, language, workshop name, business ID and address Article 6(1)(b) (contract) Contract term + 90 days
Evidencing acceptance of the agreement Versions of the accepted terms, time of acceptance, IP address and browser information Article 6(1)(b) (contract) Contract term + 90 days
Billing and payment administration Billing email, billing address, invoices, payment transaction identifier, amount and status Article 6(1)(b) (contract) Contract term + 90 days; accounting records for the period stated below
Card payments Payment identifier, amount and status; the card payment is carried out by Mollie B.V. as an independent controller Article 6(1)(b) (contract) Contract term + 90 days
Accounting Invoices and payment vouchers Article 6(1)(c) (legal obligation); Accounting Act (1336/1997), chapter 2, section 10 Accounting records for ten years and vouchers for six years from the end of the financial year
Connecting the workshop's own email service (optional) Email service credentials or authorisation token, encrypted Article 6(1)(b) (contract) Contract term + 90 days
Security and investigation of misuse Login and event logs, session data, IP address, browser information, error reports Article 6(1)(f) (legitimate interest: protecting the service and the data) Event logs 90 days; ended sessions 30 days; application logs at most 14 days; error reports 30 days

Contract term + 90 days means that we delete the account and the workshop's data 90 days after the end of the agreement. Accounting records are kept beyond that for the period required by chapter 2, section 10 of the Accounting Act.

The data requested at registration and for billing is a requirement for entering into the agreement. Without it, the user account cannot be created and the service cannot be invoiced. Providing any other data is voluntary.

4. B. Employee users

This group consists of the people a workshop has invited to use the service, for example mechanics and service advisors. The service agreement is the workshop's, not the employee's, so we process an employee user's data on the basis of legitimate interest. The legitimate interest is providing the service to the workshop, which has chosen its users itself.

Purpose Data Legal basis Retention period
Creating the user account and providing the service to the workshop Name, email address, phone number, user role, language Article 6(1)(f) (legitimate interest: providing the service to the workshop) Contract term + 90 days
Security and investigation of misuse Login and event logs, session data, IP address, browser information, error reports Article 6(1)(f) (legitimate interest: protecting the service and the data) Event logs 90 days; ended sessions 30 days; application logs at most 14 days; error reports 30 days

An employee user may object to processing based on legitimate interest as described in section 12. The user account is deleted by the workshop, or by ToCar at the workshop's request. An employee user may also send a deletion or objection request directly to us, and we assess it under the GDPR. We receive an employee user's data from the workshop that invites the user.

5. C. Demo requests and marketing

When you book a demo on our website we process the details you provide: name, workshop name, email address, phone number, your current system, and the free-text message field. We also record the submission time, language selection, IP address and browser information, together with the identifiers of the marketing campaign you arrived through.

The purpose is to respond to your request and to prepare a possible agreement. The legal bases are steps taken prior to entering into a contract and legitimate interest. Demo request data is retained for 24 months from the most recent contact, after which it is deleted automatically.

If you give separate consent to marketing communications, we also process your contact details for that purpose on the basis of consent. We send marketing communications to natural persons only with consent. We record the time of consent, the version of the accepted text, the IP address and browser information in order to demonstrate consent.

You may withdraw consent at any time. As a registered user you withdraw consent with the "Marketing emails" setting on your profile page, and in every case you may withdraw it by email to support@tocar.fi. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Purpose Data Legal basis Retention period
Responding to a demo request and preparing an agreement Name, workshop name, email address, phone number, current system, message, submission time, language, IP address, browser information, campaign identifiers Article 6(1)(b) (pre-contractual steps) and 6(1)(f) (legitimate interest: responding to the request) 24 months from the most recent contact
Marketing communications to natural persons Name, email address, time of consent, version of the accepted text, IP address, browser information Article 6(1)(a) (consent) and section 200 of the Act on Electronic Communications Services (917/2014) Until consent is withdrawn; the record of consent and its withdrawal for the retention period of the user account

6. D. Support and contacts

This group consists of the people who contact us by email or otherwise, for example with a support request or a data protection request. Our mailboxes are hosted by Infomaniak Network SA (Switzerland), which processes the messages on our behalf as a processor.

Purpose Data Legal basis Retention period
Responding to support requests, data protection requests and other contacts Name, email address, workshop, message content and attachments, message times Article 6(1)(b) (contract) where the contact concerns the workshop's agreement; otherwise 6(1)(f) (legitimate interest: responding to contacts) 24 months from the closure of the case

7. E. Website visitors

This group consists of visitors to our public pages, such as the front page, the registration page and this policy. On public pages we use a session cookie and the protective cookie (CSRF) needed to secure forms. We also use Plausible Analytics to measure visitor traffic; it does not set analytics cookies. We use no other cookies on public pages.

Purpose Data Legal basis Retention period
Operation and security of the website Server logs: IP address, browser information, requested page and time Article 6(1)(f) (legitimate interest: protecting the website and diagnosing faults) At most 14 days
Operation of forms Session cookie and protective cookie (CSRF) Article 6(1)(f) (legitimate interest: operation of the website) For the duration of the session
Visitor analytics Page path, referring site, campaign parameters, browser and device type, country, daily visitor identifier, and page-event and session records Article 6(1)(f) (legitimate interest: developing the service) According to the selected Plausible subscription's retention limit: up to 3 years on Starter and Growth, or up to 5 years on Business.

To measure visitor traffic on our website, we use Plausible Analytics (Plausible Insights OÜ, Estonia). The service stores page-event and session records and presents statistics in aggregate form. It does not store raw IP addresses or complete browser User-Agent strings; it does, however, derive information such as country, browser and device type, and a daily visitor identifier from them. The legal basis is our legitimate interest in developing the service. Plausible processes website visitor data on ToCar's behalf as a processor within the European Union. This analytics does not concern data our customers store in the Service, so Plausible is not on our customer-facing subprocessor list.

8. F. Data retrieved from other sources

We retrieve data from two external sources. Each source is an independent controller for its own processing.

Purpose Data Legal basis Retention period
Completing the workshop's company details at registration Company name and address retrieved by business ID from the open data service of the Finnish Patent and Registration Office (PRH) Article 6(1)(b) (contract) Contract term + 90 days
Vehicle lookup at the workshop's request The registration number entered by the workshop is sent to the Biluppgifter service (Sweden), which returns the vehicle data Processing on behalf of the workshop as a processor under the data processing agreement As data stored by the workshop, under the data processing agreement

A vehicle lookup is always initiated by the workshop. Biluppgifter receives only the registration number and processes it as an independent controller.

9. Recipients

We do not sell personal data. To provide the service, we use service providers that process personal data on our behalf as processors. Service providers that process workshop data are our subprocessors for that data, and the current subprocessor list is available at /subprocessors. Plausible Analytics processes website visitor data on our behalf and is not a subprocessor of workshop data.

The following recipients are independent controllers responsible for their own processing:

  • Mollie B.V. (Netherlands): ToCar Oy's own card billing and the payment links workshops send to their customers;
  • Biluppgifter (Sweden): vehicle lookup by registration number at the workshop's request;
  • the Finnish Patent and Registration Office (PRH): company lookup at registration; and
  • authorities: we disclose data when the law obliges us to, for example on a lawful demand by an authority.

A workshop may connect its own email service to the service. That service provider is then the workshop's own processor, and ToCar Oy stores the connection credentials encrypted.

10. Transfers outside the European Economic Area

The service's data is located in Finland. The following processors are established outside the European Economic Area (EEA) or may process data outside it:

  • Laravel Forge (Laravel Holdings, Inc., United States), server management: the transfer safeguard is the EU-U.S. Data Privacy Framework, under which the company is certified, and as a fallback the European Commission's standard contractual clauses (Decision (EU) 2021/914);
  • Sentry (Functional Software, Inc., United States), error reporting: the data is stored in a data region located in the EU, and the US company is covered by the Data Privacy Framework and, as a fallback, the standard contractual clauses; and
  • Infomaniak Network SA (Switzerland), mailboxes: Switzerland is covered by a European Commission adequacy decision.

You can obtain a copy of the transfer safeguard by requesting it from support@tocar.fi.

11. Security

We protect personal data with technical and organisational measures such as access control, logging and backups. For workshop customers the measures are described in the data processing agreement (/data-processing-agreement). We notify personal data breaches in accordance with Articles 33 and 34 of the GDPR.

12. Rights of the data subject

Under the GDPR you have the right to:

  • access the personal data concerning you;
  • request the rectification of inaccurate data;
  • request the erasure of data;
  • request the restriction of processing;
  • object to processing based on legitimate interest;
  • receive the data you have provided in a portable format where processing is based on a contract or consent; and
  • withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

Send your request to support@tocar.fi. We verify your identity before acting on the request, for example by replying to the email address linked to your account or by asking for further information. We respond to a request within one month of receiving it at the latest.

If you consider that we process your data unlawfully, you may lodge a complaint with a supervisory authority. In Finland the supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), whose guidance is available at tietosuoja.fi.

13. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR.

14. Children

The service is intended for business use and is not directed at children. We do not knowingly collect children's personal data for our own purposes.

15. Changes and versions

We may update this policy when the processing, the law or the service changes. The version of the policy is the date shown at the top of the policy. At registration we record the version the user has read.

We notify material changes to the workshop's billing email 30 days before the change takes effect.

Every published version is available unchanged from the archive at /legal-archive/privacy/{version}, where {version} is the date of the policy in the form YYYY-MM-DD, for example /legal-archive/privacy/2026-04-04.

If the language versions conflict, the Finnish version prevails.