Data protection

On this page you will find information about Ilmarinen's data protection: processing of personal data, cookies and other information about online behavior. You will also find privacy statements at the bottom of the page.

1. Data protection in general

Ilmarinen processes personal data carefully and systematically. We ensure our customers’ privacy and act responsibly in any processing of personal data. We disclose information on the processing of personal data and our customers’ rights openly and clearly.

Ilmarinen abides by all of the obligations laid down in data protection legislation and good data processing practices when processing personal data. The legislation governing the pension insurance sector and the codes of conduct applicable in our sector set higher-than-usual standards for our operations, and we are committed to meeting them.

Informativeness

We inform customers about the processing of personal data openly and clearly in this data protection description and in connection with the provision of services. In the data protection description, customers are also informed about their rights to their data.

Necessity

We only process necessary data. Personal data is only collected and processed for specific, explicit and legal purposes.

Quality

We ensure the quality of the data. Ilmarinen has in place adequate measures for ensuring the quality and accuracy of the data. When processing data, only appropriate and reliable sources are used.

Information security

We protect data efficiently. Information security is ensured using the necessary technical and administrative means. Ilmarinen also ensures the protection and appropriate processing of data on the part of every person processing personal data who participates in the production of services.

Responsibility

The importance of data protection is reflected in Ilmarinen’s operations. We respect insurance secrecy and process confidential information in the manner required by legislation. We ensure the protection of privacy when processing personal data.

2. Processing of personal data by Ilmarinen

Personal data is only collected and processed for specific, explicit and legal purposes. Ilmarinen collects personal data related to identifying a person (e.g. the person’s name, contact details and identifying information in IT systems) from TyEL or YEL policyholders, i.e. from employers and self-employed persons. In addition, we may collect personal data from pension applicants and pension recipients and from insured persons and trustees. In order to produce pension and rehabilitation services, Ilmarinen also collects information on work history, pension accrual history, preliminary calculations, the earnings-related pension record, benefits history and medical decisions.

We also receive data from legal official registers. Ilmarinen also collects data on the rental seekers and tenants of the flats it rents out. The personal data to be collected may also be needed to fulfil legal obligations, manage the customer relationship and the insurance portfolio and to process appeal and rectification matters. Ilmarinen also collects data for research and statistics. In its customer service, Ilmarinen collects information related to advising and contacting customers, for instance, personal data, record information and recorded phone calls and customer feedback.

Pension and insurance services’ information on policyholders is saved in Ilmarinen’s customer register and may be used to process insurance and appeal applications, make decisions, conclude agreements and transfer insurance policies. In addition, Ilmarinen saves information about the insured and pensioner as it relates to the policyholder as well as calculations concerning insurance policies and the need for insurance. Accounting, payment, invoicing and debt collection data is also saved in the customer register’s information.

Ilmarinen’s customer register also saves grouping and classification data describing a customer account. Ilmarinen also collects recommendations, subscriptions and refusals given to customer relations and marketing communications.

Ilmarinen collects information related to adopting and using online services from the www.ilmarinen.fi website and services that require logging in; this information includes online and mobile services’ user information, information required for online identification and user rights, online identifiers and information on the channels, applications, devices and browsers used.

You can read more about the collection of various personal data in Ilmarinen’s privacy statements.

Ilmarinen’s task pursuant to the Act on Employment Pension Insurance Companies is to engage in statutory pension insurance business, which is part of social security, by taking care of the implementation of statutory pension provision and the assets accruing with the company for this purpose in a manner that secures the benefits covered by the insurance. In connection with these tasks, the processing of personal data is based on statutory requirements. In Ilmarinen’s operations, personal data can be processed also on the basis of consent, an agreement or a legitimate interest. The basis for the marketing targeted at Ilmarinen’s customers is a legitimate interest or consent. The data subject has the right to withdraw his or her consent.

Ilmarinen processes personal data for the following purposes: Producing and developing the services offered by Ilmarinen and its co-operation partners, offering additional and customised services, identifying the customer, managing user rights, ensuring and authenticating service transactions and resolving errors, managing finances and money transactions, and for accounting, incl. payments, invoicing, ledgers and debt collection. Ilmarinen’s customer data may also be processed in customer relationship management and development, in implementing customer service and advice, in analysing customer relationships and operations and in customer relationship and marketing communications, when based on consent.

Ilmarinen processes personal data also to ensure the information security of services, to prevent abuse and problem situations, and to manage risks. Ilmarinen may process personal data also in order to target appropriate advertising to its potential and existing customers in online environments based on the user’s consent.

Ilmarinen speeds up and improves its customer service by using automated decision-making in the processing of insurance and pensions matters when case-specific deliberation is not involved and statutory terms and conditions are met. If the statutory terms are not met, the processing is moved to the manual process. The customer has the right to appeal decisions made by Ilmarinen that apply to him/her. Information on appeals is given in connection with the decision.

Compliance with the obligations stipulated in legislation, regulations and official decisions requires Ilmarinen to process personal data. Statutory obligations are, e.g. the prevention, detection and investigation of money laundering, terrorism funding and fraud; accounting regulations; risk-management-related risks, such as credit and insurance risks; solvency requirements; and legislative requirements related to securities and funds.

Ilmarinen can combine the personal data and online behavioural data in its customer register and marketing register in order to better target its marketing communications at potential and existing customers, based on the individual’s consent.

Ilmarinen receives personal data from data subjects themselves in connection with marketing and use of the service. Ilmarinen also receives data on the insured persons and pension recipients from other pension companies and employers, for example. Personal data is also collected in connection with service transactions and the use of services.

Ilmarinen also regularly receives personal data from the following data sources:

  • Finnish Centre for Pensions
  • Social Security Institution
  • Earnings data broker services
  • Doctors, hospitals and health centres
  • Labour authorities
  • Tax authorities
  • Social welfare authorities
  • Unemployment funds and employment offices
  • Enforcement officers
  • Insurance companies
  • Banks
  • OP Financial Group
  • Accountants
  • Suomen Asiakastieto Oy
  • Population Information System
  • Pension Appeal Board
  • Insurance Court

Pursuant to law, Ilmarinen may disclose data contained in its filing systems to producers of statutory pension and social security and the Finnish Centre for Pensions, for example. Data is disclosed to authorities pursuant to law. Ilmarinen only discloses personal data in accordance with the right to be informed based on legislation and in accordance with disclosure rights and obligations. In special cases, personal data can be disclosed also with the consent of the data subject. The disclosure parties and grounds are described in the guidelines of the Finnish Centre for Pensions.

The processing of personal data by service providers operating on behalf of Ilmarinen is always based on assignment contracts and instructions, which specify the parties’ rights and obligations in the processing and protection of personal data. We have concluded agreements that include personal data processing on behalf of Ilmarinen with selected suppliers and service providers. Such agreements have been made with, for instance, providers of software development, maintenance, server and IT support services.

Ilmarinen uses its customers’ personal data for customer communications based on Ilmarinen’s statutory obligation to report matters that are significant in terms of the customer relationship or based on Ilmarinen’s legitimate interest. Ilmarinen also uses the personal data of its customers and potential corporate customers for marketing communications, which the customer can always refuse.

Ilmarinen discloses information for scientific and historical research. We may hand over invoices to companies collecting receivables. If we sell, buy, merge or otherwise organise our business, the user’s personal data may be disclosed to the buyer and the buyer’s advisors.

Ilmarinen primarily processes personal data in Finland, the EU/EEA area or in other countries approved by the EU Commission as having a sufficient level of data protection. To ensure a sufficient level of data protection, the standard contractual clauses approved by the European Commission are used.

Adform

On certain pages related to services, Ilmarinen uses an Adform cookie that assigns a randomly generated identifier (ID) to your browser. The identifier can also be used to target advertising for Ilmarinen’s pension insurance services on other websites that sell advertising space to Ilmarinen.

Adform works with Ilmarinen as a joint controller for the cookie information and uses the information to target advertising and to develop its service. The identifier is not combined with Ilmarinen’s customer data, nor does it contain personal pension insurance information.

If you wish, you can request the removal of your browser-related ID directly through Adform’s “Right to be Forgotten” page.

Facebook

Ilmarinen and Facebook Ireland (hereinafter “Facebook”) are joint controllers, where applicable, for the community pages on Facebook. These pages are, among others, Ilmarinen’s page, https://fi-fi.facebook.com/parempaaelamaa.

For each page, Facebook processes data in accordance with its privacy policy: www.facebook.com/privacy/. Facebook is primarily responsible for ensuring compliance with the data protection legislation and for implementing information security and the rights of the data subject in the service. You can manage Facebook’s data protection settings in Facebook.

Ilmarinen processes the personal data of community pages solely for Ilmarinen’s own purposes, such as to provide information about services and products, to receive feedback, to buy advertising, and to measure pages and ads.

The information we receive from Facebook is the data subject’s name, public profile photo and other information that has been set as public. Essentially, information that is visible to anyone. You might provide us with other personal data in the comments sections of pages or in an instant messaging service, for instance, in a customer service situation. Ilmarinen does not process your personal data outside of Facebook, and the data will not be linked to other registers.

On Ilmarinen’s community pages, personal data is processed based on Ilmarinen’s legitimate interest. A data subject can limit the processing of personal data that Ilmarinen obtains from Facebook by unliking and/or unfollowing the community page.

Ilmarinen and Facebook Ireland (hereinafter “Facebook”) are joint controllers, where applicable, for the community pages on Facebook. These pages are, among others, Ilmarinen’s page, https://fi-fi.facebook.com/parempaaelamaa.

LinkedIn

Ilmarinen and LinkedIn Corporation (hereinafter “LinkedIn”) are joint controllers, where applicable, for the community pages on LinkedIn. These pages are, among others, Ilmarinen’s page, https://www.linkedin.com/company/ilmarinen/

For each page, LinkedIn processes data in accordance with its privacy policy: https://www.linkedin.com/legal/privacy-policy. LinkedIn is primarily responsible for ensuring compliance with the data protection legislation and for implementing information security and the rights of the data subject in the service. You can manage LinkedIn’s data protection settings in LinkedIn.

Ilmarinen processes the personal data of community pages solely for Ilmarinen’s own purposes, such as to provide information about services and products, to receive feedback, to buy advertising, and to measure pages and ads.

The information we receive from LinkedIn is the data subject’s name, public profile photo and other information that has been set as public. Essentially, information that is visible to anyone. You might provide us with other personal data in the comments sections of pages or in an instant messaging service, for instance, in a customer service situation. Ilmarinen does not process your personal data outside of LinkedIn, and the data will not be linked to other registers.

On Ilmarinen’s community pages, personal data is processed based on Ilmarinen’s legitimate interest. A data subject can limit the processing of personal data that Ilmarinen obtains from LinkedIn by unliking and/or unfollowing the community page.

Ilmarinen retains personal data in operations based on its statutory obligation. The retention periods are determined in accordance with earnings-related pension legislation or other applicable legislation:

  • Personal data linked to insurance: for the insurance’s period of validity and ten subsequent calendar years
  • Personal data linked to pension and rehabilitation matters: the lifetime of the insured and five subsequent calendar years
  • Personal data linked to survivors’ pension: survivors’ pension payment period and five subsequent calendar years
  • Personal data for the collection of late insurance contributions: up until the end of the collection and five subsequent calendar years
  • Personal data linked to appeals: 50 years if they do not need to be retained for a longer period based on the above points

In non-statutory operations, Ilmarinen must retain personal data for as long as any one of the processing grounds presented in section 2.2 of this privacy statement is valid and the personal data is necessary for its purposes.

Personal data shall also be erased, if necessary, when the data subject objects to the processing of personal data based on a legitimate or general interest, and there are no other grounds for the processing.

Access to devices and servers that contain personal data has been limited, through user rights, to those who need them for their duties. The persons processing the data are bound by the statutory non-disclosure obligation. Personal data is stored only for as long as required for handling the matter or until the statutory storage period expires. Ilmarinen’s entire personnel have been trained in personal data protection.

The servers used for processing personal data are located in data centres protected through access control and security systems. The filing systems containing personal data are segregated from public data networks using technical security arrangements. The use of personal data is also monitored through various technical arrangements.

Ilmarinen may use subcontractors in performing its tasks. The same regulations and non-disclosure obligations apply to subcontractors and their employees as to Ilmarinen employees.

At Ilmarinen, information security and the protection of personal data are an integral part of the functionality and architecture of the information systems. Requirements for the information systems’ security and the integrity, confidentiality, availability and continuity of the data processing are always established beforehand when the systems are designed. Ilmarinen processes all personal data securely and in the manner prescribed by legislation and systematically develops and inspects information security.

Right of access

A data subject has the right to access personal data concerning him/her that has been recorded in the register. The data subject must present in the request for access his/her name and identity number so that the data can be found. The response to the request for access will be delivered to the data subject’s verified address contained in the Finnish Population Information System.

Right to data portability

The processing of personal data at Ilmarinen is primarily based on carrying out its statutory obligation, in which case there is no right to data portability. This applies to the processing of personal data linked to earnings-related pension cover provision and the management of investment operations, in addition to Ilmarinen’s activities as an employer and company, even if the processing is specified in more detail through agreements when necessary.

Otherwise, the data subject is entitled to receive as a file the personal data processed by the information systems that applies to him/her, which he/she has supplied to the controller and whose processing is based on the data subject’s consent or an agreement with the data subject. The data subject may also request that the controller transfer the data in question to another controller if this is technically possible.

Right to rectification

The data subject is entitled to require that inaccurate personal data be rectified. The changes in personal data will primarily be made in connection with use of the service following authentication. The request must contain a name and identity number, a specific and justified request for rectification and an explanation of how the information should be rectified.

Right to object

In terms of the processing of personal data based on Ilmarinen’s statutory obligation, the data subject is not entitled to object to the processing of personal data. The data subject is entitled to object to the processing of personal data that applies to him/her when the processing is based on a general or legitimate interest, such as direct marketing. The data subject is entitled to object to the use of his/her personal data for marketing at any time. To do this, the data subject must inform Ilmarinen of a marketing ban or withdraw his/her consent.

Right to restriction of processing

The data subject can request that Ilmarinen restrict the processing of his/her personal data when:

  • The accuracy of the personal data is contested by the data subject. However, there is no right of restriction on the part of Ilmarinen’s statutory operations if the request for restriction is manifestly unfounded.
  • The processing is verifiably and justifiably unlawful and the data subject opposes the erasure of the personal data.
  • When Ilmarinen expresses that it no longer requires the personal data that has been requested to be restricted for the purposes of the processing as specified in the privacy statement, but the data subject requires them for the establishment, exercise or defence of legal claims.
  • The data subject has objected to the processing of the personal data, pending verification of whether the legitimate grounds of the controller override those of the data subject. The request must contain a name and identity number, and a specific and justified request for restriction.

Under the data protection regulation, you have the right to access the personal information we have stored about you. You can make an access request by contacting our customer service, logging into our online services, or sending us an email to tietosuoja@ilmarinen.fi. You can also use the attached form and, if you wish, specify what your access request concerns. Fill in the access request form.

We will send the response to your access request by mail to the address verified in the Population Information System, unless agreed otherwise.

3. Cookies and other online behavioural identifiers

Cookies are small pieces of text stored in a browser that may contain some information or, for example, a random identifier. Cookies are loaded into your browser when you visit websites that set them for a specific purpose. For example, on Ilmarinen’s website we can use them to help you pick up where you left off, as well as remember your preferences such as language settings. Some of our cookies are necessary to deliver the requested service, and some require your consent before they can be set. The cookies set by Ilmarinen do not harm your computer, and no personal data is disclosed to third parties through cookies without your consent.

With the help of cookies, Ilmarinen collects behavioural data from websites and online services. We use this information to analyse the use of the services, to improve the user experience, to tailor the services and the content of marketing messages, and to measure the effectiveness of advertising. We also use cookies to identify and resolve technical problems. For example, cookies allow us to recognise browsers returning to the service, as well as to detect when a marketing message has been opened and whether a user has moved from the message to Ilmarinen’s website. Information related to cookies may include the user’s IP address, browser type, time of day, page visits and web address. A cookie also stores information about the page from which the user arrived at Ilmarinen’s website. The user cannot be identified by a cookie alone, and the services cannot determine the user’s name or e-mail address on the basis of a cookie unless the user has expressly given their consent.

When logging in to Ilmarinen’s online services, we may, within the framework of legislation and based on consent, combine behavioural data generated by cookies with the personal data provided by the user. If you do not log in to Ilmarinen’s online services or arrive at Ilmarinen’s website through customer or marketing messages sent by Ilmarinen, we cannot identify you by a cookie alone. We may also combine your online behavioural data with your customer data after you have logged out of the online services, if you have used Ilmarinen’s online services while logged in and given your consent. We combine this information in order to develop our services and provide you with more relevant direct marketing.

Ilmarinen uses five different categories of cookies – necessary, performance and statistics, functional, targeting, and personalization cookies. Most of the cookies used by Ilmarinen are session cookies, which expire when the user closes the browser. Some cookies are persistent and remain stored in the browser for a defined period unless the user deletes them manually. The validity period of persistent cookies ranges from a few months to several years.

Necessary cookies

These cookies enable the basic functions of the website, such as secure login, service transactions, and the storing of privacy settings. They are technically necessary for the website to function and do not collect personal data for tracking purposes. You can set your browser to block these cookies, but essential parts of the website will then not function.

Performance and statistics cookies

When you accept these cookies, we can collect anonymous statistical data on how our website is used. This helps us understand which pages are most useful for our visitors and to improve the website’s performance. All collected data is anonymous and is used solely to develop the website. Your consent to these cookies helps us provide you with a better user experience.

Functional cookies

These cookies allow us to provide you with richer content and more personalized experiences, such as embedded videos, real-time chat support, and remembering your preferences such as language settings. When you accept these cookies, the functions of our website can better adapt to your needs. These cookies may be set by Ilmarinen or by third-party service providers whose services we use on our website.

Targeting cookies

By giving your consent to these cookies, you allow us to show you relevant advertising also on other websites. Our advertising partners may use general behavioural data to create interest profiles and display content that is likely to interest you. For this purpose, information may be shared with third parties outside Ilmarinen. By accepting these cookies, the advertisements you see can better reflect your interests.

We may also provide our partner Adform with a cookie-based identifier that is unique to your browser. Adform uses this identifier to target Ilmarinen’s advertising and to develop its targeting services. However, we do not disclose audience segments or customer data outside Ilmarinen.

Personalization cookies

When you accept personalization cookies, we can offer you an individually tailored experience on our website. These cookies are stored in your browser, for example, when you arrive on our website through an email message from us. Your consent to these cookies helps us understand which of our content interests you most, so we can prioritise the information that is most relevant to you and improve your user experience. In addition, we may show you relevant advertising both on our own website and on the websites of our partners – this means less unnecessary advertising for you and more content that is genuinely interesting.

Cookies set by Ilmarinen’s own websites and services are first-party cookies. In addition to these, Ilmarinen uses third-party cookies in its digital services, such as those from advertising networks, social media services, and measurement and tracking tools. These cookies always require your consent.

Ilmarinen may use so-called social plugins on its website, such as Like/Share buttons for social media. A social plugin can recognise that a user visiting the services is logged in to the relevant social media service in the same browser, which may cause the social media content shown to be personalised based on this information. Social plugin providers may collect information about the use of Ilmarinen’s digital services in accordance with their own privacy policies.

As regards third-party cookies, they are used for purposes such as targeting and measuring advertising on third-party websites. Targeting may be based on the user’s previous online behaviour on those browsers where our advertisements are most likely to be of interest to the user. For targeting, we may also make use of data collected from websites outside Ilmarinen’s own websites and online services.

Third parties used by Ilmarinen

Adform.net collects and analyses behavioural data about Ilmarinen’s website in order to target advertising and measure advertising effectiveness. You can read more about Adform.net’s privacy here:
https://site.adform.com/privacy-center/platform-privacy/product-and-services-privacy-policy/

Askem collects and analyses data on the quality of the content on Ilmarinen’s website and user feedback in order to improve the site. You can read more about React and Share’s privacy here:
https://www.reactandshare.com/privacy-policy

ClickDimensions collects and analyses data to provide marketing automation and website analytics. If you consent to both targeting cookies and personalization cookies, ClickDimensions may combine information from targeted marketing automation and web behaviour. You can read more about ClickDimensions’ privacy here:
https://clickdimensions.com/about/privacy-policy/

Facebook collects data to analyse how users move between Facebook and Ilmarinen’s website and to analyse the performance of advertising. You can read more about Facebook’s data policy here:
https://www.facebook.com/policy.php

Google Ads analyses the effectiveness of search engine advertising when a user arrives on Ilmarinen’s website. You can read more about Google Ads privacy here:
https://policies.google.com/technologies/ads?hl=en-US

Google Analytics is used to measure the use of Ilmarinen’s websites and online services, to assess the effectiveness of marketing campaigns and to produce statistical information. You can read more about Google Analytics privacy here:
https://policies.google.com/privacy?hl=en-US

You can read more generally about how Google processes personal data here:
https://business.safety.google/intl/fi/privacy/

Leadoo is a platform used to provide customer service and service flows on Ilmarinen’s website. Leadoo sets analytics cookies only with the user’s consent. You can read more about Leadoo’s privacy here:
https://leadoo.com/privacy-policy/

LinkedIn collects data from the “follow us” feature on Ilmarinen’s website and collects and analyses data for advertising targeting. You can read more about LinkedIn’s privacy policy here:
https://www.linkedin.com/legal/privacy-policy

Microsoft Ads analyses the effectiveness of search engine advertising when a user arrives on Ilmarinen’s website and collects and analyses data for advertising targeting. You can read more about Microsoft’s privacy here:
https://help.ads.microsoft.com/#apex/ads/en/ext60205

Microsoft Customer Insights – Journeys collects and analyses data in order to implement marketing automation and website analytics. If you consent to both targeting cookies and personalization cookies, Customer Insights – Journeys may combine information from targeted marketing communications, the information you provide in forms and your web behaviour. You can find more detailed information about cookie use and Microsoft’s privacy practices in the documentation Customer Insights – Journeys: tietosuoja ja evästeet:
https://learn.microsoft.com/en-us/dynamics365/customer-insights/journeys/real-time-journeys-cookies

Pinterest collects information about the use of the service and websites in order to enable advertising and analytics. If you consent to targeting cookies, Pinterest may use your online behaviour so that advertising and content can be better targeted. You can read more about Pinterest’s privacy here:
https://policy.pinterest.com/fi/privacy-policy

Readpeak collects and analyses data in order to display native advertisements and measure advertising performance. You can read more about Readpeak’s privacy here:
https://www.readpeak.com/readpeak-privacy-policy

Siteimprove collects and analyses data on the use of Ilmarinen’s websites and online services. You can read more about Siteimprove’s privacy here:
https://siteimprove.com/en/privacy/privacy-policy/

Surveypal collects and analyses data from surveys and customer feedback on Ilmarinen’s website. You can read more about Surveypal’s privacy here:
https://surveypal.com/privacy-policy/

Visual Website Optimizer collects and analyses data for A/B testing, session recording, page personalization and visualising website analytics. You can read more about VWO’s privacy here:
https://vwo.com/privacy-policy/

YouTube collects and analyses data on video views on Ilmarinen’s website and for advertising targeting. You can read more about YouTube’s privacy here:
https://policies.google.com/privacy

You can manage your cookie settings for Ilmarinen at any time through the Cookie Settings tool. In the tool, you can view detailed information about each cookie category and easily change your consents.

If you do not want advertising to be targeted based on your interests, you can also disable such targeting via the link below. After you have disabled targeting, you will see the same number of ads as before, but the ads will no longer be selected on the basis of your interests. Disable ad targeting here.

 

4. Privacy statements

The privacy statements describe the data contained in the personal registers maintained by Ilmarinen and the purpose for which the data is used, regular disclosures of data and data protection principles. In addition, the privacy statements contain information on the data subject’s rights, and contact details.

A personal register refers to a set of personal data in which personal data is used for consistent purposes.

Learn more about Ilmarinen’s privacy statements.

We inform the data subjects also otherwise in connection with the use of the services and with the collection of data, as necessary.

Last updated on