Fair Way Channel Privacy Notice

Read more below.

HKScan Oyj (“HKScan”, “we”, “us”) is the data controller in relation to the processing of personal data through HKScan’s Fair Way channel.

We at HKScan are committed to operating fairly and upholding high standards of ethics. On this page, we describe and provide further information on how we will collect and process personal data in connection with our Fair Way channel. Personal data means any information, which may be used to identify an individual.

It is important to us that you feel safe with how we handle your personal data. We take measures to ensure that your personal data is protected and that the processing of your personal data is carried out in accordance with applicable data protection regulations and our internal policies and procedures.

Fair Way channel” is intended for reporting suspected cases of unethical behavior in HKScan’s business. This applies to suspected violations of the law or other official regulations or deviations from HKScan’s Code of Conduct or other policies.

Reporter” is a person who reports any suspected violation through the Fair Way channel.

Alleged Wrongdoer” is a person who has, pursuant to the report, allegedly acted in violation of laws or HKScan’s Code of Conduct, values or other policies and guidelines.

Witness” is a person named on the report or communication by the Reporter as a witness to the suspected violation.

We collect personal data directly from the Reporter when he/she submits a report through the Fair Way channel’s reporting form. Additional personal data may be collected from the Reporter in connection with further communication with the Reporter through the Fairway channel after the submission of the report.

The report and/or additional information submitted by the Reporter may also contain personal data of Witnesses and Alleged Wrongdoers.

We do not process personal data submitted through the Fair Way channel for any other purpose than those specified below. We process your personal data for the following purposes:

Investigate and take necessary action in order to ensure compliance with applicable legislation

As we are a public listed company, we are required by law to maintain a reporting channel for possible breaches of laws and regulations regarding the financial markets. The processing is conducted for the purposes of ensuring that the statutory obligations are complied with and that the reported suspected violations can be investigated appropriately and necessary measures can be taken.

Categories of personal data

Legal basis

  • Any information provided by the Reporter

Legal obligation. Processing is necessary in order to fulfill legal obligations relating to possible breaches of laws and regulations regarding the financial markets.

 

Investigate and take necessary action to ensure compliance with HKScan’s Code of Conduct or other policies and guidelines

The processing is carried out for the purposes of ensuring compliance with HKScan’s Code of Conduct or other policies and guidelines. By ensuring the compliance with HKScan’s Code of Conduct and other policies and guidelines, we are able to implement our business in an effective and fair manner. The processing is also carried out in order to ensure that the reported issues can be investigated appropriately and necessary measures can be taken.  

Categories of personal data

Legal basis

  • Any information provided by the Reporter

Legitimate interests. The processing is necessary in order to fulfil our legitimate interests in investigating and taking necessary action to ensure compliance with HKScan’s Code of Conduct or other policies and guidelines.

 

Establish, exercise or defend legal claims

The processing may also be carried out for the purposes of establishing, exercising and defending legal claims where this is necessary due to the conclusions of investigating the reported case.

Categories of personal data

Legal basis

  • Any information provided by the Reporter

Legitimate interests. The processing is necessary in order to fulfil our legitimate interests in establishing, exercising or defending legal claims.

 

We retain personal data submitted through the Fair Way channel only for a period that is necessary to achieve the purposes for which personal data is processed. In general, personal data is retained for the period of handling the reported case. Once the case has been completed and closed, the personal data will be deleted in 30 days. However, if the case leads to an investigation, personal data relating to such investigation is retained for the period of handling the investigation. After this, we may retain personal data for a period necessary to establish, exercise or defend legal claims.

Where necessary, we share your personal data with others. We categorize the recipients of personal data as service providers and other recipients. Service providers’ process personal data on our behalf and in accordance with our instructions only for the purposes set out in this privacy notice. Other recipients process personal data independently on their own behalf as controllers.    

We share your personal data with:

Service providers

In order to fulfil the purposes of the processing of personal data, we share personal data with service providers that we have engaged. These service providers provide services to us in order to be able to establish and maintain the Fair Way channel and handle the reported cases. The service providers may only process your personal data for these purposes and in accordance with our instructions and not for their own purposes. We are the data controller for the processing of personal data that the service providers carry out on our behalf.

Other recipients

If the report leads to an investigation, personal data collected and processed in connection with the investigation may be disclosed to the following recipients:

Recipient

Purpose

Legal basis for the transfer

HKScan Group companies

We may share necessary personal data with other HKScan Group companies for internal administration and investigation purposes.

Legitimate interest. The processing is necessary in order to fulfill our legitimate interests of administering and investigating the reported cases.

Law enforcement authorities, e.g. police or other relevant authority

We share personal data with law en­forcement authorities if we are obligated under law to disclose information or if we have a legitimate interest for disclosing information (e.g. where we are the injured party, but there is no legal obligation to disclose information to authorities).

Legal obligation. The processing is necessary in order to fulfill legal obligations.

Legitimate interest. The processing is necessary in order to fulfil our legitimate interest in disclosing information to the authorities.

External consultants

We may share personal data with external consultants, e.g. law firms, in order to investigate the reported case as well as for the purposes of establishing, exercising and defending legal claims.

Legitimate interest. The pro­cessing is necessary in order to fulfil our legitimate interest of investigating the reported cases and managing and defending legal claims.

Personal data is processed within the EU/EEA.

Under data protection regulations, the data subject has certain rights in relation to the processing of his/her personal data. We process your personal data to the extent necessary in order to fulfill your rights. Please submit requests for exercising your rights through our data privacy website or by contacting us at privacy@hkscan.com.

Please note that you may not use all the rights set out below in case you are reported as an Alleged Wrongdoer or named as a Witness. This is because we cannot provide certain personal data to the data subject if this could impede any investigation or if refraining from providing such personal data is necessary for preventing or investigating the reported violations.

You have the right to:

Access your personal data

You have the right to access personal data we process about you. You may request a copy of your personal data through our data privacy website, which can be found here. We will provide you with it unless we have lawful reasons not to share this data or if sharing the data would adversely affect the rights and freedoms of others.

Update your personal data

You have the right to request that incorrect or incomplete personal data is corrected or completed.

Delete your personal data

Under certain circumstances you have the right to request that your personal data is deleted. However, we cannot delete your personal data if we for example are obligated under law to keep the data.

Restrict the use of your personal data

You have the right under certain circumstances to request that the processing of your personal data is restricted. If the processing of your personal data has been restricted we may only, besides storing the data, process your personal data with your consent, or in order to establish, exercise or defend legal claims or to defend rights of others.

We may occasionally update this information, e.g. if we would process personal data for new pur­poses, collect additional categories of personal data or share personal data with other recipients. In such a case we will notify you in an appropriate way, where possible. The latest version of the information is always published on this page.

If you have any questions regarding the processing of your personal data, please do not hesitate to contact us. See below for contact details. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority within your jurisdiction.

HKScan Oyj

Company registration number: 0111425-3

Lemminkäisenkatu 48, FI-20520 Turku, Finland

E-mail: privacy@hkscan.com