Privacy Statement

1. Information we collect about you

Primarily we collect data directly from you, for instance, when you register for our online services or purchase our products. However, the personal data we collect and process about you vary depending on which Nokian Tyres’ services you use and the type of personal data we choose to collect depends on the purpose of the processing.

The personal data we collect include the following:

  • Contact details: first name, family name, email address, mobile phone number, home address;

  • Purchase data: sold Nokian Tyres product(s), product item (T-code), date of purchase and other related data collected at the point of purchase;

  • Customer account data: booking related information, invoicing and payment details (such as credit card details), vehicle information (vehicle licence number, service history), tyre lifecycle information, date and time of submitting form on our website;

  • Service data: service entry ID, service type, country, service entry’s status, receipt of the purchase, picture of the damaged tyres, picture or scan of the consumer ID (optional), confirmation letter (optional), DOT code (optional), tyre status (repaired or substitute);

  • Campaign and event data: in case you register or participate in one of our marketing campaigns, events or fairs, we collect the information provided in this connection;

  • Registration data: user ID, password and any other individual identifier;

  • Permissions and consents: information on your newsletter subscriptions, such as information whether you have allowed Nokian Tyres email or mobile marketing communication;

  • Website analytics data: information about your computer, your computer’s internet protocol address (IP address), computer operating system, and your internet browser type.

2. From which sources we collect data

Personal data is primarily collected directly from you. In certain situations, we also collect personal data from other external sources upon your explicit consent or to the extent permitted by law. We collect personal data about you, when you:

  • Purchase our products or services;
  • Register for our services;
  • Subscribe to a newsletter;
  • Take part in our marketing campaigns, events or fairs;
  • Contact our customer service (via email, phone or online chat); and
  • Otherwise through use of Nokian Tyres services.

3. Purposes we use your data

We collect and process your personal data for our business operations, for instance, to provide you with the goods and services you have purchased from us. Moreover, we collect and process your personal data for developing our products and services, managing and maintaining our customer relationships, analysis and for warranty needs. We process your personal data only on legitimate grounds if it is necessary for preparing and performing customer agreements, based on your consent, if it is in our legitimate interest or whenever we are required to do so by law.

We process your data for the following purposes:

• To deliver our products and services: We process your personal data to provide you with the services you have purchased from us. This means that we process online purchase and booking related information, billing and payment details and other contact information in order to manage your customer relationship with us. We also need to process your personal data to authenticate your identity and when it is necessary for handling warranty claims. We need to process your data this way to enter into and perform contract with you.

• To improve our services: We process information about buying behaviour, customer feedback and information on your interests based on our legitimate interest in order to offer you better services. We also carry out surveys, analyse your personal data or aggregated/pseudonymized data to improve our business operations and customer insight based on our legitimate interest.

Our legitimate interest means that we have an interest which is important to us and for our business operations. We always balance our legitimate interest between your legitimate interest and fundamental rights. This means that we also take your interests into consideration and you may always object to such processing. Furthermore, you may also obtain information on the balancing test upon request privacy@nokiantyres.com.

• For marketing purposes: In case you have opted in to receive marketing communications from us, we will process your personal data to provide you marketing communications based on the preferences you have provided. We also process information on your newsletter subscriptions. The legal basis on which we process your personal data for these purposes is your explicit consent. You have the right withdraw your consent at any time. We use the collected data to create segments of our customers in order to provide you more relevant services. However, the segmentation does not allow identification of an individual.

• For website analytics: We collect information about your computer, IP address, operating system, and browser type with the help of cookies based on your consent. We use cookies for statistical and analytical purposes, to conduct surveys, to determine which parts of our website are most popular and to optimize the use of the website for you. Cookies are also used to recognize you when you return to our website in order to provide you information related to your own interests.

4. Disclosures and transfers of your data

We process your personal data confidentially. Personal data we have collected is typically stored and processed in the European Union (EU) or the European Economic Area (EEA). However, we disclose personal to third parties located outside the EU or the EEA when we use third parties to process personal data on behalf of Nokian Tyres’ (e.g. when we use service provider outside the EU or the EEA or the service provider stores data outside the EU or the EEA). In such case we ensure that the the adequate level of protection for your personal data is secured with appropriate safeguards (e.g. by using standard contractual model clauses approved by the European Commission).

There are situations where we need to share or otherwise disclose your personal data to third parties, such as stated below.

• Service providers and subcontractors: we use third party service providers and subcontractors to process your personal data, for example, for carrying out campaigns and direct marketing. In case we use third party service providers, they need to process personal data in accordance with Nokian Tyres’ instructions to ensure an adequate level of data protection in all processing of your personal data. This means that they may not use your personal data for their own purposes.

These service providers include, for example, our payment processing providers, CRM service providers (e.g. Salesforce), marketing tools (e.g. Bazaarvoice) and others. In case our service provider is located in the United States, we guarantee that the service provider we use ensures adequate level of data protection contractually or by following the rules based on the Privacy Shield agreement between the EU and the United States. You can learn more about the Privacy Shield program on the website of the European Commission.
• Mandatory disclosures: we are obliged to disclose your personal information if we are required to do so by applicable law, for instance, to public authorities. In such case, we will disclose only information which is necessary to comply with the statutory requirement. Moreover, we may give assistance in investigations of accidents, which means that we may need to disclose your data to support the investigative authorities.

• Within a group of companies: we disclose data to our affiliates or other companies within Nokian Tyres Corporation.

• Merqers and acquisitions: in case we sell, merge or otherwise re-arrangement our business operations or assets, we need to disclose your personal data to purchaser or prospective seller or buyer of such business or assets in compliance with applicable laws. In such a case we process your personal data based on our legitimate interest to ensure our business continuity. Please note that in case you object to such processing, the purchaser of our business may not be able to provide services to you anymore.

• Consent: we disclose your personal data to third parties if you have given us your explicit consent for such transfer. You have the right withdraw your consent at any time as described in section 6.

6. Access to data and using your rights

You are entitled to know whether we hold personal data about you and, if we do, you have the right to access the personal data we have collected in our register and require it to be corrected if it is inaccurate. You have the right to decide whether you wish to receive direct marketing, and in certain cases you have the right to erasure or to ask your data to be transferred to another controller. If you have any questions or you want to exercise your rights, please contact privacy@nokiantyres.com.

• The right of access and right to rectification
You have the right to access your personal data. This means that you have the right to know what personal data we have collected about you or receive confirmation that we do not have any personal data about you. In case your personal data is inaccurate or incomplete, you have the right to make a request for rectification or completion of your personal data.

• Right to restrict processing
We make all reasonable efforts to ensure that the personal data we hold about you is accurate and up to date. However, in case your personal data is in inaccurate, you have the right to demand restriction of processing. This means that the stored personal data will be marked with the aim of limiting its processing. For example, in case you believe that your personal data is not accurate, the personal data processing will be restricted until the accuracy of data is verified.

• Right to object
You have the right to object to processing, for example, in case we process your personal data based on our legitimate interest. Moreover, you have the absolute right to object to processing for direct marketing purposes at any time.

• Right to be forgotten
You have the right to be forgotten. This means you may ask your personal data to be deleted once personal data is no longer necessary for the purposes for which it was collected. We will also erase personal data if the processing was based on consent and you decide to withdraw your consent or restrict the processing, or there is no other legitimate reason for processing. However, it is good to note that in some cases there may still be legal bases for processing and retaining your personal data e.g. in order to fulfil legal obligations or for the warranty needs.

• Right to data portability
You have the right to request transferring your personal data. This means we will provide your personal data in machine-readable format so that you can utilize your personal data yourself or transfer the personal data to another controller (e.g. another service provider). In certain situations, you also have the right to receive the personal data you have provided us electronically, so you may transfer them to another controller. This is possible in situations where we process your personal data based on contract or your explicit consent, and only applies to the personal data you have provided us yourself.

• Right to withdraw a consent
If we process your personal data on the basis of your consent, you have the right to withdraw your consent at any time. For example, you can withdraw your consent to electronic direct marketing at any time. However, the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

We will respond to your requests without undue delay, but within one (1) month. In addition to the above-mentioned rights, if you are not satisfied with the processing of your personal data or the measures taken, you may contact the supervisory authority and lodge a complaint about your personal data processing.

7. Data retention

Your personal data will be retained as long as is necessary for the purpose they were collected for, as long as we are legally obligated or until we receive a request for erasure. We review personal data stored in our systems and paper archives regularly in order to ensure personal data is retained only as long as necessary to achieve the purposes it was collected.

The retention period of your data is determined by the following criteria:

  • If you have an account with us, we will keep your personal data while your account is active or for as long as needed to provide services to you or as we are legally obligated.

  • If you have made a purchase from our store or online store, we will erase your data after a reasonable period of time after or obligations related to the purchase have been fulfilled. It is good to note that we need to retain your data for the period of warranty coverage. The warranty period is five (5) years from the date of retail or six (6) years from the date of manufacture, whichever occurs first;

  • If you have opted in to receive marketing communications, we process your personal data for those purposes as long as your permission remains in force. In case you withdraw your consent, we will discontinue the processing of your data immediately.

Please note that your personal data may also be anonymized or pseudonymized by modifying them irreversibly.

8. Controller and contact information

Nokian Tyres plc is the controller of your personal data. Should you have any questions about privacy, please contact us:

Nokian Tyres plc
Pirkkalaistie 7
37100, Nokia, FINLAND

9. Revisions to this privacy statement

We are continuously developing our services, thus this privacy statement is subject to changes. Changes may also be based on changes in legislation. We recommend that you visit this privacy statement in regular basis in order to keep track of possible changes. We also inform you directly of the changes, if needed.