Privacy notice
Effective date: 07.09.2026
Ramirent undertakes to protect the privacy of the users of its services in compliance with of the General Data Protection Regulation (EU) 2016/679.
Effective date: 07.09.2026
This privacy notice explains how Ramirent (“Ramirent“, “we“, “us” or “our“) collects, uses, shares and protects personal data relating to customers, suppliers and other business partners, including their representatives and contact persons. It also explains your data protection rights and how you can contact us if you have questions.
1) Who is the controller and how can you contact us?
Company name: Ramirent Ltd
Registration number: FI09771354
Address: Tapulikaupungintie 37, 00750 Helsinki, Finland
Privacy contact email: privacy@ramirent.com
To exercise your rights: Falcony GDPR
2) What personal data do we collect?
Below we explain the types of personal data we may process about you. In Section 4, you can see why we process each type of data and which legal bases we rely on.
- Identity data includes your name, job title, employer or represented organisation, customer or supplier number, and other identifiers needed to manage the relationship. We will only process date of birth or personal identity number where this is necessary and permitted by applicable law.
- Contact data includes your email address, telephone number, postal address, and other contact details relevant to the relationship.
- Relationship data includes orders, rentals, purchases, supplies, contracts, negotiations, customer service interactions, feedback, surveys, and other records relating to the business relationship.
- Financial and payment data includes invoicing details, bank account details, payments made or received, financing-related information, and creditworthiness information from reputable sources where permitted by law and necessary for the transaction or relationship.
- Technical data includes IP address, login details, browser and device information, operating system, and similar technical information relating to the use of our websites, apps or services.
- Marketing and communications data includes your preferences for receiving marketing from us and your communication preferences.
- Camera recordings include video surveillance from certain areas of our premises where this is necessary for safety, security or incident investigation.
- Derived data includes segments or indicators we derive from other data, for example product interests, service usage groups, or customer categories created through analytics.
- Telematics or IoT data (where applicable) includes limited equipment telemetry, such as running hours, usage events, diagnostics and, where relevant, location-related data linked to a contract, service or asset. We do not collect continuous location data unless this is clearly stated for a specific service. Additional information about telematics processing, including the purposes, legal basis and retention periods, is provided in our separate telematics information / terms, where applicable.
3) Sources of personal data
We collect personal data primarily directly from you, for example when you rent, buy, supply, create an account, contact us or respond to surveys. We may also obtain personal data from your employer or represented organisation, from our systems and services, and, where permitted by law, from public sources, business information providers or credit reference agencies.
4) Why do we process your personal data and on what legal bases?
We only process your personal data where we have a valid legal basis under data protection law. The main legal bases we rely on are performance of a contract, compliance with a legal obligation, our legitimate interests, and, where required, your consent. In the table below we describe the main purposes for which we use personal data and the legal basis we rely on.
| Purpose | Examples of what we do | Categories of data | Legal basis |
| Contract management (customers & suppliers) | Register you/your company; process orders; deliver/receive goods and services; manage subscriptions and rentals; perform credit checks where needed; handle payments, returns, complaints and warranties. | Identity; Contact; Customer/Supplier; Purchase & payment; Marketing preferences (for service messages) | Contract (GDPR Art. 6(1)(b)); Legal obligation for accounting/tax (Art. 6(1)(c)) |
| Customer service & communications | Respond to queries via phone, email, web forms, chat or social media; surveys and feedback you choose to provide. | Identity; Contact; Customer/Supplier; Marketing preferences | Legitimate interests to run our business and assist users (Art. 6(1)(f)) |
| Website/app operation | Provide access, security and performance; prevent abuse/fraud; troubleshooting and maintenance. | Technical & usage; Identity/Contact (as needed) | Legitimate interests (IT operations, security) |
| Analytics & service improvement | Analyse usage to improve products, services, customer experience and support. | Technical & usage; Customer/Supplier; Purchase & payment; Inferred/derived | Legitimate interests (service improvement). Cookies requiring consent are only used with your consent. |
| Marketing (own services) | Send newsletters and offers; personalise content; measure campaign effectiveness. | Identity; Contact; Customer/Supplier; Technical & usage; Inferred/derived; Marketing preferences | Legitimate interests (direct marketing). For email/SMS/push, we use consent where required by law; you can opt out anytime. |
| Targeted advertising (if used) | Display ads on our or third‑party sites/social media based on your interests. | Technical & usage; Inferred/derived; Marketing preferences | Consent via cookies/trackers (where required). |
| Profiling & segmentation | Create customer segments (e.g., product categories, fleet size) to tailor communications and service. | Identity; Customer/Supplier; Purchase & payment; Technical & usage; Inferred/derived | Legitimate interests (relevance, growth). Consent where cookies/trackers are involved. |
| Telematics, connected equipment and asset protection | Operate connected equipment or telematics-enabled services; monitor running hours, diagnostics and maintenance needs; support customer service; protect assets; prevent misuse or theft; investigate incidents; and manage returns, billing or contract performance where relevant. | Telematics or IoT data; Identity; Contact; Relationship data; Technical data | Contract where necessary to provide the service (GDPR Art. 6(1)(b)); Legitimate interests for security, asset protection, service improvement and operational management (Art. 6(1)(f)); Legal obligation where applicable (Art. 6(1)(c)). |
| Automated tools & AI‑assisted processes | Use automated tools (e.g., customer account opening, fraud‑prevention, risk indicators, routing simple requests). We ensure human involvement for decisions that could have legal or similarly significant effects. If we ever rely on solely automated decisions of that kind, we will inform you separately and explain your rights. | Varies per tool; typically Identity; Contact; Technical & usage; Customer/Supplier; Inferred/derived | Legitimate interests (efficiency, risk management); Contract or Legal obligation where applicable. |
| Video redordings & site security | Keep people and property safe; prevent, detect and investigate incidents. | Camera recordings | Legitimate interests (safety, crime prevention); Legal obligation where applicable. |
Where we rely on legitimate interests, we assess whether our interests are balanced against your rights and freedoms. You can contact us using the details in Section 1 if you would like more information about this assessment.
5) Cookies and similar technologies
Where you use our websites or apps, we may use cookies and similar technologies. Non-essential cookies, such as analytics or advertising cookies, are used only where required consent has been obtained. Please see our separate cookie information and cookie settings for more details.
6) Telematics and connected equipment
Where we provide rental, service or other solutions involving connected equipment, vehicles or devices, we may process telematics or IoT data linked to a contract, service or asset. Depending on the service, this may include equipment identifiers, running hours, usage events, diagnostics, fault alerts, maintenance information, and, where relevant, location-related data.
We use this data only where necessary for clearly defined purposes, such as providing the service, managing assets, planning maintenance, supporting customer service, protecting equipment, preventing misuse or theft, investigating incidents, and meeting contractual or legal requirements. The legal basis will normally be performance of a contract where the processing is necessary to provide the service, or our legitimate interests where the processing is necessary for security, asset protection, service improvement or operational management. Where consent is required by law, we will ask for it.
If a specific telematics service includes location-related data, this should be clearly described in the relevant service documentation. Unless clearly stated otherwise, we do not intend this section to mean that continuous location tracking takes place in every case. We apply data minimisation and limit access to telematics data to those who need it for the relevant purpose.
Telematics data may be shared with relevant service providers, such as telematics platform providers, connectivity providers, maintenance partners, IT service providers, insurers or authorities, where necessary and lawful. We keep telematics data only for as long as needed for the relevant purpose, contract, incident handling, legal obligation or claims period. Additional service-specific information may be provided in separate telematics information, service terms or a telematics privacy notice, where applicable.
7) AI and automation
We may use automation and AI-assisted tools to support our operations and provide services more efficiently, for example to route requests, detect unusual transactions or misuse, improve forecasting, reduce spam or fraud, and generate draft responses. These tools are used with appropriate safeguards and do not replace human judgement where this could have legal or similarly significant effects on you.
Quality and risk management: we test and monitor tools, reduce the risk of errors, and provide guidance to personnel using AI-assisted outputs.
Transparency: where AI-assisted processing meaningfully affects how we provide a service or communicate with you, we aim to make that clear.
Human oversight: we do not make decisions with legal or similarly significant effects about you based solely on automated processing unless a lawful basis applies and we inform you of your rights.
Data minimisation: we limit the personal data used by such tools to what is necessary for the purpose and use de-identification, aggregation or similar safeguards where appropriate.
Vendor and transfer controls: where an AI tool is provided by a third party, we apply appropriate contractual, security and international transfer safeguards where required.
8) Who do we share your personal data with?
We may disclose your personal data to the categories of recipients below where necessary for the purposes described in Section 4 and subject to appropriate safeguards. Where a recipient acts as our processor, it may only process the data on our documented instructions and under an appropriate written agreement.
| Recipient category | How we may share data |
| Within the Ramirent group | For internal administration and use of shared IT systems, where this is necessary and lawful. |
| Service providers (processors) | For example, hosting and cloud services, IT support, CRM and marketing automation, analytics, logistics, customer service tools, printing and mailing, payment processing, and delivery/collection services. These providers act under our instructions and appropriate contracts. |
| Independent controllers | For example, payment service providers, financing partners, social media platforms when you interact on our pages or see our ads, insurers, and grant administrators where applicable. |
| Public authorities and regulators | Where disclosure is required by law or necessary for compliance, enforcement, or legal proceedings. |
| Mergers, acquisitions and corporate transactions | In connection with a business sale, merger or reorganisation, under appropriate safeguards. |
| Social media joint controllership | See Section 9 for more information on joint controllership with social media platforms. |
In some cases, a recipient may act as an independent controller, for example certain payment providers, financing partners, authorities or social media platforms. In those cases, their own privacy information will apply to their processing.
9) Social media and joint controllership
If you interact with us on social media platforms, such as by visiting our page or engaging with our content, we and the platform provider may act as joint controllers for certain limited processing activities, for example page insights, audience statistics or advertising measurement. The platform provider generally provides the technical infrastructure and is responsible for much of the processing. More information is available in the relevant platform privacy information and, where applicable, joint controller arrangement.
You can usually manage privacy settings, advertising preferences and certain rights requests directly through the relevant platform.
10) International data transfers
We primarily process and store personal data within the EU/EEA. Where personal data is transferred to a recipient outside the EU/EEA, we ensure that an appropriate transfer mechanism is in place as required by applicable data protection law, for example an adequacy decision, Standard Contractual Clauses, or another valid safeguard.
| Transfer scenario | Safeguard | How to get more information |
| A service provider processes personal data outside the EEA, or accesses it from outside the EEA | We apply an appropriate transfer safeguard under applicable data protection law, such as an adequacy decision or Standard Contractual Clauses (SCCs), together with supplementary measures where needed. | You may contact Section 1 to request more information, including a copy of the relevant SCCs where applicable (subject to redaction of confidential or security-sensitive details). |
11) How long do we keep your personal data?
We keep personal data only for as long as necessary for the purposes described in this notice, including to meet legal, tax, accounting and contractual requirements and to establish, exercise or defend legal claims.
| Data category | Illustrative retention period |
| Customer and supplier records | For the duration of the relationship and a reasonable period thereafter (e.g., claims limitation). |
| Accounting and tax records | Typically 6–10 years, as required by law. |
| Marketing consents/preferences | For as long as you subscribe or interact with our communications; we keep proof of consent for up to 2 years after the last use of that consent. |
| Video recordings | Deleted when no longer necessary, and no later than 3 months, unless needed to investigate a specific incident or as required by law. |
Data may be retained for a longer period if we are legally obliged to do so or if retention is necessary to establish, exercise or defend legal claims.
12) Your rights
Under certain circumstances, and subject to applicable law, you have the following rights:
- Access your personal data and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase your data in certain cases (“right to be forgotten”).
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests, including direct marketing (you can opt out at any time).
- Data portability for data you provided to us, where processing is based on consent or contract and carried out by automated means.
- Withdraw consent at any time (this does not affect processing carried out before withdrawal).
- Information about automated decision‑making, including profiling: if we ever make solely automated decisions that produce legal or similarly significant effects for you, we will inform you and explain your rights to human review, to express your point of view and to contest the decision.
If you want to exercise your data protection rights, please contact us using the details in Section 1. We will handle your request in accordance with applicable data protection law. You also have the right to lodge a complaint with the data protection supervisory authority Home | Data Protection Ombudsman’s Office.
13) How we protect your personal data
We apply appropriate technical and organisational measures to protect personal data, including access controls, security measures, training and vendor management. We review these measures regularly and update them where needed.
14) Changes to this notice
This privacy notice is reviewed regularly and updated to reflect changing legal, regulatory or operational requirements. We will make the latest version available at www.ramirent.com/privacy and provide additional notice where required.