Skip to content

Privacy notice

Effective date: 07.09.2026

Ramirent undertakes to protect the privacy of the users of its services in compliance with of the General Data Protection Regulation (EU) 2016/679.

Effective date: 07.09.2026

This privacy notice explains how Ramirent (“Ramirent“, “we“, “us” or “our“) collects, uses, shares and protects personal data relating to customers, suppliers and other business partners, including their representatives and contact persons. It also explains your data protection rights and how you can contact us if you have questions.

1)    Who is the controller and how can you contact us?

Company name: Ramirent Ltd

Registration number: FI09771354

Address: Tapulikaupungintie 37, 00750 Helsinki, Finland

Privacy contact email: privacy@ramirent.com

To exercise your rights: Falcony GDPR

2)    What personal data do we collect?

Below we explain the types of personal data we may process about you. In Section 4, you can see why we process each type of data and which legal bases we rely on.

3)    Sources of personal data

We collect personal data primarily directly from you, for example when you rent, buy, supply, create an account, contact us or respond to surveys. We may also obtain personal data from your employer or represented organisation, from our systems and services, and, where permitted by law, from public sources, business information providers or credit reference agencies.

4)    Why do we process your personal data and on what legal bases?

We only process your personal data where we have a valid legal basis under data protection law. The main legal bases we rely on are performance of a contract, compliance with a legal obligation, our legitimate interests, and, where required, your consent. In the table below we describe the main purposes for which we use personal data and the legal basis we rely on.

PurposeExamples of what we doCategories of dataLegal basis
Contract management (customers & suppliers)Register you/your company; process orders; deliver/receive goods and services; manage subscriptions and rentals; perform credit checks where needed; handle payments, returns, complaints and warranties.Identity; Contact; Customer/Supplier; Purchase & payment; Marketing preferences (for service messages)Contract (GDPR Art. 6(1)(b)); Legal obligation for accounting/tax (Art. 6(1)(c))
Customer service & communicationsRespond to queries via phone, email, web forms, chat or social media; surveys and feedback you choose to provide.Identity; Contact; Customer/Supplier; Marketing preferencesLegitimate interests to run our business and assist users (Art. 6(1)(f))
Website/app operationProvide access, security and performance; prevent abuse/fraud; troubleshooting and maintenance.Technical & usage; Identity/Contact (as needed)Legitimate interests (IT operations, security)
Analytics & service improvementAnalyse usage to improve products, services, customer experience and support.Technical & usage; Customer/Supplier; Purchase & payment; Inferred/derivedLegitimate interests (service improvement). Cookies requiring consent are only used with your consent.
Marketing (own services)Send newsletters and offers; personalise content; measure campaign effectiveness.Identity; Contact; Customer/Supplier; Technical & usage; Inferred/derived; Marketing preferencesLegitimate interests (direct marketing). For email/SMS/push, we use consent where required by law; you can opt out anytime.
Targeted advertising (if used)Display ads on our or third‑party sites/social media based on your interests.Technical & usage; Inferred/derived; Marketing preferencesConsent via cookies/trackers (where required).
Profiling & segmentationCreate customer segments (e.g., product categories, fleet size) to tailor communications and service.Identity; Customer/Supplier; Purchase & payment; Technical & usage; Inferred/derivedLegitimate interests (relevance, growth). Consent where cookies/trackers are involved.
Telematics, connected equipment and asset protectionOperate connected equipment or telematics-enabled services; monitor running hours, diagnostics and maintenance needs; support customer service; protect assets; prevent misuse or theft; investigate incidents; and manage returns, billing or contract performance where relevant.Telematics or IoT data; Identity; Contact; Relationship data; Technical dataContract where necessary to provide the service (GDPR Art. 6(1)(b)); Legitimate interests for security, asset protection, service improvement and operational management (Art. 6(1)(f)); Legal obligation where applicable (Art. 6(1)(c)).
Automated tools & AI‑assisted processesUse automated tools (e.g., customer account opening, fraud‑prevention, risk indicators, routing simple requests). We ensure human involvement for decisions that could have legal or similarly significant effects. If we ever rely on solely automated decisions of that kind, we will inform you separately and explain your rights.Varies per tool; typically Identity; Contact; Technical & usage; Customer/Supplier; Inferred/derivedLegitimate interests (efficiency, risk management); Contract or Legal obligation where applicable.
Video redordings & site securityKeep people and property safe; prevent, detect and investigate incidents.Camera recordingsLegitimate interests (safety, crime prevention); Legal obligation where applicable.

Where we rely on legitimate interests, we assess whether our interests are balanced against your rights and freedoms. You can contact us using the details in Section 1 if you would like more information about this assessment.

5)    Cookies and similar technologies

Where you use our websites or apps, we may use cookies and similar technologies. Non-essential cookies, such as analytics or advertising cookies, are used only where required consent has been obtained. Please see our separate cookie information and cookie settings for more details.

6)    Telematics and connected equipment

Where we provide rental, service or other solutions involving connected equipment, vehicles or devices, we may process telematics or IoT data linked to a contract, service or asset. Depending on the service, this may include equipment identifiers, running hours, usage events, diagnostics, fault alerts, maintenance information, and, where relevant, location-related data.

We use this data only where necessary for clearly defined purposes, such as providing the service, managing assets, planning maintenance, supporting customer service, protecting equipment, preventing misuse or theft, investigating incidents, and meeting contractual or legal requirements. The legal basis will normally be performance of a contract where the processing is necessary to provide the service, or our legitimate interests where the processing is necessary for security, asset protection, service improvement or operational management. Where consent is required by law, we will ask for it.

If a specific telematics service includes location-related data, this should be clearly described in the relevant service documentation. Unless clearly stated otherwise, we do not intend this section to mean that continuous location tracking takes place in every case. We apply data minimisation and limit access to telematics data to those who need it for the relevant purpose.

Telematics data may be shared with relevant service providers, such as telematics platform providers, connectivity providers, maintenance partners, IT service providers, insurers or authorities, where necessary and lawful. We keep telematics data only for as long as needed for the relevant purpose, contract, incident handling, legal obligation or claims period. Additional service-specific information may be provided in separate telematics information, service terms or a telematics privacy notice, where applicable.

7)    AI and automation

We may use automation and AI-assisted tools to support our operations and provide services more efficiently, for example to route requests, detect unusual transactions or misuse, improve forecasting, reduce spam or fraud, and generate draft responses. These tools are used with appropriate safeguards and do not replace human judgement where this could have legal or similarly significant effects on you.

Quality and risk management: we test and monitor tools, reduce the risk of errors, and provide guidance to personnel using AI-assisted outputs.

Transparency: where AI-assisted processing meaningfully affects how we provide a service or communicate with you, we aim to make that clear.

Human oversight: we do not make decisions with legal or similarly significant effects about you based solely on automated processing unless a lawful basis applies and we inform you of your rights.

Data minimisation: we limit the personal data used by such tools to what is necessary for the purpose and use de-identification, aggregation or similar safeguards where appropriate.

Vendor and transfer controls: where an AI tool is provided by a third party, we apply appropriate contractual, security and international transfer safeguards where required.

8)    Who do we share your personal data with?

We may disclose your personal data to the categories of recipients below where necessary for the purposes described in Section 4 and subject to appropriate safeguards. Where a recipient acts as our processor, it may only process the data on our documented instructions and under an appropriate written agreement.

Recipient categoryHow we may share data
Within the Ramirent groupFor internal administration and use of shared IT systems, where this is necessary and lawful.
Service providers (processors)For example, hosting and cloud services, IT support, CRM and marketing automation, analytics, logistics, customer service tools, printing and mailing, payment processing, and delivery/collection services. These providers act under our instructions and appropriate contracts.
Independent controllersFor example, payment service providers, financing partners, social media platforms when you interact on our pages or see our ads, insurers, and grant administrators where applicable.
Public authorities and regulatorsWhere disclosure is required by law or necessary for compliance, enforcement, or legal proceedings.
Mergers, acquisitions and corporate transactionsIn connection with a business sale, merger or reorganisation, under appropriate safeguards.
Social media joint controllershipSee Section 9 for more information on joint controllership with social media platforms.

In some cases, a recipient may act as an independent controller, for example certain payment providers, financing partners, authorities or social media platforms. In those cases, their own privacy information will apply to their processing.

9)    Social media and joint controllership

If you interact with us on social media platforms, such as by visiting our page or engaging with our content, we and the platform provider may act as joint controllers for certain limited processing activities, for example page insights, audience statistics or advertising measurement. The platform provider generally provides the technical infrastructure and is responsible for much of the processing. More information is available in the relevant platform privacy information and, where applicable, joint controller arrangement.

You can usually manage privacy settings, advertising preferences and certain rights requests directly through the relevant platform.

10)    International data transfers

We primarily process and store personal data within the EU/EEA. Where personal data is transferred to a recipient outside the EU/EEA, we ensure that an appropriate transfer mechanism is in place as required by applicable data protection law, for example an adequacy decision, Standard Contractual Clauses, or another valid safeguard.

Transfer scenarioSafeguardHow to get more information
A service provider processes personal data outside the EEA, or accesses it from outside the EEAWe apply an appropriate transfer safeguard under applicable data protection law, such as an adequacy decision or Standard Contractual Clauses (SCCs), together with supplementary measures where needed.You may contact Section 1 to request more information, including a copy of the relevant SCCs where applicable (subject to redaction of confidential or security-sensitive details).

11)    How long do we keep your personal data?

We keep personal data only for as long as necessary for the purposes described in this notice, including to meet legal, tax, accounting and contractual requirements and to establish, exercise or defend legal claims.

Data categoryIllustrative retention period
Customer and supplier recordsFor the duration of the relationship and a reasonable period thereafter (e.g., claims limitation).
Accounting and tax recordsTypically 6–10 years, as required by law.
Marketing consents/preferencesFor as long as you subscribe or interact with our communications; we keep proof of consent for up to 2 years after the last use of that consent.
Video recordingsDeleted when no longer necessary, and no later than 3 months, unless needed to investigate a specific incident or as required by law.

Data may be retained for a longer period if we are legally obliged to do so or if retention is necessary to establish, exercise or defend legal claims.

12)    Your rights

Under certain circumstances, and subject to applicable law, you have the following rights:

If you want to exercise your data protection rights, please contact us using the details in Section 1. We will handle your request in accordance with applicable data protection law. You also have the right to lodge a complaint with the data protection supervisory authority Home | Data Protection Ombudsman’s Office.

13)    How we protect your personal data

We apply appropriate technical and organisational measures to protect personal data, including access controls, security measures, training and vendor management. We review these measures regularly and update them where needed.

14)    Changes to this notice

This privacy notice is reviewed regularly and updated to reflect changing legal, regulatory or operational requirements. We will make the latest version available at www.ramirent.com/privacy and provide additional notice where required.