Skip to content
PAP Group, part of ProseroPAP Group, part of Prosero
Search the site

Suggested searches

Quick links

Request a quote
MenuClose

PAP Group

Privacy notice

Wondering what happens to your personal data? It is important to us that you know how we process and store it, and that you know we act lawfully and reliably. We always protect your privacy, and it is important to us that you can trust us with your personal data.

Controller

The controller of personal data for this website and for PAP Group’s customer relationships is PAP Group Oy (Business ID 2059299-8), Niittytie 25 A, 01300 Vantaa, Finland, telephone +358 29 000 1112, email info@pap.fi.

PAP Group Oy belongs to the group of Prosero Security Group AB (Prosero, registration number 559108-3752). The companies of the Prosero Group process personal data in accordance with the EU General Data Protection Regulation (GDPR). This privacy notice describes in more detail how we process personal data. Contact details for data protection matters are given at the end of this notice.

Types of personal data we collect and how we process them

The personal data we collect may vary in nature depending on the service you use and the agreement we have with each other. The personal data collected is needed so that we can provide you with the best possible service and a good customer experience, and offer the right services and tailored offers.

What personal data we collect

We collect the following personal data about you:

Customer data Customer data is the information we need in order to provide the agreed service. Customer data usually consists of name, address, telephone number and email address. The data collected may also include information about services related to you, such as orders and user names for our services. If you attach files, such as an image, to an application or message, we also process them. In some cases, we also collect other customer-specific information that we need in order to provide you with the right service.

Maintenance history Maintenance history is information we need in order to answer questions about what has previously happened at a site or in its security system. Maintenance history relates to the installation or service itself, and it may contain customer data as part of the description of a case.

Electronic log files and data Electronic log files and data are information relating to events that occur when you use our services. Such data may include, for example, mobile data traffic or data received by alarm receivers. It may also be data obtained from access control systems, alarm systems, camera systems and similar systems. This can mean, for example, names, telephone numbers, user names, IP addresses, images, video clips and other similar data.

Electronic log files and data may also be data obtained from our websites and other digital channels. Such data is collected so that we can offer you a better user experience when you visit our digital channels, and to compile statistics for developing our services. Examples include name, address, telephone number, email address, user name and similar data.

Camera surveillance Many companies of the Prosero Group use camera surveillance in and around their premises to identify, prevent and detect crime. In such camera surveillance, particular attention has been paid to ensuring that the use of cameras has a lawful purpose and that the camera surveillance is necessary and proportionate for achieving that purpose. People who may be recorded by the cameras are informed of the surveillance by signs. The cameras do not record audio, and they have not been installed in places where people have a reasonable expectation of privacy.

What personal data we do not collect

We never knowingly collect sensitive personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or data concerning health or sex life.

Nor do we ever knowingly collect personal data from children under the age of 16. If you are the parent of a child under 16 and you find out that your child has provided us with personal data, please contact us so that we can delete the data.

How we collect personal data

We collect personal data in the following ways:

  • We collect personal data that you give us orally, by email, online and by other means
  • Electronic log files and data are collected automatically when you use our services
  • We may collect personal data from other external sources, such as publicly available registers of personal data and other registers used, for example, for credit assessment.
  • We may collect personal data generated when you use marketplaces and digital channels (cookies and other data).

When we may collect personal data

The legislation clearly states that the processing of personal data must have a so-called “legal basis”. This means that at least one of the following conditions must be met for us to be able to process your personal data:

Contract The data is needed so that we can fulfil a contract we have concluded with you (or a contract to which you intend to become a party). This applies, for example, when you are our customer or have asked us for an offer, a price quotation or similar.

Legal obligation The data is needed to fulfil a legal obligation. This applies, for example, to data needed to comply with the Accounting Act and similar laws.

Legitimate interest The data is needed so that we can communicate with you and inform you about our services and about events that may be of interest to you. This is called a legitimate interest. It requires that the processing of personal data is considered necessary for the legitimate interest (such as being able to communicate with you) and that your interest in the protection of your personal data does not override it. You can always object to this processing.

Legitimate interest also includes

  • Our need to retain the maintenance history of installations and security systems for longer than the duration of our customer relationship.
  • Our right to carry out camera surveillance, which means that we have the right to carry out camera surveillance of an area without the consent of the person being monitored in cases where the surveillance is necessary for the purpose in question. Special rules apply to camera surveillance in the workplace.

Consent Consent is also a legal basis for processing personal data. For consent to be valid, you must actively give it. Examples of such active behaviour are confirming a newsletter subscription by ticking a box on a website, filling in information in an online form, requesting information by email, answering yes to a direct question about whether we should send you information, handing over a business card or similar. Pre-ticked “I accept” boxes are not accepted as consent. You can withdraw your consent at any time.

How long we retain personal data

It is important for us to be able to guarantee the operation of alarm systems and other security systems. How long we retain personal data depends on the type of data, the purpose of retention and our legal obligations.

  • Customer data is retained for as long as you have a contract with us or for as long as your customer relationship with us is active, and for 24 months thereafter. If you have not expressly terminated your contract with us, the customer relationship continues for as long as you have been in contact with us in any way – in person, by telephone, by email, online or in a similar way – during the last five years. The exception is personal data that must be retained under the Accounting Act or other legislation.
  • Maintenance history is generally retained for the entire service life of the site’s security system. If you have not expressly informed us that the system has been decommissioned, the related data and service history are retained for 15 years from the date on which we last recorded an action or event for the system.
  • Electronic log files and data received by alarm receivers are generally retained indefinitely. This type of data contains only limited personal data, and it cannot be linked to an individual person unless customer data is stored.
  • Electronic log files and image and video data are generally retained for a maximum of two months or in accordance with the camera surveillance permit granted. Exceptions are made where the data must be retained because of a legal obligation.
  • Electronic log files and data obtained from mobile data traffic are retained for as long as you are our customer or for as long as our customer relationship is active, and for 24 months thereafter. Data that accounting or other legislation requires us to keep is an exception.
  • Electronic log files and data from websites and other digital channels are retained only until the purpose of collection has been fulfilled. Normally, this type of data and statistics are retained for a maximum of 24 months, but the period may vary depending on the purpose and objectives of the collection.

Website form data

Data submitted using the website’s forms is stored, in addition to email, in PAP Group’s own customer service system, where it is processed. The personal data in a form (for example name, email, telephone number, message and attachments) is deleted automatically after the following periods:

  • Orders: 6 years (retention period under the Accounting Act).
  • Contact requests and quote requests: 24 months. If a contact request leads to a customer relationship, the data is retained for 24 months from the start of the customer relationship.
  • Open job applications with attachments: 12 months. Applications are visible only to those responsible for recruitment.
  • Requests for customer accounts: 24 months.

Form data is also sent for processing to PAP Group’s email according to the subject (for example to sales, maintenance, support or customer service), and a backup copy is kept on the website’s server for 90 days.

If you select “Remember my contact details on this device” on a form (on the order form, “Remember my contact and invoicing details on this device”), your contact and invoicing details are stored only in your browser’s own storage so that the next form can be pre-filled. They are not transferred to PAP Group until you submit the form, and you can remove them by unticking the box or by clearing your browser’s site data.

After the personal data has been deleted, we retain only data from the submission that cannot be used to identify a person (for example form type, date, subject and town), for statistical purposes.

Document downloads

Product documents can be downloaded one at a time from the product pages without giving contact details. When you compile documents for several products into a single package (ZIP or compiled PDF), we send a download link to the email address you provide. We record the request, the opening of the link and the download, together with the related data (email address, selected products and documents, and the site name and compiler if you provided them), in PAP Group’s customer system. The data is deleted after 24 months, and the request is kept on the website’s server for 90 days. The download link is valid for 7 days.

When you open the download link, a necessary cookie, pap_lataus, is stored in your browser for 30 days so that you can download packages on the same device without confirming your address again. The cookie contains only a signed reference to the download request, not your email address. If you select “I would like to receive PAP’s newsletter”, we record your consent for the purpose of sending the newsletter. You can withdraw your consent at any time.

The basis for processing is the provision of the service you requested and our legitimate interest in monitoring for which sites and products documents are downloaded, and, as regards the newsletter, your consent.

Spam protection

We protect the forms and requests for document download links against spam with the Cloudflare Turnstile service. When a form opens, the service processes technical data about the browser and device (for example IP address, browser identifier and technical characteristics of the connection) to verify that the form is being submitted by a human. The service may use necessary cookies for this purpose. The data is not used for advertising or profiling, and the content of the form is not sent to Cloudflare. The basis for processing is our legitimate interest in protecting the service against misuse. Cloudflare, Inc. acts as a processor, and the data may be transferred outside the EU (see Transfers to third countries). More information: Cloudflare’s privacy policy and Turnstile privacy addendum.

To whom may we disclose your personal data?

Within Prosero, the companies cooperate with each other and with external parties, and we provide services in which a third party may process personal data. Such a third party is called a data processor.

When personal data is shared with a data processor, a data processing agreement is signed between the companies, setting out how the personal data is to be processed. A company acting as a data processor may not use your personal data for any purpose other than that for which it has been given access to the data.

Here we describe to whom we may disclose your personal data.

Companies of the Prosero Group Prosero provides security services in Sweden, Norway, Finland and Denmark, and there is continuous cooperation between the companies. This means that personal data may be transferred between the companies in order to deliver the services you have ordered.

Subcontractors and other companies that process personal data on our behalf. We use subcontractors in various fields to deliver the services you have ordered. This may be, for example, a subcontractor carrying out an installation or maintenance task, an alarm centre responding to an alarm, personal data stored in cloud services or similar. This means that personal data may be sent to external parties in order to perform the services you have ordered.

Authorities We are obliged to disclose personal data at the request of an authority where this is based on a decision.

Others If you have given your consent, we may also in other cases disclose your personal data to companies, organisations or persons outside our own company.

Transfers to third countries

A transfer to a third country means that personal data processed in an EU or EEA country is made available to a country outside the EU/EEA. If we transfer your personal data to a service provider located in a third country, we implement appropriate safeguards and ensure that the transferred data is processed in accordance with the applicable legislation.

Transfers relating to the website:

  • Cloudflare, Inc. (United States) provides the website’s server and storage, Cloudflare Web Analytics visitor statistics, Turnstile spam protection, the sending of form emails and the server platform of PAP Group’s customer service system. Data stored on the website’s server (form data and attachments, and document download requests) is stored and kept in the EU. Cloudflare, Inc. is a US company, and some of the services (delivery of the website, Turnstile, visitor statistics, email sending and the server platform of the customer service system) run on Cloudflare’s global network, so data may also be processed outside the EU. The transfers are based on the European Commission’s standard contractual clauses. Cloudflare is also certified under the EU–US Data Privacy Framework.
  • Google Analytics (Google) data may also be processed in the United States. Google Analytics is used only if you accept analytics cookies (see Cookie policy).

How we protect your personal data

The requirements for companies in the security sector are high, and an important part of this is protecting data, documents and the privacy of customers. Our security work covers not only strong protection of our premises but also protection of our IT infrastructure. Particular attention is paid to information security in order to prevent and detect data leaks or data loss.

Your rights

We require that information about your rights and our processing of personal data is easily accessible and described clearly and concisely. Here we describe your rights step by step.

Right to information

You can request, free of charge (once a year), an extract from the register showing what types of data have been recorded about you. The requirement is that the information we provide must be given in writing (which may also be in electronic form) and in clear and plain language.

We will respond to your requests without undue delay (usually within one month), and if for some reason we are unable to fulfil your requests, we will give the reasons for this. To ensure that we do not disclose data to unauthorised persons, data is disclosed only after identification.

Right to rectification

You have the right to have your personal data rectified and completed with relevant information if you consider the data we hold to be inaccurate or insufficient. If personal data has been provided to subcontractors or similar parties, we will notify them when the personal data has been corrected. Exceptions are made where this would be impossible or too laborious. You can always request information about to whom the data has been disclosed.

Right to erasure

You have the right to have your personal data erased without undue delay. The exception is personal data that must be retained under accounting or other legislation. You can request the erasure of your personal data if one of the following conditions is met:

  • If the data is no longer needed for the purposes for which it was processed.
  • If the processing is based solely on your consent and you withdraw it.
  • If the processing takes place for direct marketing purposes and you object to the processing of the data.
  • If you object to processing based on legitimate interest, and there are no legitimate grounds for the processing that override your interests.
  • If the personal data has not been processed lawfully
  • If erasure is necessary to comply with a legal obligation.
  • If the personal data is erased and we have disclosed your personal data to subcontractors or similar organisations, we will notify them after the personal data has been erased. This does not apply if notification is impossible or would require unreasonable effort. On request, we will tell you who has received the data.

Right to restriction

You have the right to request a temporary restriction on processing your personal data. Restriction means that the data is marked so that in future it can be processed only for certain limited purposes. Processing may be restricted in the following situations:

  • When you believe that your personal data is inaccurate and you have asked us to rectify it. You can then ask us to restrict its processing while we check the accuracy of the data.
  • If the processing of the data is unlawful, but you oppose the erasure of your personal data and request the restriction of its use instead.
  • If we no longer need your personal data for our processing purposes, but you need your personal data for the establishment, exercise or defence of legal claims.
  • If you have objected to the processing of your personal data, you can request that the use of the data be restricted for the duration of the investigation.

If restriction has been requested and we have disclosed your personal data to subcontractors or similar organisations, we will notify them of the requested restriction. Notification is omitted only if it would be impossible or unreasonably laborious. You can always request information about to whom your personal data has been disclosed.

Right to data portability

You have the right to receive your personal data so that it can be used elsewhere, for example by another service provider. We must facilitate such a transfer and provide the data you have provided to us in a structured, commonly used and machine-readable format, such as a text file or a similar format.

You can request data portability if we process your personal data on the basis of consent or on the basis of a contract concluded with you. However, the right to data portability does not apply if we process this data on the basis of legitimate interest or a legal obligation.

Clarifications concerning consent, legitimate interest and legal obligation are given above in the section “When we may collect personal data”.

Right to object

If we process your personal data on the basis of legitimate interests, you always have the right to object to the processing. In that case, you must specify which processing you object to, and we must stop processing your personal data or demonstrate that there are legitimate grounds for the processing.

If your personal data is used for direct marketing, you may object to the processing at any time. If direct marketing is objected to, the data may no longer be processed for that purpose.

Right to lodge a complaint

If you believe that we are processing your personal data in breach of the applicable regulations, please contact us as soon as possible so that we can correct the incorrect processing. You can also lodge a complaint with the national supervisory authority, which will decide whether to carry out an investigation. The contact details of the supervisory authorities can be found on the European Data Protection Board website.

Right to claim compensation

If you have suffered damage because your personal data has been processed in breach of the General Data Protection Regulation, you may have the right to receive compensation from the controller or processor involved in the processing.

A processor may be liable for damages if it has breached rules specifically concerning processors or has processed your personal data contrary to the controller’s instructions.

If you have suffered damage, you can also bring an action for damages.

Processing of personal data in whistleblowing cases

You can remain completely anonymous if you wish. However, if you choose to provide personal data about yourself or other persons in a whistleblowing case, Prosero Security Group will process that personal data.

Processing carried out

Storage and processing of personal data relating to whistleblowing reports in an external reporting system.

Personal data processed

Personal data that is necessary for the whistleblowing case. Special categories of personal data may be included if this is necessary because of the nature of the case.

The identity of the person making the report is encrypted and anonymised through the reporting system. We encourage reporters not to enter information about themselves or other personal data that is not relevant into the reporting system.

Legal obligation. The processing is necessary to comply with EU Directive 2019/1937 on the protection of whistleblowers and, in Finland, the Act on the Protection of Persons Reporting Breaches of European Union and National Law (Whistleblower Protection Act 1171/2022).

A report can be made through the Prosero Group’s reporting channel.

Retention period

The data is retained for two years from the end of the processing of the whistleblowing case and/or for as long as necessary due to other legislation, court decisions or decisions by authorities.

Transfer of personal data

Where necessary, we may share your personal data with external advisers, IT service providers and authorities.

Changes to this privacy notice

We reserve the right to make changes to this privacy notice from time to time. If the changes are significant, we will inform you of the changes and what they mean for you before they take effect.

Contact details

If you wish to check, rectify, complete or erase your personal data, object to its processing, or have questions about how we process your personal data, please contact the controller: PAP Group Oy, Niittytie 25 A, 01300 Vantaa, Finland, email info@pap.fi, telephone +358 29 000 1112.

The same privacy notice is used generally within the Prosero Group. Contact details for other Prosero companies can be found at prosero.com.

This cookie policy explains what cookies and browser storage our website uses and how you can manage them.

What are cookies?

Cookies are small text files that are stored on the user’s device when they visit a website. In addition to cookies, the website may store data in the browser’s own storage. Session storage is cleared when you close the browser tab; browser storage is kept until you clear your browser’s site data.

Necessary cookies and storage

These are needed for the website to work or for functions that you use yourself. They are not used for tracking and do not require consent.

  • pap-suostumus (browser storage): your cookie choices, 12 months.
  • pap-teema (browser storage): the light or dark theme you have chosen.
  • pap-tarjouskori (browser storage): the products you have added to a quote request.
  • pap-dokumentit (browser storage): the products you have selected for document download.
  • pap-lomaketiedot (browser storage): your contact and invoicing details, only if you choose to have them remembered on a form (see Website form data).
  • pap_lataus (cookie): email confirmation for document downloads, 30 days (see Document downloads).
  • Storage items beginning with pap-liidi (session storage, one per form): prevent the same form submission from being recorded twice.
  • pap-asiantuntija (session storage): the state of the expert card. The card shows the contact details of the appropriate team once you have explored a topic. The data (for example the topics of pages viewed and active time) is calculated in the browser and is not sent anywhere.
  • pap-palopainike-vinkki, pap-pohjapiirros and pap-pohjapiirros2 (session storage): the state of the website’s demonstration features during the same visit.
  • Cloudflare Turnstile may use necessary cookies for spam protection of forms (see Spam protection).

We use the Google Analytics 4 service to compile statistics on the use of the website only if you accept analytics cookies. No data is sent to Google before consent is given.

  • _ga and _ga_L83VQHW7PG (cookies): Google Analytics visitor identifiers, up to 2 years.
  • pap-kampanja (session storage): campaign data on how you arrived at the website (for example UTM parameters) is attached to a form submission only with analytics consent and only for the duration of the same visit.

We also use the Cloudflare Web Analytics service, which calculates visitor statistics without cookies and without storing data on your device.

We also count, on the website’s own server, how many contact requests, quote requests, orders, phone and email link clicks, document downloads and other actions take place on the website. The count uses no cookies, stores nothing on your device and cannot be linked to you: we only store daily totals by page, language, referring website (domain or campaign UTM tag) and device type (mobile or desktop). Your IP address is used only momentarily to prevent abuse and is not stored. The legal basis is our legitimate interest in developing the website and our marketing.

Managing cookies

You can change or withdraw your consent using the Cookie settings button at any time in the website footer. When you withdraw consent for analytics, Google’s cookies are deleted.

You can also manage cookies and clear site data in your browser settings. Please note that deleting necessary storage may affect how the website works, for example the quote request basket.

We update this cookie policy when the use of cookies or the applicable legislation changes.

Expert help

Where should you start with your property?

Tell us about your property and what you need help with – we will put you in touch with the right specialist.