- We have a culture of respecting your privacy.
- We need to process certain data to provide you with our services.
- Whenever feasible, we make your data anonymous or near-anonymous.
- We know security.
Our guiding principles for processing your personal data are here.
Our data collection can be categorized as follows:
- Service data; the data that we automatically process to provide you with the services that you have requested. This also includes the data that you actively submit to us when subscribing to our services. This is explained in this policy.
- Analytics data; additional anonymous or pseudonymous data that we collect to learn when and how our services are found and used. This is explained here.
This is what we mean when we make certain references within this policy.
"Client", "you", refers to a private or corporate user or any other data subjects who buy, register for use, or use our services and who may have submitted personally identifiable information to us. This information may have been submitted through the use of our services (including web solutions), web sites, telephone, e-mail, registration forms, or other similar channels.
"Personal data" refers to any information on private individuals and their personal characteristics or circumstances, which are identifiable to them or their family or household members. This information may include names, e-mail and mailing addresses, telephone numbers, billing and account information, and other information incidental to the services and their provisioning.
"Services" refer to any services or products that are manufactured or distributed by F-Secure, including software, web solutions, tools, and related support services.
"Web site" refers to the www.f-secure.com web site or any other web site that F-Secure hosts or controls, including sub-sites and browser-based service portals.
What do we collect?
We typically need to ask at least for your email address, phone number, and name to be able to provide our services. The individual services also collect additional data directly both on our service and from your device and related data traffic. In cases of such automated collection, the focus of data collection is on our services, not on your private data.
The adjoining service and interaction-specific policies explain in more detail the personal data collected per service type.
What do we do with it?
This list describes the general purposes for the collected personal data.
- Customer journey. To identify authorized users and check customer qualifications, process and track transactions such as administering accounts, shipping, invoicing, and managing licenses;
- Deliver, fix, and enhance. To deliver our services to you, maintain and develop our services and web sites, and to provide help and support for the services;
- Analyze. To track how our services are acquired and used so that we can improve the services, manage your customer relationship, and approach you with relevant messages;
- Communicate. To send you information relating to the services, conduct customer surveys, arrange competitions, advertise and market our services to you;
- Regulatory. To prevent fraudulent activities, remove or stop sharing of illegal or infringing material, and comply with legal or regulatory requirements.
The adjoining service and interaction-specific policies explain in more detail the specific purposes for the collected personal data.
Why we need to process your data
By using our services, you are our client. Because of this relationship, we have a right to process relevant personal data.
Such data processing may occur when you communicate with us or our business partners relating to our services, install and use our services, fill out a form or survey, register to use our services, submit information through our web solutions, enter a contest or sweepstakes, register your e-mail address with us, or send us e-mail.
We need to automatically collect and process relevant personal data for our services to work, to enhance them, and to provide them to you. Due to the nature of our services, it is impossible to completely avoid data collection without preventing the services from functioning. As such processing is inseparable from the services we provide to you, this gives us a valid need to process your data and legal authorization to do so. However, we seek to give you as much control as possible. For example, we may ask you for your separate consent for some data collected or provide a possibility to opt out from non-critical data collection.
While some of our services have dedicated privacy policies to help you better understand the data collected by that particular service, we consider you a client of F-Secure, not a client of the individual service. Hence, data collected by different services (e.g. SAFE) and interactions (e.g. contacting support) are combined to your F-Secure account. However, we do not aggregate data against our specific privacy promises (for example, we maintain a hands-off approach to your traffic inside our VPN service).
We do much ourselves, but also have partners to help us provide our services. This also means that we need to exchange data with our partners. When doing so, we take great care in sharing only the necessary personal data.
We have explained below the two main instances of such personal data exchanges.
We may disclose some of your personal data to subcontractors and F-Secure group companies who provide parts of our services that you use.
2) Sales and marketing
We exchange (both disclose and receive) some of your personal data with our distribution partners (resellers of corporate IT services, operators, webstores, etc,), who market, sell and distribute our services. We provide these companies access to such personal data that they need for their agreed activities. The logic of this data sharing is to provide a seamless customer experience. This includes activities such as customer management, service support and problem resolution, direct marketing, and invoicing. Our distribution partners must also comply with the agreements and legislation when handling your personal data.
Most of our distribution partners may have a pre-existing customer relationship with you and are processing your personal data as an independent entity. In such cases, both F-Secure and the distribution partner have separate customer data entries on your customer relationship that are subject to our respective policies.
Some of our affiliates, subcontractors, distributors, and partners are located outside the European Economic Area to ensure the global reach and availability of our services. When we transfer personal data outside the European Economic Area, we secure such transfers of personal data according to the requirements of the law. We do this by imposing appropriate technical and contractual safeguards on relevant subcontractors and F-Secure group companies, for example by using data transfer clauses that are approved by the European Union. We only do global or cross-border data transfers for a good reason and after assessing the resulting privacy risk.
More importantly, we store more sensitive customer data within Finland and the European Economic Area and keep it under our own control.
One example includes complying with a court order or a warrant issued by the authorities in the relevant jurisdiction to compel the production of information. We weigh each disclosure requirement carefully and take the possibility of such disclosure requests into account when deciding where and how we store your personal data.
Disclosing your personal data may also be justified to protect ourselves against liability or to prevent fraudulent activity, or where it is necessary to solve or contain an ongoing problem. In any such action, we will act according to the applicable laws.
We may also need to transfer your personal data as part of a corporate transaction, such as a sale, merger, spin-off, or other corporate reorganization of F-Secure, where the information is provided to the new controlling entity in the regular course of business.
We may also disclose your personal data to our insurers and to governmental regulatory agencies if so required by applicable laws.
We retain your personal data in our databases in line with our data retention practices.
The default rule under Finnish – and many other applicable – laws, is that personal data should be deleted or anonymized once we no longer need it for the purpose it was collected.
Consequently, we store the personal data of our customers for varying durations, depending on the type of data. This also means that we may retain your personal data beyond the end of your client relationship with us, but only as long as we continue to have a valid reason. Typical reasons include:
- to allow us to pursue available remedies or to limit any damages that we may sustain (e.g. due to an ongoing dispute or investigation)
- to solve or contain a recurring problem or to have enough information to respond to future issues (e.g. your support ticket related to a problem that was not permanently corrected during your customership)
- to uphold agreements between you and us (e.g. you continue to subscribe to our other services)
- to prevent fraudulent activity (e.g. to enforce a ban on our community)
- if applicable laws require us to store the data (e.g. to keep track of your purchase and the payment of our services)
- to communicate with you (e.g. keeping your personal data stored for the grace period after the end of your subscription or sending you communications after your customership if you have elected to receive them).
We do not seek to store your customer account data indefinitely. Once there has been no activity in any of our services related with your customer account or in our community for a set time, we delete your account. We will contact you in advance of such deletion so that we do not delete your account against your wishes.
For more sensitive data relating to specific services, we have separate retention practices.
Data that does not contain personal data (e.g. security data and aggregate analytical data) is retained as long as such data is needed and is useful for the purpose it was collected.
We apply strict security measures to protect the confidentiality and integrity of your personal data when transferring, storing or processing it.
We use physical, administrative and technical security measures to reduce the risk of loss, misuse or unauthorized access, disclosure or modification of your personal data.
We seek to keep your personal data accurate, complete, and up to date.
Some of our services portals allow you to update your customer information. For such, you should update any changes to your personal data, for example, change of address or e-mail address. If you cannot update the changes yourself, you may inform us of the necessary changes.
You can contact us for more details about how your personal data is processed or to cancel your consent. Our contact information is included in this policy. You can unsubscribe from receiving marketing messages by following the instructions that are included in each message.
You have the right to ask us what personal data we have on you.
If you wish to minimize the data we collect when providing our services to you, we provide you the possibility to opt out from non-critical data collection. The same applies to our communications.
Our services and websites may embed or interoperate with third-party services.
The most prevalent such scenarios are the following:
- Webstore. Our webstore is partially run by a third-party reseller. While the data you enter in the registration phase is handled under F-Secure policies, our webstore providers' policies apply to the actual purchase and related activities.
- Device location queries. When you query the location of your device via our services, the provider of maps needs to process the related geographical data. On the publication date of this policy, F-Secure uses Google maps in our device location and search features. Google privacy policies shall apply accordingly to your use of the features.
- External features. Where the third-party service is a visible, separately branded part of your user experience, such third-party services' privacy policies apply in lieu of this policy.
While we collect the majority of the above-mentioned data directly from you or your device, we also receive data from our affiliates, distribution partners (such as operators), and corporate entities from whom you have purchased the services. Such entities may be our resellers, but also include our external webstore partners. We also acquire some basic personal data (order data on purchases) and aggregate analytical data from app stores in which our services are sold. Such other sources may further include subcontractors who have provided you with support services, or advertising partners who have assisted us in conducting our marketing activities.
We do this to create a seamless customer experience and to have the necessary information for solving support cases.
Typical examples of this kind of "third-party collection" are:
- collection of your data from registration information that you have submitted to our external webstore,
- we acquire your contact data from previous sign-in data from our operator reseller partner providing our service to you, and
- when you use your social media account to register to our services, we collect the e-mail address from your account to enable us to authenticate your registration and to contact you.
- To provide services that our customers need, we analyze how our services are used.
- We look at trends among our users, not at individual users.
- We do this on our web site and in our products.
- You can choose whether you want to participate.
Why we do this. We want to give you a more personal customer experience and provide you with even better services in the future. For that we need to track usage patterns and customer segments in aggregate. For example, what features are used most, where the service fails, what needs fixing, and how you found out about our services.
What we collect. Data analytics running in our services include things like the Internet browser that you use, elements clicked, timestamps, general location, device identifier and relations between devices / users / user groups, service operation time, device metrics (such as phone model and operation system, language), partial IP address, service errors, problematic files and service performance data, how you interact with our services (such as which features are used and how often), the domain name from which you connect to the service and the service features that you use, effectiveness of our commercials, installation success, installation and activation paths, performance, operation environment, connections, data routing, quota, as well as other similar data.
Data analytics running on our web sites are described in a dedicated policy.
How we treat such data. We are interested in the needs and behavior of our customers as part of a group, not in the names of those customers. When analyzing data inside F-Secure, we transfer the collected analytics data to statistics, demographics, and customer segments. We treat the collected analytics data as anonymous and have safeguards to prevent the identification of individual customers.
We keep the full data set safe. We use the full set of collected data only internally and do not give it to others.
Some data is exchanged. Because of the technical environment (that is, the Internet, the app store ecosystem, and social media), we are not able to do all of the data analytics collection and activities ourselves. We have to exchange some pseudonymous data (such as "Android marketing identifier" and other like identifiers) with our online analytics and marketing partners. Data on your actions may be shared in the following scenarios, for example:
- We use data aggregators to enable you to access our product through other applications and to track the immediately following actions. In such cases, the data created from such activity is shared to the relevant parties.
- Our subcontractors that provide us with analytics services may also create and publish aggregate reports on the data that they have collected. The statistics and aggregate reports do not contain any data that could be linked to any individual person.
This is a necessary evil in almost all digital analytics and marketing activities. The only way this may be visible to you is in the types of ads you see when browsing or using our applications, but it has no impact on the amount of ads you see in your online life.
We do not sacrifice your privacy. Where we differ from most companies doing this is in that we understand how the ecosystem works and go through great pains to select our few partners with care, removing all data that is not absolutely necessary for the above purpose. You can naturally opt out from the collection of analytics data at any time via the service settings.
We also limit such added analytics only to the surface of our services and keep them at arm's length from the core privacy areas of our services. For example, we do not have any external analytics in our security cloud or in the traffic inside our VPN service.
- We aim to keep our marketing relevant.
- The marketing permission links the aggregated results of data analytics to your account.
- You can adjust your marketing choices in your subscription portal.
Our marketing activities
We hope to send you relevant news, advice, offers, and other marketing communications. These help you get more our of our services and to protect your online life.
Firstly; with your consent, we send you direct marketing communications to your email or similar contact information that we have for you (e.g. you have indicated that you wish to receive our newsletters when subscribing to our service or when participating in a competition).
Secondly; in addition to direct marketing communications, we may also send you communications related to services, unless you have asked not to receive such communications.
Thirdly; we do marketing on the Internet, through third-party apps, and through other channels.
We seek to make our marketing communications relevant to you. Where allowed by your service and browser settings, we profile you based on your interaction with our services, web sites and the data collected via our online and in-app marketing activities. In so doing, we aggregate data, use pseudonyms and take other measures to keep our marketing analytics non-intrusive.
When you give permission for direct marketing, we connect the results of data analysis to you, so we can better serve you. You can request to be removed from our marketing communications at any time.
We may use our subcontractors and partners to undertake marketing activities on our behalf. Our marketing communications relate primarily to our services. In some cases, they may also relate to services of our distribution partners that relate to our services. However, our business models do not rely on selling your personal data to third-party mass marketers. For us, you are not a product. For us, you are a customer.
Your choices with analytics and marketing
We have sought to create a mutually beneficial solution by pairing your level of engagement with us and how accurate our analytical data is on your account.
By default, the analytics data you contribute to us is treated as anonymous. However, if we have your permission to send you "tips and offers" on how to better use our services, we will connect some of the information derived from the analytics data to you in order to give you more relevant tips and offers.
If you opt out from receiving our "tips and offers", then any analytics data you submit is only used for building better products, but the link between analytics data and your customer account is severed.
You can choose on a service-per-service basis whether you want to contribute to our analytics activities. The choice of whether you wish to have "tips and offers" from us and have derivative information from the analytics data connected to you is common for all services that you have under the same F-Secure user account. You can further adjust such settings from your subscription center, which we will gradually make available to all our services.
We really appreciate it if you help us improve our services. However, if you want to minimize all data traffic towards F-Secure, we respect that. Those of our services that employ additional analytics allow you to opt out from subsequent collection of such non-essential data collection.
If you have opted out from all analytics data collection, our messaging to you will be only based on the service data collection (the data we collect in any case to provide you with the services) and our tips are likely to be less relevant.
If you are against the collection of any data analytics, the more wholesale method for preventing online advertisers from profiling your mobile device usage is to reset the advertising identifier from time to time and to turn on the do-not-track setting in your device settings or use our privacy product.
This version of the policy clarifies, updates, and replaces the previous policy. To continue keeping this policy up to date, we will make changes and additions to this from time to time also in the future.
© F-Secure, December 2015