Effective date 1 November 2018
Effective date 1 November 2018
We care about your privacy
We will give you additional privacy information that is specific to a product or service in Supplements to this Policy and other notices you may see while using our products or services. If there is a difference between such notices and this Policy, the notices should be considered first.
Please take a moment to familiarise yourself with our Policy and let us know if you have any questions.
What information do we collect?
We collect your personal data and other information when you make a purchase, use or register into our products and services, take part in campaigns or research, or otherwise interact with us. This includes the following categories:
- Product and service activations. HMD products and services may require electronic activation, where your device and application type, as well as unique device, application, network and subscription identifiers are sent to HMD.
Use of products and services.
- When you access our services online, our web servers automatically create records of your visit. These records typically include IP addresses, access times, the sites linked from, pages visited, the links and features used, the content viewed or requested, browser or application type, language and other such information. Our applications may contact our servers periodically, for example to check for updates or to send us information relating to service usage.
- Improvement Programs. We may invite you to join voluntary product and service improvement or research programs, where detailed information is collected. For more information, see our User Experience Program Supplement.
- Positioning and Location data. Location-based services establish either your exact or approximate location through the use of satellite, mobile, Wi-Fi or other network-based positioning methods. These technologies may involve exchanging your location data and unique device and mobile, Wi-Fi or other network related identifiers with HMD. We do not use this information to identify you personally without your consent.
- Information you provide us. When you create an account, make a purchase, request services, participate in research or campaigns or otherwise interact with us, we may ask for information such as your name, email address, phone number, street address, user names and passwords, feedback, information relating to your devices, age, gender, and language, bank account number, credit card details and other such financial information. We also maintain records of your consents, preferences and settings relating to, for example, location data, marketing and sharing of personal data.
- Information we receive from third-party sources. We receive certain information from third-party social network services, for example when you log in to your account by using your social network account login details. See our account Supplement for Nokia phones for more information.
- Your transactions with us. We maintain records of your purchases, downloads, the content you have provided us with, your requests, the products and services provided to you, payment and delivery details, your contacts and communications and other interactions with us. We may, in accordance with applicable law, record your communication with our customer care or with other such contact points.
Why do we process personal data?
HMD may process your personal data for the following purposes. One or more purposes may apply simultaneously.
- Providing products and services. We use your personal data to provide you with our products and services, to process your requests or as otherwise may be necessary to perform the contract between you and HMD, to ensure the functionality and security of our products and services, to identify you as well as to prevent and investigate fraud and other misuses. For example, we use device activation data to activate your device warranty and to provide you with related customer care services.
- Personalising products and services. We use your personal data to personalise our products and services that you are using and to provide you with more relevant services that match with your profile and interests, for example, to make recommendations and to display customised content in our services.
- Accounts. Some services require an account to help you manage your content and preferences. For more information, see our account Supplement for Nokia phones.
- Developing products and services. We use your personal data to develop our products, services, customer care, sales and marketing. For example, you can join our User Experience Program to provide us with your personal data to improve the quality and performance of our products and services. For more information about how we use your personal data to develop our products and services, see our User Experience Supplement. We may combine personal data collected in connection with your use of a particular HMD product and/or service with other personal data we may have about you, unless such personal data was collected for a different purpose.
- Communicating with you. We use your personal data to communicate with you, for example to inform you that our services have changed or to send you critical alerts and other such notices relating to our products and/or services and to contact you for customer care related purposes. For more information about how we use your personal data to provide you with our customer care services, see our Nokia Mobile Care Supplement.
- Marketing. We may contact you to inform you of new products, services or promotions we may offer and to conduct market research when we have your consent or it is otherwise allowed. We may use your personal data to personalise what we offer and to provide you with more relevant services that match with your profile and interests for marketing purposes, for example displaying customised content in our services, and to make recommendations for accessories. This may include displaying HMD and third-party content.
What are the bases for this processing?
HMD processes your personal data only when it is lawful to do so. The processing is based on the following legal grounds:
Contract. Processing your personal data is necessary for the performance of a contract between you and HMD. We use your personal data to provide you with our products and services and to ensure their functionality and security. If you do not provide us with the necessary information, it means that we are not able to provide the product or service to you. The contract is the basis for this processing, for example, when
- We collect necessary personal data to process the payment and deliver your purchases.
- We communicate with you, for example, to inform you about software updates, to send you critical alerts and other important notices relating to our products and/or services and to contact you for customer care-related purposes.
Legitimate interest. HMD processes personal data when it is necessary for the purposes of legitimate interests pursued by HMD. Legitimate interest refers to an interest that is lawful and important for HMD. In processing activities based on legitimate interest, your rights are taken into account and balanced with the interests of HMD. You may obtain more information on the balancing tests by contacting us. You have the right to object to processing based on legitimate interest. Read more about your rights and how to contact us in section "What are your rights?" Legitimate interest is the basis for the processing, for example, when
- You activate HMD products and services electronically and your device and application type, as well as unique device, application, network and subscription identifiers are sent to HMD.
- We contact you to inform you of new similar products or services that you have previously obtained from us.
- We may use your personal data to personalise our offering and to provide you with more relevant services that match with your profile and interests, for example, to make recommendations and to display customised content and marketing in our services. This may include displaying third-party content.
- We analyse information about your interests, buying behaviour and feedback to develop our business operations, products and services.
- We process personal data to prevent and investigate fraud and other misuses and defend HMD's legitimate interests, for example, in civil or criminal legal proceedings.
Consent. Processing your personal data can be based on your consent. In these situations, we ask your consent before your personal data is processed. Giving consent is always voluntary and you have the possibility to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before the withdrawal. We maintain records of your consents, preferences and settings relating to, for example, marketing, location data, and sharing of personal data. Consent is the basis for processing in the following situations:
- You participate in the User Experience Program and we collect details of how you use a particular HMD product and/or service. We use the data to improve our products and services. You can withdraw your consent in your device's settings. For more information, please see our User Experience Program Supplement.
- You subscribe to our mailing list to hear about new products, services and promotions. You can withdraw your consent for marketing by using the unsubscribe link at the bottom of the newsletter.
- The service requires an account to help you manage your content and preferences. You can manage your consents for the processing in your account's settings.
- Use of HMD products and services may involve use of location data based on your consent. You can withdraw your consent for the processing of location data in your device's or application's settings.
- Legal obligation. HMD may need to process your personal data to comply with legal requirements to which HMD is subjected. HMD can have, for example, a legal obligation to disclose your personal data to the authorities when requested.
Do we share personal data?
We do not sell, lease or rent your personal data to third parties. We disclose your personal data to third parties in the following situations only:
- HMD companies and authorised third parties. We may share your personal data with other HMD companies or authorised third parties who process personal data for HMD the purposes described in this Policy. This may include for example billing through your network service provider or otherwise, delivery of your purchases, providing services including customer service, managing and analysing consumer data, credit checks and conducting research. When you purchase an HMD product, we may need to exchange information with your network service provider. These third parties are not permitted to use your personal data for any other purposes. We require them to act consistently with this Policy and to use appropriate security measures to protect your personal data.
- Marketing. We may share your personal data with our marketing partners, for example to manage marketing campaigns. We may conduct joint marketing and other communications with our partners. To avoid duplicate or unnecessary communications and to tailor the message to you, we may need to match information that HMD has collected with information that the partner has collected where this is permitted by law. Our marketing partners are not permitted to use your personal data for any other purposes. We require them to act consistently with this Policy and to use appropriate security measures to protect your personal data.
- International transfers of personal data. Our products and services are provided using resources and servers located in various countries and regions around the world, including the European Union, United States of America, Singapore and China. Therefore your personal data may be transferred across international borders outside the country where you use our products and services, including to countries outside the European Economic Area (EEA) that do not have laws providing specific protection for personal data or that have different legal rules on data protection. In such cases we ensure that there is a legal basis for such a transfer and that adequate protection for your personal data is provided as required by applicable law, for example, by using standard agreements approved by relevant authorities (where necessary) and by requiring the use of other appropriate technical and organisational information security measures.
- Mandatory disclosures. We may be obliged by mandatory law to disclose your personal data to certain authorities or other third parties, for example, to law enforcement agencies in the countries where we or third parties acting on our behalf operate. We may also disclose and otherwise process your personal data in accordance with applicable law to defend HMD’s legitimate interests, for example, in civil or criminal legal proceedings.
- Mergers and Acquisitions. If we decide to sell, buy, merge or otherwise re-organise our businesses in certain countries, this may involve us disclosing personal data to prospective or actual purchasers and their advisers, or receiving personal data from sellers and their advisers.
How do we address the privacy of children?
HMD products and services are typically intended for general audiences. HMD does not knowingly collect information relating to children without the consent of their parents or guardians.
What steps are taken to safeguard personal data?
Privacy and security are key considerations in the creation and delivery of our products and services. We have assigned specific responsibilities to address privacy and security related matters. We enforce our internal policies and guidelines through an appropriate selection of activities, including proactive and reactive risk management, security and privacy engineering, training and assessments. We take appropriate steps to address online security, physical security, risk of data loss and other such risks taking into consideration the risk represented by the processing and the nature of the data being protected. Also, we limit access to our databases containing personal data to those authorised persons who have a justified need to access such information.
How long is the data retained?
We take reasonable steps to keep the personal data we possess accurate and to delete incorrect or unnecessary personal data. Retention periods vary depending on type of data and the service or product in question. The retention time of your personal data is determined in accordance with the following criteria:
|Data type||Retention time|
|Product and service activation information (e.g. unique device, application, network and subscription identifiers)||The data is retained during the warranty period and 24 months after the warranty period ends.|
|User experience program data (e.g. IMEI, stability, battery status)||The data is retained for 6 months after the data is collected or if you withdraw your consent for the processing.|
|Account information (e.g. name, email address, user names, passwords)||The data is retained as long as the account is active. If the account has been inactive for 24 months, the data will be deleted.|
|Purchase information (e.g. records of purchases and downloads, bank account number, credit card details)||In order to comply with accounting regulations, the data is retained for 10 years after the data has been collected.|
|Communications and interactions information (e.g. name, email, requests)||The data is retainded for 24 months after the data is collected.|
In addition, HMD is subject to legal obligations to retain the data to comply with the mandatory laws.
What are your rights?
You have a right to know what personal data we hold about you as specified below. You have a right to get any incomplete, incorrect, or outdated personal data completed or updated. In certain cases you have a right to erasure, restriction or data portability, or to object to processing of your personal data. You may exercise your rights by managing your account and choices through available profile management tools on your device and our services or by contacting us. In some cases, especially if you wish us to delete or stop processing your personal data, this may also mean that we may not be able to continue to provide the services to you.
- Right of access. You have a right to know what personal data we hold about you or to receive a confirmation that we do not process data concerning you. You can access your data through your account's settings. You can also request access to your data by using the contact details below.
- Right to rectification. You have the right to get any incomplete or incorrect personal data rectified. You can correct and update your data through your account's settings and we encourage you to do this from time to time to ensure your personal data is up to date. You can also request the rectification or completion of your data by using the contact details below.
- Right to be forgotten. You have the right to get your personal data erased in certain situations, for example, when the processing of your data is no longer necessary for the purposes for which it was collected, or if the processing is based on your consent and you want to withdraw your consent and there are no other bases for processing. Please note that the data can be necessary to perform the contract between you and HMD, or HMD can have compelling legitimate grounds to retain certain data. If you want to delete such information, it means that we may not be able to continue to provide the services to you. You can erase your data via your account's settings or by using the contact details below.
- Right to object. When the processing of your personal data is based on a legitimate interest, you have the right to object to such processing. You can request that we stop processing your personal data for direct marketing or profiling purposes. You can unsubscribe from our newsletter by clicking on the unsubscribe link at the bottom of our newsletters. Critical alerts and other important notices may still be sent to you. You can use your right to object via your account's settings or by using the contact details below.
- Right to restriction of processing. In certain situations you may have the right to restrict the processing of your data. When the processing has been restricted, your data will only be stored and not processed further. For example, if you contest the accuracy of your data, you have the right to have the contested data under a restriction of processing while it is ensured that your data is accurate. You can use your right to restrict the processing by using the contact details below.
- Right to data portability. When processing is carried out by automated means and based on a contract or consent, you have the right to obtain the data you have provided to HMD in a machine-readable format so that you can transfer it to another controller. This can be executed through your account's settings or by using the contact details below.
If you cannot use your rights directly through the HMD products and services you use, you can contact us via
- Nokia phones account portal: www.nokia.com/phones/sso/login
- Customer support: www.nokia.com/en_ca/phones/support#contact-us
- Support application in your Nokia phone
- Mail: HMD Global Oy, c/o Privacy, Bertel Jungin aukio 9, 02600 Espoo, Finland
Who is the controller of your personal data?
HMD Global Oy is the controller of your personal data when the personal data is processed in connection with your Nokia phone, Nokia phones account and other related services. Our Data Protection Officer is Jari Koljonen.
In matters pertaining to HMD’s privacy practices you may also contact us at:
HMD Global Oy, c/o Privacy, Bertel Jungin aukio 9, 02600 Espoo, Finland
Our products or services may contain links to other companies’ websites and services that have privacy policies of their own. All links to such websites and services are provided for your convenience only. Before submitting your personal data to third parties, HMD recommends you take a moment to familiarise yourself with these third-party privacy policies.