Privacy Policy

Woltti EV charging service — last updated 18 August 2026

This privacy policy describes how Wolttinen Oy (business address Lemuntie 7A, 00510 Helsinki, Finland; “Woltti”, “we”) collects and processes personal data when you use the Woltti electric vehicle charging service — the Woltti web portal, the Woltti mobile applications and charging stations connected to the Woltti platform (together the “Service”). Wolttinen Oy is the data controller for this processing within the meaning of the EU General Data Protection Regulation (GDPR).

1. Data we collect

CategoryExamplesSource
Account data Name, email address, phone number, preferred language, account credentials Provided by you at registration, or by your organisation’s administrator
Google sign-in data Name, email address, email verification status, Google account identifier Google, when you choose to sign in with your Google account (see section 2)
Apple sign-in data Name (shared once, at first sign-in), email address or Apple private relay address, Apple account identifier Apple, when you choose to sign in with your Apple account (see section 2)
Charging data Charging sessions (station, time, energy consumed, price), RFID tag identifiers, vehicle information you add (e.g. registration plate, battery capacity) Generated by your use of the Service; provided by you
Billing data Invoices, receipts, account balance, payment transaction references Generated by your use of the Service; our payment service provider
Technical data Log entries, IP address, browser/app version, cookies required for signing in Generated by your use of the Service

Payment card details are handled by our payment service provider and are never stored on Woltti servers.

2. Sign-in with Google or Apple

You can optionally sign in to the Service with your Google or Apple account. If you do, we receive from the provider only your name, your email address, its verification status and a unique account identifier. From Google we request the openid, profile and email scopes; from Apple the name and email scopes (Apple shares your name only once, at your first sign-in). We use this information solely to:

If you use Apple’s Hide My Email option, we receive and use the private relay address that Apple generates for you instead of your real email address.

We do not use Google or Apple user data for advertising, we do not sell it, and we do not share it with third parties except with the service providers listed in section 5 to the extent needed to operate your charging account. Woltti’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke Woltti’s access to your Google account at any time in your Google account security settings, and to your Apple account in your Apple account settings under Sign in with Apple. After revoking access you can continue to use your Woltti account with your email address and password.

3. Why we process your data

PurposeLegal basis (GDPR art. 6)
Providing the Service: authentication, starting and monitoring charging sessions, customer supportPerformance of a contract (6(1)(b))
Billing, receipts and payment collectionPerformance of a contract (6(1)(b)); legal obligation (6(1)(c), accounting legislation)
Securing the Service, preventing misuse, resolving technical issuesLegitimate interest (6(1)(f))
Service-related communication (e.g. receipts, verification codes, service announcements)Performance of a contract (6(1)(b))
Optional sign-in with GooglePerformance of a contract (6(1)(b)); you choose whether to use it

4. Cookies

The Service uses only cookies that are necessary for its operation: keeping you signed in, protecting forms against forgery, remembering your language selection and completing external sign-in. We do not use advertising or cross-site tracking cookies.

5. Sharing of data

We share personal data only as needed to operate the Service:

We do not sell personal data. Where a service provider processes data outside the EU/EEA, we rely on safeguards recognised by the GDPR, such as the European Commission’s standard contractual clauses or an adequacy decision.

6. Retention

We keep your account data for as long as your account is active. Charging and billing records are kept for the period required by Finnish accounting legislation (generally six years from the end of the financial year). Technical logs are kept for a shorter period appropriate to security and troubleshooting. When data is no longer needed, it is deleted or anonymised.

7. Your rights

Under the GDPR you have the right to:

To exercise your rights, contact us using the details below.

8. Security

Data is stored in access-controlled cloud environments within the EU, transferred over encrypted connections and protected by role-based access controls. Access to personal data is limited to personnel who need it for their work.

9. Changes to this policy

We may update this policy as the Service evolves. The current version is always available at this address, and the date at the top shows when it was last updated. If changes are significant, we will inform you through the Service.

10. Contact

Wolttinen Oy
Lemuntie 7A, 00510 Helsinki, Finland
asiakaspalvelu@wolttinen.fi