Cookie Preferences

We use cookies to provide a better user experience and personalised service. By consenting to the use of cookies, we can develop an even better service and will be able to provide content that is interesting to you. You are in control of your cookie preferences, and you may change them at any time. Read more about our cookies.

Skip to content
Shop Jewellery Watches Coins Banknotes Collecting accessories Literature Orders and decorations Militaria Medals Olympic memorabilia Silver items Other items Auction Next auction Buying at auctions Selling at auctions Grades of preservation and abbreviations Terms of Bidding Evaluation Evaluation of jewelry Valuation of watches Valuation of items Trading gold with trust since 1949 Estates of the deceased For insurance companies About us Contact The HOLMASTO company The Holmasto story Caritha Holmasto – von Schantz in memoriam 1942-2017 Press & Media Blog News

Privacy policy

PRIVACY POLICY

Updated: 18 September 2026

1. Data Controller

Rahaliike Holmasto seur. Mynthandel Ky

0888544-8

Aleksanterinkatu 50 00100 Helsinki

Email for data protection matters: info@holmasto.fi

You may contact us at the email address above regarding data protection matters.

2. What personal data does Holmasto process?

Holmasto processes personal data when a customer uses Holmasto’s services or conducts business with Holmasto. The data processed depends on the service used by the customer and the nature of the customer relationship.

Data is primarily obtained from the customer themselves. Data is also generated in connection with the use of Holmasto’s services and transactions carried out with Holmasto. Where necessary, Holmasto may obtain data from its service providers, official registers and other reliable sources when this is necessary to provide the service or to fulfil statutory obligations.

Providing the personal data required to provide the service is a prerequisite for entering into a contract and using the service. Providing the identification and background information required by anti-money laundering legislation is a statutory requirement. If the customer does not provide the necessary information, Holmasto may not be able to create a user account, enter into a contract, carry out a transaction or provide the service requested by the customer.

3. Auction

When a customer registers for or participates in an auction, Holmasto processes, for example, the customer’s name, address, telephone number, email address, user account details, information relating to user account verification, bids placed by the customer, bidding history, items won by the customer, and payment and contact details relating to the auction.

Holmasto processes this data for the purposes of creating and managing user accounts, enabling participation in auctions, receiving bids, conducting auctions, handling the sale and payment of items won, and communicating with the customer.

The processing is primarily based on the performance of a contract and pre-contractual measures. Data may also be processed to fulfil legal obligations and on the basis of Holmaston’s legitimate interest in ensuring the security of the auction and in preventing and investigating any potential misuse.

Verification of user account

Participation in the auction requires the verification of a user account. A user account can be verified via bank authentication, credit card-based verification or manual approval carried out by Holmasto.

When using bank authentication, Holmasto does not receive the customer’s personal identification number from the authentication service. Holmasto records information on the verification method used and whether the verification was successful.

In the case of credit card-based verification, information regarding the verification method, the last four digits of the card, the card’s expiry date and whether the verification was successful may be stored. Holmasto does not store the full credit card number in this context.

If a user account is approved manually, information regarding the approval is stored in the system.

4. Online shop

When a customer makes a purchase in Holmasto’s online shop, Holmasto processes, for example, the customer’s name, address, telephone number, email address, order and purchase details, payment-related information, and information relating to deliveries and any returns.

This data is used to receive and process orders, handle payments, deliver products, manage returns, provide customer service, and for accounting and other statutory obligations.

The processing is primarily based on the performance of the contract with the customer and Holmaston’s statutory obligations.

5. Purchase and sale of items

Holmasto purchases items from private individuals and accepts items for sale through Holmasto.

When a customer sells an item to Holmasto or entrusts an item to Holmasto for sale, Holmasto processes, for the purposes of handling the transaction or commission, data such as the customer’s name, contact details, bank details, information relating to the item for sale, transaction and commission details, settlement details and information relating to communications with the customer.

Holmasto is also a reporting entity as defined by anti-money laundering legislation. For this reason, particularly when a customer sells items to Holmasto or through Holmasto, Holmasto must collect, to the extent required by law, identification and background information about the customer that would not necessarily be collected in the context of a normal customer relationship.

Depending on the situation, this may include a personal identification number, information relating to identity verification, details of an identity document and, where necessary, a copy of the identity document, as well as other information required by law relating to the origin of the item, the customer’s activities or the transaction.

The data is processed for the purpose of carrying out a transaction or order, for payment and settlement, for accounting purposes, and to fulfil Holmasto’s statutory obligations.

6. Customer identification and anti-money laundering legislation

Holmasto is a reporting entity as defined in the Act on the Prevention of Money Laundering and Terrorist Financing. Consequently, Holmasto is obliged to know its customers and to monitor the customer relationship to the extent required by anti-money laundering legislation.

Knowing the customer means that Holmasto must, where necessary, identify the customer and verify their identity, as well as have sufficient knowledge of the customer’s activities and the transactions carried out with them. For this reason, Holmaston also records details of the amounts involved and the transactions relating to purchases, sales, auctions and other business dealings carried out with the customer.

In order to comply with anti-money laundering legislation regarding customer due diligence and data retention, Holmasto must be able to review transactions carried out with the customer over a longer period of time.

Depending on the situation, the data processed may include, for example, name, date of birth, personal identification number, address, nationality, information relating to identity verification, details of identity documents and, where necessary, a copy of an identity document, as well as information relating to the customer’s activities, transactions and, where necessary, the origin of funds or assets being traded.

The scope of the data collected depends on the customer relationship, the service used by the customer, the transactions carried out and the risk assessment in accordance with anti-money laundering legislation. Consequently, the same identification and customer due diligence information is not collected from all customers.

In order to know its customers, Holmasto may also process information on whether the customer or a person associated with the customer is a politically exposed person, a family member of such a person, or a close business associate. In addition, Holmasto may process data relating to international sanctions. In the case of corporate clients, Holmasto may also process identification and customer due diligence data concerning the client’s representatives and beneficial owners.

Customer identification data and other personal data collected under anti-money laundering legislation are processed to fulfil Holmasto’s statutory obligations and to prevent, detection and investigation, and to ensure that related offences are brought to trial in accordance with anti-money laundering legislation.

7. Customer communications

Holmasto uses the customer’s contact details to manage the customer relationship and the service used by the customer.

Holmasto may send the customer necessary messages relating, for example, to their participation in an auction, a bid they have made, an item they have won, an online shop order, a transaction, a sales mandate or the result of a valuation mandate. Holmasto may also notify the customer when other assignments have been completed.

Holmasto does not use its customer register for general direct marketing.

8. Website, cookies and analytics

Holmasto’s website uses cookies that are essential for the functioning of the service, as well as other cookies and similar technologies based on the user’s choices.

Holmasto uses the Google Analytics service to analyse website usage. Where consent is required for the use of analytics, Google Analytics will only be activated once the user has given their consent.

9. CCTV surveillance

CCTV surveillance is used on Holmasto’s premises.

CCTV surveillance involves the processing of images of customers, staff and other individuals moving within the monitored area, as well as information regarding the time of the event.

The purpose of CCTV is to ensure the safety of individuals, to protect property, and to prevent and investigate crimes, misconduct and other situations that jeopardise safety or property.

The legal basis for the processing of CCTV footage is Holmaston’s legitimate interest in safeguarding the safety of individuals and property, as well as in preventing and investigating misconduct.

Access to the recordings is restricted to those whose duties include the processing of such recordings. Where necessary, recordings may be disclosed to the competent authorities, for example to investigate a crime or other security incident.

Recordings are retained only for as long as is necessary to fulfil the purposes of CCTV surveillance. A recording may be retained for a longer period if this is necessary, for example, to deal with a crime, damage, misconduct or any other incident requiring investigation.

10. Service providers and disclosure of data

Holmasto uses external service providers in the course of its operations. Personal data may be processed, for example, in connection with systems required to provide the online shop, auction system, email, payment transactions, accounting, authentication, deliveries, analytics and other Holmasto services.

Holmasto, in turn, requires service providers processing personal data to ensure appropriate protection of personal data and compliance with applicable data protection legislation.

Data may also be disclosed to public authorities or other parties where required or permitted by law.

11. Transfers of personal data outside the EU and EEA

The service providers used by Holmasto may utilise international information systems and subcontractors, which means that, in some situations, personal data may also be processed outside the EU or EEA.

If personal data is transferred outside the EU or the EEA, such transfers will be carried out in accordance with data protection legislation. Such transfers may be based, for example, on a decision by the European Commission on an adequate level of data protection or on standard data protection clauses approved by the European Commission, supplemented where necessary by additional safeguards.

Further information on international transfers of personal data and the safeguards applicable to them may be requested from the data protection contact details provided in section 1.

12. Retention of personal data

Holmasto retains personal data only for as long as it is necessary for the purpose for which it was collected, or for as long as required by law.

Data relating to customer relationships, user accounts, the online shop, auctions and items bought and sold will be retained for as long as necessary to manage the customer relationship, contracts and business transactions, to fulfil statutory obligations, or to prepare, bring or defend any legal claims.

Customer identification data collected under anti-money laundering legislation is retained for the period required by law. As a general rule, data is retained for five years from the end of a regular customer relationship or from the completion of an occasional transaction as defined by law.

Accounting records are retained for the periods required by accounting legislation. The retention period depends on the accounting records in question.

When there is no longer any basis for retaining personal data, the data is deleted in an appropriate manner.

13. Protection of personal data

Holmasto protects the personal data it processes using appropriate technical and organisational measures.

Access to personal data is restricted to those whose job duties require them to process such data. Access rights are managed in accordance with roles and needs, and those involved in the processing of personal data are bound by a duty of confidentiality.

The protection of personal data takes into account, amongst other things, the management of system access rights, user authentication, the maintenance and updating of systems and software, data backups, and other technical and organisational security measures appropriate to the data being processed and the associated risks.

14. The Customer’s Rights

In accordance with data protection legislation and depending on the legal basis for processing, the customer has the right to obtain information about the processing of their personal data and to access their own data, to request the rectification of incorrect or incomplete data, to request the erasure of data or the restriction of processing, object to the processing of personal data in certain circumstances, request the transfer of data from one system to another where applicable, and withdraw their consent where processing is based on consent.

These rights are not absolute in all circumstances. For example, Holmasto cannot delete personal data which it is required by law to retain.

Holmasto may, if necessary, request further information from the customer to verify their identity.

Requests regarding data protection may be sent to the email address specified in section 1.

15. Right to lodge a complaint

If a customer considers that their personal data has been processed in breach of data protection regulations, they have the right to lodge a complaint with the competent supervisory authority. In Finland, the data protection supervisory authority is the Office of the Data Protection Ombudsman.

16. Automated decision-making

Holmasto does not make decisions concerning customers that are based solely on automated processing of personal data and which would have legal effects on the customer as referred to in the General Data Protection Regulation or which would otherwise significantly affect them in a similar manner.

17. Updating the Privacy Policy

Holmasto may update this Privacy Policy if there are changes to the processing of personal data, Holmasto’s services, the systems used by Holmasto, or the relevant legislation.

The up-to-date Privacy Policy is available on Holmasto’s website.

18. Language versions

This privacy notice may be published in several languages. In the event of any conflicts, discrepancies or ambiguities between the language versions, the Finnish version shall take precedence.