This notice is not finished.
The operator of this instance has not filled in the company details it needs. Until they do, it is a template and not a binding notice.
- Controller
- —
- Business ID
- —
- Address
- —
- Contact
- —
- Phone
- —
- Privacy contact
- —
- Data protection officer
- —
- In force since
- —
1 · What this notice covers
This notice covers personal data processed by the operator named above as controller: the accounts people use to sign in, the record of what they did in the service, and the visitor data collected on these public pages.
It does not cover the packaging data our customers put into the service. There, the customer is the controller and we act only on their instructions as a processor. That relationship is set out in the data processing agreement.
2 · What we process, and why
Account data
Name, work email address, organisation name, password (stored only as a hash), role, and the times of account creation and sign-in.
Purpose: to give you an account and keep it secure. Legal basis: performance of a contract, Article 6(1)(b).
Usage and audit records
A log of actions taken in the service — sign-ins, changes to a product record, account changes — with the user, the time and the IP address.
Purpose: to let an organisation see who changed what, to investigate misuse, and to keep the service secure. Legal basis: legitimate interest, Article 6(1)(f), in operating a service that can be audited. Our assessment is that a customer expects this of a compliance tool and could not use it responsibly without it.
Sign-in attempts
Failed sign-in attempts are counted per email address and per IP address, and discarded after 24 hours.
Purpose: to slow down password guessing. Legal basis: legitimate interest, Article 6(1)(f), in keeping accounts from being taken over.
Billing records
Organisation, plan, subscription status and amounts, and any reference held by a payment provider.
Purpose: to invoice and to keep the accounts. Legal basis: contract, Article 6(1)(b), and legal obligation, Article 6(1)(c), for the accounting records Finnish law requires us to retain.
Analytics on these public pages
Only if you agree. Nothing that sets a cookie for analytics runs before you accept it. What is set, and by whom, is listed in the cookie policy.
Legal basis: consent, Article 6(1)(a), which you may withdraw at any time.
3 · Where the data comes from
From you: when an account is created, when your organisation adds you, and as you use the service. We do not buy personal data and we do not enrich it from third-party sources.
4 · Who else sees it
The people who run this instance, for support and operations. Beyond that, only the sub-processors listed below, each bound by a written agreement to process the data only on our instructions.
We do not sell personal data, and we do not disclose it for anyone else's marketing.
5 · Transfers outside the EU and EEA
Our intention is to keep the data in the EU or EEA. Where a sub-processor listed above is outside it, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses; ask the privacy contact above for a copy of the relevant safeguards.
If the list above names no location outside the EEA, no such transfer takes place.
6 · How long we keep it
- Account data: for as long as the account exists, then deleted within {days} days of the organisation closing its account.
- Audit records: kept with the organisation's account and deleted with it.
- Failed sign-in attempts: 24 hours.
- Accounting records: as long as the Finnish Accounting Act requires, currently six years from the end of the accounting year.
- Analytics: for the period the analytics provider states in its own documentation.
7 · Your rights
Under the GDPR you may ask us to:
- confirm whether we process data about you, and give you a copy of it (Article 15);
- correct data that is wrong or incomplete (Article 16);
- delete data we no longer have grounds to keep (Article 17);
- restrict processing while a dispute about it is resolved (Article 18);
- give you the data you provided in a machine-readable form, or send it to another controller (Article 20);
- stop processing based on legitimate interest, where your situation gives you grounds to object (Article 21);
- withdraw consent to analytics, at any time and without giving a reason (Article 7(3)).
Write to the privacy contact above. We answer within one month, and will say so if we need longer. There is no charge unless a request is manifestly unfounded or excessive.
If you are not satisfied, you may complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi) or to the supervisory authority where you live or work.
8 · Automated decision-making
None. The service calculates compliance results from data you enter, but no decision producing a legal effect for a person is made automatically.
9 · How the data is protected
- Passwords are stored only as a salted hash, never in a form that can be reversed.
- Sessions use HttpOnly, SameSite=Strict cookies; only a hash of the session token is stored.
- Each organisation's data is separated at the database key, so one customer cannot read another's.
- Access by the people who run the service is limited to what operations require, and is logged.
- The service is served over TLS, with a strict content security policy.
If a breach is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and tell you directly where the risk is high.
10 · Changes
If this notice changes materially we will say so in the service before the change takes effect. The date it came into force is at the top of this page.