What personal data this service processes, why, and what you can require of us. Written under Articles 13 and 14 of the GDPR. In Finnish this document is a tietosuojaseloste — the term rekisteriseloste comes from the Personal Data Act that the GDPR replaced in 2018, and is no longer the right name for it.
This notice covers personal data processed by the operator named above as controller: the accounts people use to sign in, the record of what they did in the service, and the visitor data collected on these public pages.
It does not cover the packaging data our customers put into the service. There, the customer is the controller and we act only on their instructions as a processor. That relationship is set out in the data processing agreement.
Name, work email address, organisation name, password (stored only as a hash), role, and the times of account creation and sign-in.
Purpose: to give you an account and keep it secure. Legal basis: performance of a contract, Article 6(1)(b).
A log of actions taken in the service — sign-ins, changes to a product record, account changes — with the user, the time and the IP address.
Purpose: to let an organisation see who changed what, to investigate misuse, and to keep the service secure. Legal basis: legitimate interest, Article 6(1)(f), in operating a service that can be audited. Our assessment is that a customer expects this of a compliance tool and could not use it responsibly without it.
Failed sign-in attempts are counted per email address and per IP address, and discarded after 24 hours.
Purpose: to slow down password guessing. Legal basis: legitimate interest, Article 6(1)(f), in keeping accounts from being taken over.
Organisation, plan, subscription status and amounts, and any reference held by a payment provider.
Purpose: to invoice and to keep the accounts. Legal basis: contract, Article 6(1)(b), and legal obligation, Article 6(1)(c), for the accounting records Finnish law requires us to retain.
Only if you agree. Nothing that sets a cookie for analytics runs before you accept it. What is set, and by whom, is listed in the cookie policy.
Legal basis: consent, Article 6(1)(a), which you may withdraw at any time.
From you: when an account is created, when your organisation adds you, and as you use the service. We do not buy personal data and we do not enrich it from third-party sources.
The people who run this instance, for support and operations. Beyond that, only the sub-processors listed below, each bound by a written agreement to process the data only on our instructions.
We do not sell personal data, and we do not disclose it for anyone else's marketing.
Our intention is to keep the data in the EU or EEA. Where a sub-processor listed above is outside it, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses; ask the privacy contact above for a copy of the relevant safeguards.
If the list above names no location outside the EEA, no such transfer takes place.
Under the GDPR you may ask us to:
Write to the privacy contact above. We answer within one month, and will say so if we need longer. There is no charge unless a request is manifestly unfounded or excessive.
If you are not satisfied, you may complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi) or to the supervisory authority where you live or work.
None. The service calculates compliance results from data you enter, but no decision producing a legal effect for a person is made automatically.
If a breach is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and tell you directly where the risk is high.
If this notice changes materially we will say so in the service before the change takes effect. The date it came into force is at the top of this page.