SopiSafe
Privacy policy

What we collect, why, and what you can do

This policy applies to SopiSafe Oy and the SopiSafe platform at app.sopisafe.com. Last updated: June 2026.

This page is the human-readable summary. The full legal notice is published as its own document. Both say the same thing. If they ever conflict, the full notice takes precedence.

Plain English summary

The short version

WHAT WE COLLECT

Invoice data, contract data, and vendor records โ€” because that's what we need to find billing drift. Your account info (name, email, company) to run your account. Usage logs for security and debugging.

WHAT WE DON'T COLLECT

We don't collect payment details. We don't collect personal data about your employees unless they're directly linked to a billed seat. We don't track you across other websites.

WHAT WE DO WITH IT

We use it to find supplier billing discrepancies and generate findings for your review. We don't sell it. We don't use it to train AI models. We don't share it with third parties except our infrastructure providers (listed below), who are all GDPR-compliant EU-hosted services.

HOW LONG WE KEEP IT

Until you ask us to delete it, or until 90 days after your subscription ends โ€” whichever comes first. Some billing records we're legally required to keep for 7 years (Finnish accounting law), but those don't contain your supplier data.

WHERE IT'S STORED

GCP Hamina, Finland (europe-north1). No data leaves the EU. No transfers to the US or any non-EU country. Standard Contractual Clauses in place with all sub-processors.

YOUR RIGHTS

You can access, correct, export, or delete your data at any time. Email privacy@sopisafe.com. We respond within 30 days. If you're unhappy with how we've handled something, you can complain to the Finnish DPA.

Data categories

What we collect in detail

CATEGORYWHAT SPECIFICALLYWHY WE NEED ITHOW LONG
Invoice dataInvoice amounts, line items, dates, supplier references, invoice numbers, VAT amountsThis is the primary input for drift detection. We match invoice lines against contract terms.Subscription term plus 90 days. Deleted on demand.
Contract dataContract terms, agreed rates, discount schedules, seat caps, renewal dates, order form contentsThis is the other primary input โ€” the 'agreed' side of the contract-to-invoice match.Subscription term plus 90 days. Deleted on demand.
Vendor recordsSupplier names, supplier IDs, payment terms, contact info where provided in your exportsFor matching invoices to the right contract, and for supplier segmentation in reports.Subscription term plus 90 days.
Account dataYour name, work email address, company name, and roleTo run your account and send you findings, invoices, and security notifications.Until you close your account, plus 12 months.
Usage logsWhich pages you access in the platform, actions you take, timestampsFor debugging, security monitoring, and product improvement. We don't sell or share this.90 days rolling.
Your rights (GDPR)

Six things you can ask us to do

ACCESS

You can ask for a copy of all personal data we hold about you. We'll send it within 30 days in a readable format.

RECTIFICATION

If something we hold is wrong, you can ask us to correct it. We'll act within 30 days.

ERASURE

You can ask us to delete your personal data. We'll do it within 30 days. Some data we're legally required to keep for a period (billing records, for instance) โ€” we'll tell you what those are.

PORTABILITY

You can ask for your data in a machine-readable format (JSON or CSV) so you can move it to another service.

OBJECT TO PROCESSING

You can object to us processing your data in certain ways, particularly for marketing. If you object, we stop.

LODGE A COMPLAINT

If you think we've mishandled your data, you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi) or the data protection authority in your EU country of residence.

To exercise any of these rights, email privacy@sopisafe.com. We respond within 30 days. No fee. No friction.

Sub-processors

Three third-party services. All EU-hosted

These are the only external services that may process your data. All three have signed Data Processing Agreements. None of them can use your data for their own purposes.
Google Cloud Platform (GCP)
Cloud hosting and data storage
Cloud hosting and data storage
EU (Hamina, Finland โ€” europe-north1)DPA signed
Mailjet
Transactional email (account notifications, finding summaries)
Transactional email (account notifications, finding summaries)
EUDPA signed
Plausible Analytics
Website analytics (privacy-first, no cookies, no cross-site tracking)
Website analytics (privacy-first, no cookies, no cross-site tracking)
EU (Germany)DPA signed

We don't use advertising networks, social media pixels, third-party analytics that track users across sites, or any service that might share your data with non-EU entities. If that changes, we'll update this page and notify all customers by email before the change takes effect.

Cookies

Two types. No advertising

Session cookies
In use

Keep you logged in while you're using the platform. These are deleted when you close your browser. You can't use the platform without them.

Functional cookies
In use

Remember your preferences (display settings, language, last-viewed section). These persist across sessions. Also required for the platform to work properly.

Analytics (website only)
Not used

We use Plausible Analytics on the marketing site (sopisafe.com). It doesn't use cookies and doesn't track you across sites. It counts page views in aggregate, nothing personal.

Advertising or tracking
Not used

We don't use these. No retargeting pixels, no Meta or Google tracking scripts, no cross-site cookie syncing. If you've come here from an ad, that ad platform stopped seeing you when you clicked.

Privacy contact

Questions about this policy?

Email us. We'll respond within 30 days. For urgent data breach notifications, the subject line "URGENT: Data breach" will get it to the right person faster.

privacy@sopisafe.com โ†’

SopiSafe Oy

Business ID: 3456789-1

Kalevankatu 44, 00100 Helsinki, Finland

Legal basis

Why we're allowed to process your data

CONTRACT PERFORMANCE

Processing invoice and contract data is necessary to provide the service you've contracted us for. Without it, we can't find drift.

LEGITIMATE INTERESTS

Usage logging for security monitoring. We have a legitimate interest in keeping the platform secure, and logging is proportionate to that interest.

This policy was last updated in June 2026. We'll notify customers by email of any material changes before they take effect. The current version is always at sopisafe.com/privacy. Archived versions available on request.