1. Introduction
This Privacy Notice explains how SopiSafe Oy ("SopiSafe", "we", "us", "our"), a company incorporated and registered in Finland, collects, uses, stores, and shares personal data in connection with the SopiSafe platform โ our contract-to-invoice control layer for detecting supplier billing drift and preparing recovery claims (the "Service").
We process personal data in compliance with the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Finnish Data Protection Act (Tietosuojalaki 1050/2018), and other applicable data protection legislation.
This notice applies to:
- Visitors to our websites
- Users of the SopiSafe platform (authorized representatives of our business customers)
- Prospective customers, partners, and other business contacts
- Individuals whose personal data may be contained in Customer Content uploaded to the Service
2. Data controller
SopiSafe Oy ยท Helsinki, Finland
Email: privacy@sopisafe.com
Website: sopisafe.com
For Customer Content that contains personal data of third parties, the customer is the data controller and SopiSafe acts as a data processor under a Data Processing Agreement (available on request from legal@sopisafe.com).
3. What we collect
| Category | What it includes |
|---|---|
| Account & organization data | Full name, email address, organization name, role within the organization (admin, member), account preferences, subscription plan and billing-related information |
| Authentication & security data | Password hash (never plaintext), MFA status and encrypted secrets, API key metadata (prefix, name, scopes, last used), session tokens, last login timestamp, email verification tokens |
| Service usage data | Vendors tracked, contracts monitored, invoices processed, drift scans executed, API calls, billing period and usage metrics, notification preferences, feature interaction logs |
| Customer Content | Vendor information (names, domains, contact emails, categories, notes), contract documents and extracted terms, invoice data (numbers, dates, amounts, line items, source documents), drift findings and recovery claim details, notes attached to records |
| Technical & log data | IP address, browser type and version, operating system, access timestamps, referring URLs, pages viewed, error and performance logs |
| Payment data | We do not store payment card details. Payments are processed by Wise (TransferWise Ltd), which acts as an independent data controller for payment transaction data |
| Communication data | Support request content, email correspondence, transactional email metadata |
Customer Content and third parties. Customer Content may contain personal data of third parties โ for example supplier contact persons or contract signatories. As the data controller for your Customer Content, you are responsible for ensuring you have a lawful basis to provide that data to us.
4. Why we process data, and on what legal basis
| Purpose | Data categories | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing and maintaining the Service | Account, authentication, Customer Content, usage | 6(1)(b) โ contract |
| Authentication and access control | Authentication & security | 6(1)(b) โ contract |
| Drift detection, analysis, and recovery claims | Customer Content, usage | 6(1)(b) โ contract |
| Billing, invoicing, and subscription management | Account, usage, payment | 6(1)(b) โ contract |
| Transactional notifications (alerts, drift reports, system messages) | Account, communication | 6(1)(b) โ contract |
| Customer support | Account, communication | 6(1)(b) โ contract |
| Security monitoring, fraud prevention, abuse detection | Authentication, technical & log | 6(1)(f) โ legitimate interest |
| Service improvement and analytics | Usage, technical & log | 6(1)(f) โ legitimate interest |
| Legal obligations (accounting, tax, AML) | Account, payment, usage | 6(1)(c) โ legal obligation |
| Marketing communications (opt-in only) | Account (email, name) | 6(1)(a) โ consent |
| Establishing, exercising, or defending legal claims | All categories as necessary | 6(1)(f) โ legitimate interest |
Legitimate interest assessments are documented internally and available on request.
5. Sharing and sub-processors
We share personal data only when necessary to provide the Service, comply with legal obligations, or protect our legitimate interests. We do not sell personal data, and we never disclose it to third parties for their independent marketing purposes.
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure, compute, storage, database hosting โ all data encrypted at rest and in transit | EU โ Hamina, Finland (europe-north1) | Google Cloud DPA, EU SCCs, ISO 27001, SOC 2 |
| Mailjet (Mailjet SAS) | Transactional and notification email | EU โ France | Mailjet DPA, ISO 27001 |
| Wise (TransferWise Ltd) | Payment processing โ acts as an independent controller for payment data | EU/EEA โ Estonia / Belgium | Wise privacy policy, PCI DSS, regulated |
| Plausible Analytics | Website analytics โ cookieless, no cross-site tracking, aggregated only | EU โ Germany | Plausible DPA |
Customers under a Data Processing Agreement are notified of sub-processor changes and may object in accordance with the DPA. We may also disclose personal data to professional advisors under confidentiality obligations, to authorities when required by law, and to potential acquirers in connection with a merger or acquisition โ subject to confidentiality and this notice.
6. International transfers
Our primary infrastructure runs on Google Cloud Platform in the EU (europe-north1 โ Hamina, Finland). We keep personal data within the EU/EEA.
If any transfer outside the EU/EEA ever becomes necessary, we ensure appropriate safeguards:
- EU Standard Contractual Clauses (SCCs) adopted by the European Commission
- European Commission adequacy decisions, where applicable
- Supplementary measures where required after assessing the recipient country's data protection regime
You may request a copy of the applicable transfer mechanism at privacy@sopisafe.com.
7. How long we keep data
| Data category | Retention period | Why |
|---|---|---|
| Account & organization data | Contract duration + 12 months | Service delivery; reasonable re-activation window |
| Authentication & security data | Account duration; API keys until revoked or expired | Service security |
| Customer Content | Contract duration + 30 days | Service delivery; grace period for data export |
| Service usage & billing data | Contract duration + 6 years | Finnish Accounting Act (kirjanpitolaki 1336/1997) |
| Technical & log data | 90 days, rolling | Security monitoring and debugging |
| Communication data (support) | 2 years from last communication | Service improvement; dispute resolution |
| Marketing consent records | Consent duration + 3 years | Demonstrating consent under the GDPR |
On contract termination we delete or anonymize personal data per the periods above, unless longer retention is required by law or necessary for legal claims. Customers may request immediate deletion of Customer Content at any time (see section 8).
8. Your rights
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your personal data, subject to legal retention obligations |
| Restriction (Art. 18) | Request that we restrict processing in certain circumstances |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format (JSON/CSV) |
| Objection (Art. 21) | Object to processing based on legitimate interests; we stop unless we demonstrate compelling grounds |
| Withdraw consent (Art. 7) | Withdraw consent at any time where processing is based on it โ without affecting prior processing |
| Automated decisions (Art. 22) | Not to be subject to solely automated decisions with legal effects. SopiSafe does not make such decisions |
How to exercise them. Email privacy@sopisafe.com. We respond within one month; in complex cases this may extend by up to two further months, and we will tell you why within the first month. We may need to verify your identity. We do not charge a fee unless a request is manifestly unfounded or excessive.
Right to complain. If you believe our processing infringes the GDPR, you may lodge a complaint with the Finnish supervisory authority:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Lintulahdenkuja 4, 00530 Helsinki, Finland
+358 29 566 6700 ยท tietosuoja@om.fi ยท tietosuoja.fi/en
9. Security
We implement appropriate technical and organizational measures to protect personal data, including:
Technical
- Encryption at rest (AES-256) and in transit (TLS 1.2+) for all data
- Isolated database instances per service โ defense in depth
- Password hashing with industry-standard algorithms (bcrypt); no plaintext passwords
- Token-based authentication with configurable expiration, and multi-factor authentication
- API keys with scoped permissions; encrypted storage of integration tokens
- Rate limiting at the API gateway and strict CORS policy enforcement
Organizational
- Access limited to authorized personnel on a need-to-know basis
- Data processing agreements with all sub-processors
- Regular security reviews and vulnerability assessments
- Documented incident response procedures โ affected customers notified within 72 hours
- Staff training on data protection, and separated development, staging, and production environments
10. Cookies
The SopiSafe platform uses the following categories of cookies:
| Category | Purpose | Consent required |
|---|---|---|
| Strictly necessary | Session management, authentication tokens, CSRF protection | No โ essential |
| Functional | User preferences, language settings | No โ essential |
| Analytics | Aggregated usage patterns and performance monitoring | Yes โ opt-in |
| Marketing | Not used | โ |
Our public website uses Plausible Analytics, which is cookieless and does not track you across sites. Where non-essential cookies are used, we obtain prior opt-in consent in accordance with the Finnish Act on Electronic Communication Services (917/2014) and the GDPR, and you can withdraw it at any time via the cookie settings in the site footer.
11. Children
SopiSafe is a B2B service and is not directed at children under 16. We do not knowingly collect personal data from children; if we become aware that we have, we will delete it promptly.
12. Changes to this notice
We may update this notice to reflect changes in our practices, technology, or legal requirements. We will:
- Post the updated notice here with a revised โLast updatedโ date
- Notify registered users of material changes by email or in-app notification at least 30 days before they take effect
- Seek consent to material changes where the law requires it
13. Contact
Questions, requests, or concerns about this notice or our data protection practices: privacy@sopisafe.com. Data subject requests go to the same address.
This Privacy Notice is governed by Finnish law and the GDPR. In the event of any discrepancy between language versions, the English version prevails.