This privacy policy ("Policy") describes, as required by the EU General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council, "GDPR"), how we at Heppu AI Oy ("Controller", "we", "us", "our" and, as set out below, also "Processor") process the personal data ("Data") of natural persons ("Data Subject") and what rights the Data Subject has.
The Policy covers both the Data we collect as Controller and the Data we process under a data processing agreement ("DPA") between us and our customer companies ("Customer"). Where processing is based on a DPA, our Customer acts as the controller ("Client") and we act as Processor.
Controller and contact person
Heppu AI Oy (Business ID 3517137-9)
Keilaranta 16, 02150 Espoo, Finland
Questions about the processing of personal data and requests to exercise your rights are handled by:
Mika Jordanov
mika@heppu.ai
Legal basis for processing personal data
We process personal data primarily on the basis of the Data Subject's consent. We also process personal data to fulfil contractual obligations and on the basis of the legitimate interests of the Controller and the Client. Legitimate interest is the legal basis when we use Data for processing needs that are part of ordinary business operations.
The service agreement between us and the Client ("Service Agreement") also counts as a contractual obligation. To deliver the service agreed in the Service Agreement, we process personal data either as Controller or as Processor, depending on whether the Data Subject is a representative of the Client or a customer or prospective customer of the Client.
Purpose of processing personal data
We process personal data lawfully and only for the specific purpose set out in this Policy.
Processing personal data is necessary
- to provide and market our services;
- to manage the customer relationship, including customer communication, marketing and invoicing;
- to fulfil and deliver the services agreed in the Service Agreement;
- to operate our website;
- to pursue the legitimate interests of the Controller and the Client; and
- to comply with legal obligations.
Data sources
We collect Data both automatically and from the Data Subject directly (for example through website forms and customer communication). We have the right to verify and supplement the data received from the Data Subject using publicly available sources such as the Finnish Trade Register.
Automatic data collection and processing is based on the use of our website and our other online services.
Under the Service Agreement and the DPA, we receive Data from the Client. The Client is responsible for what data is disclosed to us and what it is used for.
Cookies and website tracking
Our website uses the services and cookies listed below. Our visitor analytics (Plausible) uses no cookies and stores no personal data, so it does not require consent. To measure advertising we use Google Ads and LinkedIn cookies, which we enable only with your consent. You can accept or reject marketing cookies in the cookie notice on the site. If you accept marketing cookies, we share the email address and phone number you enter in a form with Google Ireland Limited in hashed form for conversion matching (enhanced conversions). In the same way, we share the email address you enter in a form with LinkedIn Ireland Unlimited Company in hashed form for ad targeting and measurement (enhanced matching).
| Service or cookie | Provider | Purpose | Duration | Legal basis |
|---|---|---|---|---|
| Plausible Analytics | Plausible Insights OÜ (Estonia, EU) | Visitor counting. Uses no cookies and stores no IP address or other personal data. | No cookie | Legitimate interest |
| Google Ads (_gcl_* cookies) | Google Ireland Limited (Ireland, EU; transfers to the United States under the EU-US Data Privacy Framework) | Measuring ad performance and conversions, and remarketing. Enabled only with consent; without consent, measurement is cookieless and anonymous (Consent Mode). | Up to 90 days | Consent |
| LinkedIn Insight Tag (including UserMatchHistory, bcookie, lidc, li_sugr) | LinkedIn Ireland Unlimited Company (Ireland, EU; transfers to the United States under the EU-US Data Privacy Framework) | Ad targeting and conversion measurement on LinkedIn, and remarketing. Loaded only with consent. | Up to 12 months | Consent |
| Cloudflare Turnstile | Cloudflare, Inc. (United States, EU-US Data Privacy Framework) | Protects the site's forms from bots and abuse. | Session | Legitimate interest (security) |
| Heppu chat widget | Heppu AI Oy | Enables the chat conversation on the page. Processes only the data given in the conversation. | Session | Legitimate interest (service operation) |
| heppu_hero_variant (cookie) | Heppu AI Oy | Keeps the homepage content version the same between visits. Contains only a version identifier, no unique identifier. | 90 days | Legitimate interest |
Personal data we process
We process the personal data needed to manage the customer relationship and to fulfil the obligations related to it. This includes:
- Identification and contact details (such as name, phone number, postal address, date of birth or personal identity code, email, and details about the customer company, including the details of a sole trader);
- Data related to electronic direct marketing (such as subscription details, consents and opt-outs);
- Data related to website visitor tracking (such as IP addresses and behaviour on the website);
- Data the customer gives voluntarily, such as customer feedback;
Personal data processed under the Service Agreement and the DPA may also include the following Data:
- details of property being registered (for example a vehicle registration number or property details)
Disclosure and transfer of personal data to third parties
As a rule, Data is not disclosed to outside parties. Data (such as customer feedback) may, however, be published as agreed with the customer.
Data may be disclosed to our partners to the extent necessary to perform a contract, or on the basis of our or the Client's legitimate interest. In these cases our partners process the Data on behalf of the controller.
To deliver our service we use sub-processors. When we do, we are responsible for making sure that the sub-processors also follow the Client's instructions.
We may transfer Data for the following purposes:
- to deliver the AI service: the list of sub-processors we use is available at https://heppu.ai/gdpr
- to our partners who process the Data in order to provide their own services (for example accounting, IT systems, banking, insurance);
- with the Data Subject's consent, to the parties the consent concerns; and
- to authorities or legal advisers where disclosure is necessary under the law or on the basis of our legitimate interest.
Transfer of personal data to third countries
To deliver our service we use external service providers, some of which may be located outside the EU and the European Economic Area. We have made sure that these service providers comply with the GDPR.
Protection of personal data
Data is protected with appropriate technical and organisational safeguards. Everyone who processes personal data has committed to keeping the Data Subjects' Data confidential and to processing it only for the purpose set out in this Policy.
Retention period
As Controller, we keep Data for as long as it is needed for the purpose it was collected for. Data collected for a Service Agreement is deleted one year after the end of the calendar year in which the Service Agreement ended, unless the law requires otherwise.
Law or other regulation may require a longer retention period (for example the retention periods under the Finnish Accounting Act 1336/1997).
When we act as Processor, we process data according to the Client's instructions, in the Client's system or through integrations with the Client's systems. The Client retains data according to its own practice.
Profiling and automated decision-making
Data is not used for profiling or for other automated decision-making.
Profiling means automated processing of Data that evaluates a person's personal characteristics.
Rights of the data subject
Under the GDPR, the Data Subject has:
The right of access:
The Data Subject has the right to confirmation of whether Data concerning them is being processed and, if it is, the right to a copy of their Data;
The right to rectification:
The Data Subject has the right to request that inaccurate or incorrect Data concerning them is corrected. The Data Subject also has the right to have incomplete Data completed by providing the necessary additional information;
The right to erasure:
The Data Subject has the right to request the erasure of Data concerning them if
- the Data is no longer needed for the purposes for which it was collected; or
- the Data has been processed unlawfully.
The right to restriction of processing:
The Data Subject has the right to restrict the processing of Data concerning them if
- the Data Subject contests the accuracy of their Data;
- the processing is unlawful and the Data Subject opposes the erasure of their Data and asks for its use to be restricted instead; or
- the Controller no longer needs the Data for the original purposes of the processing, but the Data Subject needs it to establish, exercise or defend a legal claim.
The right to data portability:
The Data Subject has the right to receive the Data concerning them, which they have provided themselves, in a structured, commonly used and machine-readable format, and the right to transfer that Data to another controller.
The right to lodge a complaint with a supervisory authority:
The national supervisory authority for personal data matters in Finland is the Office of the Data Protection Ombudsman, which operates in connection with the Ministry of Justice. The Data Subject has the right to bring a matter concerning their Data before the supervisory authority if they consider the processing of the Data to be unlawful.
The Controller responds to a request concerning the Data Subject's rights within one month of receiving it. For specific reasons, the response time may be extended by up to two months.
The Controller is not obliged to carry out all measures requested by the Data Subject. In that case we inform the Data Subject of the reasons for the refusal without delay and at the latest within one month.
Changes to our privacy practices and to this policy
We develop our operations continuously, so we may change and update our privacy practices from time to time. Changes may also follow from changes in legislation.
If the changes introduce new purposes for processing Data or otherwise change the Policy materially, we will announce the changes on our website and, where necessary, ask for consent. The date of the latest update is shown at the top of this page.
This is an English translation of the Finnish privacy policy. If the two versions differ, the Finnish version applies.