Skip to content

LEGAL

Privacy notice.

What we collect, why, who else sees it, and what is not in place yet.

Reviewed by counsel, 30 July 2026. Factually updated on 15 August 2026 — billing went live and self-service export and deletion shipped; the updated sections are with counsel for re-review. Updated again on 10 September 2026, when the whitepaper became open to read: its entry below now lists every field the optional email form takes, and that change has not yet been reviewed by counsel. This notice is written to be accurate rather than reassuring. Where something is not in place, it says so.

Who is responsible

The controller is Paraproven Oy, Helsinki, Finland, trading as EdSSA — VAT FI36373159, Business ID 3637315-9. “EdSSA”, “we” and “us” below mean that company.

For anything in this notice, including a request to exercise your rights: contact@edssa.io. We have not appointed a Data Protection Officer; we are not required to, and saying so is more useful than leaving the question open.

Two services, two different pictures

This notice covers both, and they are not alike. edssa.io, the public website, has no login and no account — you can read every page and download all 170 example reports without identifying yourself. app.edssa.io, the Compliance Cloud, has accounts, and an account is an email address.

What we collect, and why

On the public site (edssa.io)

  • Contact form — name, role, company, email address and your message. Used to answer you. It is relayed straight to a mailbox and is not stored in a database.
  • Whitepaper by email — optional; the whitepaper itself is open to read without it. Name and email address, plus role, company and your M2M challenge if you choose to give them. Used to send you the link and to answer anything you asked. Like the contact form, it is relayed straight to a mailbox and not stored in a database; the relay on our own server logs the address the link was sent to.
  • Analytics — aggregate page-view counts via Plausible. Cookieless, EU-hosted, no cross-site tracking, no personal data, and no consent banner because there is nothing to consent to.
  • Report downloads — we count how many times each example report is downloaded. The counter records the file and the time. It does not record who.

In the Compliance Cloud (app.edssa.io)

  • Your email address. The only identifier. There is no password — you sign in by clicking a one-time link we email you, so your address is not an optional extra, it is the account.
  • Sign-in tokens. Only a SHA-256 hash of the link is stored, never the link itself, and it expires 15 minutes after it is issued.
  • Timestamps — account created, email verified, session activity. Used to expire sessions and to answer support questions.
  • Reports you generate — the organisation name, sector and figures you type in. These are facts about your systems rather than about a person, but they are yours and we treat them as confidential.
  • Product events — that an account signed in, generated a report, or downloaded one, and in which format. Recorded server-side against the account, with no device or network identifier attached.
  • One session cookie. Opaque, strictly necessary, no tracking value, deleted when you sign out.

What we deliberately do not collect

These are not aspirations. They are properties of the database schema, and they are the reason neither service shows you a cookie banner:

  • No IP addresses. No table has a column for one. An IP is used transiently, in memory, to rate-limit form submissions and sign-in attempts, and is discarded when that window closes.
  • No user-agent strings. Same — no column exists.
  • No passwords, because there are none to store.
  • No advertising or analytics cookies, no third-party trackers, no pixels and no cross-site identifiers, on either service.
  • No profiling and no automated decision-making with legal or similarly significant effects, within the meaning of GDPR Article 22.
  • We do not sell personal data and do not share it for anyone else’s marketing.

Lawful basis (GDPR Article 6)

  • Performance of a contract (Art. 6(1)(b)) — the account email address and everything needed to run the Compliance Cloud for you. You cannot withdraw this while keeping the account, because the address is the account; the equivalent action is deleting it.
  • Legitimate interests (Art. 6(1)(f)) — answering an inquiry you sent us; counting downloads and product events so we know which parts of the product get used; rate-limiting and security. Our interest is running and improving a service you asked for, and the data involved is minimal and not shared.
  • Consent (Art. 6(1)(a)) — the whitepaper and any marketing email. Withdrawable at any time, by the unsubscribe link or by emailing us. Withdrawal does not affect processing that happened before it.
  • Legal obligation (Art. 6(1)(c)) — accounting records, once there are any to keep.

How long we keep it

  • Account data — for as long as the account exists, and deleted when it is deleted.
  • Sign-in tokens — 15 minutes.
  • Sessions — until they expire or you sign out.
  • Reports you generated — kept while the account exists. A compliance artefact you may need to produce later is not something to delete on a timer.
  • Inquiry email — kept in the mailbox while the conversation is live, then archived. We do not operate a CRM.
  • Server logs — the web server keeps access logs containing IP addresses on our own machine, rotated within 30 days. They are operational and are not joined to accounts.

Who else processes it

The full list, with what each one can actually see. There are four, and only two of them touch the Compliance Cloud:

ProcessorWhat forWhereTransfer basis
Hetzner Online GmbHHosting for app.edssa.io — the server, its disks, its backupsHelsinki, FinlandNone needed — stays in the EU
MigaduSending email: sign-in links, and our own inbound mailSwitzerlandAdequacy decision
StripePayment processing for paid subscriptions. Sees what the payer enters on Stripe’s hosted checkout — name, email, billing address, VAT ID, card details — and nothing else: no reports, no evidence, no chains. Card numbers never transit our servers.Contracting entity being confirmed — see belowStripe’s DPA and SCCs; being confirmed
Cloudflare, Inc.DNS, CDN and TLS for the public site. No account data.Global edge; US companyStandard Contractual Clauses
Plausible AnalyticsAggregate page views. No personal data.EUNone needed — stays in the EU

Two things worth stating plainly. Cloudflare is not in the path of the Compliance Cloud — app.edssa.io resolves directly to the Hetzner machine, so session cookies and sign-in links do not pass through a US provider. And Migadu can see the recipient address and the body of the email, which for a sign-in message is a one-time link; it holds no other account data.

Stripe became a processor when payments opened in August 2026. An earlier version of this notice promised to be updated before that happened, not after; the update in fact came after, and we state that rather than hide it. Only accounts that go through checkout are affected, and payment webhook payloads — which carry the billing contact’s details — are redacted after 30 days. Which Stripe entity is the counterparty, and on what basis any transfer outside the EU occurs, is being confirmed against the signed agreement; this notice will state the answer rather than an assumption.

Your rights

Under GDPR Articles 15–22 you have the rights of access, rectification, erasure, restriction, portability and objection, plus the right to withdraw consent where consent is the basis. Email contact@edssa.io and we will act within one month.

Honestly, about how: since August 2026 there is a self-service export and a self-service delete in the account itself, and the deletion is a genuine hard delete — rows, stored report files, and the account’s storage area, not a flag on a row. Anything the endpoints do not cover is carried out by hand, by a person, within the same one-month window.

If you think we have got this wrong you can complain to the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), at tietosuoja.fi. You can do that without contacting us first.

Security

TLS on every connection. Sign-in links are single-use, hashed at rest and expire in 15 minutes. Sessions are per-account and individually revocable, and every request re-checks that the session still belongs to the account it claims. Reports are scoped to the account in the query itself, so another account’s report id returns “not found” rather than “forbidden” — the id does not confirm that it exists.

Changes

Last updated 30 July 2026, a full rewrite: the previous version predated the Compliance Cloud, named a subprocessor we no longer use, and omitted two that we do. If we make a material change we will say so here and email active account holders.