Privacy

Privacy policy

How Sutja processes personal data as a data controller.

Updated 14 September 2026

Overview

This policy explains how plops Oy processes personal data as a data controller. It covers visitors to our website, people who contact us, and the contact persons of our subscribing customers.

When our customer processes their own employees' data in the service (shifts, absences and other HR), the customer is the data controller and Sutja acts as a data processor. That processing is governed by a separate data processing agreement, described on the GDPR page.

Data controller

The data controller is plops Oy (business ID 3596026-3). Postal address: Linnanpellonkatu 52, 70300 Kuopio, Finland.

We have not appointed a separate data protection officer, but for data protection matters you can contact tietosuoja@sutja.fi.

Controller or processor

Sutja is the controller for the data it controls itself: website visitors, enquiries and the contact persons of customers.

For the personal data a customer enters about their own employees, the customer is the controller and Sutja processes the data on the customer's behalf. This policy does not cover that processing; it is governed by the data processing agreement with the customer.

What we use data for

We process personal data for the following purposes:

  • Providing the service, managing user accounts and sign-in
  • Customer relationship management, support and communication
  • Billing and statutory accounting obligations
  • Improving the service, security and abuse prevention
  • Marketing and contact with business contact persons
  • Meeting legal obligations

What data we process

We mainly process the following data:

  • Contact details: name, work email, phone number, organisation and role
  • Account data: user identifier and account settings
  • Contract and billing data
  • Enquiries and support correspondence
  • Technical data: log data, IP address and session data to keep the service working and secure

Where data comes from

We receive data mainly from the data subject or their employer (the customer organisation) when the service is taken into use or used. Some data is generated through use of the service. Company information may be supplemented from public registers such as the trade register.

Legal bases for processing

Processing is based on the following GDPR legal bases:

  • Contract: providing the service to the subscriber and users
  • Legitimate interest: customer relationship management, service development and security
  • Consent: electronic direct marketing
  • Legal obligation: for example accounting legislation

Where processing is based on legitimate interest, we have assessed each of the purposes listed above separately and concluded that our legitimate interest is not overridden by the interests, rights or freedoms of the data subject. The assessments are documented and reviewed annually.

You have the right to object to processing based on legitimate interest on grounds relating to your particular situation. Tell us at tietosuoja@sutja.fi and we will stop the processing unless there are compelling legitimate grounds for continuing it.

Some data is necessary to enter into the agreement or use the service; without it we cannot provide the service.

Recipients and processors

We do not sell personal data. Data is processed on our behalf by carefully selected processors that provide, for example, hosting, email and accounting services. All the providers we use are located in Finland or elsewhere in the EU, and a data processing agreement is in place with each of them.

An up-to-date list is on our GDPR page. That page also distinguishes which providers process the data covered by this policy on our behalf and which act as sub-processors for the data a customer stores in their workspace. The two roles are worth keeping apart: a sub-processor is not a recipient under this policy but part of the chain under the data processing agreement made with the customer.

Subscription invoicing is handled in Procountor (Accountor Finago Oy). When we invoice a customer's subscription, we transfer the billing details there: company name, business ID, billing address, the billing contact's email address and the invoice details. Procountor also produces and delivers the invoice and serves as our accounting system, so invoice data is retained for the period required by accounting legislation.

Data may be disclosed to authorities where required by law.

The customer can grant an external payroll clerk limited access to a workspace without creating an employment relationship. The clerk can view payroll data, individual time entries and reimbursements, and the personal and employment details needed to set up employees in payroll, including personal identity codes, bank accounts, addresses and salary information. The clerk can correct payroll IDs, cost centre codes and payroll settings and initiate payroll exports, but cannot approve hours or reimbursements. The customer is responsible for granting access and for its own payroll clerk; the clerk is not a subprocessor selected by Sutja. Opening employee details is recorded in the activity log without the identity code, bank account or other displayed values. Access can be revoked in workspace settings.

Transfers outside the EU and EEA

Personal data is stored in Finland and is not stored outside the EU or EEA.

Nor is the service's traffic processed outside the EU: DNS, content delivery and the firewall are provided by BunnyWay (bunny.net), a Slovenian company, and traffic is served from EU locations under a documented restriction recorded in the data processing agreement.

How long we keep data

We keep personal data only as long as necessary:

  • Account and customer data: for the duration of the customer relationship and up to 90 days after it ends, after which data is deleted or anonymised
  • A user account with no active workspace membership: anonymised automatically once the account has been unused for 90 days
  • Accounting-related data: for the period required by accounting law, generally 6 years
  • Enquiries: up to 12 months
  • Error and performance data we process for troubleshooting and improving the service: at most 60 days
  • Traffic logs from the protection layer, processed for security and abuse prevention: 3 days
  • The service usage log, which contains the IP address and browser identifier: 24 months. The log arises in the customer's workspace and the customer is its controller, but Sutja also uses the same log to monitor its own security
  • Backups: rotated in roughly 30-day cycles

When a workspace is deleted, access ends immediately and the data is destroyed permanently after 60 days. As the last step of that destruction we destroy the workspace's encryption key, which makes its encrypted data permanently unreadable. In backups taken before the deletion, unencrypted data remains for as long as those backups stay in rotation.

The employee data a customer stores in their workspace is subject to its own staged retention periods. The controller for that data is the customer, so it falls outside this policy. They are collected into a single table on the GDPR page.

Your rights

You have the right to:

  • Access and review your data
  • Have inaccurate data corrected
  • Request erasure of your data
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent you have given

You can delete your own user account yourself on your profile page in the service. For other rights, contact tietosuoja@sutja.fi. We respond to requests generally within one month.

If your request concerns data your employer has stored in their workspace, your employer is the controller and we route the request to them. The stages of deletion and the retention periods are described on our GDPR page.

Automated decision-making

We do not carry out automated decision-making or profiling covered by this policy that produces legal or similarly significant effects on you.

The automated shift planning performed in the service concerns the customer's employees' data, where the customer acts as the controller. That processing is governed by the data processing agreement.

Security

We protect personal data with appropriate technical and organisational measures. Data is encrypted in transit and at rest, access is restricted by role on a least-privilege basis, and use is monitored through logs. Data is stored in Finnish data centres and backed up regularly.

The most sensitive data, such as absence reasons and their attachments, bank account, address and the contents of employment contracts, is additionally encrypted field by field and file by file with the workspace's own encryption key before it is stored. The master key is not kept in the database, and keys can be rotated. Within the employer organisation, this data is visible only to the employee, their own supervisor chain and administrators. Once a workspace's key is destroyed, the fields and files encrypted with it cannot be recovered with any key.

If a personal data breach occurs, we notify the supervisory authority and, where required, you, as required by law.

Right to lodge a complaint

If you consider that the processing of your personal data is unlawful, you can lodge a complaint with the supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi).

Cookies

Our website uses no tracking or analytics cookies and no third-party ad tracking. Fonts and other resources are served from our own server. The service itself uses only essential cookies to maintain sign-in and sessions.

Changes to this policy

We may update this policy as the service or legislation changes. We publish the current version on this page and note the update date at the top.

Join the waitlist

You're on the list!

Thanks! We've sent a confirmation to your inbox and will let you know the moment Sutja opens.

Sutja is opening soon. Leave your email and we'll let you know the moment you can get in.

Something went wrong. Please try again or email us at hello@sutja.fi.

By submitting you accept our privacy policy.