Privacy Policy
Information on processing of personal data under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR). Updated 12 August 2026.
The most important point first: the contents of your documents never reach us. PDF files and images are processed entirely on your own device and are not sent to, stored in or backed up by our systems. This policy therefore covers other data: enquiries, orders, licence administration and website visitor statistics.
1. Data controller
- Controller
- Koukku Kapital Oy (auxiliary trade name Koukku Digital)
- Business ID
- 3331246-5
- Domicile
- Turku, Finland
- Street address
- Kärsämäentie 35, 20360 Turku, Finland
- Postal address
- P.O. Box 3, 20201 Turku, Finland
- Contact person for data protection
- John Tammi, john@koukku.ai
- Orders and licence matters
- myynti@koukku.ai
We have not appointed a data protection officer, because the conditions of Article 37 GDPR are not met. Data protection matters are handled by the contact person named above.
2. Who the data concerns
- People who have sent a quote request, a trial request or a contact form
- Contact persons at customer organisations and those who order licences
- Users of customer organisations' workstations, to the extent that per-workstation licence keys are issued (section 3.3)
- Website visitors
3. What data we process
3.1 Enquiry and quote request data
Name, email address, organisation name, number of workstations, business ID, e-invoicing address (OVT), any phone number, and the free-form content of the message.
3.2 Customer, licence and invoicing data
Contact person's name and email, order number, number of licences ordered, contract period, licence keys issued, invoicing and payment details, and customer correspondence.
3.3 Workstation technical identifier
When a customer orders per-workstation licence keys, the customer's own IT runs a collection script we provide on their workstations and sends us the resulting file. From that file we process:
- the workstation's technical identifier: a one-way value computed from technical values read from the machine. The original values are not stored or transmitted as such, and they cannot be derived back from the identifier;
- the machine name provided by the customer: this column exists in the file for the customer's own record keeping. The customer may delete the column before sending the file, and the keys are still issued correctly.
We do not claim this data is anonymous. Hashing limits the damage, but because we maintain the identifier precisely in order to identify a machine, and a workstation is often used by a named individual, we treat it as personal data and apply every right and obligation in this policy to it.
The collection script does not read user names, IP addresses, files, documents or installed software. The application does not send the identifier anywhere during use: it is computed and compared locally on the machine. The only transfer is this one-off collection, which the customer performs themselves and whose result the customer can inspect before sending. The same description is in the deployment guide (in Finnish).
3.4 Website visitor data
The website uses Plausible Analytics, a cookie-free visitor measurement service hosted in the EU. It processes page paths, the referring address, browser and device type, and a coarse location (country) derived from the IP address.
The measurement stores nothing on your device and reads nothing from it — no cookie, no browser local storage, no device fingerprint. For this reason it falls outside the scope of section 205 of the Finnish Act on Electronic Communications Services (917/2014), and the site therefore has no cookie banner.
We do not claim the measurement is entirely data-free. Unique visitors are counted on the server from a hash formed of a daily random salt, the domain name, the IP address and the browser information. The salt is rotated and destroyed every 24 hours, and neither the IP address nor the browser information is stored at any point. The momentary processing of the IP address is processing of personal data on the basis of legitimate interest (Article 6(1)(f) GDPR): the need to know how much the site is used without tracking visitors.
The desktop application loads no analytics at all — it opens no network connections for its use.
3.5 What we do not process
We do not receive, store or process the contents of the documents you work on, their file names, or the personal data contained in them. Nor do we process payment card details: there is no card payment on this site.
4. Purposes and legal bases
| Purpose | Data category | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Responding to quote requests and enquiries, preparing quotes | 3.1 | Steps prior to entering into a contract (6(1)(b)) |
| Delivering a trial key | 3.1 | Steps prior to entering into a contract (6(1)(b)) |
| Delivering the order, licence administration and customer support | 3.2 | Performance of a contract (6(1)(b)) |
| Issuing licences per workstation and verifying the agreed licence count | 3.3 | Performance of a contract (6(1)(b)) |
| Invoicing and accounting | 3.2 | Legal obligation (6(1)(c)) — Finnish Accounting Act |
| Measuring and improving use of the website | 3.4 | Legitimate interest (6(1)(f)): monitoring the functioning and usability of the service |
| A single follow-up contact after a trial | 3.1 | Legitimate interest (6(1)(f)): establishing a customer relationship |
5. Where the data comes from
Data is generally obtained from the data subject themselves via forms on the website or by email. The data in section 3.3 is obtained from the customer organisation, which collects it on its own workstations and sends it to us. The data in section 3.4 arises from use of the website.
6. Processors — which services we use and for what
We use the following service providers. Each processes personal data only on our behalf and on our instructions. None of them processes the contents of your documents, because that content never leaves your device.
| Service | What it is used for | Data category | Location of processing |
|---|---|---|---|
| Google — Firebase Hosting and Cloud Functions | Delivering the website and application to the browser; receiving form submissions | 3.1, 3.4 | The server region we use is the EU (europe-west1). The provider is part of a US group. |
| Google — Firestore | Storing quote and trial requests | 3.1 | EU region |
| Plausible Analytics | Cookie-free visitor measurement on the website | 3.4 | EU region. The provider is an Estonian company and the infrastructure is owned by European companies; visitor data does not leave the EU. |
| Resend | Sending order, trial and licence emails | 3.1, 3.2 | United States |
| HubSpot | Customer relationship management: quote requests, quotes and customer correspondence | 3.1, 3.2 | United States |
The workstation identifiers in section 3.3 are not fed into the marketing or analytics services listed above. They are processed as part of issuing licences and stored separately. They are not disclosed to third parties.
We do not sell or rent personal data. Data may be disclosed to an authority where the law requires it.
Note on visitor measurement: the website previously used Google Analytics. It was replaced on 12 August 2026 with cookie-free analytics hosted in the EU, so visitor data is no longer transferred to the United States and the site requires no consent for visitor measurement. Public sector customers can still be offered a version with no third-party analytics at all.
7. Transfers outside the EU/EEA
Some of our processors (Resend and HubSpot) are US services, which means some personal data is transferred outside the EU/EEA. This concerns the data in sections 3.1 and 3.2 — not document contents, not the identifiers in section 3.3, and not the visitor data in section 3.4.
Visitor measurement is no longer transferred outside the EU. Google Analytics was replaced on 12 August 2026 with cookie-free analytics hosted in the EU, so the data in section 3.4 is processed entirely within the EU.
Transfers rely on the European Commission's standard contractual clauses (SCC) or on an adequacy decision (EU–US Data Privacy Framework), whichever applies to each provider. On request we can provide an account of the transfer basis as an annex to a procurement.
Document contents are not transferred at all — neither within nor outside the EU — because they never leave the user's device. For this reason the Chapter V transfer assessments of the GDPR do not apply to document work.
8. Retention periods
| Data category | Retention period |
|---|---|
| Quote and trial requests that do not lead to a customer relationship | 24 months from the last contact |
| Customer and licence data | For the duration of the contract and 24 months after it ends |
| Workstation technical identifier and machine name (3.3) | For the contract period and at most 12 months after it, so that renewals and a replacement key for a broken machine can be handled |
| Invoicing and accounting material | Under the Finnish Accounting Act, six years from the end of the calendar year in which the financial period ends |
| Visitor measurement data | The factor that would make identification possible (the daily salt) is destroyed every 24 hours. Neither the IP address nor the browser information is stored at all, so all that remains is statistics that cannot be linked to a person, retained for as long as the service is in use. |
Once the retention period ends, the data is deleted or altered so that it can no longer be linked to a person.
9. Cookies
The website uses no analytics or marketing cookies. Visitor measurement is cookie-free: it stores nothing on your device and reads nothing from it.
The only things stored on your device are those necessary for the service to work, and they are kept in your browser's local storage on your own device: the language selection, the licence key status, the local usage log described in section 12, and settings you have entered yourself such as a saved signature and the author name for annotations. These are data necessary for providing the service within the meaning of section 205 of the Act on Electronic Communications Services (917/2014) and therefore require no consent. None of it reaches us — it stays on your device.
This is why the site has no cookie banner. The banner is not missing by oversight: there is nothing on the site that consent would need to be requested for. You can clear the local storage at any time in your browser settings; the language selection and any licence key will then return to their defaults.
The desktop application sets no cookies, loads no analytics and makes no network connection for its use.
10. Your rights as a data subject
You have the right to:
- access your data and obtain a copy of it
- have inaccurate or incomplete data corrected
- request erasure of your data
- restrict processing and object to processing based on legitimate interest
- port the data you have provided from one system to another
- withdraw consent, where processing is based on consent
Requests can be sent to john@koukku.ai. We respond within one month. We may ask you to verify your identity before releasing data.
If you work for an organisation that has purchased a licence and your request concerns the data in section 3.3, we will first direct you to your own organisation's IT lead: the collection of machine identifiers is carried out and decided by your employer. We will nevertheless also handle your request ourselves.
11. Right to lodge a complaint
If you consider that we process your personal data contrary to data protection law, you may lodge a complaint with the supervisory authority. In Finland the supervisory authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).
12. Security of processing
- Data exists in digital form only. Access is limited to people whose duties require it and is protected with personal credentials and multi-factor authentication.
- Traffic between the website and the user is encrypted (HTTPS).
- The identifiers in section 3.3 are stored separately from the marketing and analytics systems.
- The application has a local usage log to support GDPR accountability. It is stored only on the user's own device and can be inspected and cleared by the user — it does not reach us.
13. Our role under the GDPR
As regards your documents, we are generally not a processor of personal data at all, because the content never leaves the controller's control. As regards licence and contact data, we act as the controller ourselves. If a procurement requires a data processing agreement, we provide one: DPA template (in Finnish).
14. Changes to this policy
We update this policy when our processing changes. We notify our customers of material changes. The date of the latest update is always shown at the top of the page.