This document is currently only available in English.
Privacy Policy
EntrepreJee Last updated: [date]
1. Who we are
[Company Legal Name] ("EntrepreJee", "we", "us"), business ID (Y-tunnus) [0000000-0], registered address [Street, Postal Code, City, Finland], is the data controller for the personal data described in section 3 below. Contact us about privacy at [privacy@entreprejee.com]. Given our size, we are not required to appoint a Data Protection Officer under Article 37 GDPR, but privacy questions are handled directly by us at the address above.
2. Scope: two different roles
This policy covers two different relationships, because EntrepreJee plays two different roles under GDPR:
- As data controller — for your own account and business-profile data (section 3.1), we decide why and how it's processed, and this policy tells you how.
- As data processor — for personal data you enter about your customers (names, emails, addresses, notes — section 3.2), you are the controller and we just process it on your instructions, under the terms of our Data Processing Agreement. If one of your customers wants to exercise a GDPR right over data you've stored about them in EntrepreJee, they should contact you, not us — we'll help you fulfill that request.
3. What personal data we process
3.1 Your account and business data (we are the controller)
- Account: email address, authentication data (managed by our database/auth provider, see section 6).
- Business profile: business name, VAT/business ID, address, postal code, country, currency, language, subscription plan.
- Usage and log data: IP address, browser/device information, timestamps, and error logs, collected automatically for security and reliability purposes. In particular, each time you sign in we record a login event (IP address, browser/device information, and timestamp) against your business account, visible only to the business owner, so that unauthorized access can be detected and investigated — see "How long we keep it" below for how long these are kept.
3.2 Data you enter about your customers (you are the controller, we are the processor)
- Customer records: name, email, phone, address, notes.
- Documents you generate: invoices, quotes, delivery notes, and other business documents, and the data they contain (line items, prices, dates).
- Time-tracking and project data linked to your customers, where you choose to record it.
We do not access, use, or analyse this data for our own purposes beyond providing and maintaining the Service (e.g. troubleshooting a bug you report).
4. How we collect your data
We collect personal data in three ways:
- Directly from you — when you create an account, complete your business profile, or enter data into the Service, such as customer records, invoices, quotes, expenses, time entries, and documents.
- Automatically from your browser — technical data such as your IP address, browser and device information, and timestamps, collected automatically as you use the Service, for security and reliability purposes and via the cookies/local storage described in our Cookie Policy.
- From our authentication provider — our authentication provider (see section 6, Sub-processors) supplies account-related data it generates when you sign up or log in, such as your verified email address, sign-in timestamps, and authentication status.
5. Why we process it and our legal basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and operating your account | Performance of a contract (1(b)) |
| Generating invoices, VAT/ALV summaries, and reports | Performance of a contract (1(b)); legal obligation (1(c)) where bookkeeping law requires it |
| Billing you for a paid plan | Performance of a contract (1(b)) |
| Keeping the Service secure and preventing abuse | Legitimate interest (1(f)) |
| Responding to support requests | Performance of a contract (1(b)) / legitimate interest (1(f)) |
| Sending service-related emails (e.g. password reset) | Performance of a contract (1(b)) |
We do not use your data for advertising, and we do not sell personal data to third parties.
6. Who else processes this data (sub-processors)
We use the following sub-processors to run the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication, encryption at rest/in transit | [Supabase project region, e.g. EU (Frankfurt)] |
| [Hosting provider, e.g. Vercel Inc.] | Application hosting | [region] |
| [Email delivery provider, if any] | Transactional emails (e.g. password reset, email confirmation) | [region] |
| Stripe | Payment processing and subscription billing for your EntrepreJee account (plan and Pay-per-use charges) — Stripe receives your name, email, and payment details; we never see or store your card number | [Stripe processing region, e.g. EU/US] |
Where a sub-processor is located outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (or an equivalent adequacy mechanism) to protect your data. We'll update this list if it changes, and material changes affecting how your customers' data (section 3.2) is processed will also be notified under our Data Processing Agreement.
We do not currently use any third-party analytics, advertising, or tracking services — see our Cookie Policy for the full list of cookies and similar technologies we do use.
(As of this draft, no online payment processor is connected — subscription plan changes don't move money yet. Once billing is enabled, this section and the Terms of Service will be updated to name the payment processor and describe how your payment details are handled by them.)
7. How long we keep it
- Account and business data: for as long as your account is active, plus a reasonable period afterward for backups and legal purposes.
- Invoices and accounting-relevant records: retained for at least the period required by the Finnish Bookkeeping Act (Kirjanpitolaki 1336/1997) — currently 6 years from the end of the financial year for accounting materials, and up to 10 years for certain records (e.g. the general ledger and financial statements) — even if you delete your account, so that you and, where relevant, we can meet statutory bookkeeping obligations.
- Customer records you enter (section 3.2): retained until you delete them or close your account, after which they are deleted subject to the retention period above for any records that form part of your accounting materials (e.g. a customer's name on an invoice).
- Login/access events (IP address, browser/device information, timestamp): kept for 60 days, then automatically deleted, for security and access-monitoring purposes.
- Other logs (e.g. error logs): kept for a limited period (typically no more than [12] months) for security and debugging purposes.
8. Security
We rely on our database provider's built-in encryption at rest and in transit, and enforce access control at the database level using row-level security policies, so that each business can only ever read or write its own data — this is a deliberate architectural choice rather than per-field application-level encryption. Access to production data is restricted to what's necessary to operate the Service. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. See our Data Processing Agreement (section 6) for a fuller breakdown of technical and organisational measures, including which are not yet in place.
9. Data breach notification
We handle personal data breaches in accordance with Articles 33 and 34 GDPR. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (in Finland, the Office of the Data Protection Ombudsman) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly, without undue delay. Where the affected data is data you control (section 3.2 — your customers' data), our obligation as processor is to notify you without undue delay, per our Data Processing Agreement, so that you can meet your own notification obligations as controller.
10. International data transfers
Where personal data is transferred outside the EEA (see section 6), we ensure an appropriate safeguard is in place, such as the European Commission's Standard Contractual Clauses, before the transfer occurs.
11. Automated decision-making
We do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR. No decision producing legal effects concerning you, or similarly significantly affecting you, is made solely by automated means without human involvement.
12. Your rights
Under the GDPR, you (and, where you are the data subject rather than another controller, your end customers via you) have the right to:
- Access the personal data we hold about you (Art. 15)
- Correct inaccurate data (Art. 16)
- Request erasure ("right to be forgotten"), subject to our bookkeeping retention obligations (Art. 17)
- Restrict or object to certain processing (Art. 18, 21)
- Receive your data in a portable format (Art. 20) — see "What you can export" below
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi), or your local EU supervisory authority
To exercise any of these rights over your own account data, contact us at [privacy@entreprejee.com]. We will normally respond within one month of receiving your request; where necessary — for example, if the request is complex or we've received a high volume of requests — we may extend this by a further two months, in which case we'll tell you why within the first month.
What you can export. Most of your business data (customers, invoices, quotes, products, expenses, time entries, documents) can be viewed, corrected, or deleted directly within the app. As of this draft, the Service also lets you export or download the following directly:
- Invoices — download any invoice as a PDF from its detail page.
- Quotes — download any quote as a PDF from its detail page.
- VAT/ALV report — export the VAT summary for a chosen period as a CSV file, from Reports.
- Documents — download any document you've created as a text file, from its detail page.
- Expense receipts — view or download an individual uploaded receipt image from its expense's detail page.
There is currently no single "export everything" bulk download covering all of your data at once. If you need a complete copy of your account data — for example, before closing your account, or to respond to a data subject request from one of your own customers — contact us at [privacy@entreprejee.com] and we will help you obtain it.
13. Children's privacy
The Service is intended for business use by adults and is not directed at, or knowingly used to collect data from, individuals under 18.
14. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will notify you (e.g. by email or in-app notice) before they take effect.
15. Contact
Questions about this policy or your data can be sent to [privacy@entreprejee.com]. You also have the right to contact the Finnish Office of the Data Protection Ombudsman directly.
This is a generic starting template, not legal advice. It makes factual claims about how the product currently works (e.g. no analytics, no payment processor yet, Supabase sub-processor, RLS-based security, exactly what can be exported today) that must be kept in sync with reality as the product changes — a Privacy Policy that describes data handling you don't actually do (or omits data handling you do) is itself a compliance problem. If a future feature adds automated decision-making/profiling, section 11's statement must be revisited immediately, not left stale. Have a qualified Finnish/EU lawyer review it, especially sections 6, 7, 9, and 10, before publishing.