Privacy policy
Updated: 14 August 2026
1. Data controller
Fisas Oy
Business ID: 3628711-1
Email: privacy@fisas.fi
2. Contact person for data protection
Johannes Koponen
Email: privacy@fisas.fi
3. Scope of this policy
This policy covers both visitors to the fisas.fi website and registered users of the fisas.app application. Application users may refer to this policy instead of a separate privacy page in the app.
4. Data we collect
Website visitors:
- Cookies and analytics data (Google Analytics 4)
- Advertising measurement data (Google Ads, only with consent)
- From the contact form: name, email, phone (optional), company (optional), message
- IP address (anonymised)
Application users:
- User details: name, email, phone number
- Company details: name, business ID, address
- Business data: projects, invoices, quotes, work hours, tasks and notes
- Subcontractor and customer data
- Photos, videos, audio recordings, documents and files
- In-app messages and their attachments
- Location data when the user explicitly allows it (e.g. logging work time)
- Push notification device identifiers, and device and usage data
- Content submitted to AI features (text, images, audio) and, with the user's consent, other data stored in the service, processed to generate a response
Fisas Oy acts as the data controller for user, account and billing data, and as a data processor for the business and personal data the customer enters into the service. The customer owns all data they store in the service.
5. Legal basis and purpose of processing
- Performance of a contract: providing the application services
- Legitimate interest: service development, information security
- Consent: analytics and marketing cookies, marketing communication
- Legal obligation: accounting, taxation
6. Data retention period
Application user data is retained for the duration of the contract. After the contract ends you may request your data for one (1) month. Data is deleted automatically no later than twelve (12) months after the contract ends; you may also request deletion earlier. Some data may be retained longer where legislation (for example the Accounting Act, 6 years) requires it. Analytics data is retained for 26 months.
7. Disclosure of data
We do not sell or disclose personal data to third parties for marketing purposes. We use the following subprocessors to provide the service:
- Database and storage services
- Email service
- Visitor analytics (Google Analytics, only with consent)
- Advertising and its measurement (Google Ads, only with consent)
- AI feature provider
- Payment service
- Web hosting
We have concluded data processing agreements with our subprocessors. Data is processed primarily within the EU/EEA; any transfers outside the EU/EEA are protected by appropriate safeguards, such as the EU Standard Contractual Clauses (SCC).
A user may connect their own AI assistant to the service. The connection is always opened on the user's own initiative and with their own credentials, and the assistant can only reach data the user is entitled to see anyway. The provider the user chooses then processes the content read from the service under its own terms. That provider is a separate company from FiSAS Oy, and FiSAS Oy is not responsible for how the data is processed or stored there. The organisation administrator decides whether the connection is enabled, what data the assistant may use, and whether it may also bring data into the service. Content brought in is stored as a draft: a draft is not a valid document, and the user reviews and approves it in the service. The connection can be disconnected at any time.
8. Cookies
We use necessary cookies to ensure the service works, analytics cookies to develop the service, and marketing cookies to measure the results of advertising. Analytics and marketing cookies are set only with your consent, and you can accept them separately. You can manage your cookie settings from the site's cookie banner or in your browser settings.
If you have accepted marketing cookies, advertising measurement data may also be processed when you move from the website to the application.
9. Rights of the data subject
- The right to access your own data
- The right to rectify inaccurate data
- The right to erase data ("the right to be forgotten")
- The right to restrict processing
- The right to transfer data to another service
- The right to object to processing
To make a request: privacy@fisas.fi. We respond within one month.
10. Information security
Data is transferred over an encrypted HTTPS connection. The database is protected with access control, and access to data is limited to those who need it for their duties.
11. Right to lodge a complaint
You have the right to lodge a complaint with the data protection authority (Office of the Data Protection Ombudsman, tietosuoja.fi) if you consider that the processing of your personal data is unlawful.
12. Changes to this privacy policy
We update this policy when necessary and publish updates on this page. We aim to inform users of significant changes.
13. Contact
Fisas Oy
privacy@fisas.fi