Source: https://www.vainu.com/legal-stuff/customer-register/

Customer Privacy Statement

Latest update: 30th of September 2026

1. Controller

Name: Vainu. io Software Oy (Business-ID 2557864-2) (hereinafter “Vainu” or “controller”). All subsidiaries of Vainu Corporation also apply the principles and policies described herein.

Address: Siltasaarenkatu 8-10, 00530 Helsinki

Contact Details: privacy@vainu.io

2. Data Privacy Officer

Name: Sami Kekäläinen

Address: Siltasaarenkatu 8-10, 00530 Helsinki, Finland

Contact Details: dpo@vainu.io

3. Personal data processed, purposes and legal basis

Data subjects are Customers of Vainu and parties who have subscribed to the free trial version of Vainu’s service (“hereinafter Customers”).

Personal data

Purpose of processing

Legal basis

Basic information such as name, title, role, email address, phone number, company information

To create, develop, operate, deliver, and improve products, services, content, and advertising

Our legitimate interest to develop, market and improve our products and services

Contact information such as email address, phone number, address details

Data related to use of products and services, such as user credentials (personal user identification and password), authentication data for integrations, saved searches, permissions, saved reports, prompt data (queries and inputs provided by users)

Historical data such as signup date, last login, other usage data, analytics

Historical data such as signup date, last login, other usage data, analytics

Client feedback and marketing data such as chat and other communication with prospects and Customers, feedback from Customers

Fulfilling our contractual and other promises and obligations

Creation of personal user identification and password mandatory for using the service and administering such prospective client and user

Direct marketing based on customer relationship

Performance of a contract

Our legitimate interest to market our services

Direct marketing bans and consents

Respecting the Customer's wish regarding direct marketing

Our legal obligation to comply with the prohibition on direct marketing

Customer and contract information such as information about past and current contracts and orders, correspondence and other communications, payment information and information the Customer has voluntarily provided to our systems

Fulfilling our contractual and other promises and obligations

Billing

Customer communications such as sending notices, communications about purchases, and changes to our terms, conditions, and policies

Performance of a contract

Customer-specific information such as information received from meetings or phone calls, which is deemed necessary for the administration of customer relationships

Carrying out and administering the customer relationships

Creating statistics and analytics about Customers

Carrying out customer satisfaction surveys and monitoring the results

Accounting

Our legitimate interest in managing and developing the customer relationship

Legal obligation

ICT and security data such as IP-address, cookies (please see Privacy Policy https://www.vainu.com/legal-stuff/privacy-policy/ for further information regarding the use of cookies)

Targeting advertising on our online services

Consent

In addition, Vainu’s Service provides to the end-users of our Customers the possibility to link their email or other accounts to the Service. Explicit consent is required from the end-users for this processing. In doing so, we may receive the limited data as explicitly granted by you that we will process in accordance with this statement.

In general, our services are designed in a manner that we do not collect or store all of the data to which you may provide us access, but minimize our processing through technology. The purpose is to provide the end-users with automated information concerning the legal entities from the Service they are in contact with through their email or other accounts.

The end users may at any time disconnect the link between the Service and their email or other accounts at their own will, after which the processing will cease. Vainu does not store the contact details or contents of any emails during the processing.

4. Regular sources of personal data

Personal data is primarily collected from the signed agreements by Customers and from the data subject or colleague/manager of the data subject. In the registration process, the nature of the content of collected data depends on information that the Customer/user has submitted. Personal data is also collected directly from the Customers in connection with the use of the Service and information received during phone calls, meetings, or other collaboration in connection with the administration of the business relationship, which may be added by Vainu employees.

5. Automated Decision-making and Profiling

Data concerning the use of the service by Customers are assessed by Vainu. The purpose is to provide targeted customer content both when using the software and customer communication (emails, website, software, chat, 1 on 1 communication, recommendations on available features) based on the used features, the adaptation of content, and customer satisfaction feedback. These procedures include automated profiling, but do not constitute automated decision-making that would have effects corresponding to legal effects on individuals.

As part of the services, Vainu provides its Customers with tools that utilize Large Language Models (LLMs) to process and summarize data. These procedures assist Customers in company information retrieval but do not constitute automated decision-making under GDPR Article 22. Personal data will not be used to train AI models or for any high‑risk processing activities as defined in the EU AI Act. Vainu complies with all AI related regulations in its operations.

6. The Recipients of Personal Data

Vainu may disclose the personal data to its group companies, subsidiaries and other third parties based on contractual obligations or authority demands.

Personal information may be shared with companies who provide services such as information processing, maintenance, fulfilling customer orders, delivering services, managing and enhancing customer data, providing customer service, assessing interest in products and services, and conducting customer research or satisfaction surveys.

For the above-mentioned purposes, personal data of the Customers can, based on the performance of a contract, be disclosed to the following parties:

- System vendors and administrators of the servers
- Cooperation partners and service providers
- Communication platforms such as Slack.
- Contact register. Customer data is partly transferred to the internal contact register of Vainu.

- AI prompts, LLM providers. Vainu utilizes enterprise-grade subscriptions. Under these agreements, we have ensured that our LLM providers are contractually prohibited from using Customer prompts or any other Customer data to train their foundational models (such as Gemini) or for any other purposes outside of providing the service to Vainu and its Customers.

In case necessary by law, legal process, litigation, and/or requests from public and governmental authorities, Vainu may disclose your personal information.

7. Transfer of Data outside EU/EAA

In connection with the purposes for processing personal data, Vainu may transfer certain information to trusted third parties, which transfer and store the data outside EU/EAA area. Transfer of personal data is secured in accordance with the requirements of law. Only a limited amount of personal data is transferred to Vainu’s service providers, which is necessary for the performance of the tasks in accordance with the service contract in place.

Vainu will only disclose personal data based on a contract to third parties operating outside EU/EAA, which have taken steps to ensure that adequate data protection arrangements are in place in accordance with the data protection regulation. These may include but are not limited to Data Protection Agreements, adequacy decision or standard contractual clauses provided by the European Commission.

8. Storage Period of Personal Data

Personal data will be stored only as long as and only to the extent that is necessary in relation to the initial and compatible purposes of processing. In any event, the personal data is stored in accordance with the possible applicable lawful storing period. Personal data will be stored with the following time period or criteria used to determine that time period: The personal data received based on customer relationship is stored for a period of two (2) years, from the termination of the contract. AI prompts and related outputs are retained for a maximum period of ninety (90) days from the date of creation, after which they are automatically deleted from our systems and the systems of the LLM providers.

Vainu evaluates the need to store personal data regularly. In addition, the Vainu performs all possible reasonable measures to ensure that any inaccurate, incorrect, or outdated personal data will be deleted or corrected without delay.

9. Data Security

The vast majority of the Vainu's personal data is in electronic form. In case there are physical documents containing personal data, such documentation is destroyed immediately. The servers used by the controller are protected by appropriate firewalls and technical security.

All databases and information systems are accessible only with individual and personal login information (username and password) granted by the controller. The rights to access the database are restricted so that the information can only be viewed and processed by persons who are legally admitted and required to do so.

Vainu maintains logical separation of Customer data. Prompts processed by our agents are isolated to the specific Customer's session and are not shared with other Vainu customers or used to improve Vainu's general algorithms at the expense of Customer privacy.

The employees of Vainu have bound themselves to comply with professional secrecy and concealment regarding the information they receive during the processing of personal information. Privacy and security guidelines have been communicated to employees and strictly enforce privacy safeguards within the company.

10. Rights of the Data Subject

Information and access to personal data

Data subject has right to receive information; what data is being collected, the purposes of the processing for which the personal data are intended as well as the legal basis for the processing and the recipients or categories of recipients of the personal data if any.

Right of access by the data subject

Data subject shall have the right to obtain confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data. At the request of the data subject, the controller shall provide a copy of the personal data undergoing processing.

Right to rectification

Data subject shall have the right to rectify inaccurate personal data concerning him or her. Taking into account the purposes of the processing, data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement. In case there are changes in personal data, the data subject must notify such changes the controller. The controller rectifies any personal data it identifies as erroneous on its own initiative.

Right to object direct marketing

Data subject has the right to object to direct marketing at any time and free of charge.

Right to erasure

The controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

  • personal data that is no longer necessary in relation to the purposes for which they were processed;
  • the data subject withdraws consent on which the processing is based and there is no other legal ground for the processing;
  • personal data have been unlawfully processed;
  • personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;

Despite the request for erasure, the data does need to be erased in case the controller is obliged to process personal data for the establishment, exercise, or defense of legal claims or when the controller has a legal obligation to process the personal data in question.

Right to restriction of processing

Data subject has the right to restrict processing for example, when the processing is unlawful and data subject opposes the erasure of the personal data and requests the restriction of their use instead or when the controller no longer needs the personal data for the purposes of the processing, but they are required by data subject for the establishment, exercise or defence of legal claims.

Right to withdraw consent and right to object

Data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her when the processing is based on controller’s legitimate interests.

Right to Data Portability

When the processing is based on consent or on a contract, the data subject has the right to receive the personal data concerning him or her in a structured, commonly used and machine-readable format and to transmit those data to another controller, in case technically appropriate and not disproportionate for the controller.

Right to lodge a complaint to the supervisory authority

Data subject has a right to lodge a complaint with a supervisory authority, in case data subject considers that the processing of personal data violates the relevant data protection legislation in force. The national supervisory authority is Data Protection Ombudsman (tietosuoja@om.fi).

11. Contact information and changes to the Customer Privacy Statement

Any request to exercise data subject rights may be submitted to the following address privacy@vainu.io or to the Data Privacy Officer dpo@vainu.io.

Vainu has the right to change or update this Customer Privacy Statement at any time, and we recommend that you read it from time to time.