Back

    Privacy Policy

    Last updated: 2026-08-02

    Lue suomeksi →

    1. Controller and contact details

    Pohjantähti Kiinteistöt Oy
    Business ID: 3457557-4
    Pekkalantie 6 A17, 15560 Nastola, Finland
    Email: info@pohjantahtikiinteistot.fi

    The service is provided under the product brand Salkkunen (salkkunen.fi) — a rental-property management SaaS for private Finnish landlords. Below, "Salkkunen" refers to the controller as the provider of the service.

    Contact:

    • Support: support@salkkunen.fi
    • Data protection contact: info@pohjantahtikiinteistot.fi
    • No Data Protection Officer appointed (see section 13).

    2. Data subjects

    This policy covers three groups:

    1. Users (landlords) — our direct customers with accounts.
    2. Tenants — third parties whose personal data the landlord enters into the system. Tenants have no account and no direct relationship with us.
    3. Signers of lease documents and bidders in the marketplace (once the marketplace feature is enabled) — persons whose data is processed in e-signing and in the property auction.

    For tenant data, Salkkunen acts principally as a processor (Article 28 GDPR) on the instructions of the landlord (controller). Where a landlord falls outside the GDPR's scope (section 3), Salkkunen is the controller or joint controller, as assessed.

    3. GDPR applicability and controllership of tenant data

    Under GDPR Article 2(2)(c) and Recital 18, the Regulation does not apply to purely personal or household activity, but it always applies to a controller or processor that provides the means for such processing. Salkkunen supplies those means, so the GDPR always applies to Salkkunen's operations.

    Whether Salkkunen is the controller of tenant data (Article 4(7)) where the landlord falls outside scope depends on who determines the purposes and means of processing — Salkkunen would likely be a controller (or joint controller), but this is a case-by-case assessment, not an automatic consequence. Rental activity is income-generating activity, so ordinary rental activity is not "purely personal or household" activity within Article 2(2)(c).

    4. Purposes and legal bases

    PurposeLegal basis (GDPR Art. 6)
    Account creation and maintenanceContract (6(1)(b))
    Billing and payments (Stripe)Contract (6(1)(b)); VAT invoicing obligations where applicable
    Henkilötunnus processing (landlord's own only)Data Protection Act § 29 (see section 5)
    Tenant data on the landlord's behalfAs processor on the landlord's instructions (Art. 28); the Art. 6 basis is the landlord's (controller's)
    E-signing of leasesContract (6(1)(b))
    Tax reports to VeroThe landlord's legal obligation (6(1)(c)) on the user's initiative; Salkkunen's own basis is contract performance (6(1)(b)) plus its processor/agent role
    Expense and rent accounting, receiptsContract (6(1)(b))
    Bank data retrieval and reconciliation (PSD2)Contract (6(1)(b)); user's consent to the bank connection
    Marketplace bids and deposit holds (once enabled)Contract (6(1)(b))
    Non-essential analytics and error tracking (PostHog, Sentry)Consent (6(1)(a)) — see section 10
    Security, abuse prevention, legal claimsLegitimate interest (6(1)(f))

    5. Processing of the henkilötunnus (personal identity code)

    Salkkunen processes henkilötunnus values in two roles: (1) the landlord's own henkilötunnus, provided voluntarily by the user in their landlord profile (Salkkunen as controller), and (2) the tenant's henkilötunnus, which the landlord may voluntarily enter in the tenant's details to unambiguously identify the contracting party in a generated lease (landlord as controller, Salkkunen as processor — see section 3).

    Processing is based on § 29 of the Finnish Data Protection Act (1050/2018), as amended by Act 1225/2023 (in force 1 January 2024):

    • § 29(1): the henkilötunnus may be processed with the data subject's consent or where processing is provided for by law; and for unambiguous identification where important for a task provided for by law, the rights and obligations of the data subject or controller, or scientific or historical research.
    • § 29(2): the henkilötunnus may be processed for unambiguous identification in, among others, rental and lending activity. Rental activity is thus an expressly permitted basis.
    • § 29(4): the henkilötunnus should not be unnecessarily marked on documents printed or prepared on the basis of the register.
    • § 29(5): identification must not rely solely on the henkilötunnus, nor on the henkilötunnus and name combined, without a separate identification method.

    Processing of the henkilötunnus in rental activity was confirmed by KHO:2023:56 ("Data Protection Act § 29 makes henkilötunnus processing possible in rental activity"), provided the GDPR Article 5 principles are respected. The same reading appears in the Data Protection Ombudsman's decision practice. KHO:2023:56 also shows this does not displace data minimisation — routine collection of children's henkilötunnukset was held unnecessary.

    The landlord's henkilötunnus is stored persistently in the landlord profile because:

    • tax reports to Vero require the henkilötunnus repeatedly;
    • lease-contract generation requires unambiguous party identification;
    • rental activity is a lawful processing basis (§ 29(2)).

    The tenant's henkilötunnus is an optional field. Where the landlord enters it, it is used for unambiguous identification of the contracting party in the generated lease contract (§ 29(2)) and is printed on the contract document. As controller of tenant data, the landlord is responsible for ensuring that collecting the henkilötunnus is necessary in each case (see KHO:2023:56 and section 3).

    Processing respects the principles of data minimisation (5(1)(c)) and purpose limitation (5(1)(b)). The henkilötunnus is not unnecessarily marked on documents (§ 29(4)) and is not used for identification alone (§ 29(5)).

    6. Personal data processed

    Users (landlords): first/last name, email, unique phone, bcrypt password hash, optional birth date, referral code, acquisition source, account timestamps, subscription and trial status, AI-scan abuse flags.

    Landlord profiles: entity type (person/company), legal name, business ID, and — for individuals, provided voluntarily — the henkilötunnus (stored persistently, see section 5).

    Tenants: first/last name, phone, email, and — as an optional field — the henkilötunnus (see section 5). Entered by the landlord; used in leases, e-signing and rent tracking. The henkilötunnus is printed on the generated lease contract to identify the contracting party.

    Banking (PSD2, read-only via Enable Banking): bank session ID, bank (ASPSP) name and country, account UIDs, consent validity dates; fetched transactions (amount, booking date, debtor name, remittance info). A reconciliation audit log stores HMAC-pseudonymised debtor names; users may opt out of this log. Consent is renewed approximately every 180 days.

    Leases & e-signing: lease documents (PDFs) with full party details are stored in object storage. The signing provider receives only the signer's name and email address and the document to be signed; the signer performs strong authentication (bank ID / FTN) directly with the signing provider — Salkkunen does not transmit the signer's henkilötunnus to the signing service. Signed PDFs are stored.

    Tax: full rental income/expense/deduction data per property; tax reports (incl. the landlord's henkilötunnus) submitted to Vero via their mTLS API on the user's initiative; submission payloads and responses stored.

    Expenses & files: expense records, receipt images, property photos and documents in self-hosted MinIO object storage.

    Marketplace (upcoming feature, not yet enabled): once enabled: bidder identity verification (Signicat FTN), verification session IDs, bid amounts, and a Stripe payment-method token (not card data) for deposit holds.

    Logs: notification log (channel, recipient, subject, body), audit logs, self-hosted infrastructure logs (30-day retention).

    Technical: JWT auth (15-min access token, HTTP-only refresh cookie, Redis revocation), locale preferences, IP addresses and device data (error tracking and analytics).

    7. Processors and recipients

    1. Stripe (Ireland/USA) — subscription billing, one-off signature purchases, and marketplace deposit holds (once that feature is enabled; a payment-method token — not a card number — will then also be stored in our database).
    2. Enable Banking Oy (Finland) — PSD2 account information services.
    3. Signicat (Norway/EU) — eIDAS e-signing and FTN identity verification; receives the signer's name and email and the lease documents to be signed. The signer authenticates with their bank credentials directly with Signicat; Salkkunen does not transmit the henkilötunnus to Signicat.
    4. Vero / Finnish Tax Administration (Finland) — an authority, not a processor; receives tax reports (incl. the landlord's henkilötunnus) on the user's initiative.
    5. Anthropic (USA) — Claude API. Receipts and imported documents (which may contain names, addresses and, where present, the henkilötunnus) are sent for AI extraction/OCR.
    6. Google (Places API, EU/USA) — address autocomplete (strings only).
    7. PostHog (EU cloud, eu.i.posthog.com) — product analytics: user IDs, pageviews, events, user properties, and session recording in production with all inputs and text masked. Only with consent.
    8. Sentry (USA) — error tracking with session replay on errors: stack traces, user ID, IP, browser context. Only with consent.
    9. Resend (USA) — transactional email delivery.
    10. Sinch (Sweden/EU) — SMS delivery (OTP codes, rent reminders).
    11. Tilastokeskus / Statistics Finland (Finland) — we only read public statistics; no personal data is sent.

    Hosting: self-managed Docker on an EU-located VPS; PostgreSQL, Redis and MinIO on a private network; TLS via Caddy/Let's Encrypt.

    8. International transfers

    Personal data is transferred outside the EEA (mainly the USA) to: Anthropic, Stripe (US part), Google (US part), Sentry, Resend.

    • EU–US Data Privacy Framework (DPF): transfers to DPF-certified recipients are based on the European Commission's adequacy decision C(2023) 4745 of 10 July 2023 under GDPR Article 45.
    • Standard Contractual Clauses (SCCs): where a recipient is not DPF-certified, transfers rely on SCCs (Commission Decision 2021/914) plus a transfer impact assessment (TIA).

    9. AI-based processing

    Salkkunen uses Anthropic's Claude API for automatic extraction/OCR of receipts and imported documents. Documents may contain names, addresses and, where present, the henkilötunnus. Data is not used for solely automated decision-making with legal effects or significant impact (GDPR Article 22); rental or credit decisions are made by the landlord. The AI is an assistive extraction tool. Users are informed when document data is processed by AI.

    10. Cookies and local storage

    Essential: authentication tokens (localStorage + HTTP-only refresh cookie), locale, UI flags. These cannot be disabled.

    Non-essential: PostHog analytics cookies and Sentry error tracking. These are not set without consent, in accordance with § 205 of the Act on Electronic Communications Services (917/2014) and Article 5(3) of the ePrivacy Directive. Consent is voluntary and can be withdrawn as easily as given. Before consent and cookie placement, the user is shown a consent banner.

    11. Retention

    Data groupRetentionBasis
    User account and related dataUntil the account is deleted; data deleted on account deletionGDPR 5(1)(e)
    Accounting and tax records (Salkkunen's own invoicing)Financial statements, reports and books 10 years from end of financial period; vouchers and business correspondence 6 years from end of the year in which the financial period endedBookkeeping Act 1336/1997, § 2:10
    Landlord tax records (record-keeping-obligated)Notes and vouchers 6 years from the start of the year following the tax year (VML § 12); generally 3 years under Vero's decision § 9, 6 years in the specified casesVML § 12
    VAT invoicesAVL § 209n: 6 years — applies to VAT-registered businesses (i.e. Salkkunen's own invoicing); a VAT-exempt private landlord is not bound by it (retention under the VML)AVL § 209n
    Property-investment invoices and vouchers13 yearsAVL § 209q
    Reconciliation audit log30 days (automated purge)Operational
    Sentry errors90 daysOperational
    Infrastructure logs30 daysOperational
    AI-scan misuse records3 months (automated purge)Proportionality

    Account deletion: on the user's request, the account and related data are deleted from all database tables (users, tenants, leases, rents, expenses, bank data, logs, settings) and from object storage (receipts, lease PDFs, photos), giving effect to the Article 17 erasure right and the Article 5(1)(e) storage limitation. Data subject to statutory retention obligations is kept for the required period.

    Data portability (Article 20): users can download their data from the service in machine-readable form (CSV export, ZIP bundle: profile and settings, units, tenants, leases, rents, payments, expenses, loans, bank connections, tax reports).

    12. Security

    We use TLS in transit, role-based access controls, pseudonymisation (HMAC of debtor names) in the reconciliation log, bcrypt password hashing and short-lived auth tokens. Files in the object store (receipts, lease PDFs, photos) are also encrypted at rest (SSE-KMS, GDPR Article 32).

    13. Data Protection Officer

    No DPO is appointed. The henkilötunnus is not an Article 9 special category, so Article 37(1)(c) does not require a DPO. Article 37(1)(b) (large-scale regular and systematic monitoring) is fact-dependent; appointing a DPO is prudent but not clearly mandatory.

    14. Data subject rights

    Data subjects have the right to:

    • access their data (Art. 15);
    • rectification (Art. 16);
    • erasure (Art. 17);
    • restriction (Art. 18);
    • object (Art. 21);
    • data portability (Art. 20);
    • not be subject to solely automated decision-making (Art. 22);
    • lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).

    To exercise any of these rights, contact us at info@pohjantahtikiinteistot.fi. We will respond within 30 days.

    Tenants: a tenant may exercise these rights by contacting info@pohjantahtikiinteistot.fi. Salkkunen forwards the request to the landlord (controller) and assists in handling it. Where Salkkunen is the controller of that processing (section 3), Salkkunen handles the request directly. Tenants are told which entity is the controller for each data group.

    Requests may also be sent to support@salkkunen.fi or info@pohjantahtikiinteistot.fi.

    15. Changes to this policy

    This policy may be updated as law or operations change. The updated policy is published in the service.

    © 2026 Pohjantähti Kiinteistöt Oy. All rights reserved.