We use analytics and error-reporting tools (PostHog, Sentry) to improve the service. They are only enabled with your consent. Essential features work without it. Privacy policy
Pohjantähti Kiinteistöt Oy
Business ID: 3457557-4
Pekkalantie 6 A17, 15560 Nastola, Finland
Email: info@pohjantahtikiinteistot.fi
The service is provided under the product brand Salkkunen (salkkunen.fi) — a rental-property management SaaS for private Finnish landlords. Below, "Salkkunen" refers to the controller as the provider of the service.
Contact:
This policy covers three groups:
For tenant data, Salkkunen acts principally as a processor (Article 28 GDPR) on the instructions of the landlord (controller). Where a landlord falls outside the GDPR's scope (section 3), Salkkunen is the controller or joint controller, as assessed.
Under GDPR Article 2(2)(c) and Recital 18, the Regulation does not apply to purely personal or household activity, but it always applies to a controller or processor that provides the means for such processing. Salkkunen supplies those means, so the GDPR always applies to Salkkunen's operations.
Whether Salkkunen is the controller of tenant data (Article 4(7)) where the landlord falls outside scope depends on who determines the purposes and means of processing — Salkkunen would likely be a controller (or joint controller), but this is a case-by-case assessment, not an automatic consequence. Rental activity is income-generating activity, so ordinary rental activity is not "purely personal or household" activity within Article 2(2)(c).
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Account creation and maintenance | Contract (6(1)(b)) |
| Billing and payments (Stripe) | Contract (6(1)(b)); VAT invoicing obligations where applicable |
| Henkilötunnus processing (landlord's own only) | Data Protection Act § 29 (see section 5) |
| Tenant data on the landlord's behalf | As processor on the landlord's instructions (Art. 28); the Art. 6 basis is the landlord's (controller's) |
| E-signing of leases | Contract (6(1)(b)) |
| Tax reports to Vero | The landlord's legal obligation (6(1)(c)) on the user's initiative; Salkkunen's own basis is contract performance (6(1)(b)) plus its processor/agent role |
| Expense and rent accounting, receipts | Contract (6(1)(b)) |
| Bank data retrieval and reconciliation (PSD2) | Contract (6(1)(b)); user's consent to the bank connection |
| Marketplace bids and deposit holds (once enabled) | Contract (6(1)(b)) |
| Non-essential analytics and error tracking (PostHog, Sentry) | Consent (6(1)(a)) — see section 10 |
| Security, abuse prevention, legal claims | Legitimate interest (6(1)(f)) |
Salkkunen processes henkilötunnus values in two roles: (1) the landlord's own henkilötunnus, provided voluntarily by the user in their landlord profile (Salkkunen as controller), and (2) the tenant's henkilötunnus, which the landlord may voluntarily enter in the tenant's details to unambiguously identify the contracting party in a generated lease (landlord as controller, Salkkunen as processor — see section 3).
Processing is based on § 29 of the Finnish Data Protection Act (1050/2018), as amended by Act 1225/2023 (in force 1 January 2024):
Processing of the henkilötunnus in rental activity was confirmed by KHO:2023:56 ("Data Protection Act § 29 makes henkilötunnus processing possible in rental activity"), provided the GDPR Article 5 principles are respected. The same reading appears in the Data Protection Ombudsman's decision practice. KHO:2023:56 also shows this does not displace data minimisation — routine collection of children's henkilötunnukset was held unnecessary.
The landlord's henkilötunnus is stored persistently in the landlord profile because:
The tenant's henkilötunnus is an optional field. Where the landlord enters it, it is used for unambiguous identification of the contracting party in the generated lease contract (§ 29(2)) and is printed on the contract document. As controller of tenant data, the landlord is responsible for ensuring that collecting the henkilötunnus is necessary in each case (see KHO:2023:56 and section 3).
Processing respects the principles of data minimisation (5(1)(c)) and purpose limitation (5(1)(b)). The henkilötunnus is not unnecessarily marked on documents (§ 29(4)) and is not used for identification alone (§ 29(5)).
Users (landlords): first/last name, email, unique phone, bcrypt password hash, optional birth date, referral code, acquisition source, account timestamps, subscription and trial status, AI-scan abuse flags.
Landlord profiles: entity type (person/company), legal name, business ID, and — for individuals, provided voluntarily — the henkilötunnus (stored persistently, see section 5).
Tenants: first/last name, phone, email, and — as an optional field — the henkilötunnus (see section 5). Entered by the landlord; used in leases, e-signing and rent tracking. The henkilötunnus is printed on the generated lease contract to identify the contracting party.
Banking (PSD2, read-only via Enable Banking): bank session ID, bank (ASPSP) name and country, account UIDs, consent validity dates; fetched transactions (amount, booking date, debtor name, remittance info). A reconciliation audit log stores HMAC-pseudonymised debtor names; users may opt out of this log. Consent is renewed approximately every 180 days.
Leases & e-signing: lease documents (PDFs) with full party details are stored in object storage. The signing provider receives only the signer's name and email address and the document to be signed; the signer performs strong authentication (bank ID / FTN) directly with the signing provider — Salkkunen does not transmit the signer's henkilötunnus to the signing service. Signed PDFs are stored.
Tax: full rental income/expense/deduction data per property; tax reports (incl. the landlord's henkilötunnus) submitted to Vero via their mTLS API on the user's initiative; submission payloads and responses stored.
Expenses & files: expense records, receipt images, property photos and documents in self-hosted MinIO object storage.
Marketplace (upcoming feature, not yet enabled): once enabled: bidder identity verification (Signicat FTN), verification session IDs, bid amounts, and a Stripe payment-method token (not card data) for deposit holds.
Logs: notification log (channel, recipient, subject, body), audit logs, self-hosted infrastructure logs (30-day retention).
Technical: JWT auth (15-min access token, HTTP-only refresh cookie, Redis revocation), locale preferences, IP addresses and device data (error tracking and analytics).
Hosting: self-managed Docker on an EU-located VPS; PostgreSQL, Redis and MinIO on a private network; TLS via Caddy/Let's Encrypt.
Personal data is transferred outside the EEA (mainly the USA) to: Anthropic, Stripe (US part), Google (US part), Sentry, Resend.
Salkkunen uses Anthropic's Claude API for automatic extraction/OCR of receipts and imported documents. Documents may contain names, addresses and, where present, the henkilötunnus. Data is not used for solely automated decision-making with legal effects or significant impact (GDPR Article 22); rental or credit decisions are made by the landlord. The AI is an assistive extraction tool. Users are informed when document data is processed by AI.
Essential: authentication tokens (localStorage + HTTP-only refresh cookie), locale, UI flags. These cannot be disabled.
Non-essential: PostHog analytics cookies and Sentry error tracking. These are not set without consent, in accordance with § 205 of the Act on Electronic Communications Services (917/2014) and Article 5(3) of the ePrivacy Directive. Consent is voluntary and can be withdrawn as easily as given. Before consent and cookie placement, the user is shown a consent banner.
| Data group | Retention | Basis |
|---|---|---|
| User account and related data | Until the account is deleted; data deleted on account deletion | GDPR 5(1)(e) |
| Accounting and tax records (Salkkunen's own invoicing) | Financial statements, reports and books 10 years from end of financial period; vouchers and business correspondence 6 years from end of the year in which the financial period ended | Bookkeeping Act 1336/1997, § 2:10 |
| Landlord tax records (record-keeping-obligated) | Notes and vouchers 6 years from the start of the year following the tax year (VML § 12); generally 3 years under Vero's decision § 9, 6 years in the specified cases | VML § 12 |
| VAT invoices | AVL § 209n: 6 years — applies to VAT-registered businesses (i.e. Salkkunen's own invoicing); a VAT-exempt private landlord is not bound by it (retention under the VML) | AVL § 209n |
| Property-investment invoices and vouchers | 13 years | AVL § 209q |
| Reconciliation audit log | 30 days (automated purge) | Operational |
| Sentry errors | 90 days | Operational |
| Infrastructure logs | 30 days | Operational |
| AI-scan misuse records | 3 months (automated purge) | Proportionality |
Account deletion: on the user's request, the account and related data are deleted from all database tables (users, tenants, leases, rents, expenses, bank data, logs, settings) and from object storage (receipts, lease PDFs, photos), giving effect to the Article 17 erasure right and the Article 5(1)(e) storage limitation. Data subject to statutory retention obligations is kept for the required period.
Data portability (Article 20): users can download their data from the service in machine-readable form (CSV export, ZIP bundle: profile and settings, units, tenants, leases, rents, payments, expenses, loans, bank connections, tax reports).
We use TLS in transit, role-based access controls, pseudonymisation (HMAC of debtor names) in the reconciliation log, bcrypt password hashing and short-lived auth tokens. Files in the object store (receipts, lease PDFs, photos) are also encrypted at rest (SSE-KMS, GDPR Article 32).
No DPO is appointed. The henkilötunnus is not an Article 9 special category, so Article 37(1)(c) does not require a DPO. Article 37(1)(b) (large-scale regular and systematic monitoring) is fact-dependent; appointing a DPO is prudent but not clearly mandatory.
Data subjects have the right to:
To exercise any of these rights, contact us at info@pohjantahtikiinteistot.fi. We will respond within 30 days.
Tenants: a tenant may exercise these rights by contacting info@pohjantahtikiinteistot.fi. Salkkunen forwards the request to the landlord (controller) and assists in handling it. Where Salkkunen is the controller of that processing (section 3), Salkkunen handles the request directly. Tenants are told which entity is the controller for each data group.
Requests may also be sent to support@salkkunen.fi or info@pohjantahtikiinteistot.fi.
This policy may be updated as law or operations change. The updated policy is published in the service.
© 2026 Pohjantähti Kiinteistöt Oy. All rights reserved.