GDPR and privacy
How Sutja meets its GDPR obligations as a data processor and where the customer's data lives.
Updated 13 September 2026
Privacy at Sutja
Sutja is built privacy-first. All personal data is stored and processed in Finland and the EU. This page explains how Sutja meets its GDPR obligations, who the sub-processors are, and why every one of them is a European company.
This page is written for the customer, that is the employer subscribing to the service, who is the controller for its employees' data. It describes Sutja's obligations as a processor in plain language; the binding wording is in the data processing agreement. In case of conflict, the agreement prevails.
Questions about an employee's own data are for their employer as controller, not for Sutja. The data Sutja processes in its own controller role is described in the privacy policy.
Controller and processor
When a customer uses Sutja to manage its employees' shift and HR data, the customer is the controller and Sutja acts as a processor on the customer's behalf.
As controller, the customer decides what data is stored in the service, for what purpose and on what legal basis, and is responsible for informing employees appropriately. Sutja does not make these decisions and does not use the data for its own purposes.
Sutja processes the data only on the customer's documented instructions. Those instructions comprise the data processing agreement and the way the customer uses the service. If Sutja considers an instruction to infringe data protection law, it informs the customer.
Sutja is itself the controller only for data arising from its own business: website visitors, enquiries and the contact persons of customers. That data is covered by the privacy policy.
The customer can grant an external payroll clerk limited access to a workspace without creating an employment relationship. The clerk can view payroll data, individual time entries and reimbursements, and the personal and employment details needed to set up employees in payroll, including personal identity codes, bank accounts, addresses and salary information. The clerk can correct payroll IDs, cost centre codes and payroll settings and initiate payroll exports, but cannot approve hours or reimbursements. The customer is responsible for granting access and for its own payroll clerk; the clerk is not a subprocessor selected by Sutja. Opening employee details is recorded in the activity log without the identity code, bank account or other displayed values. Access can be revoked in workspace settings.
Data location: Finland and the EU
The service, database, files and sign-in run in the Finnish provider UpCloud's data centres in Finland. Email is delivered through Lettermint, a Dutch company whose sending infrastructure is in the Netherlands and Germany. Personal data is not stored outside the EU or EEA.
The traffic path is European as well: DNS, content delivery and the firewall are provided by BunnyWay (bunny.net), a Slovenian company. Traffic is served from EU locations, and the restriction is recorded in the data processing agreement as a documented instruction.
Sub-processors and other providers
Sutja uses a limited set of carefully selected providers, with agreements containing data protection obligations in place. Personal data is stored and processed in Finland and the EU, and all the providers are European companies.
The table marks which role each provider acts in. A sub-processor processes the data a customer stores in their workspace on Sutja's behalf, so the contractual chain runs through the data processing agreement to the customer. A provider marked as Sutja's own register processes only data for which Sutja is itself the controller, such as invoicing and accounting.
The marking states the widest role a provider may act in, not only what it does at this moment. Brevo, for example, is primarily customer relationship management, but it is also the fallback path for sending email, so it is marked as a sub-processor.
App users are not transferred into customer relationship management. They are customers' employees, not Sutja's contacts. Only a workspace's billing contact is sent to Brevo's CRM for the subscription, alongside website leads. Marketing messages are sent only with explicit consent.
Sutja notifies intended sub-processor changes in advance, and the customer may object to a change on reasonable grounds. The procedure is set out in section 7 of the data processing agreement.
UpCloud Ltd
Hosting, database, files and sign-in (self-hosted)
BunnyWay d.o.o. (bunny.net)
DNS, content delivery and firewall. Traffic and security logs are processed at EU locations under a restriction recorded in the data processing agreement.
Lettermint B.V.
Email delivery (sign-in codes and notifications)
AppSignal B.V.
Error and performance monitoring. No session replay. Alerts go to our own infrastructure, not through AppSignal email notifiers.
Sendinblue SAS (Brevo)
Customer relationship management: company, subscription and billing contact. Also the fallback path for sending email: if enabled, Brevo delivers the same messages as Lettermint.
Mistral AI SAS
Two AI capabilities. Receipt recognition: the receipt image and the result read from it. Planning assistant: a snapshot of the period, made up of the names of shift templates, work locations and skills, days, opening hours and counts. The snapshot is not built from employee names, wishes or absences. The input and output of both capabilities are retained for at most 30 days for abuse monitoring, after which the copies are deleted, and they are not used to train models. Both are included in the Intelligence plans and enabled by default there; a workspace can turn each of them off separately, after which nothing is sent from that capability.
When the planning assistant is enabled, its message field falls outside the personal-data limitation described above: whatever is typed into it is passed on verbatim, so an employee name goes along if you write one. The interface says so next to the field.
Accountor Finago Oy (Procountor)
Accounting and invoicing
| Provider | Purpose | Location |
|---|---|---|
UpCloud Ltd Sub-processor | Hosting, database, files and sign-in (self-hosted) | Finland |
BunnyWay d.o.o. (bunny.net) Sub-processor | DNS, content delivery and firewall. Traffic and security logs are processed at EU locations under a restriction recorded in the data processing agreement. | Slovenia |
Lettermint B.V. Sub-processor | Email delivery (sign-in codes and notifications) | Netherlands (EU) |
AppSignal B.V. Sub-processor | Error and performance monitoring. No session replay. Alerts go to our own infrastructure, not through AppSignal email notifiers. | Netherlands (EU) |
Sendinblue SAS (Brevo) Sub-processor | Customer relationship management: company, subscription and billing contact. Also the fallback path for sending email: if enabled, Brevo delivers the same messages as Lettermint. | France (EU) |
Mistral AI SAS Sub-processor | Two AI capabilities. Receipt recognition: the receipt image and the result read from it. Planning assistant: a snapshot of the period, made up of the names of shift templates, work locations and skills, days, opening hours and counts. The snapshot is not built from employee names, wishes or absences. The input and output of both capabilities are retained for at most 30 days for abuse monitoring, after which the copies are deleted, and they are not used to train models. Both are included in the Intelligence plans and enabled by default there; a workspace can turn each of them off separately, after which nothing is sent from that capability. When the planning assistant is enabled, its message field falls outside the personal-data limitation described above: whatever is typed into it is passed on verbatim, so an employee name goes along if you write one. The interface says so next to the field. | France (EU) |
Accountor Finago Oy (Procountor) Sutja's own register | Accounting and invoicing | Finland |
Supporting data subject rights
Sutja supports data subject rights: access, rectification, erasure, portability and restriction of processing. Because the controller for employee data is the customer, such requests are routed to the customer and Sutja assists in fulfilling them.
The service includes tools for this. A workspace administrator can export the workspace's data from the Privacy section of the settings; the same section also offers the signed data processing agreement as a download. The export produces a compressed, machine-readable JSON file that stays available for 7 days, and every download is logged. Attachments are not yet included in the package; they are downloaded from the service separately. Deletion happens through the service's own functions: an employee is removed from the staff view, a workspace is deleted from its settings page, and a user account is deleted from the profile page.
Assistance is included in the service fee. Sutja does not charge separately for supporting a response to a data subject request or for providing the information about the service needed for a data protection impact assessment (DPIA). Exceptionally extensive separate work is agreed in advance, and the term is set out in section 9 of the data processing agreement.
Data minimisation and anonymisation
As controller, the customer decides what data is stored in the workspace. Sutja has built the service so that its standard features ask only for what shift planning, working time records and the basis for paying wages require. Sutja does not collect data from a workspace for its own purposes and does not use customer data to train AI models.
Some data has a specific basis of its own. The personal identity code is asked for in order to pay wages and to meet the employer's related statutory obligations, and section 29 of the Finnish Data Protection Act permits processing it in those tasks: they require identifying the employee unambiguously, and a name is not a unique identifier. The same applies to paying reimbursements: when the customer has enabled the accounting integration, the code is sent to the financial system the customer has chosen, so that the travel expense claim is matched to the right recipient rather than to a namesake. In the application the code is visible only to the employee, their own supervisor chain and administrators, and it is cleared after the membership ends as set out in the retention table.
In Sutja's own reporting and product development, aggregated or anonymised data is used, from which an individual cannot be identified.
When the retention period ends, data is either deleted or irreversibly anonymised. This happens automatically and requires no separate request from the customer.
Security
Data is encrypted in transit and at rest, access is role-based and follows the least-privilege principle, and activity is monitored through logs and change history.
A plain-language description is on the security page. At the contractual level the measures are specified in Appendix 1 to the data processing agreement, which sets out point by point how encryption, key management, confidentiality, integrity, availability and resilience are implemented. The appendix is not published, because it describes the details of the safeguards. It is available on request at tietosuoja@sutja.fi.
Retention and deletion
Sutja processes data only for the duration of the agreement. When processing ends, the customer's data is returned or deleted within 90 days, except for data that law requires to be retained. The same deadline is written into the data processing agreement.
Below is a single table of every retention period that applies to the data a customer stores in their workspace. The customer is the controller for that data. Data arising in Sutja's own controller role has its own retention periods, listed in the privacy policy.
The same information is also shown in the Privacy section of the workspace settings, where the table is generated directly from the system's own rules. The table on this page is checked against those same rules by an automated gate before every release, so the description cannot drift apart from what the service actually does.
| Data | Retention | Counted from |
|---|---|---|
Sickness absence reason and medical certificate | 60 days | end of the absence |
Wishes, skills and labels | 90 days | end of the membership |
Bank account, personal identity code, address, date of birth and emergency contacts | 6 months | end of the membership |
Shifts, working time records, absences, documents and the member record | 24 months | end of the membership |
Data and attachments of a deleted workspace | 60 days | deletion of the workspace |
Service usage log (IP address and browser identifier) | 24 months | the event |
Read notification | 180 days | reading |
Dismissed notification | 90 days | dismissal |
Unused push subscription | 180 days | last use |
Deleted push subscription | 30 days | deletion of the subscription |
Used, revoked or expired invitation with its email address | 12 months | end of the invitation |
Data export package | 7 days | completion of the package |
Return or deletion of data after the agreement ends | 90 days | end of the service agreement |
Backups | approx. 30 days | the backup being taken |
The retention period starts from the moment in the right-hand column, not from the end of the agreement. The staging is not slowness but statutory retention duties: working time records may not be destroyed before the limitation period under the Working Hours Act has expired.
How deletion proceeds
Deletion is not a single moment but several stages. They are spelled out because the difference matters to a controller:
- Access ends immediately. When a workspace or a user account is deleted, sign-in and access to the data stop at once.
- Data is destroyed after a grace period. The rows of a deleted workspace are removed from the database and its attachments from file storage 60 days after the deletion.
- The encryption key is destroyed last. Once everything else has been destroyed, the workspace's encryption key is destroyed, after which the fields and files encrypted with it cannot be recovered with any key.
The workspace owner receives a reminder 14 and 2 days before the destruction and a confirmation message afterwards. Data should be exported before deleting, because deletion ends access to the workspace immediately and self-service export is no longer available after that. During the grace period the workspace can still be restored by contacting us, after which exporting works normally.
Sick leave certificates and sickness-based absence reasons are health data within the meaning of GDPR Article 9. They are destroyed 60 days after the absence ends, whether or not the employment continues: health data must be destroyed once the basis for processing it, namely paying and checking sick pay, has been handled. The customer as controller is responsible for the legal basis and for who in the employer organisation may handle health data; the applicable provisions are GDPR Article 9(2) and section 5 of the Finnish Act on the Protection of Privacy in Working Life (759/2004).
Deleting a user account anonymises the account immediately: the name and contact details are replaced, sessions are invalidated, the profile picture is removed and the CRM contact is deleted. The same is done automatically for an account that has no active workspace membership and has been unused for 90 days.
Destroying an encryption key has its limits, and it is more honest to say so than to leave it unsaid. Destroying the key makes unreadable only what was encrypted field by field or file by file; the rest is removed from the database and file storage row by row and object by object. In backups taken before the deletion, unencrypted data remains until those backups have rotated out. The cycle is approximately 30 days, so even the last copy predating the deletion is removed within that period. Encrypted data in backups is unreadable as soon as the key has been destroyed.
One thing is worth handling before the 24-month limit: Sutja is not the employer's permanent archive. The duty to provide an employment certificate extends to 10 years from the end of employment, so employment documents such as employment contracts and the source data for certificates must be moved into the organisation's own archive before the 24-month retention period ends. The data export collects the workspace's records in machine-readable form, but attachments must for now be downloaded from the service separately.
Data processing agreement
Sutja offers customers a data processing agreement under GDPR Article 28 as part of the service terms. The agreement is in force without a separate request and covers the subject matter and purpose of processing, processing on the customer's documented instructions, confidentiality, security, sub-processors, support for data subject rights, personal data breaches, audits and the end of processing.
Appendix 1 to the agreement specifies how the security obligations in section 6 are implemented in practice. The appendix is not published on the website; Sutja provides it to the customer on request at no additional charge.
A signed copy can be downloaded from the Privacy section of the service settings. It can also be requested at tietosuoja@sutja.fi.
Data breaches
If personal data is subject to a breach, Sutja notifies the customer acting as controller without undue delay and within 72 hours of Sutja becoming aware of the breach at the latest.
The initial notification is made as soon as the breach is confirmed, even if not all details have been established, and it is supplemented in phases as the investigation progresses. The customer's own 72-hour deadline for notifying the supervisory authority starts when the customer becomes aware of the breach, so Sutja does not wait for a complete picture before the initial notification.