vakka.aivakka.ai

Privacy notice

Updated: 23 August 2026

This notice explains how Vakka AI Oy processes personal data. We act in two roles: as controller for our website, our sales activity and the service's user accounts, and as processor for the material our customers store in the service. Both are described separately below.

1. Controller and contact details

Vakka AI Oy (business ID 3621436-9), Finland. Vakka AI Oy is a wholly owned subsidiary of Conventio Oy.

  • Privacy and security matters: tietoturva@vakka.ai — we reply within one business day.
  • Everything else: asiakaspalvelu@vakka.ai.
  • We have not appointed a data protection officer under Article 37 GDPR. Privacy matters are owned by the founder responsible for technology.

2. Two roles: controller and processor

As controller we process technical logs about website visitors, details of people who contact us and of our customers' contact persons, the service's user accounts, and billing and support data. This notice applies to those.

As processor we handle the material a customer stores in the service: contracts, attachments, counterparty records, tasks and conversations. In that role we act on the customer's behalf and on its instructions, and the processing is governed by the data processing agreement.

If you work for one of our customers, or are a counterparty of one, and your request concerns material stored in the service, address it to that organisation. We cannot answer requests about a customer's material on our own initiative.

3. The vakka.ai website

The site sets no cookies and has no visitor analytics, ad networks, tracking pixels or forms. Contact happens by email, and the site sends nothing about you to third parties.

Your theme choice (light or dark) is stored in your browser's local storage. It never reaches us and is not linked to you.

  • The site's technical platform produces server logs (request time, path, response code, and IP address and user agent to the extent the platform records them).
  • Purpose: keeping the site working, diagnosing faults and preventing abuse. The legal basis is legitimate interest.
  • Retention: 3 months at most.

4. Enquiries and sales

When you contact us or we discuss working together, we process your name, work email, phone number, organisation and role, and the content of our correspondence.

  • Purpose: answering enquiries, running demos, making offers and preparing a customer relationship.
  • Legal basis: legitimate interest in business-to-business communication, or steps taken prior to entering into a contract.
  • Retention: at most 24 months from the last contact if no customer relationship follows. You can ask us to delete it at any time.
  • We do not send marketing without a specific request or an existing customer relationship, and every message can be opted out of.

5. User accounts in the service

Accounts are created at the customer organisation's request. That organisation decides who gets an account and what the account may do.

  • Data processed: first name, last name, work email, phone number (optional), language preference, profile picture (optional), user identifier, roles and permissions, and multi-factor authentication data.
  • Sign-ins and user actions are also written to an audit log. Audit rows record that something happened — they never contain document content or field values.
  • Multi-factor authentication (TOTP) is mandatory for every user and every operator.
  • Legal basis: the agreement with the customer organisation, and our legitimate interest in keeping the service secure.
  • Retention: for the duration of the customer relationship. Accounts and audit rows are deleted together with the customer's material, per section 9.

6. Billing and payments

  • We process billing details, subscription details and receipts.
  • Card details are handled by the payment provider. We never see or store the card number: we keep only the token the provider returns, the card brand, the last four digits and the expiry date.
  • Legal basis: contract and legal obligation.
  • Retention: as required by the Finnish Accounting Act — six years from the end of the calendar year in which the financial period ended, for accounting vouchers.

7. Support

  • For support requests we process contact details, the content of the request and any files attached to it.
  • Files attached to a support request are deleted automatically after two years. The conversation itself is kept for the duration of the customer relationship.
  • Legal basis: contract.

8. Recipients and subprocessors

We do not sell personal data and we do not disclose it for marketing purposes. We use a small set of subprocessors: a provider of cloud infrastructure, storage, authentication and email delivery; language model services; payment processing; and accounting.

Our subprocessors, and where they process data, are named in Annex C of the data processing agreement on this site. The list is kept current and changes are notified to customers 30 days in advance.

We disclose data to authorities only where the law requires it.

9. Retention and deletion

  • Material a customer stores in the service: for the duration of the customer relationship. When the agreement ends we return the material within 30 days and delete it — backups included — within 30 days of the return. A deletion certificate is provided on request.
  • User accounts and audit log: deleted together with the customer's material. The audit log is not deleted earlier, because it is the record that access control was honoured.
  • Enquiries and sales conversations: 24 months at most.
  • Website technical logs: 3 months at most.
  • Accounting records: the statutory retention period. This material is not deleted on the basis of an erasure request.

10. Where data lives, and transfers outside the EU

All persistent storage — documents, database, search indexes, backups and logs — is in the EU. AI processing also happens in EU data centres.

Personal data is not transferred outside the EU or EEA. Should a transfer ever become necessary, we agree it with the customer in advance and implement it under the Commission's standard contractual clauses.

11. Security

  • Data in transit is protected with TLS and data at rest is encrypted. Attachments marked confidential are encrypted with a customer-specific key.
  • Permissions are role-based and are checked on every request in a single central place.
  • Multi-factor authentication is mandatory. Production access is restricted to named operator roles.
  • Every AI response is screened before it is shown: national identity numbers and bank account numbers are always blocked, and blocks are logged.
  • The full list of technical and organisational measures is in Annex B of the data processing agreement.

12. AI and automated decision-making

The service uses AI to extract, search and summarise contract data. AI-produced values are proposals: they are labelled as AI-generated and a human confirms them before they are relied on. Tasks the AI suggests also require human approval.

The service makes no automated decisions about you that produce legal effects or similarly significant effects.

Customer material is never used to train AI models — not by us and not by our subprocessors.

13. Your rights

You have the right to access your data, to have inaccurate data corrected, to request erasure or restriction of processing, to object to processing based on legitimate interest, and to receive your data in a portable format. Where processing is based on consent, you may withdraw it at any time.

  • Send your request to tietoturva@vakka.ai. We respond within one month. We verify your identity before disclosing anything.
  • If your request concerns material a customer has stored in the service, we forward it to that customer and assist them in handling it.
  • You may lodge a complaint with a supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi).

14. Changes to this notice

We update this notice when our processing changes. The date at the top of the page shows the most recent change. We notify customers of material changes by email.