SustainSide
Language: en
Menu

Legal

Privacy policy

Draft. This text has not yet been reviewed by legal counsel and will be finalised before launch.

Who is responsible

The controller for the personal data described here is [[TO FILL: company name, business ID, address]] ("SustainSide", "we"). Contact for data protection questions: privacy@sustainside.com. For the business data a company enters to prepare its sustainability report, SustainSide acts as a processor on behalf of that company under our data processing agreement (DPA). This notice covers the personal data of the people who use SustainSide.

What we process

• Account: name, work email address, preferred language, password (stored only as an Argon2id hash), passkey public keys, two-step verification settings (the secret is stored encrypted). • Sign-in and security: active sessions with IP address and browser type, a record of security-relevant actions (for example sign-ins, changes of roles, downloads), and rate-limit counters. • Company work: the companies you belong to and your role, invitations you send or receive (the invitee's email address), questionnaire answers, comments and revision requests you write, documents you upload, and the reports we deliver. • Emails we send you (type and delivery status, not the content). The questionnaire does not ask for personal data about employees; workforce figures are collected as totals. Please do not upload documents that contain personal data you do not need to share (for example payslips); a document with a total is enough.

Purposes and legal bases

• Providing the service and preparing, reviewing and delivering your report (Art. 6(1)(b) GDPR). • Security of accounts and systems, preventing abuse, virus scanning of uploads and keeping a security log (Art. 6(1)(f) GDPR; our legitimate interest is a secure service). • Sending invitations on behalf of a company that wants to work with you (Art. 6(1)(f) GDPR; the legitimate interest of the inviting company). • Legal obligations, for example bookkeeping once paid plans are introduced (Art. 6(1)(c) GDPR).

How we use AI

We use the Anthropic Claude API as a processor for two tasks: • Writing report drafts: for each section of your report, the relevant answers and calculated figures are sent. The system instructions and our knowledge base contain no customer data. • Reading documents you upload (PDF, JPG, PNG, Excel, CSV): the document is sent so that values for the questionnaire can be suggested, each with a quote from the document. Nothing is entered in your questionnaire until you confirm the value yourself. Every report draft is checked by a SustainSide sustainability expert before it is delivered. No decision with legal or similarly significant effect on you is made automatically (Art. 22 GDPR). Under Anthropic's commercial terms, data sent through the API is not used to train models. [[Legal review: confirm Anthropic's current retention period for API data and the DPA reference.]]

Security

Data is transferred only over encrypted connections. Uploaded documents and generated reports are stored encrypted, each file with its own key. Every upload is checked for its file type and scanned for viruses before it is stored; only PDF, JPG, PNG, Excel (without macros) and CSV files are accepted. Two-step verification and passkeys are available for all accounts and required for SustainSide staff. Database backups are encrypted.

Processors and international transfers

We use a small number of processors, listed on the subprocessors page with their purpose and location. Our servers and backups are in the EU. Where a processor may access data from outside the EU/EEA (Anthropic, Resend), the transfer is based on the EU–US Data Privacy Framework or on the European Commission's Standard Contractual Clauses.

Cookies

We only use cookies that are strictly necessary: the session cookie, a language preference and, if you choose "trust this device" at two-step verification, a cookie that remembers this device for 30 days. We do not use advertising, analytics or tracking cookies, so no consent banner is shown.

How long we keep data

• While your account is active, we keep your account and company data. • If you delete your account, it is locked at once and erased after 30 days; within that time you can cancel by signing in. On erasure, companies you are the only member of are deleted with all their reports and documents; in companies shared with others, your membership is removed and the company's data stays with the company. Your name and email address are removed; records that other people still need (for example a revision request you wrote in a shared company) keep only a pseudonymous identifier. • Security logs are kept for up to 12 months. Encrypted backups are overwritten within 90 days, so erased data disappears from backups by then. • Invitations expire after 7 days. Sessions expire after 7 days of inactivity or when you sign out. • Invoices will be kept for the period required by accounting law once paid plans are introduced.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. In your account settings you can download your data as a machine-readable JSON file and delete your account yourself. For anything else, write to privacy@sustainside.com; we answer within one month. You can lodge a complaint with a supervisory authority, in particular in the country where you live or work. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi).

Changes

We will update this notice when our processing changes and show the date of the last update below. We will inform you by email about significant changes.

Last updated: 24.09.2026