Privacy policy
Read the Plenaxy Privacy Policy to learn how we collect, process and protect personal data across our services.
This Privacy Policy describes the principles according to which SK Protect Oy, as the controller, collects and processes personal data in connection with customer relationship management, marketing and the operation of its online store.
1. Data controller
SK Protect Oy, Business ID 1700958-9
Satamatie 330, 67100 Kokkola, Finland,
http://www.protect.fi
2. Contact person for matters concerning the registers
Managing Director: Pertti Salo, +358 44 0665 916, pertti.salo@protect.fi
Data Protection Officer: Saija Pottala, +358 43 8200 064, saija.pottala@protect.fi
3. Name of the register
Customer register, marketing register and online store.
4. Purpose of processing personal data
We collect, store and process personal data only for predefined purposes.
Customer register
We process personal data in order to manage the customer relationship and ensure that the statutory rights and obligations of both the customer and the controller are fulfilled. This means, for example, delivering a service or product, providing customer service, processing orders and payments, fulfilling statutory accounting and tax obligations, and safeguarding rights and interests in possible contractual or dispute situations. The legal basis for the processing is contract. (Art. 6.1 b)
Marketing register
We process personal data for sending marketing communications, organising events and webinars, delivering downloadable materials, responding to contact requests, analysing website use, developing our services and targeting marketing.
The processing is based on the controller’s legitimate interest. Processing based on consent is used, for example, for electronic direct marketing when consent is required by law, and for marketing and analytics cookies. Processing based on legitimate interest is used, for example, for B2B marketing, maintaining customer and stakeholder relationships, developing services, ensuring the technical functionality of the website and targeting marketing based on a professional role or company connection.
The controller’s legitimate interest is based on the need to maintain and develop customer, partner and stakeholder relationships, market its services to corporate customers and other persons acting in a professional role, and ensure the functionality and information security of the website and services. The data subject may at any time object to the processing of their personal data for direct marketing and related profiling.
Online store, Trial, SaaS service subscriptions, payments and subscription relationship management
We process personal data for receiving, processing and managing SaaS service subscriptions and Trial periods made through the online store, verifying the customer’s company and tax status, deploying the service, managing access rights, user accounts, direct links and API credentials, maintaining the customer and subscription relationship, receiving and processing payments, managing one-off and recurring payments, confirming purchase transactions, customer communications, invoicing, accounting, customer support, processing changes to service packages and modules, processing complaints and payment disputes, and preventing and investigating possible misuse, payment fraud, sanctions risks and information security incidents.
We also process personal data when assessing whether to accept an order, the suitability of a payment method, the possibility of invoicing, the need for advance payment, payment defaults, credit information or other justified reasons for rejecting, restricting or suspending an order.
We use Stripe for payment processing. We use Stripe Checkout, Stripe Subscriptions, Stripe Customer Portal and Stripe Radar. We do not use Stripe Payment Element or Stripe Link.
The legal basis for the processing is the performance of a contract when we process data to start a Trial, receive a SaaS service subscription, deploy the service, manage access rights, execute a payment, manage the subscription relationship, provide the customer portal and arrange customer support.
Processing related to accounting, taxation, invoicing, payments, debt collection, compliance with sanctions and other statutory or official obligations is based on the controller’s legal obligation.
Processing related to preventing misuse, ensuring payment transaction security, preventing payment fraud, assessing credit risk, handling payment defaults, chargebacks and payment disputes, maintaining information security, ensuring service continuity, restricting or suspending a customer’s or individual user’s access rights, and establishing, presenting or defending legal claims is based on the controller’s legitimate interest.
The controller’s legitimate interest is based on the need to ensure the secure and reliable implementation of the online store, payments, the SaaS service, Trial periods, subscription relationships and customer relationships, ensure compliance with the terms of service, prevent misuse and payment fraud, manage credit and payment default risks, and investigate possible complaints, errors, payment disputes, information security incidents and legal claims.
The use of broader marketing material containing personal data, such as statements, customer stories or reference content linked to a contact person, is based on separate approval or another applicable legal basis for processing.
Your data may also be collected and processed to fulfil statutory obligations, such as for accounting and official purposes. (Art. 6.1 c)
The data subject has the right to withdraw their consent to the processing of personal data at any time by contacting us using the contact methods stated in this Privacy Policy.
Mandatory provision of data and consequences of not providing data
Providing personal data is necessary when the data is needed to enter into or perform a contract, deliver a service, carry out invoicing, manage a customer relationship, register for an event or webinar, deliver downloadable material or respond to a contact request.
If the data subject does not provide the data required for these purposes, we may not be able to enter into or perform a contract, deliver the service or material, process the registration or respond to the contact request.
When processing is based on consent, providing data is voluntary. However, not giving or withdrawing consent may affect whether marketing communications can be sent to the data subject, whether cookies requiring consent can be used, or whether data can be processed for the purpose based on that consent.
Starting a Trial of the SaaS service, subscribing through the online store, executing a payment, managing the subscription relationship, opening access rights, providing the customer portal, invoicing, customer support, verifying company and tax status, and possible checks of credit information, payment defaults or sanctions risks require the provision of personal data necessary for the order, invoicing, payment and customer relationship.
If the customer or the customer’s contact person does not provide this data, we may not be able to accept the order, start the Trial, open or maintain access rights, process the payment, offer invoicing as a payment method, manage the subscription, provide the customer portal, provide customer support or fulfil our statutory obligations.
5. Data content of the register and retention period
The register may contain the following data about customers:
• Name, Business ID and contact details
• Company and position
• Legal persons, contact person’s name and contact details
• Customer number and/or other corresponding identifier
• Data related to the customer relationship and contracts, and customer history
• Invoicing details
• Other additional data received from the customer or collected with the customer’s consent
• Other classification data describing the company’s/customer’s operations
• Customer feedback data
• IP address data or other identifier
• Data collected through cookies
• Newsletter subscription and analytics
• Which of our expert materials you have ordered/downloaded
• Website behaviour and analytics
• Data collected from social media channels
• Participation in events
• Image and video material from events or separately arranged photo/video shoots
• Direct marketing opt-out
In connection with SaaS service subscriptions, Trial periods, payments and subscription relationship management through the online store, we may process the following personal data:
• name
• work role or job title
• company name, Business ID, VAT, GST or other corresponding company tax identifier
• professional contact details, such as work email address and work phone number
• billing address and other company and contact details required for invoicing
• time of order, Trial or customer account creation
• order content, order number, service package, modules, additional services, billing period and order history
• data concerning the SaaS service subscription, such as subscription status, number of licences, start and end date, renewal and cancellation data, and payment periods
• data related to user management, such as data concerning the main user, billing contact and other contact persons designated by the corporate customer
• data related to access rights, user accounts, direct links, API credentials and other service access authorisations
• payment method, payment status, payment transaction identifiers, payment amount, payment time, failed charge attempts, outstanding payments, refunds, payment disputes, delays, debt collection data and chargeback data
• data related to verifying credit information, payment defaults, sanctions risks, company and tax status or B2B tax treatment, insofar as such data is processed to accept an order, offer an invoicing method or comply with statutory obligations
• invoicing, receipt, tax and accounting data
• data related to customer communications, customer support, complaints, service deployment, changes to the service package or modules, and customer relationship management
• data related to the use of Stripe Customer Portal, such as updates made by the customer to subscriptions, billing details or payment methods
• data related to service suspension, restriction, closure, termination or cancellation of the contract
• technical data necessary for the security of the online store, payments and SaaS service, such as IP address, device and browser data, log data, event logs, usage and monitoring data, and data related to payment transaction risk assessment
• data related to the reference use of the customer company, such as the company name and any prohibition given by the customer on using the name as a reference.
Retention periods of personal data
We store personal data only for as long as necessary to fulfil the purposes of processing personal data or to fulfil statutory obligations.
Data related to the customer and contractual relationship is stored for the duration of the customer or contractual relationship and thereafter for as long as necessary due to contractual liabilities, complaints, legal claims, accounting and tax obligations or other statutory obligations.
Personal data included in invoicing and accounting material is stored for the period required by accounting legislation.
Data related to payment transactions, payment security, Stripe Radar risk assessment, chargebacks, payment disputes, payment defaults, credit risk assessment, debt collection and sanctions risk assessment may be stored for as long as necessary to execute the payment, investigate errors, prevent fraud and misuse, fulfil statutory obligations, or establish, present or defend legal claims.
Trial and subscription data is stored for the duration of the customer or subscription relationship and thereafter for as long as necessary to handle contractual liabilities, invoicing, payment disputes, debt collection, information security and legal claims.
Data related to the SaaS service subscription relationship is stored for the duration of the customer or subscription relationship and thereafter for as long as necessary to handle invoicing, payments, cancellations, customer support, contractual liabilities, information security, payment disputes, debt collection or legal claims.
Marketing register data is stored for as long as the data subject belongs to the target group of marketing communications, or until the data subject withdraws their consent, opts out of direct marketing or objects to the processing of their personal data for direct marketing purposes.
Data related to events, webinars, downloadable materials and contact requests is stored for as long as necessary to process the matter, carry out communications, develop the service and handle possible later contacts.
Data collected by cookies and similar technologies is stored in accordance with the retention periods stated in the cookie banner or cookie preferences.
We regularly assess the necessity of personal data and delete or anonymise the data when there is no longer a basis for storing it.
6. Regular sources of data
Data is collected directly through the website’s data form, entered by the person themselves, or otherwise directly from the data subject. Personal data may be updated from public or generally available sources.
Personal data is stored in the marketing register when a person orders SK Protect Oy’s services or downloadable material, registers for an event or webinar, or submits a contact request or application. Personal data is stored in the customer register if the person belongs to an SK Protect Oy partner or customer company. Register data for direct marketing is obtained from the data subject themselves or from the public internet.
If personal data is obtained from sources other than the data subject themselves, the sources of the data may include publicly available sources, such as company websites, the Trade Register, company and contact information services, LinkedIn or other professional networks, as well as data provided by the customer, partner or employer.
In such cases, the data processed mainly concerns the person’s name, work role, employer, professional contact details and other data necessary for the customer, partner, marketing or stakeholder relationship.
If personal data has not been obtained from the data subject themselves, we inform the data subject in the manner required by data protection legislation no later than at the time of first contact or at another time in accordance with data protection legislation, unless an exemption from the obligation to provide information applies under law.
7. Regular disclosures of data
Personal data is not sold or disclosed to external parties for their own direct marketing purposes.
We may disclose personal data to authorities if required by law or a binding order from an authority. In addition, data may be disclosed with the data subject’s consent or when the disclosure is necessary for the performance of a contract, the establishment, presentation or defence of a legal claim, or the fulfilment of the controller’s statutory obligations.
We use service providers in the processing of personal data who process personal data on our behalf and in accordance with our instructions. Such categories of recipients may include, for example:
• IT, hosting, cloud and system service providers
• technical website maintenance providers and analytics service providers
• marketing, newsletter and marketing automation service providers
• customer relationship management and communication system providers
• event and webinar system providers
• financial administration, invoicing and accounting service providers
• service providers related to payments, debt collection, legal matters and auditing
• social media and advertising partners insofar as they are used for targeting or measuring marketing.
Agreements concerning the processing of personal data required by data protection legislation have been concluded with service providers when the service provider processes personal data on behalf of the controller.
We use Stripe as a payment service provider for processing online store payments. We use Stripe Checkout to execute payments, Stripe Subscriptions to manage SaaS subscriptions and recurring payments, Stripe Customer Portal to manage customer subscriptions, billing details and payment methods, and Stripe Radar to ensure payment transaction security and prevent fraud.
To execute a payment, SaaS subscription, Trial or subscription relationship, Stripe may process personal data related to the payment transaction and customer relationship, such as the payer’s name, professional contact details, billing details, company details, payment method, payment transaction identifiers, payment amount, payment status, subscription relationship status, billing periods, failed payment attempts, refunds, chargebacks, and technical and risk assessment data necessary for payment transaction security and prevention of misuse.
Stripe may process personal data on behalf of the controller to provide the payment service, SaaS subscription management, the customer portal and fraud prevention, and in some situations as an independent controller, for example in connection with its statutory obligations, payment security, fraud prevention, regulatory compliance, dispute handling and development of its payment services. Stripe is responsible for the processing of personal data it carries out as an independent controller in accordance with its own privacy policy.
In addition, personal data may be processed or disclosed to technical service providers of the online store, system, hosting, cloud and IT service providers used to produce the SaaS service, customer relationship management and support system providers, service providers used to verify company and tax status, service providers used to check credit information, service providers used for sanctions and risk checks, financial administration and accounting service providers, payment intermediation, invoicing and debt collection service providers, auditors, legal advisers, a possible UK representative and authorities when required by law.
8. Transfer of data outside the EU or EEA
As a rule, personal data is not transferred outside the EU or EEA.
If a service provider we use, or its subcontractor, processes personal data outside the EU or EEA, we ensure that there is a basis for the transfer in accordance with data protection legislation. The transfer may be based, for example, on an adequacy decision by the European Commission, the EU Standard Contractual Clauses or another transfer basis permitted by data protection legislation. Where necessary, we also use supplementary safeguards.
The data subject may request further information on the transfer bases and safeguards used by contacting the contact person stated in this Policy.
In connection with online store payments, SaaS subscriptions, Trial periods, the customer portal and fraud prevention, Stripe and its group companies or subcontractors used by us may also process personal data outside the EU or EEA.
In such cases, we ensure that there is a transfer basis in accordance with data protection legislation, such as an adequacy decision by the European Commission, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework or another transfer mechanism permitted by data protection legislation. The data subject may request further information on the transfer bases and safeguards used by contacting the contact person stated in this Policy.
9. Principles of register protection
Personal data is processed only in electronic form. If personal data is temporarily in paper form, it is converted into electronic form without delay and the paper versions are disposed of appropriately.
Appropriate technical and organisational measures are used to protect personal data against unauthorised access, alteration, loss or destruction. The measures are based on risk assessment and comply with the principles and requirements of the ISO 27001 information security standard.
Technical safeguards include, for example, firewalls, encryption, user authentication and access control. Organisational measures include staff information security training, access rights management and regular review of information security practices.
Personal data may be accessed only by employees and service providers who have the right and obligation to do so because of their work, and who have undertaken to comply with confidentiality obligations.
We process personal data in a way that minimises risks to data subjects. If a personal data breach occurs, we act in accordance with applicable data protection legislation and notify the authorities and, where necessary, the data subjects without undue delay.
We regularly assess the data protection risks of processing activities. If processing is likely to result in a high risk, we carry out a data protection impact assessment before starting the processing and implement the necessary risk management measures.
10. Cookies on the website
Cookies are small text files that are automatically stored on your device when you visit websites. We use cookies to make our service user-friendly, functional and high-quality.
The cookies we use are divided into necessary cookies and cookies requiring consent:
• The use of necessary cookies and similar technologies does not require consent insofar as they are necessary to provide a service explicitly requested by the user or to technically transmit communications. The legal basis for the related processing of personal data is the controller’s legitimate interest or the performance of a contract, depending on the situation.
• Analytics, marketing, social media and other non-essential cookies or similar technologies are set only with the user’s consent.
Cookies are used to analyse and develop website use, and to target and optimise marketing. We also use cookies to tailor content and advertisements, support social media features and monitor visitor numbers. We also share data collected through cookies with our marketing, analytics and social media partners, who may combine it with other data.
You can manage and change your consent through the cookie notice. A detailed list of the cookies we use can be found in our cookie banner. Most browsers also allow cookies to be blocked, but this may affect the functionality of the service. The use of Google Analytics can be prevented in accordance with Google’s instructions.
The website also uses third-party cookies.
Detailed information on the cookies in use, their purposes, service providers and retention periods is presented in the cookie banner or cookie preferences. The data subject may change or withdraw their consent to cookies requiring consent through the cookie preferences.
Necessary cookies are used to implement the technical operation and security of the website and the choices made by the user. The use of these cookies is based on the controller’s legitimate interest in ensuring the functionality and security of the website.
In connection with the online store, Trial, SaaS service subscription, customer portal and payments, Stripe may use cookies or similar technologies to technically execute payments, ensure security, prevent fraud and maintain the functionality of the payment service. These technologies are used insofar as they are necessary for the technical operation of the payment service, online store and subscription relationship, and for the security of payment transactions.
11. Rights of the data subject
In accordance with Articles 15–21 of the EU General Data Protection Regulation 679/2016, the data subject has the right to access their data, request rectification or erasure of data, restrict processing, transfer data from one system to another and object to the processing of personal data.
We do not make decisions or carry out profiling based solely on automated processing that would have legal or similarly significant effects on data subjects. You have the right at any time to object to the processing of your personal data for direct marketing and related profiling.
We use Stripe Radar to ensure payment transaction security and to prevent fraud and misuse. Stripe Radar may use automated methods to assess payment transaction risks and identify payment fraud.
A payment transaction, order or use of an invoicing method may be blocked, suspended, rejected or referred for further review if the payment transaction, order, customer’s company or tax status, payment default information, sanctions risk or other risk factor appears unusual or risky from the perspective of payment security, fraud prevention, credit risk, statutory obligation or service security.
Insofar as the risk assessment leads to a material restriction of the order, payment method or use of the service, the decision is reviewed manually where necessary. The risk assessment may lead to further review, but a material rejection of an order, refusal of an invoicing method or significant restriction of service use by Protect is not based solely on automated processing; the decision is reviewed by a human.
The data subject may exercise their rights by contacting the contact person mentioned in section 2 by email or using another contact method stated in this Policy. Where necessary, we may request additional information to verify the identity of the data subject before implementing the request.
If your request is manifestly unfounded or unreasonable, we may either charge a reasonable fee based on administrative costs for implementing the request or refuse to carry out the requested action.
If you consider that the processing of your personal data violates data protection legislation, you have the right to lodge a complaint with the supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (www.tietosuoja.fi).
12. Other rights relating to the processing of personal data
The register is not disclosed to external parties for direct advertising, distance selling, other direct marketing, or market or opinion research.
_____________________________________________________________________________________________________________________________________________
Addendum concerning customers and users in the UK
If we provide the SaaS service through the online store to corporate customers in the United Kingdom, we process the personal data of these customers’ contact persons, main users, billing contacts and service users for the purposes described in this Privacy Policy.
In addition to the EU General Data Protection Regulation and Finnish data protection legislation, such processing may also be subject to United Kingdom data protection legislation, including the UK GDPR and the Data Protection Act 2018, insofar as the processing relates to the provision of services to data subjects in the United Kingdom.
International transfers of personal data concerning the UK
Personal data may be processed in Finland, elsewhere in the European Economic Area, in the United Kingdom and, depending on the location of our service providers, also in other countries.
Transfers of personal data from the European Economic Area to the United Kingdom are based on the European Commission’s adequacy decision concerning the United Kingdom for as long as the decision remains in force.
Transfers of personal data from the United Kingdom to the European Economic Area may be based on the adequacy of the EEA under United Kingdom data protection regulation. If personal data subject to the UK GDPR is transferred to other countries, we use an applicable transfer basis under the UK GDPR, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, a United Kingdom adequacy decision or another applicable transfer mechanism.
Stripe and our other service providers may also process personal data related to payments, the subscription relationship, customer portal, fraud prevention, SaaS service provision, customer support or technical maintenance outside the United Kingdom, EU or EEA. In such cases, we use applicable transfer bases and safeguards in accordance with data protection legislation.
The data subject may request further information on the transfer bases and safeguards used by contacting the contact person stated in this Privacy Policy.
Rights and supervisory authority of data subjects in the UK
Data subjects in the United Kingdom have rights concerning their personal data in accordance with applicable data protection legislation. These may include the right to access their own data, the right to rectification of data, the right to erasure of data, the right to restriction of processing, the right to object to processing, the right to data portability, the right to withdraw consent and the right not to be subject, in certain situations, to a decision based solely on automated decision-making.
If the data subject considers that their personal data has been processed in violation of data protection legislation, they have the right to lodge a complaint with the competent supervisory authority. In Finland, the competent supervisory authority is the Office of the Data Protection Ombudsman. In the United Kingdom, the competent supervisory authority is the Information Commissioner’s Office, or ICO.
Privacy policy updated 7.8.2026
Translation notice
This Privacy Policy has been translated from the original Finnish version. In the event of any discrepancies, interpretation differences or translation-related inconsistencies, the Finnish version shall prevail.