Legal
General Terms of Service
These Terms of Service explain the conditions that apply when you access and use Plenaxy's services. Please read them carefully, as they define the rights and responsibilities of both the user and Plenaxy.
1. Applicability
1.1 These terms of service apply to the provision and use of any software, content, information or application (hereinafter collectively referred to as the "Service") SK Protect Oy ("SK Protect Oy") offers through the internet, as a cloud service or as a mobile application to a customer who uses the Service (hereinafter referred to as the "User" or "Customer"). The Service is intended exclusively for corporate, community, and other professional customers, and the Service is not sold to consumers. The User agrees to use the Service in compliance with these terms throughout the term of the user right and agreement and as long as the User uses the Service. If the User enters into a user agreement on behalf of an entity, such as a company or other legal entity, the User represents that it has the legal authority to bind that entity to a user agreement concerning the use of the Service. These terms may be updated by SK Protect Oy from time to time by providing prior written notice.
2. Service Provider
2.1 SK Protect Oy's contact details for complaints, customer service and support:
SK Protect Oy
Business ID: 1700958-9
VAT ID: FI17009589
Satamatie 330
67900 KOKKOLA, FINLAND
Internet: protect.fi/en/
SK Protect Oy owns the auxiliary business name/brand name Plenaxy.
3. The Service
3.1 The Service is a browser-based tool for managing corporate Health, Safety, Environment, and Quality (HSEQ) matters. More detailed and up-to-date service descriptions for the Service are provided upon request and may also be available at Plenaxy's website (https://plenaxy.com/legal/).
3.2 Use of the Service may require, depending on the applicable service:
- data connection;
- device, such as a computer, smartphone or tablet computer with a web browser or other software;
- acceptance of these terms and conditions (always mandatory);
- downloading and installing an application;
- creation of a user account; and
- logging into the account for using the Service.
3.3 By registering a user account and/or using the Service, the User (1) agrees to be bound by these terms and conditions, and (2) understands that SK Protect Oy may process personal data relating to the User in accordance with its privacy policy in force from time to time.
3.4 The User is responsible at its own expense for acquiring and configuring the device, data connection and software required for using the Service. SK Protect Oy does not provide any warranties that the Service will function error-free on all possible devices, browsers and operating environments.
4. Changes to the Service and to These Terms
4.1 SK Protect Oy reserves the right to make changes to these terms and conditions and to the Service. SK Protect Oy informs about essential changes to these terms and the Service on Plenaxy website and/or by email or through the Service. By continuing to use the Service after the terms or the Service have been changed, the User is deemed to have accepted the changes and committed to comply with them.
5. Use of the Service
5.1 SK Protect Oy grants the User a limited, non-exclusive, personal and non-transferable license to use and access the Service in accordance with these terms and conditions, the applicable laws and any other terms and conditions possibly agreed between SK Protect Oy and the User when concluding a user agreement for the Service.
5.2 Use of the Service requires the creation of a user account and the provision of certain personal data in connection with the creation of the user account.
5.3 The Customer is responsible:
- for all use of the Service, which takes place under the User's user account and user agreement;
- for user management, including granting, modifying, and removing access rights within its own organization;
- for providing correct, sufficient and truthful information required for creating and maintaining a user account;
- for keeping the username and password confidential and secure, not sharing them with anyone and not using any other person's username and password;
- for not sharing personal user accounts among multiple users;
- for not violating any third-party rights when using the Service, entering content into the Service, creating content in the Service or sharing content through or from the Service;
- for not using the Service for fraudulent, criminal, illegal or deceptive activities;
- for not copying, modifying, or creating derivative works of the Service, technology related to it, or information contained therein;
- for not misusing the Service by knowingly or negligently introducing viruses, trojans, worms or other materials that damage or are technically harmful to the Service; and
- for not storing or entering sensitive personal data into the Service excessively, as it may not have been designed for such purposes.
5.4 SK Protect Oy has the right, but no obligation, to monitor that the User uses the Service in compliance with these terms. If SK Protect Oy becomes aware of activity that it considers to be violating these terms, it may restrict or suspend access, delete or modify content, terminate the account responsible for such activity, or take any other measures it considers appropriate.
6. Prices and Fees
6.1 With the exception of free trial versions and features, the use of the Service is subject to payment of applicable fees. The pricing of the Service is based on the billing period selected by the Customer, which is either a monthly charge or an annual charge. SK Protect Oy may update its prices and fees by a written notification. If the User continues using the Service after a price increase, the User is deemed to have accepted the price increase or change for the subsequent contract term.
6.2 Unless otherwise notified, value added tax (VAT) or other similar taxes and fees are not included in the prices and fees.
6.3 The subscription continues automatically at the end of the selected billing period for a new billing period of the same length, unless the Customer cancels the subscription before the end of the current billing period. Under an automatic renewal, SK Protect Oy has the right to charge the subsequent billing period's fee via the Customer's designated payment method or send an invoice in accordance with the valid price list.
6.4 Self-service orders are available only to corporate customers whose business and tax status can be verified. The Customer must provide a valid VAT, GST, or equivalent business tax identifier. Where the reverse charge mechanism or similar B2B tax treatment applies, the Customer is solely responsible for reporting and paying the applicable taxes in its own country. SK Protect Oy reserves the right to reject an order if the Customer's business or tax status cannot be verified.
6.5 The payment methods available to the Customer are determined in accordance with the options offered by SK Protect from time to time. If the Customer pays by credit card or other electronic payment method, the Customer authorizes SK Protect Oy or its payment service provider to charge the fees automatically in accordance with the selected billing period. If the payment method is invoicing, the payment term is fourteen (14) days net from the date of the invoice, unless otherwise agreed. SK Protect Oy reserves the right to check the Customer's credit information.
6.6 The Customer may upgrade or downgrade their service package or add/remove modules. If the Customer upgrades to a higher package or adds modules mid-billing cycle, the change takes effect immediately, and the price difference for the remainder of the current billing cycle will be invoiced immediately. If the Customer downgrades to a lower package or removes modules mid-billing cycle, the change takes effect at the end of the current billing cycle, and no fees already paid will be refunded or credited.
7. Personal Data and Privacy
7.1 As a data controller, SK Protect Oy processes personal data pursuant to its privacy policy in force from time to time.
7.2 If personal data of the Customer is processed in connection with the Service, a separate Data Processing Agreement ("DPA") (Appendix 1) shall apply between the parties, which forms an integral part of this agreement.
8. Availability, Maintenance and Interruptions
8.1 The Service is usually available 24/7. However, SK Protect Oy does not guarantee uninterrupted or error-free use of the Service. The Service may from time to time be completely or partially unavailable due to necessary backups, maintenance, improvements, security updates or similar activities. SK Protect Oy will inform the Users of planned outages whenever possible. SK Protect Oy is not responsible for any damages or harm caused by interruptions in the use of the Service.
8.2 All maintenance and support work is by default performed remotely from SK Protect Oy's location on weekdays during normal business hours.
8.3 More detailed service levels, support hours, response times, and potential service credits related to the availability of the Service and support are defined in the terms and conditions of SK Protect Oy's separate Service Level Agreement ("SLA"). The SLA in force from time to time is available on Plenaxy's website and forms an integral part of the agreement.
9. Intellectual Property Rights and Data Entered by the User to the Service
9.1 The Service (including any modifications, updates and bug fixes to it) and content and services relating to it are protected by copyright and other intellectual property right laws and are and shall remain the sole and exclusive property of SK Protect Oy or its licensors.
9.2 The Customer owns all data they store in the Service and the data generated in connection with the use of the Service ("Customer Data"). SK Protect Oy has the right to process Customer Data solely for the purposes of providing, maintaining, and developing the Service in accordance with this Agreement.
10. Term and Termination
10.1 The agreement is valid until further notice. The subscription for the Service is automatically renewed for a new similar billing period, unless the Customer terminates the subscription before the current billing period ends, or SK Protect Oy terminates the agreement by giving a thirty (30) days' written notice.
10.2 SK Protect Oy may also terminate the agreement with immediate effect or by giving a reasonable notice, if the User does not pay the applicable service fees, the User uses the Service in violation of these terms, the User's account has remained inactive and/or unaccessed for a substantial period of time, as reasonably considered by SK Protect Oy, or SK Protect Oy makes a decision to end or substantially modify the provision of the Service.
10.3 Upon termination of the agreement, (a) SK Protect Oy has the right to deactivate and delete the User's account as well as any data entered by the User, as soon as reasonably practicable after the effective date of termination or expiration, unless a specific time period is provided in these terms, (b) the User must stop using and prevent the further usage of the Service by the effective date of termination as well as pay any amounts owed by it to SK Protect Oy under these terms and the agreement. If an agreement is terminated, the User is not entitled to any refund on payments invoiced or made prior to the effective date of termination, unless otherwise specifically agreed. The terms and conditions which by their nature and purpose are intended to survive termination, shall survive any termination or expiration of an agreement.
11. Applicable Law and Dispute Resolution
11.1 An agreement between the User and SK Protect Oy, these terms and the use of the Service are governed by the laws of Finland, without regard to its conflicts of law rules and principles.
11.2 Any dispute arising between the parties will be settled amicably. Failing amicable settlement, the dispute will be finally settled by arbitration in accordance with the rules of expedited arbitration under the Finnish Central Chamber of Commerce. The arbitration shall be held in Helsinki, Finland and the arbitration proceedings shall be conducted in English. SK Protect Oy shall also, however, have the right to bring up any claim, related to an overdue receivable, in any district court in the User's jurisdiction.
12. Limitation of Liability
12.1 SK Protect Oy does not give any guarantees about the results that may arise from the use of the Service or the suitability of the Service for a specific purpose. SK Protect Oy is not responsible to the User or to any third party for indirect damages, or lost profits, revenue, savings or goodwill, loss of data, consequential damages or punitive damages.
12.2 Unless otherwise determined by mandatory laws, the aggregate cumulative liability of SK Protect Oy to a User is limited to the maximum of the fees (excluding VAT) paid by the Customer for the Service over the last twelve (12) months preceding the submission of the first claim. Prior to claiming any monetary damages from SK Protect Oy, SK Protect Oy shall always have the primary right to correct a breach or deficiency by correcting its performance or reperforming it. Any claims for damages against SK Protect Oy must be brought no later than six (6) months after the User became aware of the event giving rise to the respective claim. Thereafter all claims arising out of that event against SK Protect Oy shall be barred.
12.3 The limitations of SK Protect Oy's liability apply whether an action is in contract or tort and regardless of the theory of liability.
12.4 These limitations of liability apply to the extent permitted by mandatory legislation.
13. General Terms
13.1 SK Protect Oy shall not be deemed to be in breach of agreement, or otherwise be liable to the User, for any failure to perform, or any delay in performance, caused by reasons beyond SK Protect Oy's control.
13.2 These terms and the additional agreed-upon terms in a user agreement contain the entire agreement between the parties and supersede all prior communication, discussions and agreements relating to the subject matter.
13.3 The User does not have the right to transfer the user agreement, its user rights to the Service, or any other rights or obligations related to a user agreement, in whole or in part, to a third party if not expressly agreed by SK Protect Oy in writing. SK Protect Oy may assign the agreement and its rights and duties to a third party without the User's permission, including, without limitation, in connection with debt collection, any merger, consolidation, or sale of all or substantially all of associated assets, or similar transaction or business reorganization.
13.4 SK Protect Oy is entitled to use the Customer's name as a reference in its reference lists and on its website, unless the Customer explicitly prohibits such use in writing. The use of the Customer's logo, statements, customer stories, or other broader marketing materials requires the Customer's prior approval.
14. Switching, Cancellation and Data Portability (EU Data Act)
14.1 Right to Switch and Assistance. The User may request to switch from the Service to (i) another data processing provider, or (ii) the User's own on-premises ICT infrastructure, or request the deletion of their Customer Data. SK Protect Oy shall assist the Customer in the switching process and provide, within reasonable technical limits, the necessary information and instructions to execute the switch. SK Protect Oy commits to ensuring a high level of security, data integrity, and confidentiality throughout the switching process.
14.2 Transition Period. The transition period shall be completed within a maximum of thirty (30) days from the end of the notice period or the Customer's notification of switching. If the transition process cannot be reasonably completed within this timeframe due to technical reasons, the Customer has the right to request a single extension. However, for technical reasons, the absolute maximum transition period is seven (7) months. SK Protect Oy shall inform the Customer without undue delay if a 30-day timeframe cannot be met, providing justifications and an estimated timeline.
14.3 Data Format and Fees. SK Protect Oy shall provide the transferable Customer Data free of charge in a commonly used, machine-readable, and where possible, standardized format. SK Protect Oy shall not impose any switching charges on the Customer for the data transfer, to the extent such charges are prohibited by mandatory laws (including the EU Data Act). If the Customer requests separate additional services, custom conversions, or support exceeding statutory minimum obligations, SK Protect Oy may charge reasonable fees according to its current price list.
14.4 Exportable Data. Transferable Customer Data includes the data stored by the Customer in the Service and data generated in connection with the use of the Service. The transferable data strictly excludes SK Protect Oy's trade secrets, source code, algorithms, technical logs, operating and monitoring systems, and any other information protected by SK Protect Oy's intellectual property rights.
14.5 Data Retrieval and Deletion. After the transition period or termination of the agreement, the Customer shall have a retrieval period of at least thirty (30) calendar days to retrieve its Customer Data. After the retrieval period, SK Protect Oy shall irreversibly delete all transferable Customer Data from the user interface and production environments in a reasonable time. Data in backups will be permanently deleted according to SK Protect Oy's standard backup cycles, but no later than six (6) months after the termination of the agreement, unless mandatory law requires longer retention.
14.6 Scope and Limitations of Applicability. This Section 14 applies strictly to the extent mandated by the mandatory provisions of the EU Data Act (Regulation (EU) 2023/2854). To the extent that SK Protect Oy is not legally obligated to provide the switching rights or services described herein under the applicable mandatory legislation, SK Protect Oy reserves the right, at its sole discretion, to restrict, modify, or unilaterally waive the applicability of this Section 14 by providing a written notice to the Customer.
Appendix 1: Data Processing Agreement
1. Introduction
This Data Processing Agreement ("DPA") is applied as part of the commercial agreement ("Agreement") to the processing of personal data carried out by SK Protect Oy ("Processor") in connection with providing SaaS services ("Services") to the customer who is a contracting party in the Agreement as well as the data controller of such personal data ("Controller"), which Services are described in more detail in the Agreement concluded by and between the Processor and the Controller.
This DPA is an integral and inseparable part of the Agreement between the parties. All terms used in this DPA, but not defined, have the same meaning as they have in the Agreement. If there is a conflict between the Agreement and this DPA, the terms of the DPA take precedence.
2. Definitions
"Controller" means the natural person or legal entity, authority, agency or other body mentioned in this DPA, which alone or jointly with others defines the purposes and means of personal data processing.
"Data Protection Law(s)" means the Data Protection Act (1050/2018) and the EU General Data Protection Regulation (2016/679) with amendments and replacement regulations as well as other valid and applicable data protection legislation and instructions and binding regulations of data protection authorities.
"Data Subject" means an identified or identifiable natural person whose Personal Data is Processed on the basis of this DPA.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Personal Data Breach" means a data security breach event resulting in the accidental or illegal destruction, loss, alteration, unauthorized disclosure or access to personal data transferred, stored or otherwise processed.
"Processing" means the function or functions that are applied to Personal Data or data sets containing Personal Data in connection with the provision of Services.
"Processor" means the natural person or legal entity, authority, agency or other body mentioned in this DPA that Processes Personal Data on behalf of the Controller.
"Standard Contractual Clauses" means the Standard Contractual Clauses (EU) 2021/914 as of 4 June 2021.
"Subprocessor" means a natural person or legal entity in a contractual relationship with the Processor, who processes Personal Data as a subcontractor of the Processor as part of performing Services for the Controller.
3. Scope of Processing and Processing Activities
This DPA applies to the Processing of Personal Data for which the Controller acts as the sole data controller.
The Processor Processes Personal Data (i) in accordance with Data Protection Laws and the terms of this DPA to fulfill the obligations described in the Agreement; and (ii) in compliance with the written instructions given by the Controller from time to time, unless otherwise required by the Data Protection Laws applicable to the Processor. The Processor may not process Personal Data for any of its own purposes or hand it over to third parties, unless this DPA allows it. The Processor must notify the Controller if it considers or suspects that the Controller's written instructions violate the Data Protection Laws. Unless otherwise stipulated in this DPA or its appendices, the Processor may Process Personal Data only for the duration of the Agreement.
The Controller (i) undertakes to comply with the obligations in accordance with the Data Protection Laws applicable to it in the Processing of Personal Data; and (ii) is responsible for the fact that it, as the sole data controller, has the right to Process Personal Data and that it has fulfilled its obligation to inform the Data Subjects and/or received (or will receive) all the consents required by the applicable Data Protection Laws.
More detailed information about the Processing, such as the nature of the processing, types of Personal Data and groups of Data Subjects, are described in Appendix A.
However, the Controller acknowledges and accepts that as part of providing the Services to the Controller, the Processor has the right to use information related to the operation, support or use of the Service or obtained in connection with it for its legal and legitimate internal business purposes, such as (i) invoicing the Service based on usage or number of users, (ii) delivery of the Service and for managing the provision thereof, (iii) for the functional and technical development of the Service, (iv) for compliance with applicable laws, (v) for ensuring the security of the Service, and (vi) for preventing fraud and abuse or reducing risks.
4. Subcontractors and Subprocessors
The Processor has the right to use Subprocessors in the Processing. Upon request, the Processor must provide the Controller with more information about the Subprocessors it uses. If the Processor makes significant changes to its Subprocessors it must notify the Controller in writing. The Controller has the right to prohibit the use of a specific Subprocessor for a justified reason. If the Controller prohibits the use of a particular Subprocessor and it is not reasonably possible to transfer the tasks of that Subprocessor to anyone else, the Processor has the right to terminate the DPA and end the Processing. The Controller is not entitled to any compensation solely on the basis that the Processing ends and the DPA has been terminated due to the Controller prohibiting the use of a specific Subprocessor.
The Processor must enter into a written agreement with each Subprocessor, which contains the terms and conditions required by the Data Protection Laws and essentially similar types of obligations as the Processor has under this DPA. The Processor is responsible for the Subprocessors it uses, just as it is for its own actions.
5. Data Security
The Processor must implement appropriate technical, physical and organizational measures to ensure a high level of security in the Processing of Personal Data by the Processor and to protect Personal Data from unauthorized or illegal processing and from unintentional loss, destruction, damage, change or transfer.
The Processor must take measures to ensure that every natural person working under the Processor who has access to Personal Data processes it only in accordance with the instructions of the Controller, unless otherwise required by applicable Data Protection legislation. The Processor is responsible, in accordance with its own policies, for taking backups of the data and files of the Controller in its possession and for checking their functionality.
Without limiting the requirements and obligations described above, the specific technical and organizational security measures implemented by the Processor are defined in SK Protect Oy's separate Service Description in force from time to time, which forms an integral part of this agreement.
6. Confidentiality
The Processor must ensure, to the extent reasonably possible, that only those persons acting on its behalf who have a need to access the information in order to fulfill the purpose of this DPA have access to the Personal Data, and that the persons who have the right to process the Personal Data are committed to complying with the obligation of confidentiality or are subject to the appropriate statutory obligation of confidentiality.
7. International Data Transfers
The Processor may transfer to a country outside the European Union or the European Economic Area. The Processor must always comply with the conditions and requirements of the Data Protection Laws when transferring data to countries outside the European Union or the European Economic Area, such as using standard contract clauses published by the EU Commission applicable to data transfer.
If the Processor is located inside the EEA and the Controller outside the EEA, the transfer of Personal Data shall be governed by the Standard Contractual Clauses which are incorporated herein by reference and form an integral part of the DPA.
8. Personal Data Breaches and Reporting Obligations
The Processor must notify the Controller of all real or suspected Personal Data breaches without undue delay after becoming aware of the breach. The Processor must provide the Controller with all available information about the Personal Data Breach, which the Controller may need to fulfill its own investigation and reporting obligations. The Processor must otherwise assist and cooperate with the Controller in the investigation of the Personal Data Breach and in possible matters related to notifications to authorities and interested parties. The Processor must also take the necessary reasonable follow-up measures to mitigate the adverse effects of the Personal Data Breach, repair the violation or breach that has occurred, and prevent future violations.
Unless otherwise required by the Data Protection Laws or the order of the competent authority, the Controller makes the final decision at its own discretion on whether the Personal Data Breach must be notified to the authorities or other parties involved, and on the possible way to make such notifications. If the Processor reports a Personal Data Breach to the authorities or other interested parties, they must be approved in advance by the Controller.
9. Documentation and Auditing Rights
A party has the obligation to make available to the other party all the required information and documents that are necessary for demonstrating compliance with this DPA and the Data Protection Laws.
At the request of the Controller, the Processor must also allow audits of the Processing, Services, information security measures and the Processor's information systems and processes and participate at reasonable intervals to such audits for the purpose of ensuring compliance with this DPA and the Data Protection Laws. Such audits may be carried out no more than once a year, unless there is a justified reason to assume that the Processor does not comply with the DPA or the Data Protection Laws. Each party is responsible for its own costs related to the audit. The Processor must be notified of planned audits at least thirty (30) days before the intended audit. Information about the Processor's activities obtained by the Controller during the audit is confidential.
10. Assisting the Controller
The Processor must, at the request and expense of the Controller, reasonably assist the Controller in complying with the obligations data controllers have in accordance with the Data Protection Laws. The duty to assist applies to the following matters:
10.1 Access to Personal Data
Insofar as the Personal Data is not available directly through the Services, the Processor shall, upon request, provide the Controller with the data in question.
10.2 Fulfillment of Data Subjects' rights and requests from the supervisory authority
The Processor must notify the Controller without delay: (i) of all requests, complaints or notifications made by the supervisory authority or other competent authority; and (ii) of any requests received directly from the Data Subject. The Processor may respond directly to the request only if the Controller has given permission and instructions to do so in advance.
10.3 Data protection Impact Assessment
If the Processor becomes aware that the planned Processing would cause a high risk in terms of the rights and freedoms of a natural person, it must inform the Controller of this and, if necessary, assist the Controller in carrying out an impact assessment.
10.4 Correction, Deletion and Restriction of Personal Data
The Processor must either (i) offer the possibility to correct, delete or limit the processing of Personal Data through the functions of the Service or (ii) correct, delete or limit the processing of Personal Data in accordance with the instructions of the Controller.
11. Term and Termination
Unless otherwise agreed, this DPA enters into force at the same time as the Agreement and remains valid as long as the Processor Processes the Controller's Personal Data in connection with the provision of its Services.
Upon termination of the DPA, the Processor must, at the Controller's choice, either delete all Personal Data Processed on behalf of the Controller or, alternatively, return all Personal Data to the Controller and delete existing copies, unless the Data Protection Laws or other regulation require retention of Personal Data. If the Controller has not given any instructions regarding the deletion or return of Personal Data, the Processor may on its own initiative delete the Personal Data in its possession when six (6) months have passed from the end of the DPA.
12. Other Terms
All changes to this DPA must be agreed in writing between the parties.
If the Data Subject suffers damage due to a violation of the Data Protection Laws, the responsibility of the Controller and the Processor for the damage is determined in accordance with Article 82 of the EU General Data Protection Regulation (2016/679). Each party is responsible for possible administrative fines imposed by the supervisory authority on the basis of a violation of the Data Protection Laws. A party's liability for damages to the other party based on a breach of contract of this DPA is a total maximum amount that corresponds to the VAT-free service fees paid on the basis of the Agreement for the six (6) months preceding the submission of the first claim for damages. In other respects, the terms of limitation of liability that may be contained in the Agreement between the parties or its appendices also apply to this DPA.
Regarding the applicable law and the resolution of disputes, the terms of the Agreement between the parties are followed, unless the Data Protection Laws state otherwise. If the Agreement does not state applicable law or contain dispute resolution terms, the DPA shall be governed by the substantive laws of the Processor's domicile.
Appendix A to DPA: Description of Transfer/Processing
Data Exporter: Controller (Customer) using SK Protect Oy's PRO24 SaaS Service.
Data Importer / Processor: SK Protect Oy.
Categories of Data Subjects: The Customer's employees and stakeholders.
Categories of Personal Data: Name, email address, phone number, job title/task, and tax number. Personal data may also be stored by the Customer in free-form data collection fields.
Nature and Purpose of Processing: Processing personal data on behalf of the Controller to provide the service, including handling support requests, performing expert work, and troubleshooting.
Duration: The duration of the commercial agreement. Data is removed from the user interface level three (3) months after the end of the notice period and permanently deleted from backups three (3) months after that.
Location of Processing: Data is primarily located and processed in Finland and EU/EEA area.
Approved Subprocessors: Seclan Oy (1774372-4) (capacity services; domiciled in Finland).