Legal
Service Description
1. PRO24 system
PRO24 is a browser-based management tool for handling an organisation's HSEQ (health, safety, environment and quality) matters comprehensively. It has been developed entirely in Finland since 2009 and has always been wholly Finnish-owned.
This service description outlines the system's main features and modules, the support services, information security, and how the system is developed and maintained. More detailed, module-specific instructions are available within the system itself.
2. System features
PRO24 is built around the organisation's own property hierarchy, which is defined when the system is taken into use and forms the backbone that the system's modules connect to. The following describes the system's capabilities at a general level; each module includes more detailed guidance inside the system.
Modules
PRO24 Observations. A configurable tool for building an organisation's reporting procedures in electronic form - creating observation types, defining observation-specific workflows, sending automatic email notifications, assigning accountability for observations and measures, and following up on both. Confidentiality can be limited to specific user groups. It works directly in the device browser with no separate app to install, and its API enables data transfer to other systems.
PRO24 Assessments. Supports a wide range of evaluation processes - work and machine risk assessments, safety walks (5S, 6S), internal audits, and business or process risks and opportunities - using ready-made or self-built forms. Each assessment defines a person in charge, corrective actions and scheduled follow-up, and the system provides visual views for monitoring open assessments and measures.
PRO24 Desktops. A visual platform that gathers documents, links and management-system content - for example ISO 9001, ISO 14001 and ISO 45001 systems, quality manuals, induction materials, ATEX and regulatory authority documentation - into a uniform presentation. Documents are managed with rich metadata such as type, author, person in charge, approval workflow, version numbering and revision history, so they can be reused across the system.
Note for customers in Finland. PRO24 also includes a guided wizard for preparing and maintaining statutory rescue plans (pelastussuunnitelma). The wizard is based on Finnish legislation and references the relevant statutory provisions, so it is intended for use in Finland only and cannot be used as such in other countries.
PRO24 Chemicals. An electronic chemical register in which an organisation manages its own chemical information and chemical risk assessments, with chemicals listed by where they are used and stored. The module offers two types of chemical store. The first is a country-specific store that is shared by all customers: users can pick chemicals from it into use and attach them to their own storage and/or use locations, and only Protect's employees can add chemicals to this shared store. The second is a company-specific store, available only to that customer and not to others, in which the company can freely maintain all of its own chemical information, including safety data sheets (SDS). Chemicals can be searched by name, location, supplier or hazard properties, and a chemical risk assessment can be carried out for each chemical, with the system calculating consequences automatically from the chemical's H-phrases while the user assesses the likelihood of exposure.
Adding chemicals to the shared store. When taking the system into use, you can submit a reasonable number of chemicals to Protect, which we then add to the shared, country-specific store for you; larger volumes are always agreed separately. Protect accepts only official safety data sheets, and only in PDF format.
PRO24 Induction. A digital induction system and training register for standardising onboarding and online training. Study modules can be created to standardise induction and training, with trainees progressing at their own pace regardless of time or place. The built-in training register gives an up-to-date view of staff training and qualifications and their validity from a single platform, functioning as a competence management system that keeps information readily available for audits and regulatory requirements. Competence can be verified with browser-based exams, for example on completion of induction, with no separate app to install.
Languages
PRO24 is available in Finnish, Swedish, English and Estonian, and users in the same organisation can each use their preferred interface language, which is remembered between sessions. A built-in translation tool lets organisations translate their own content, such as self-made assessment forms or exams, into the supported languages.
User management
The system has four user levels - administrator, superuser, classificator and user - and user groups can further restrict access to information. Rights can be granted globally or per module - for example, module-specific administrator rights can be assigned to a user without granting the global administrator role.
Administrators have access to the whole system (excluding user management unless separately granted) and act as their organisation's key users and link to Protect. Superusers have more limited rights, typically at supervisor level, and cannot edit core configuration such as the property hierarchy. Classificators can classify observations and otherwise hold basic user rights. Users can create observations, take responsibility for measures, and read information according to their user group, but generally cannot edit items unless responsibility for them has been assigned.
In addition, end users can access specific parts of the system without authentication via direct links, which always restrict access to that particular content.
Authentication
Authentication uses a username and password, single sign-on (SSO), or a combination of these. The password policy enforces strong, long passwords and checks them against known data breaches to prevent the use of compromised credentials. SSO is implemented via the customer organisation's Entra ID and can be set up on a self-service basis; other SSO methods are not currently supported.
Interfaces
PRO24 currently provides an external API to the Observations module; new interfaces are evaluated case by case based on client feedback. Through the observation API, clients can build integrations with data analytics tools or other systems such as ERP or EAM. The client is responsible for implementing integrations, with assistance from Protect as needed. API documentation is available at api.pro24.fi.
3. Use support
A support request form is available directly in the system for questions about using PRO24 and for reporting any incidents. Requests are routed to Protect's specialists and picked up by the first available person. Support messages are received 24/7/365, with responses targeted for the next weekday between 8:00 and 16:00; critical requests are always handled as quickly as possible. Written support and call requests are available in Finnish and English.
Use support covers recording service requests, communicating solutions to the client, and advice on basic user-interface functions. It does not include professional services such as configuring the system for the client, editing information in the system, end-user training, planning and implementing changes, consultation, or retrieving and delivering information from the system.
PRO24 is designed to be taken into use on a self-service basis, so a separate deployment project is not required. A built-in setup guide walks administrators through the basic functions module by module, step by step, helping the organisation understand how the system works and configure it independently. When broader support is wanted, Protect also offers optional, chargeable services that are purchased separately and can be tailored to the client's needs and scope of use - for example assisted onboarding, user training and workshops, and data update services. Assisted onboarding is a paid service and is not included in the self-service setup guide described above. Terms may differ for these separately agreed services.
4. Information security
Providing PRO24 is based on a strong, confidential relationship between Protect and the client. Protect's information security management is certified to the ISO/IEC 27001 standard. Protect handles all client data confidentially and stores it appropriately, following its own information security policy to which every employee commits. Information security incidents are handled according to Protect's incident-handling process, and Protect holds a cyber security insurance policy. The client owns all data stored in the system.
Encryption
The system operates over the HTTPS protocol and uses modern TLS encryption (TLS 1.2 and 1.3) to transfer data securely over the web.
Hosting and resilience
Services run in two access-controlled, burglar-alarmed server rooms in two separate locations in Finland. Power is UPS-backed - and generator-backed for the main room - the main room has an automatic fire alarm system, cooling is temperature-controlled, and data, firewall and power supply are duplicated. Databases and the application are backed up daily to a separate geographic location, with defined retention cycles for daily, weekly and monthly backups. All client data stored in the PRO24 system is located in Finland and is not transferred outside the EU/EEA. The amount of data storage included in the PRO24 agreement is 5 GB, unless otherwise agreed.
Maintenance and audits
The system is maintained and monitored in cooperation with Protect's server provider, over encrypted connections: both server health and the application itself are continuously monitored using automated monitoring software, and updates are applied regularly according to an update plan. SK Protect Oy and its subcontractors are responsible for maintaining and auditing the system and equipment, and conduct regular audits of premises and services according to their own audit plan.
Access control and data ownership
Protect personnel authenticate to PRO24 with personal credentials via strong authentication (Entra ID), over encrypted and monitored connections. Protect employees have no default access to customer environments or the data stored in them: access always requires the customer's explicit approval through an access request handled in the system's Helpdesk, is granted case by case for a limited period and defined scope, and is removed automatically at expiry or manually at any time. Protect processes data only to the extent necessary to provide the service, maintain the system or resolve technical issues, and always on a customer assignment. All access requests and changes to access rights are logged.
Client-specific information is isolated so that one organisation cannot access another's information. Clients can delete their data at any time; deleted data remains only in backups until its retention cycle ends, after which it can no longer be restored. When the customer relationship ends in accordance with the agreement, or on the client's separate written request, the client's data is removed from the system and databases and finally deleted after the backup cycle.
Monitoring and logging
The service logs key events - such as user logins, changes to users and access rights, key administrative actions and major API events - to ensure security and support the investigation of errors. Data deletions and exports are monitored, and anomalies such as repeated failed login attempts can trigger automatic responses. Log data is accessible only to a limited group of PRO24 administrators at Protect. Access to different parts of the system can be restricted on a client-specific basis using IP rules, which the client's administrators define with Protect's help as needed. The PRO24 website uses the Google Analytics service and its cookies to monitor website usage; the stored data is anonymised from the organisation level downwards and may be processed by Google outside the EU/EEA.
5. Technology
PRO24 is a multi-tenant SaaS (Software as a Service). Protect is responsible for operating and maintaining the servers, data network and software, as well as backups and recovery from error situations. The system uses third-party and open-source components where applicable, and employs Google reCAPTCHA to protect unauthenticated access points - such as direct observation links - against automated spam and bot attacks. System availability can be monitored via the link provided in the system's operating instructions.
6. Endpoint requirements
PRO24 is used directly in a web browser on any device - computer, phone or tablet - with no separate applications or browser extensions to install; cookies and JavaScript must be enabled. Built to HTML, CSS and JavaScript standards, the service works in commonly used modern browsers such as Chrome, Edge, Firefox and Safari (the obsolete Internet Explorer is no longer supported). Testing targets current browser versions, and any browser version restrictions are notified separately.
7. Software development, updates and releases
PRO24 is developed entirely in Finland by Protect's own staff together with a subcontractor, using agile development methods. Development follows recognised security practices, monitoring for example the OWASP Top 10 for web applications and the vulnerability bulletins of national cyber security authorities.
As a SaaS service, all clients always use the latest, most up-to-date version. The system is typically updated one to two times a month, included in the SaaS price with no separate charge. Updates bring general improvements and fixes, and a few times a year new features for the applications; any chargeable new feature is always optional and agreed separately with the client. Updates are scheduled in advance and users are notified on the login screen and in the system; the detailed update and maintenance windows are described in the Service Level Agreement (SLA). New features and major releases are also communicated via the PRO24 administrators' mailing list, which can be joined from within the system.