Privacy Policy

Palvelulinkki Oy (PalveluX)

English translation of the Privacy Policy published at https://palvelux.fi/tietosuojaseloste. In case of any discrepancy, the Finnish version prevails.

Privacy policy of Palvelulinkki Oy (PalveluX) in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
Updated: 22 June 2026. Version 2.0

1. Data controller

Palvelulinkki Oy
Business ID: 3531510-9
Email: info@palvelux.fi
Address: Savikkosaarentie 2 B 4, 60560 Seinäjoki, Finland

2. Person responsible for data protection matters

Name: Jani Latvala
Email: jani.latvala@palvelux.fi

3. Name of the register

Palvelulinkki Oy’s customer, marketing and service register (incl. PalveluX service user data).

4. Purpose and legal basis of processing personal data

We process personal data for the following purposes:

  • Providing and delivering the services: producing the SWOT analysis, strategy report and marketing content based on the information you provide, and saving the results to your account.
  • Targeting and personalising content: based on your company information and the ratings you give, a psychological and brand profile is formed, used to fit the produced content to your company’s tone and audience (see section 4.1, profiling).
  • Managing the customer relationship and communication.
  • Invoicing and processing payments.
  • Developing the services and quality monitoring: feedback, satisfaction surveys and analysis of usage events.
  • Abuse prevention and information security: e.g. limiting the usage volume of the free analysis.
  • Marketing and customer communication (e.g. newsletters).

Processing is based on:

  • performance of a contract (ordered and used services, saving of results),
  • consent (storing profiling data from the anonymous SWOT analysis, newsletter subscription),
  • the controller’s legitimate interest (maintaining the customer relationship, developing the service and information security), and
  • a legal obligation (e.g. the Accounting Act).

Users are asked not to enter into the service personal data belonging to special categories (e.g. health data, political opinions, religious beliefs) unless it is necessary for the purpose of using the service.

4.1 Profiling and automated processing

From the information and ratings you provide, the service automatically forms a psychological baseline profile and a brand profile (brand vector), as well as a learning profile based on your choices. These are used solely to target the produced marketing content to your company. This does not constitute decision-making based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). You may request more information about the logic of the profiling from the contact person in section 2.

5. Data content of the register

The register may contain:

Basic and contact information

  • Name, company name and business ID, email, phone number, address
  • User account details (WordPress account)

Data generated through use of the service

  • Company description, industry, target audience, strengths and challenges (inputs from the SWOT and strategy forms)
  • Slider ratings you give (e.g. buying-behaviour baseline, brand statements, AI experience 1–5)
  • SWOT analyses, strategy reports and marketing content produced in the service, and their edits
  • Satisfaction feedback and free-form development wishes you give
  • Usage event log (generation, version selection, editing, purchase, document download)
  • Technical usage and cost log (e.g. number and cost of AI calls; does not include produced content)

Customer and payment data

  • Ordered services, order status, quotas and credits
  • The payment intermediary’s (Stripe) customer identifier. Payment card details are not processed or stored in our own systems — they are processed by Stripe.

Consent and marketing data

  • Marketing permissions and prohibitions
  • In connection with the anonymous SWOT analysis: consent, the time of consent and IP address

Technical data

IP address, browser, operating system, time of visit and cookie data (see the separate Cookie Policy).

6. Regular sources of data

Data is obtained primarily from the data subject themselves through use of the service, forms, orders and contacts. Data may be supplemented from public company registers (e.g. the Finnish Business Information System, YTJ). Some data is generated automatically through use of the service (usage and event logs).

7. Recipients and processors of data (subcontractors)

We use trusted personal-data processors to provide the service, who process data on our behalf and according to our instructions under a data processing agreement (DPA):

ProcessorPurposeData processed
AI provider: Anthropic, PBC (Claude) and/or OpenAI, L.L.C.Producing marketing content and analysesSubmitted text: company description, SWOT/strategy inputs, content briefs
Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.)Payment processingPayment and invoicing transactions, customer identifier
smxtek OyTechnical maintenance and data storage of the serviceAll data stored in the service
Brevo/MailchimpLead and marketing communicationsEmail and communication data
Google Ireland Ltd, Meta Platforms Ireland LtdWebsite analytics and advertising (consent-based)Pseudonymised usage data

Data entered by the user, content produced in the service, edits made by the user and feedback may be transmitted to AI service providers to the extent necessary to deliver the service’s features, to assure quality or to produce the content requested by the user.

In accordance with Palvelulinkki Oy’s contractual settings, data transmitted to service providers is not used to train AI models unless the provider’s terms state otherwise. Data is not disclosed to other third parties without your consent unless required by law (e.g. authorities). If Palvelulinkki Oy merges or is sold, the data may transfer to the new controller as part of the business.

8. Transfer of personal data outside the EU or EEA

Some of the service’s processors, in particular the AI provider and possibly the payment intermediary, may process data outside the EU/EEA (e.g. the United States). Such transfers are made using the safeguards required by the GDPR: the EU Commission’s Standard Contractual Clauses (SCCs) and/or the recipient’s data processing agreement (DPA), and where applicable on the basis of the EU–US Data Privacy Framework.

9. Retention period of personal data

We retain data only for as long as the purpose of processing or the law requires:

  • Customer and invoicing data: at least 6 years (Accounting Act)
  • Reports and content produced in the service: for the duration of the account, or until you delete it / request deletion
  • Anonymous SWOT analysis lead data (without registration): 12 months, unless the user registers
  • Text sent to the AI provider: data is retained in the provider’s systems only for as long as necessary to deliver the service, in accordance with the provider’s documented retention practices (generally no more than 30 days).
  • Usage and event logs: for 6 months
  • Marketing data: until consent is withdrawn, or at most 2 years from the last contact
  • Technical/cookie data: 90–180 days or according to the cookie’s lifespan

10. Rights of the data subject

You have the right to:

  • access data concerning you,
  • request rectification of inaccurate data,
  • request erasure of data (“right to be forgotten”, under certain conditions),
  • object to or restrict processing,
  • receive the data you provided in a transferable format (data portability),
  • withdraw consent at any time (e.g. newsletter, storage of the anonymous analysis),
  • lodge a complaint with the supervisory authority (Office of the Data Protection Ombudsman, tietosuoja.fi).

Requests are addressed to the contact person in section 2. We may ask you to confirm your identity if necessary.

11. Information security

Access to personal data is limited to those persons and processors who have a basis for it in their duties. Data is stored in a protected environment; documents produced in the service (PDFs) are stored in a user-specific private directory with no public access. We use appropriate technical and organisational safeguards. The website uses cookies; you can manage them from the cookie banner (see the Cookie Policy).

12. Changes to this policy

We update this policy as the services and legislation change. The current version is always available on our website. We aim to communicate material changes separately.

A plain-language summary of how your data flows: see the “Where your data flows” page. Contact: info@palvelux.fi.


Contact
info@palvelux.fi · +358 50 353 5714
Savikkosaarentie 2, 60560 Seinäjoki, Finland
Business ID: 3531510-9

Scroll to Top