Privacy Policy
This is a courtesy English translation. The Finnish version is the legally binding one.
In this policy we explain clearly what personal data Ritu processes, for what purposes, for how long, and what your rights are. We process data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.
1. Data controller
Data controller: Tuittupaa Productions Oy, business ID 3640226-3, registered office Helsinki, Finland.
Contact for data protection matters: tuulia.virhia@gmail.com.
Data protection officer (if appointed): not appointed.
Roles in brief: We act as the data controller for account management, email sign-in, security, and the technical operation of the service. When a family admin adds a loved one's and family members' data to the service, the admin acts as the data controller and we act as the data processor — this is described in the Data Processing Agreement (DPA).
2. What data we process
| Data category | Examples |
|---|---|
| Account data | Admin's email address, sign-in and session data |
| Security data | Hashes of the family PIN, admin PIN and invite codes (not in plaintext), sign-in attempt data |
| Family content | Names, dates of birth, family relationships, events, notes and photos of the loved one and family members |
| Technical data | Device data, IP address, log data for delivering the service and for security |
We do not collect more data than is necessary to provide the service, and we do not use data for advertising or profiling.
3. Purposes and legal basis for processing
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service and maintaining the account | Performance of a contract (6(1)(b)) |
| Sign-in and security (e.g. rate limiting, encryption) | Legitimate interest and legal obligation (6(1)(f), 6(1)(c)) |
| Customer support and communication | Contract and legitimate interest (6(1)(b), 6(1)(f)) |
| Processing family members' and the loved one's content data | Admin's consent/choice; we act as the processor on the admin's behalf |
| Complying with legal obligations (e.g. accounting) | Legal obligation (6(1)(c)) |
4. Health-related data
The service is intended to support a person with a memory illness, so content stored in the service may reveal health-related data (a special category of personal data under GDPR Art. 9). Adding such data is based on the family admin's decision and explicit consent (9(2)(a)). The admin is responsible for ensuring that they have the right to add data concerning another person.
5. Where the data comes from
We obtain the data primarily from you: when you register, create a family, and add content to the service. Technical data is generated automatically in connection with the use of the service.
6. Disclosures and processors
We do not sell personal data, nor do we disclose it to outside parties for marketing purposes. We use trusted service providers (processors) who process data on our behalf in accordance with a contract and data protection obligations:
| Processor | Task | Location |
|---|---|---|
| Supabase | Database, authentication and image storage | EU region |
| Vercel | Application delivery and technical logs | EU / global CDN |
We may disclose data to authorities if required by law.
7. Retention period
We retain personal data for as long as the account and family are active. When you delete content, clear the family's data, or leave the family, the data is deleted or anonymised within a reasonable time, unless the law requires longer retention (e.g. accounting). Backups are removed according to their rotation cycle.
8. Transfers outside the EU
Data is stored and processed primarily within the EU/EEA area. If a processor processes data outside the EEA (e.g. for technical logs), we ensure appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCC).
9. Data security
We protect data with technical and organisational measures, including:
- data on servers within the EU region;
- encrypted data transfer (TLS) and encryption of data at rest;
- per-family isolation using database row-level security rules (RLS);
- protection of PIN and sign-in codes with strong hashing (bcrypt);
- rate limiting of sign-in attempts and access control.
10. Your rights
You have the following rights under the GDPR:
- Right of access — to find out what data is being processed about you.
- Rectification — to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — to request the deletion of your data.
- Restriction and objection — to restrict or object to processing in certain situations.
- Right to data portability — to receive the data you have provided in a machine-readable format.
- Withdrawal of consent — where processing is based on consent, you can withdraw it at any time.
Many actions (editing and deleting data) can be done directly in the app. You can also contact us at tuulia.virhia@gmail.com. We respond to requests without undue delay, at the latest within one month.
11. Cookies and local storage
The service is a progressive web application that stores technically necessary data in your browser (e.g. session and local cache for offline use). These are essential for the service to function, and we do not use tracking or advertising cookies. You can clear local data from your browser settings or by leaving the family on the device.
12. Right to lodge a complaint
If you consider that we process your data in breach of data protection legislation, you can lodge a complaint with the supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi). We hope, however, that you will contact us first.
13. Changes to this policy
We may update this policy as the service or legislation changes. The up-to-date version is always on this page, and we will notify you of material changes in the service or by email.
14. Contact details
Data controller: Tuittupaa Productions Oy (business ID 3640226-3), registered office Helsinki, Finland
Email: tuulia.virhia@gmail.com