Privacy Policy
Stoa Technologies Oy
Version 2.1. Effective . Supersedes version 2.0 of 11 September 2026.
How Stoa Technologies Oy ("Stoa", "we") processes personal data as a controller under the GDPR: when you visit stoabuild.com, contact us, or use the Stoa service (the "Service") as a user of a customer's account.
1. Controller
Stoa Technologies Oy, Business ID 3633842-5, Kampinkuja 2, 00100 Helsinki, Finland. Data protection contact: eino@stoabuild.com. We are not required to appoint a data protection officer and have not appointed one.
2. Documents in the Service
Customers place project documentation in the Service. It may contain personal data: names in minutes, signatures on inspection records, contact details in correspondence. For that data the customer is the controller and Stoa its processor, acting only on the customer's instructions under the Data Processing Agreement. If your data appears in a customer's documents, contact the customer; we help it respond. This Policy covers everything else.
3. What we process and why
Users of the Service. Name, work email address, organisation, projects and role, and the data needed to sign you in and keep your session secure (identifiers, session tokens, IP address, browser and device, sign-in events). To provide and secure the Service and communicate about it, for example when a colleague invites you or assigns you a task. Basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in operating and securing the Service (Article 6(1)(f)).
Usage analytics. Pages viewed, features used, actions taken, the minutes you are active in the Service, and browser, device and approximate location from your IP address. After sign-in these are linked to your user identifier, name and email address so that we can understand how each customer's team uses the product. Never the content of documents, questions or answers. Measured without cookies: nothing is stored on your device for it, and you may object at any time (Section 8). Cookies that recognise your browser across visits, and session recordings that replay how a screen was used so that we can fix problems, are enabled only after you accept them in the cookie banner (Section 6). Basis: our legitimate interest in improving the Service (Article 6(1)(f)); consent for the cookies and recordings (Article 6(1)(a)).
Business contacts. Name, email address, telephone number, organisation, position and the content of your message when you contact us or we work with you. Basis: our legitimate interest in conducting our business (Article 6(1)(f)) and pre-contractual steps (Article 6(1)(b)). Marketing email goes to business contacts on the basis of legitimate interest, and to individuals only with consent; opt out at any time via the link in each message.
Security and legal obligations. Logs and records to detect and investigate security incidents, to handle legal claims and to meet statutory obligations. Basis: Article 6(1)(f) and 6(1)(c).
We make no automated decisions with legal or similar effects and do not profile individuals.
4. Recipients and transfers
The following providers process personal data on our instructions under data processing agreements. The same list, with legal entities, certifications and transfer mechanisms, is Annex IV of the Data Processing Agreement.
- Clerk
- Authentication, user identity and enterprise single sign-on. United States (primary). Clerk's DPA permits processing wherever Clerk or its sub-processors maintain facilities; its sub-processor list is published in its trust centre.
- Supabase
- Database and storage. EU, AWS eu-north-1 (Stockholm, Sweden).
- PostHog
- Product analytics for Stoa's own purposes: without cookies by default; cookies and session recordings only after consent. EU, PostHog Cloud EU (Frankfurt, Germany).
- Cloudflare
- Delivers and protects the website and the Service. Global edge network; a request is handled at the data centre nearest the user.
- Google Workspace
- Email and documents for our own business correspondence. EU data region.
We also disclose personal data where the law requires, to professional advisers under confidentiality, and to a successor in a merger or acquisition. We do not sell personal data.
Outside the EU/EEA. Two providers process in the United States: the identity platform (Clerk, Inc.) hosts authentication data there, and the edge network (Cloudflare, Inc.) handles requests at the data centre nearest to you. Our analytics provider (PostHog, Inc.) keeps event data in the EU but is a United States company. Each relies on EU-US Data Privacy Framework certification and on the European Commission's standard contractual clauses. A copy of the safeguards is available on request.
5. Retention
- User accounts: for the customer's agreement with us, then deleted within 30 days of its end under the Data Processing Agreement. A customer can deactivate your account at any time.
- Security logs: 90 days for application logs; authentication events for the period the identity platform retains them; AI activity records for 12 months unless a customer has agreed a different period.
- Usage analytics: while the account exists, then deleted or anonymised.
- Business contacts: while the relationship is active and two years after our last contact.
- Contracts and invoices: as required by the Finnish Accounting Act and limitation periods, six to ten years.
- Backups: expire within 30 days of deletion from production.
6. Cookies
- Strictly necessary: cookies set by our identity platform to keep you signed in and protect the sign-in flow, a setting that remembers your language, and a local storage entry that remembers your cookie choice.
- Analytics cookies and session recordings, only with your consent: cookies and local storage entries set by our analytics provider to recognise your browser across visits, and recordings of how you use the Service. Set only after you accept them in the cookie banner. If you decline, nothing is set and no recording is made; use is still measured without cookies as described in Section 3.
We use no advertising or marketing cookies. Change your choice at any time through "Cookie settings" in the footer of every page, or by deleting site data in your browser. The Service works the same either way.
7. Security
Personal data is protected by the measures in Annex III of the Data Processing Agreement: encryption in transit and at rest, multi-factor authentication for all of our own accounts, least-privilege access for named personnel bound by confidentiality, tested backups, logging, and a documented incident process with notification to affected customers within 48 hours.
8. Your rights
You may access the personal data we hold about you, have it corrected or erased, restrict or object to its processing, receive the data you provided in a portable format, and withdraw consent at any time. You may object at any time to processing based on our legitimate interests, including marketing and analytics. Email eino@stoabuild.com; we respond within one month and may ask you to verify your identity. Requests concerning a customer's documents are forwarded to that customer. You may also complain to the Office of the Data Protection Ombudsman (tietosuoja.fi).
9. Changes
Each version of this Policy carries a version number and effective date, and the change log records what changed. Material changes are announced to users of the Service at least thirty (30) days before they take effect. The Service is not intended for anyone under 18.
Contact
Stoa Technologies Oy (Business ID 3633842-5)
Data protection contact
Kampinkuja 2
00100 Helsinki
Finland
Email: eino@stoabuild.com