Privacy policy / Tietosuojaseloste
Last updated: 26 May 2026
Data controller / Rekisterinpitäjä
Easy Host Oy (Y-tunnus 3288005-7)
c/o Sörnäistenkatu 19 B 21, 00580 Helsinki, Finland
Contact: Joona Taskinen · joona@easy-host.fi · +358 50 4633 591
Who this applies to
Anyone with an account in this portal: Easy Host Oy employees, Easy Host's payroll manager, and contracted partners (cleaning companies, contractors).
What we collect, and why
- Identity: name, work email, Finnish personal identity code where it appears on the employment contract, Y-tunnus for partners. Required to identify you and to fulfil legal obligations (Vuosilomalaki, payroll, tax reporting).
- Employment data (employees): hire date, daily hour target, salary, fringe benefits, bonus eligibility, leave balances, sick leave with thresholds per Sairausvakuutuslaki. Required to compute work-time balance and statutory entitlements.
- Contract data (partners): hourly rate, bank account, extra-work logs, expense claims with receipts, unavailability. Required to process payments and plan scheduling.
- Authentication data: Google account identity (email and basic profile) via Sign in with Google, or magic-link login via email. We use this only to verify it's you and to maintain your session. We do not access your Google Drive, Gmail, or other Google data.
- Operational data: hours logged, leave requests, expense claims, admin actions audit log. Required for internal record-keeping and statutory documentation.
- Cleaning operations: cleaning jobs assigned to you, start/end timestamps, photos uploaded after a job, issues reported, lost-and-found items logged. Required to plan and verify cleaning work for our apartment owners.
- Photos: images uploaded during cleaning End-flow or issue logging. Stored on Cloudflare R2 (EU region). Photos may incidentally contain personal items (e.g. forgotten belongings). Photos are retained as long as the related cleaning record exists; lost-and-found photos for 14 days from the found date unless an extension is set.
- Push notification subscriptions: when you opt in, your browser's push endpoint URL + cryptographic keys are stored so we can send reminders (assignment, photo reminder, reassignment). You can revoke at any time from your browser's site settings.
- Slack identifier (optional): if you provide your Slack user ID, our bot sends operational DMs (photo reminders, reassignment notifications). Setting it is optional and only used for outbound messages.
- Documents: work contracts and amendments stored on your record, accessible only to you and authorised admins.
Legal basis
- Performance of a contract (your employment or service agreement)
- Compliance with a legal obligation (employment law, tax law, GDPR)
- Legitimate interest (operational reporting, scheduling, fraud prevention)
- Consent (push notifications, optional Slack DMs)
Where data is stored
On Railway's managed PostgreSQL service (EU region). Photos and uploaded receipts on Cloudflare R2 (EU region). All connections use TLS. Daily backups. We do not transfer your data outside the EU/EEA without an adequate legal basis.
External processors
- Railway (USA — Standard Contractual Clauses) — application hosting and managed PostgreSQL.
- Cloudflare R2 (EU — Standard Contractual Clauses) — photo and receipt storage.
- Resend (USA — SCC) — transactional email delivery (magic-link login, welcome emails, delegated-maintenance messages).
- Google (Sign-in only) — OAuth authentication. We receive your name + email; we do not access your Google Drive, Gmail, or other Google data.
- Slack (USA — SCC) — operational DMs to opted-in employees / partners (photo reminders, reassignment notifications).
- Hostaway (USA — SCC) — short-term rental management platform. We pull reservation data (guest name, arrival/departure dates, host notes) to create cleaning jobs. We do not push your personal data to Hostaway.
- Anthropic (USA — SCC) — when a Hostaway host note exceeds 80 characters, we send the note text to Anthropic's Claude API to distill it for the cleaner. The text is processed transiently and not used to train Anthropic models.
- Palkka-apu (Finland) — our payroll bureau. We export pay-period data (your hours and approved expense rows) once a month and send to them by email.
Who can see your data
- You — your own page (/me or /partner): hours, leave, balances, documents, jobs assigned to you, photos you uploaded.
- Easy Host admins — full visibility for legitimate HR / contractor management purposes.
- The payroll manager — read-only access to information needed for payroll, including hours and balances of all employees.
How long we keep it
- Active accounts: data retained for the duration of your engagement.
- Payroll records: retained for the period required by Finnish employment and accounting law (typically 10 years).
- Cleaning photos: retained as long as the related cleaning record exists (for audit / dispute resolution with apartment owners).
- Lost-and-found photos: 14 days from the found date by default; extended manually if a guest is in contact about pickup.
- Push subscriptions: deleted when you revoke in browser settings, or after repeated delivery failures.
- After your engagement ends: account is deactivated; records required for legal compliance are retained for the statutory period; non-required personal data is anonymised on request (see below).
Your rights under GDPR
You have the following rights with respect to your personal data:
- Right of access (Article 15): while logged in you can download your own data at any time from /me/data-export as a JSON file. The download includes your profile, time entries, leave requests, jobs assigned to you, photo URLs, issues you logged, lost-and-found items you logged, and partner extras/expenses if applicable.
- Right to rectification (Article 16): edit your own data inline, or email joona@easy-host.fi if a field isn't self-editable.
- Right to erasure (Article 17): email joona@easy-host.fi. Note that records required for statutory payroll/tax retention (typically 10 years) cannot be erased before the retention period ends; we will anonymise where possible and delete the rest.
- Right to restrict or object to processing (Articles 18 + 21): email us.
- Right to data portability (Article 20): use the data-export endpoint above; the JSON is machine-readable and can be re-imported elsewhere.
- Right to withdraw consent: turn off push notifications in browser settings; remove your Slack user ID via your admin; revoke Google login by disconnecting our app in your Google account settings.
You also have the right to lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) at tietosuoja.fi.
Cookies
We use a single session cookie set by our authentication provider (Better Auth) to keep you logged in. No third-party tracking, advertising, or analytics cookies.
Changes
If we change this policy materially, we will notify active users by email or via an in-app banner. The current version is always at this URL with the "Last updated" date at the top.
This policy reflects the current data flows of the Easy Host ERP application. Review with a Finnish-law privacy specialist before relying on it for SaaS customers outside Easy Host.