Privacy Policy

Updated: 4 September 2026

Created 15 December 2025

Your privacy and the protection of your personal data matter to us. This policy explains how HavuHR Oy processes personal data on our website, in sales and customer communication, in the HavuHR service, and in the service's optional Microsoft Teams, Slack and Netvisor integrations. We process personal data in accordance with the EU General Data Protection Regulation (GDPR, EU 2016/679), other applicable legislation and the agreements made with our customers.

1. Controller and contact details

HavuHR Oy, Business ID 3149813-9

Address: Lapinlahdenkatu 16, 00180 Helsinki, Finland

Person responsible for data protection: Susanna Vilkka

Email: susanna.vilkka@havuhr.fi

Phone: +358 40 809 6591

2. Our role: controller or processor?

HavuHR Oy acts as the controller for its own website, sales, marketing and customer relationship data. This policy primarily describes that processing.

When HavuHR processes HR data of a customer organisation's employees and other individuals in the HavuHR service on the customer's behalf, the customer organisation is the controller and HavuHR is the processor. In a service delivered through a partner, the end customer is the controller, the partner is the processor and HavuHR is a sub-processor. The exact roles, processing instructions and responsibilities are defined in the service agreement and data processing agreement (DPA) made with the customer.

If you are an employee of a customer organisation, please direct requests concerning your personal data primarily to your employer, who is the controller of your data.

3. What personal data do we process and why?

Website and contact requests

We process your name, contact details, company, role and the content of your message when you contact us through a form or by email. The data is used for communication, customer service and service development.

Legal basis: preparation and performance of a contract, and legitimate interest (communication and customer relationship management).

Retention period: two (2) years from the last contact, unless the contact leads to a customer relationship, in which case the data is retained according to the retention periods for customer data.

Customer relationship management and sales

We process the names, contact details (email, phone, address) and contract, order, purchase history and communication data of our customers and their contact persons for managing the customer relationship, developing the product and acquiring customers.

Legal basis: performance of a contract and legitimate interest (managing and developing the customer relationship).

Retention period: for the duration of the customer relationship and, after it ends, for as long as necessary to handle rights and obligations arising from the contract, for example possible complaints or invoicing-related claims. Data that belongs to accounting records, such as invoices and contracts, is retained for the period required by the Finnish Accounting Act.

Communication and customer service

We process emails, Microsoft 365 messages and attachments for the company's internal and external communication and for customer service.

Legal basis: performance of a contract and legitimate interest (effective communication).

Retention period: for as long as the communication is needed for its purpose. We delete messages when they are no longer needed, and at the latest when the customer relationship or other basis for processing has ended. Messages that belong to contract or accounting records are retained according to the retention periods for customer data.

Marketing

We process contact details for marketing communication, newsletters and event invitations. You can withdraw your consent or opt out of direct marketing at any time by notifying us or by using the unsubscribe link in our messages.

Legal basis: consent or legitimate interest (marketing to existing customers).

Retention period: data based on consent is retained until you withdraw your consent. Marketing based on the customer relationship continues for the duration of the relationship and for a reasonable time after it ends, unless you opt out earlier. Information about a marketing opt-out is retained indefinitely so that we can honour it.

HavuHR service

We process service users' account, work and contact details, access rights and events related to the use of the service, as well as the HR data the customer stores in HavuHR. For HR data stored by the customer, HavuHR acts as a processor as described in section 2, and the details of the processing are described in the DPA made with the customer.

Integrations (Microsoft Teams, Slack, Netvisor)

When a customer enables an integration, we process only the identifiers, settings, messages, synchronised data, logs and protected credentials necessary for that function. Integration-specific processing is described in section 5.

4. Legal bases and sources of data

Depending on the situation, processing is based on a contract or its preparation, the customer's documented instructions (when we act as a processor), a legal obligation, consent, or HavuHR's legitimate interest in protecting, maintaining and developing the service.

We obtain personal data mainly from you (for example contact forms and emails), from data generated during the customer relationship and cooperation, and from data the customer stores in the HavuHR service. We may also use public sources, such as company websites.

The customer is responsible for having the right to process and transfer personnel data to the integrations it chooses and for informing its personnel appropriately.

5. Integration-specific processing

Microsoft Teams

  • The Helmi assistant works only in a personal Teams chat. No company data is disclosed from channel or group conversations.
  • We process the Microsoft Entra tenant identifier, the user's permanent Entra identifier, basic sign-in information and a protected personal reply reference. Users are not identified by their Teams display name.
  • Only openid, profile and email data is requested when connecting. The integration does not request Microsoft Graph permissions and does not store Microsoft access or refresh tokens.
  • The technical event receipt does not contain the question, the answer, attachments or the raw Teams event. Helmi questions and answers are processed in HavuHR's protected Helmi conversation storage.
  • Disconnecting removes the active Microsoft tenant link and employees' personal reply references.

Slack

  • HavuHR links an active employee to a Slack user based on their work email address.
  • From Slack, we may process personal messages and commands related to Helmi questions, open tasks, task completion or a supported own absence request.
  • HavuHR may send task and summary messages, signature links and reminders, Helmi replies and test messages. The one-time signature verification code is never sent to Slack.
  • The app uses the scopes chat:write, im:write, im:history, users:read and users:read.email, and receives message.im events.
  • The bot token is stored encrypted. The technical event receipt does not copy message text or files, and receipts older than seven days are deleted. Technical metadata of a completed absence draft is deleted after 30 days at the latest.
  • Disconnecting Slack in HavuHR removes the installation and operating state, employee links, event receipts, task message metadata and unfinished absence drafts.

Netvisor

  • The main data flow runs from HavuHR to Netvisor. Depending on the selected settings, the transferred data may include the employee's basic details, personal identity code or foreign identifier, contact and address details, employment details, workplace, language and region details, bank details, closed working time rows and approved absences.
  • HavuHR reads from Netvisor the employee, employment, pay type and working day data needed for safe synchronisation.
  • The description of a working time row may contain the work type name and the note on the time entry. The description of an absence row contains the absence type name, not the comments, messages or cancellation reasons of the absence request.
  • The customer's Customer key and selected personal override values are stored encrypted. At most the latest 1,000 rows of synchronisation logs are kept, and rows older than 90 days are not retained.
  • HavuHR modifies or deletes only Netvisor working time rows identified as managed by the integration. Removing an employee from HavuHR does not automatically delete Netvisor payroll or working time history.

6. Recipients and international transfers

Data is processed by HavuHR's authorised personnel and by the service providers needed to deliver the service (processors and sub-processors). These include:

  • Google Cloud Platform (Google LLC): the main infrastructure, database and uploaded files of the HavuHR service. The Helmi AI assistant's answers are also generated with Anthropic's Claude language model, run in the Google Cloud Platform environment. Processing location: Europe (Hamina, Finland).
  • Microsoft Azure (Microsoft Corporation): the service's automatic email notifications. Processing location: Europe (North Europe).
  • HubSpot (HubSpot, Inc.): customer relationship management, i.e. processing of customer, sales and marketing data.
  • Microsoft 365 (Microsoft Corporation): HavuHR's own email, Teams communication and documents. Processing location: EU.
  • Calendly (Calendly LLC): website appointment booking. Processes the name, email and selected time given when booking.
  • Other service providers needed to deliver the service, such as IT services and the accounting firm, each within their own tasks.

When an integration is used, data is transmitted to the Microsoft, Slack or Netvisor service chosen by the customer. These act as recipients selected by the customer, and their own processing is governed by the terms and privacy practices of the respective provider.

Data may be disclosed to authorities to fulfil legal obligations. We do not disclose personal data to third parties for commercial purposes.

We process personal data of the HavuHR service within the EU/EEA. Some of the service providers we use, such as HubSpot and Calendly, are US companies, so data may also be processed outside the EU/EEA. In these cases we make sure the transfer has a legal basis: either the provider is committed to the EU–US Data Privacy Framework, or we have agreed on standard contractual clauses approved by the European Commission.

An up-to-date list of sub-processors is available on request or on our website.

7. Data security

We protect data with appropriate technical and organisational measures. These include encrypted connections, data encryption and pseudonymisation where applicable, multi-factor authentication (MFA), role-based access restrictions, customer- and user-level isolation, secure secrets management, verification of signed events, logging and anomaly monitoring, and regular backups with recovery testing. Our personnel are bound by confidentiality obligations. Integrations use only the permissions required for their function.

8. Retention and deletion

We retain personal data only for as long as necessary to provide the service, fulfil contractual obligations, ensure security or comply with the law. Retention periods by data category are described in section 3.

Personal data processed in the HavuHR service on the customer's behalf is deleted or anonymised in accordance with the data processing agreement, at the latest within 90 days of the end of the agreement.

Disconnecting an integration stops future processing and deletes the local connection and link data described in section 5. Data previously transferred to Microsoft, Slack or Netvisor may remain in that service according to the customer's settings, agreement and statutory retention periods. The customer is responsible for deleting it in that service.

9. Your rights as a data subject

Under applicable law, you have the following rights:

  • Right of access: to know what data about you has been stored.
  • Right to rectification: to request correction of inaccurate data.
  • Right to erasure: to request deletion of your data in certain situations ("right to be forgotten").
  • Right to restriction of processing: to request that the processing of your data be restricted.
  • Right to object: to object to processing, in particular direct marketing.
  • Right to data portability: to receive your data in a machine-readable format and transfer it to another controller.
  • Withdrawal of consent: to withdraw your consent at any time, if processing is based on consent.

An employee of a customer organisation should primarily direct requests to their employer. Requests concerning HavuHR's own registers can be sent to the person responsible for data protection, Susanna Vilkka, at susanna.vilkka@havuhr.fi. You also have the right to lodge a complaint with a supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman, www.tietosuoja.fi.

10. Cookies

We use necessary cookies on our website to ensure it functions properly.

The website uses the Calendly booking service, which may set its own cookies in connection with the booking function. With your consent, we may also use analytics cookies to develop the site. You can manage your cookie choices in the site's cookie settings.

11. Data breaches

If we detect a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and, where required, the supervisory authority without undue delay. When we act as a processor, we notify the customer acting as controller of incidents affecting its data without undue delay.

12. Changes to this policy

We update this policy when the service, integrations or processing practices change. The current version and the date of the last update are always available on this page. We will notify separately of significant changes.

HavuHR Oy | 3149813-9