Last updated: February 2026 · Effective date: February 2026
JPu Engineering
J. Puska, yksityinen elinkeinonharjoittaja (sole proprietorship)
Muinaistie 33, 96460 Rovaniemi, Finland
Business ID: 3581353-8
Email: [email protected]
Website: https://jpu.fi
This Privacy Policy explains how JPu Engineering ("we", "us", "our") collects, uses, stores, and protects personal data when you use the Erppi ERP service ("Service"), available at https://erppi.jpu.fi and related domains.
This policy applies to:
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018). The legal grounds for processing are:
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Performance of a contract (Art. 6(1)(b)) |
| Account authentication and security | Performance of a contract; Legitimate interest (Art. 6(1)(b), (f)) |
| Billing and payments | Performance of a contract; Legal obligation (Art. 6(1)(b), (c)) |
| Customer support | Performance of a contract (Art. 6(1)(b)) |
| Service improvement and analytics | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance (accounting, tax) | Legal obligation (Art. 6(1)(c)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
When the HR module is used, the following data may be stored. This data is encrypted at rest using AES-256-GCM encryption:
Payment processing is handled by Stripe, Inc. We do not store credit card numbers or payment method details. We store:
We use personal data exclusively for:
We do not:
All Service data is stored on servers located within the European Union (Finland). The infrastructure provider may change over time; any changes will be reflected in the sub-processor list and notified in accordance with our Data Processing Agreement.
Access to production systems and data is limited to authorized personnel. We follow the principle of least privilege.
We share personal data with the following third-party service providers (sub-processors) who process data on our behalf:
| Sub-Processor | Purpose | Location | Data Shared |
|---|---|---|---|
| Cloudflare, Inc. | Network tunnel, DDoS protection, DNS | EU / USA (EU-US Data Privacy Framework) | Network traffic metadata, IP addresses |
| Stripe, Inc. | Payment processing | USA (EU-US Data Privacy Framework) | Email, name, payment data |
We require all sub-processors to:
| Data Type | Retention Period | Basis |
|---|---|---|
| Account data | Duration of account + 30 days after deletion | Contract performance |
| Customer business data (transactions, invoices, HR, etc.) | Duration of subscription + 30 days | Contract performance |
| Technical logs (IP, user agent) | 30 days | Legitimate interest (security) |
| Backup data | 90 days (rolling) | Legitimate interest (disaster recovery) |
After the retention period expires, data is permanently deleted. The Customer is responsible for exporting and retaining any data required for their own legal obligations (e.g., Finnish Accounting Act) before the deletion deadline.
As a data subject, you have the following rights:
You may request a copy of all personal data we hold about you.
You may request correction of inaccurate personal data. Most data can be corrected directly in the Service.
You may request deletion of your personal data. We will process erasure requests in accordance with GDPR Article 17. Some data may be anonymized rather than deleted where necessary to maintain system integrity.
You may request an export of your data in a structured, machine-readable format (ZIP archive).
You may request that we limit how we process your data in certain circumstances.
You may object to processing based on legitimate interest. If you object to direct marketing, we will stop immediately.
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
Send your request to: [email protected]
We will respond within 30 days. We may ask you to verify your identity before processing the request. Requests are free of charge unless manifestly unfounded or excessive.
The Erppi Service includes built-in GDPR tools for data inventory, export, and erasure that organization administrators can use directly.
When organizations use Erppi to store their own customers' and employees' data, we act as a Data Processor under GDPR. The organization is the Data Controller for that data.
In this capacity:
All primary data processing occurs within the EU/EEA. If any sub-processor operates outside the EU/EEA (e.g., Stripe), we ensure appropriate safeguards are in place, including:
The Erppi Service uses:
We do not use:
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will delete it promptly.
In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects:
We may update this Privacy Policy from time to time. We will notify users of material changes via email or in-app notification at least 30 days before the changes take effect.
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Lintulahdenkuja 4, 00530 Helsinki
Phone: +358 29 566 6700
Email: [email protected]
Website: https://tietosuoja.fi
For questions about this Privacy Policy or to exercise your data rights:
JPu Engineering
J. Puska, yksityinen elinkeinonharjoittaja (sole proprietorship)
Muinaistie 33, 96460 Rovaniemi, Finland
Business ID: 3581353-8
Email: [email protected]
Website: https://jpu.fi
© JPu Engineering. All rights reserved.