PROCESSING OF PERSONAL DATA

Last updated: 1 August 2025

1. Purpose of the Agreement

1.1.

The user of the Bisse.fi service (the “Customer”) and RNN Group Oy, the owner of Bisse.fi and the service provider (Business ID: 3091611-6; registered address: Hitsaajankatu 6, 00810 Helsinki, Finland) (“RNN”), jointly referred to as the “Parties”, have entered into an agreement in accordance with the Terms of Service (the “Agreement”). Under the Agreement, RNN provides the Customer with invoicing services and other additional services described in the Terms of Service.

1.2.

When providing the Service, RNN processes personal data (the “Data”) on behalf of the Customer. For the purposes of the EU General Data Protection Regulation (GDPR), the Customer is the Data Controller and RNN is the Data Processor.

1.3.

When processing Personal Data, the Parties agree to follow best practices and comply with the GDPR, the Finnish Data Protection Act (1050/2018, enacted on 5 December 2018), and all other applicable data protection legislation in force (collectively, “Data Protection Legislation”).

1.4.

The Customer, in its capacity as Data Controller, warrants that it has the right to use the Personal Data and provide it to RNN for processing in accordance with the Agreement.

1.5.

The Data is collected primarily from Customers. Personal Data may also be collected from and updated using information obtained from public authorities where necessary to provide the Service and/or additional services.

2. RNN’s Obligations

2.1.

The Data Processor must keep Personal Data confidential and process it only for the purposes of providing and developing the Service and additional services, in accordance with Data Protection Legislation.

2.2.

The Data Processor may process Personal Data in the course of its operations for the duration of the Agreement. Where required by law, Personal Data may be retained beyond the term of the Agreement.

2.3.

In connection with the Service, the Data Processor processes the Personal Data necessary to provide the Service, including but not limited to:

  • Name
  • Contact details (telephone number, address, and email address)
  • Age
  • Occupation
  • Personal identity code
  • Tax information
  • Payroll-related information
  • Customer data (information about Clients) and assignment-related information
  • Necessary identification and technical usage data, such as cookies and log data
  • Nationality and work permit information, where necessary
  • A copy of an identity document, where necessary

2.4.

Personal Data may be processed for customer relationship management, service provision, analysis, and development.

2.5.

The Data Processor must ensure that all persons who process Personal Data perform their duties in confidence.

2.6.

By entering into the Agreement, the Customer consents to the Data Processor engaging other personal data processors (sub-processors), provided that the Data Processor ensures compliance with the same data protection obligations.

2.7.

The Data Processor may not transfer Personal Data to a third party outside the EU or EEA without the Customer’s prior written consent, except in the circumstances described in section 2.7.1 below.

2.7.1.

By entering into the service agreement, the Customer expressly consents to Personal Data being processed in connection with the Service by the following companies operating in the United States. By giving this consent, the Customer acknowledges that such transfers may involve certain risks due to the possible absence of safeguards equivalent to those provided in the EU:

  • Google LLC (services used: Analytics, Google Workspace, and YouTube): Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA: Google Privacy
  • GCloud (services used: App Engine, Kubernetes Engine, Storage, and Database): Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA: Google Cloud Privacy Notice. Data is stored in Hamina, Finland, and Belgium.

2.8.

At the Customer’s request, RNN will provide a copy of the Customer’s stored Personal Data without undue delay.

2.9.

The Data Processor must ensure that Personal Data is processed securely. All Personal Data breaches must be reported to the relevant authority and, where necessary, communicated to the affected data subjects.

2.10.

The Data Processor may not sell the Customer’s Personal Data to third parties.

2.11.

The RNN Group’s maximum liability for damages under the Agreement is limited to the annual Service Fee charged to the Customer for the Service. RNN is not liable for any indirect loss or damage incurred by the Customer, including loss of profit, loss of business, or any similar loss.

3. Term

3.1.

The terms described here take effect when the Customer registers as a Service User of the Bisse.fi service provided by RNN.

3.2.

RNN has the right to update these terms for the processing of Personal Data. The Customer must be notified before any changes take effect.

3.3.

Personal Data is retained for as long as necessary to fulfil the purposes for which it was collected, but no longer than 10 years from the Customer’s most recent use of the Service, unless the Customer has withdrawn consent to the processing of the Data.

Last updated: 1 August 2025

RNN Group Oy