Legal
Privacy Policy
Last updated 2026-07-26. This policy describes how perukirja.io collects, uses, and protects your personal data in compliance with GDPR and Finnish data protection law.
1. Privacy at a Glance
We believe legal tools should be transparent. Here is the summary of how we handle your data:
• Your Data is Yours: We use your account and estate data to provide the service, generate probate documents, process payments, and support your use of the service. We do not sell personal data.
• Security First: All data, including personal identity codes, is encrypted at rest by our database and storage infrastructure using AES-256.
• AI Privacy: Our AI Assistant uses Google Vertex AI. Your private estate data is processed to provide the assistant service but is not used to train or fine-tune AI models without permission.
• Infrastructure: Application hosting is configured in the AWS Frankfurt region. Some service providers may process limited data outside the EEA as described below.
• Control: Settings includes self-service Export your data and Delete account controls. You can download a JSON copy of application-held account and case records or request account deletion. Legal retention duties, provider restore history, and service-provider records may limit immediate or complete erasure.
2. Data Controller
Regulus Holding Oy
Business ID: 3424114-4
Konkelonkatu 24
33870 Tampere, Finland
Email: tuki@perukirja.io
Phone: +358 50 593 4915
For privacy questions or to exercise your rights, contact tuki@perukirja.io.
3. What Data We Collect & Why
We process the following categories of data to provide and operate the service:
3.1 Account & Authentication
- Name, email address, preferred language, and profile image
- Password hash or linked OAuth account identifiers
- IP address, user agent, sessions, and security metadata
- Terms acceptance, marketing consent, and email preferences
3.2 Estate & Probate Data (Sensitive)
- Deceased person's details, including name, personal identity code, and date of death
- Estate shareholder and heir details, including names, personal identity codes, and contact information
- Assets, debts, spouse information, form responses, notes, document checks, and workflow progress
- Other information you enter for preparing the estate inventory deed
3.3 AI Assistant Interactions
- User chat prompts
- Assistant replies
- Metadata (model identifier, token usage)
3.4 Usage & Analytics
- Feature usage, page views, and workflow events
- Technical, security, rate-limit, device, browser, and attribution metadata
- Cookie and advertising consent choices
- Page-view, article, feature, and attribution events sent with in-memory browser persistence before a cookie choice; no tracking cookies or identifiers are stored before your choice
- Consent-based registration source, a short label recording which of our own article or calculator pages you arrived from when you registered; it is collected from the src parameter of the registration link through a short-lived, single-use first-party signup_src cookie (valid for about 30 minutes) only if you have accepted analytics cookies, and is stored with your account
- Operational events sent from the server, including registration, email, payment, workflow, and account-deletion events
3.5 Payments & Communications
- Payment status, transaction identifiers, payment method, amounts, VAT, invoice and refund details
- Payer name and email address, service description, and payment callback records
- Transactional email delivery logs and communication preferences
4. Purposes and Legal Bases
We process personal data for the following purposes:
- Account creation, login, and security controls
Legal basis: Contract performance; legitimate interests (security and fraud prevention). - Delivering the probate workflow, storing case data, and providing self-service export and deletion controls
Legal basis: Contract performance. - Sending transactional and service emails, including verification, password reset, deadline, payment, and deletion messages. We also send reminders if an estate inventory is left unstarted or unfinished: their timing is based on your registration date, the case creation date, and when the case was last edited. The sequence is bounded (at most three messages, ending in a final message) and does not market the paid service. You can stop the reminders from a link in the message without signing in, which also covers reminders about the statutory deadline. In the settings each reminder type has its own toggle. Payment receipts and security notifications cannot be switched off, as they are records of a sale and account-security notices.
Legal basis: Contract performance; legitimate interests (account security and service communications, and supporting completion of an estate inventory you started). These reminders are service communications, not direct marketing; we do not send electronic direct marketing without your consent. - AI assistant functionality and chat history
Legal basis: Contract performance. - Product analytics, advertising measurement, abuse prevention, rate limiting, and operational monitoring
Legal basis: Before your cookie choice, we process page-view, feature, and attribution events (in-memory browser persistence, with no tracking cookies or identifiers) and server-side operational, security, and service-reliability events based on legitimate interests. Persistent browser analytics and advertising are based on your consent where the law requires it. The registration source stored with your account is collected only with your consent (analytics cookies); without consent no source is recorded. We use it solely to improve our own content, do not share it with third parties or send it to external analytics or advertising platforms, and delete it when your account is deleted; if you withdraw analytics consent while signed in, we erase it then as well. - Processing payments, refunds, accounting records, and legal requests
Legal basis: Contract performance; legal obligation; legitimate interests in financial administration and legal compliance.
5. Data Sources
- Directly from you through registration, settings, forms, chats, and support interactions.
- From other users who enter information about an estate, deceased person, heir, shareholder, or spouse.
- Automatically from your browser, device, and use of the service.
- From authentication, payment, email, analytics, consent-management, and advertising providers when they deliver their services.
6. Service Providers and Recipients
We use the following service providers and recipients to operate the service:
- Amazon Web Services (AWS): Application hosting, file storage, and content delivery (EU Frankfurt)
- Neon: PostgreSQL database hosting (AWS Europe Central 1, Frankfurt)
- Google Cloud (Vertex AI): AI processing (EU region)
- PostHog: Product and operational analytics through the configured EU endpoint; requests are routed through our own first-party proxy address (AWS CloudFront) to PostHog's EU service; a CookieYes decision controls browser persistence and subsequent capture, while limited pre-decision in-memory events and server-side events may also be processed
- Resend: Transactional email delivery
- Paytrail: Payment processing, refunds, and payment-status callbacks
- Google OAuth: Optional Google account sign-in
- CookieYes: Cookie and consent management
- Dealfront (Leadfeeder): Identification of visiting companies on our partner page only (perukirja.io/kumppanit); based on your consent to advertising cookies, and not used on any other page or anywhere inside the signed-in service
- Google Ads: Consent-controlled conversion measurement and remarketing; with your advertising consent, conversion events may include your email address in hashed form (enhanced conversions)
Google Cloud's Vertex AI terms state that customer data is not used to train or fine-tune AI models without the customer's prior permission or instruction.
7. International Transfers
Application hosting is configured in Frankfurt, Germany. AI processing is configured in the EU region. Email, authentication, database, consent-management, advertising, and provider subprocessor operations may involve processing outside the EEA. Where processing takes place outside the EEA, transfers are based on European Commission adequacy decisions (including the EU-US Data Privacy Framework) or the Commission's Standard Contractual Clauses. You can obtain a copy of the applicable safeguards by contacting us.
8. Data Retention
We don't keep your data longer than necessary:
- Active Accounts: Account, estate, chat, preference, and communication-log data is generally kept while your account remains active and as needed to provide the service.
- Case Deletion: Cases with no payments can be deleted from the case dashboard. Once a payment — including a pending or failed payment attempt — is linked to a case, the case can no longer be deleted separately because its payment record must remain consistent; you can use Delete account in Settings or contact support.
- Account Deletion: You request deletion through the self-service Delete account control in Settings and confirm it through a link sent to your email. When confirmed, the active user account, authentication records, cases, estate data, chats, preferences, and application email logs are deleted. Short-lived security rate-limit records, which may contain an IP address or pseudonymous account identifier, are deleted after at most seven days, and trusted-device records expire automatically within at most 30 days. De-identified security audit events may remain after account links are removed; if support deletes your account for you, the audit record of that action may retain your name and email address.
- Payment and Accounting Records: Records required by Finnish bookkeeping and payment obligations are retained for at least six years after the end of the relevant financial year. They may include payer name and email, transaction identifiers, amount, VAT, dates, refund information, and a service description that includes the deceased person's name. Where collected with your advertising consent, the payment record may also include an advertising click identifier (such as gclid) and the payment provider's callback data. Account and case foreign-key links are removed when the account is deleted.
- Provider Restore History: Deleted database content may remain temporarily in encrypted provider backup or point-in-time restore history until the configured recovery window expires. It is retained for disaster recovery and is not used as active application data.
- Service-Provider Records: Payment, email, consent, advertising, security, and analytics providers may retain records under their own lawful retention periods. Self-service account deletion does not automatically erase every provider-held record; contact us to exercise rights concerning those records.
9. Data Subject Rights
Under GDPR, you have the right to:
- Access your personal data
- Request rectification of inaccurate data
- Request erasure ('Right to be Forgotten')
- Request data portability
- Object to or restrict processing
- Withdraw your consent at any time (via the cookie settings or by contacting us), without affecting the lawfulness of processing carried out before withdrawal
The self-service Export your data control in Settings downloads a JSON copy of account and case records held in the application database. Delete account starts an email-confirmed account-deletion flow. The export excludes password hashes, OAuth and session tokens, linked sign-in provider identifiers, session technical metadata (such as IP addresses), passkey credential secrets, security audit and rate-limit records, account ban status and admin notes, and records held only by service providers; you can request any of these from us by email. For a broader access request, rectification, restriction, objection, portability request, or deletion request concerning service-provider records, email tuki@perukirja.io. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman or another competent supervisory authority.
10. Security Measures
We protect your data using:
- Encryption in transit (TLS 1.2 or newer)
- Encryption at Rest (AES-256)
- Account protection: password hashing, sign-in rate limiting, and optional passkey or two-step verification
- Logical Data Isolation
- Regular security reviews as part of our development process
While no system is 100% secure, we continuously improve our safeguards.
11. Children
The service is not intended for children. Users must have the authority to submit data related to estate processes. Estates may, however, include minor heirs, whose details are processed as part of the estate data with the same safeguards as other sensitive data.
12. Policy Changes
We may update this policy. Material changes will be communicated via email or a prominent notice in the app.
13. Contact
Regulus Holding Oy
Konkelonkatu 24
33870 Tampere, Finland
Email: tuki@perukirja.io
Phone: +358 50 593 4915