1. Introduction
This Privacy Policy explains how Arctic Mopping Ltd, trading as Event Production Toolkit EPTK ("we", "us", "our"), collects, uses, and protects your personal data when you use the eptk.cloud service ("the Service") or visit the eptk.cloud website. It applies to both.
We are committed to protecting your privacy and processing your data in compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Our Role: Controller and Processor
Arctic Mopping Ltd (Business ID 3218773-8), operating under its auxiliary trade name Event Production Toolkit EPTK
PL 11, 00811 Helsinki, Finland
Email: support@eptk.cloud
We act in two different capacities, and which one applies depends on the data:
- Controller — for account data, usage data, billing data and website data (sections 3.1, 3.3, 3.4 and 3.6). We decide why and how these are processed, and this Policy governs them.
- Processor — for the content stored in a workspace (section 3.2). The customer organisation that owns the workspace is the controller of that content. It decides the purposes for which the content is processed, and we process it on that organisation's instructions and on its behalf.
Where we act as processor, that organisation's own privacy information governs the content, and the arrangement between us is set out in our agreement with it.
3. Data We Collect
3.1 Account Data
- Full name
- Email address
- Profile photo (if provided)
- Authentication credentials (password hash or OAuth tokens)
3.2 Workspace Data
- Workspace names and settings
- Team member lists and roles
- Event data (names, dates, schedules, budgets, logistics)
- Files and documents uploaded to the Service
We process this content as a processor on behalf of the customer organisation that owns the workspace (section 2).
3.3 Usage Data
- Login timestamps and IP addresses
- Feature usage patterns (pseudonymous). Your IP address reaches our analytics processor as an inherent part of the network request your browser makes to it, and no setting can prevent that. The processor discards the address on receipt and does not store it. Before discarding it, the processor derives an approximate location from it — country, region, city, postal code, approximate coordinates, time zone and an accuracy radius — and those are stored alongside the event for the period given in section 8.
- Error and crash reports
- Device and browser information
3.4 Billing Data
- Subscription plan and status
- Payment processing is handled by Stripe, Inc. We do not store credit card numbers.
3.5 Location Data
- Venue addresses and coordinates to provide event logistics and mapping features.
- The pick-up, drop-off and stop places of a transport, chosen from address suggestions or on a map, and the road route calculated between them. The Service does not track the live position of vehicles or drivers.
- An approximate location our analytics processor derives from the connection your browser makes to it. This is not GPS, is not tied to any transport task, and is accurate at roughly city level; section 3.3 says what is derived and section 8 how long it is kept.
3.6 Website Data
- Waitlist sign-up: email address, the date of sign-up, and a record of the consent given.
- Feedback submitted through the public feedback form: the title, the description, any screenshots attached, and an email address if one is given so that we can reply.
4. Legal Basis for Processing
Where we act as controller (section 2), we process your data based on:
- Contract performance (Art. 6(1)(b) GDPR): To provide the Service you subscribed to
- Legitimate interest (Art. 6(1)(f) GDPR): To improve the Service, ensure security, and prevent fraud
- Consent (Art. 6(1)(a) GDPR): For optional activities such as joining the waitlist and other non-essential communications
- Legal obligation (Art. 6(1)(c) GDPR): Tax and accounting requirements
Where we act as processor, the legal basis for the content held in a workspace is determined by the customer organisation that controls it, not by us.
5. How We Use Your Data
- To provide, maintain, and improve the Service
- To authenticate your identity and manage your account
- To communicate with you about the Service (updates, security alerts)
- To process billing and subscriptions
- To ensure the security and integrity of the Service
- To notify waitlist subscribers when the Service launches, and to respond to feedback where an email address has been given
- To comply with legal obligations
6. Data Sharing
We share your data only with:
- Service providers (sub-processors): each one is named in our Sub-processors list, with what it does for us and where it processes personal data. That list is the only place they are listed, so there is no second copy of it to fall out of date. Where a provider's own terms make it an independent controller of some of the data for purposes of its own, the list says so; today that is Twilio SendGrid, for the email it delivers.
- Workspace members: Your name, email, and role are visible to other members of your workspace(s)
- Legal requirements: When required by law, court order, or governmental request
- Customer-provided storage: Where a workspace connects its own file storage, uploaded files are stored in the customer's account with that provider, under the customer's agreement with them.
- Content loaded in the browser: Map tiles, weather layers and web fonts are loaded directly from the provider, and the user's IP address is disclosed to that provider. These requests contain no other personal data. Weather data is provided by Vaisala Xweather, and flight status by AirLabs; from our servers these receive only a set of coordinates or a flight number, which is linked to an individual or an event only within our own systems.
- Google Maps Platform, as an independent controller: map features use Google Maps Platform, which under its own terms is not our sub-processor but an independent controller of what it receives. It receives the text typed into an address field or given to the assistant to find a place, the coordinates and departure time of a transport being routed, and, when a map is shown, your IP address. Google's Privacy Policy governs that data; section 6 of the Sub-processors list describes it.
We do not sell your personal data to third parties.
AI Data Privacy Guarantee: All AI-powered features within the eptk.cloud service are processed strictly within Google Cloud's secure enterprise boundary, on its European endpoint. Personal and event data are never used by Google to train Google's generative or foundational models, and are not logged for manual review by third parties. We reserve the right to use aggregated, anonymized, or de-identified data to train and improve our own proprietary machine learning models and algorithms to enhance the Service.
7. Data Location and Transfers
Processing locations by data category:
- Database: European Union
- Uploaded files: European Union
- AI processing: European Union
- Authentication data (email address, password hash, sign-in identifiers): United States
Authentication is provided by Firebase Authentication, and the transfer is made under the European Commission's adequacy decision for the EU-US Data Privacy Framework and under Standard Contractual Clauses, as set out in the provider's data processing terms.
Other sub-processors may process data outside the EU under equivalent safeguards; the Sub-processors list states which, and under what.
8. Data Retention
- Account data: Retained while your account exists. Deleting your account erases it immediately — there is no waiting period. We do not delete inactive accounts automatically.
- Workspace data: Retention follows the instructions of the customer organisation that controls the workspace. Absent other instructions, content is retained while the workspace exists; deleting a workspace begins a 30-day retention period and the content is removed no later than 31 days after that. Files the customer keeps in their own connected storage (for example Google Drive, SharePoint or Dropbox) are controlled by that customer and are not removed by us.
- Usage data: Diagnostics data is retained for up to 24 months. Pseudonymous product-analytics data is retained by our analytics processor for up to 7 years; erasure requests apply to it.
- Billing records: Retained for 6 years from the end of the calendar year in which the accounting period ends, as required of accounting vouchers by the Finnish Accounting Act.
- Waitlist entries: Retained until the Service launches, or until an erasure request is made.
- Feedback and support requests: Retained for as long as the request is being handled and followed up on.
9. Your Rights
Under GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data ("right to be forgotten") (Art. 17)
- Restrict processing (Art. 18)
- Data portability — receive your data in a structured format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time (Art. 7(3))
To exercise these rights over the data we control (section 2), contact us at support@eptk.cloud. We will respond within 30 days.
For content held in a workspace we act as processor, and we are not permitted to act on such a request on our own initiative. Direct it to the customer organisation that owns the workspace. Where it reaches us instead, we will pass it on to that organisation and assist it in answering.
10. Data Security
We implement appropriate technical and organizational measures, including:
- Encryption in transit (TLS) and at rest
- Encrypted backups of the database and of account data, stored in the EU
- Database security rules for fine-grained access control
- Role-based access within workspaces
- Regular security reviews
11. Cookies and Analytics
- Essential Cookies: The Service uses only essential technical cookies required for authentication and session management. We do not use third-party tracking, advertising, or behavioral profiling cookies.
- The public website: The eptk.cloud website sets no cookies and runs no analytics. The waitlist and feedback forms transmit only what is entered into them.
- Application Analytics: We use PostHog for product analytics — to understand how the app is used so we can improve it. Analytics data is pseudonymous and hosted in the EU (Frankfurt); PostHog Inc. participates in the EU-US Data Privacy Framework and Standard Contractual Clauses. Analytics data is never used or shared for marketing or behavioral advertising, and you can opt out of analytics at any time in your profile settings.
12. Children's Privacy
The Service is intended for use by adults acting in a professional capacity. It is not directed at minors, and we do not knowingly collect personal data from minors through user accounts.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service. Your continued use constitutes acceptance of the updated policy.
14. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuojavaltuutettu):
- Website: tietosuoja.fi/en/home
- Email: tietosuoja@om.fi
15. Contact
For questions about this Privacy Policy:
- Email: support@eptk.cloud
- Address: Arctic Mopping Ltd (Business ID 3218773-8) / Event Production Toolkit EPTK, PL 11, 00811 Helsinki, Finland