Privacy Policy
Version: 1.0 Last updated: 6 September 2026
1. About this Privacy Policy
This Privacy Policy explains how Axantem Oy processes Personal Data in connection with Vuokravirta.
Controller contact
Axantem Oy Business ID 3004294-9 Vallikatu 10 B 9 33240 Tampere Finland
Email: vuokravirta@anttiivanoff.com
2. Our dual GDPR role
Vuokravirta has two principal data-protection roles.
Axantem as Controller
Axantem generally acts as Controller for Personal Data used for its own purposes, including:
- user registration and account administration;
- Customer relationship administration;
- billing;
- security and fraud prevention;
- direct product support;
- service administration;
- legal compliance;
- contractual records; and
- Axantem's own website and communications.
Axantem as Processor
Where a Customer uses Vuokravirta to process information relating to tenants, leases, payers, rental obligations, bank transactions or rental-management communications, the Customer normally determines why the information is processed.
In these circumstances:
Customer / landlord = Controller Axantem Oy / Vuokravirta = Processor
The applicable Data Processing Agreement governs this processing.
If a Customer itself acts as Processor for another Controller, Axantem may act as Subprocessor.
Contractual labels do not override the actual roles required by applicable data-protection law.
3. Personal Data Axantem processes as Controller
Depending on how you interact with Vuokravirta, we may process:
Account information
- name;
- email address;
- authentication identifiers;
- organisation membership;
- role and permissions;
- account settings.
Customer and contractual information
- Customer organisation;
- contact details;
- subscription information;
- contractual acceptance records;
- billing identifiers;
- invoices and payment status.
Payment-card information may be processed directly by a payment provider rather than stored by Vuokravirta.
Support information
- emails and support enquiries;
- information supplied when troubleshooting;
- relevant technical information.
Please do not send passwords, MFA codes, banking credentials or unnecessary sensitive Personal Data in support messages.
Security and technical information
Depending on production configuration:
- IP address;
- device/browser information;
- timestamps;
- authentication and security events;
- error information;
- request metadata;
- audit information.
We seek to minimise Personal Data in application and monitoring logs.
4. Personal Data processed for Customers
Customer-controlled Personal Data may include:
- tenant and co-tenant names;
- contact details where supported;
- property and unit information;
- lease information;
- rent and other obligations;
- payment dates and amounts;
- arrears information;
- payer names;
- bank references;
- limited payment-message information;
- account identifiers or derived identifiers;
- transaction classifications;
- matching results;
- reminders and communications;
- audit information; and
- other rental-management information enabled in the Service.
Features introduced later may process additional categories such as documents or tenant communications. Material changes will be reflected in this Privacy Policy and, where applicable, the Subprocessor Register and DPA.
5. Third-party payers
Rental payments are not always made by the named tenant.
Vuokravirta may therefore process transaction information concerning persons or organisations such as:
- spouses;
- parents;
- relatives;
- employers;
- companies;
- public authorities;
- benefit providers; or
- other third-party payers.
Axantem processes such information for the relevant Customer and does not use it for unrelated advertising or independent tenant profiling.
6. Bank imports
Vuokravirta may support manual import of bank transactions.
In the current supported architecture, source CSV, HTML or PDF information may be parsed locally in the user's browser.
Selected and normalised transaction information is subsequently sent to and stored in Vuokravirta.
The Service is not designed to upload and retain the complete original bank statement merely because the user selects a file for supported browser-side parsing.
Selected transaction data may nevertheless include Personal Data from the statement.
Customers should keep original banking records they independently need for accounting, taxation or evidence.
Future connected-banking functionality may use an authorised external account-information provider. The relevant provider and privacy information will be disclosed before such processing is enabled.
7. Lawful bases when Axantem acts as Controller
Axantem relies on different lawful bases for different purposes.
Contract — Article 6(1)(b) GDPR
We may process Personal Data where necessary to:
- create and administer your account;
- provide the Service;
- manage subscriptions;
- provide requested support;
- administer our contractual relationship.
Legal obligation — Article 6(1)(c)
We may process information where necessary to comply with legal duties, including applicable:
- accounting;
- taxation;
- regulatory; and
- legal-record requirements.
Legitimate interests — Article 6(1)(f)
Subject to an appropriate balancing of interests, Axantem may rely on legitimate interests for purposes including:
- securing the Service;
- preventing abuse and fraud;
- investigating incidents;
- maintaining auditability;
- improving reliability;
- diagnosing technical problems;
- defending and establishing legal claims;
- administering business relationships; and
- measuring or improving the Service using appropriately minimised information.
Consent — Article 6(1)(a)
Consent may be used where required, particularly for optional non-essential tracking or certain marketing activities.
Consent may be withdrawn at any time without affecting earlier lawful processing.
8. Customer lawful bases
Axantem does not determine the Customer's lawful basis for tenant, payer and rental-management processing.
The Customer, as Controller, is responsible for determining the applicable lawful basis and providing information required under Articles 13 or 14 GDPR where applicable.
Using a software processor such as Vuokravirta does not automatically mean a landlord must obtain GDPR consent from every tenant.
9. Incidental sensitive information
Vuokravirta does not currently provide dedicated fields intended for storing unnecessary health information, criminal information or Finnish personal identity codes.
However, ordinary transaction messages or future communications can incidentally reveal private or sensitive matters, including information concerning public benefits, family circumstances or health.
Customers should avoid unnecessary sensitive information.
Axantem does not intentionally use such incidental information for unrelated profiling, advertising or marketing.
10. Storage and processing locations
Vuokravirta follows an EU-first hosting architecture.
The approved production architecture uses a specifically selected Supabase AWS Europe (Frankfurt), Germany (`eu-central-1`) region for the primary production database, authentication and supported storage.
Server-side application compute is configured primarily in Vercel Frankfurt, Germany (`fra1`) where supported by the relevant runtime.
These configurations do not mean that every technical operation occurs exclusively in Germany, Finland, the EU or EEA.
Global content-delivery networks, technical routing, security functions, support operations and subprocessors may involve processing or access in other countries.
Before this statement is published as a production fact, Axantem verifies that the relevant production configurations are actually enabled.
11. International transfers
Where Personal Data is transferred outside the EEA and a GDPR Chapter V transfer mechanism is required, Axantem uses an appropriate safeguard such as:
- an adequacy decision;
- the European Commission's Standard Contractual Clauses; or
- another lawful transfer mechanism.
Supplementary safeguards are applied where required.
12. Subprocessors
Axantem uses service providers to operate Vuokravirta.
Providers that process Customer Personal Data on Axantem's behalf are listed in the Vuokravirta Subprocessor Register.
A package or integration present in the software source code is not treated as an active Subprocessor merely because the software supports it.
The register reflects providers actually enabled to process relevant production Personal Data.
13. Retention
We keep Personal Data only for as long as reasonably necessary for the relevant purpose or required by law.
Account and contractual data
Generally retained for the duration of the Customer relationship and thereafter to the extent reasonably necessary for legal, contractual, security and claims-management purposes.
Billing and accounting information
Retained for the period required under applicable accounting, taxation and other legal obligations.
Support information
Retained for as long as reasonably necessary to resolve the matter, maintain relevant service history, secure the Service and establish or defend legal claims.
Security information
Retained according to a risk-based security retention period appropriate to the relevant log or event.
Customer-controlled rental data
Processed for the duration of the Customer's instructions and agreement and returned or deleted in accordance with the Data Processing Agreement.
Customer Data may remain temporarily in protected infrastructure backups after deletion from active systems until those backups expire or are overwritten through the normal documented backup lifecycle.
Backup copies are not intended for ordinary operational use.
If a backup containing previously deleted Customer Data must be restored, relevant deletion instructions will be reapplied where appropriate.
Axantem does not publish a fixed maximum backup deletion period until the production backup lifecycle has been technically verified.
14. Security
Axantem applies technical and organisational measures appropriate to the risks of the Service.
These include, as applicable:
- authenticated access;
- organisation-based access controls;
- row-level data separation;
- least-privilege access;
- encryption in transit;
- protected secrets;
- restricted privileged access;
- audit logging;
- environment separation;
- secure hosting;
- backup and recovery arrangements;
- security monitoring;
- incident handling; and
- data minimisation.
No online service can guarantee absolute security.
15. Artificial intelligence and automation
At the current launch stage, Vuokravirta's core payment matching is based on rules, scoring and deterministic processing rather than a shared externally trained tenant model.
Vuokravirta may introduce AI-assisted functions in the future, including:
- transaction interpretation;
- document processing;
- drafting reminders;
- communication assistance;
- categorisation;
- summarisation; or
- proposed actions.
Where Customer Personal Data is sent to an external AI provider, the provider will be assessed and, where it acts as Subprocessor, added to the Subprocessor Register before production use.
Axantem's default policy is not to permit an external AI provider to use Customer Personal Data submitted through Vuokravirta to train or improve that provider's general or shared models for its own purposes.
At launch, Axantem does not use identifiable or merely pseudonymised tenant, payer or Customer Personal Data to train a shared cross-Customer Vuokravirta AI model for a separate secondary purpose.
Axantem may use synthetic, aggregated or genuinely anonymised information to test and improve the Service.
Any future materially different use of Personal Data for model development requires a new privacy assessment and appropriate transparency before activation.
16. Automated decisions
Vuokravirta may automatically classify or match information.
For example, it may calculate how confidently a bank transaction corresponds to a rental obligation.
At launch, Vuokravirta is not intended to make solely automated decisions that independently produce legal or similarly significant adverse effects on tenants.
Material future features concerning tenant creditworthiness, tenant rejection or similarly consequential automated decisions require separate assessment before deployment.
17. Personal Data Breaches
Axantem maintains procedures for investigating Personal Data Breaches.
Where Axantem acts as Processor and becomes aware of a Personal Data Breach concerning Customer Personal Data, Axantem will notify the affected Customer without undue delay.
Information may be provided in phases where complete information is not initially available.
Where Axantem acts as Controller, Axantem will assess its notification obligations under applicable data-protection law.
18. Your rights when Axantem is Controller
Subject to applicable conditions and exceptions, you may have the right to:
- obtain information about processing;
- access your Personal Data;
- correct inaccurate information;
- request erasure;
- request restriction;
- object to certain processing;
- receive portable data where applicable;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a supervisory authority.
Requests concerning Personal Data for which Axantem is Controller can be sent to:
We may need to verify your identity before fulfilling a request.
19. Tenant and payer requests
If your information is stored in Vuokravirta by your landlord or another Vuokravirta Customer, that Customer normally acts as Controller.
You should normally direct your privacy request to the landlord or organisation that uses Vuokravirta.
If Axantem receives such a request, we may forward it to or identify the relevant Customer and assist that Customer with fulfilling its obligations.
We will not disclose another Customer's information or circumvent appropriate identity verification merely because a request is made directly to Axantem.
20. Supervisory authority
You have the right to lodge a complaint with a competent data-protection supervisory authority.
The Finnish supervisory authority is:
Office of the Data Protection Ombudsman P.O. Box 800 00531 Helsinki Finland
Email: tietosuoja@om.fi Telephone: +358 29 566 6700
21. Children
Vuokravirta user accounts are not intended for children.
A person creating an account must be at least 18 years old or otherwise have the legal capacity and authority required to enter into the relevant agreement.
Customer-controlled rental-management records may concern minors where the Customer has a lawful and necessary rental-management reason for processing such information.
22. Changes to this Privacy Policy
We may update this Privacy Policy when:
- the Service changes;
- processing changes;
- providers change;
- laws or regulatory guidance change; or
- clarification is necessary.
Material changes will be communicated appropriately.
The current version and update date are published on this page.