Punasaari Research · Y-tunnus 3580452-7 · Varistonkuja 2, 01660 Vantaa, Finland
Privacy Policy
How Punasaari Research processes personal data in Somemind AI.
- Effective
- 25 August 2026
- Version
- 3.0
1. Controller
Punasaari Research · Y-tunnus 3580452-7 · Varistonkuja 2, 01660 Vantaa, Finland is controller for account, billing, security and service-administration data. Contact: info@punasaariresearch.fi.
2. Data categories
We process account and profile details, company/workspace settings, legal acceptance evidence, billing status, customer content and media, automation settings, encrypted social-platform tokens, platform identifiers, publishing results, permitted analytics, support communications, IP addresses, audit events and technical logs. Card data is processed by Stripe and is not stored by Somemind.
3. Purposes and legal bases
We process data to enter into and perform the business contract, authenticate users, provide automation and publishing, process billing, secure the service, prevent abuse, comply with accounting and legal duties, and improve reliability. Legal bases are contract, legal obligation, legitimate interests and consent where legally required.
4. Signup and trial evidence
We retain immutable evidence of accepted Terms and Privacy versions, business authority, locale, timestamp, IP address, user agent and automatic-renewal confirmation. Email addresses are represented in this evidence by a keyed cryptographic digest. Stripe Checkout Session and subscription identifiers may be retained to prove the transaction and resolve disputes.
5. Facebook, Instagram and TikTok
Facebook Pages, Instagram professional accounts and TikTok accounts are active. We process identifiers, granted permission names, encrypted access/refresh tokens, publishing instructions, external post IDs and permitted insight metrics only to provide the connected functions. Users can disconnect accounts and request deletion. Meta and TikTok also act under their own terms and privacy notices.
6. Processors and recipients
Service providers include Supabase, Vercel, Cloudflare R2, Stripe, Resend, Google Gemini, FAL, Meta and TikTok as needed for the requested function. We do not sell personal data or connected-platform data. EEA transfers use an applicable adequacy decision, Standard Contractual Clauses or another lawful safeguard.
7. Retention
Operational account and workspace data is kept while the service is active and then deleted or anonymized according to the deletion workflow and backups. Legal acceptance, security and transaction evidence is retained as necessary to establish claims. Accounting records and invoices may be retained for seven years or longer if law requires. Social tokens are erased on disconnect or deletion.
8. Security
Controls include tenant-scoped access policies, encryption of social tokens, signed OAuth state, limited service credentials, immutable audit evidence, rate limiting, signed storage URLs, webhook verification and incident monitoring. No system can guarantee absolute security.
9. Rights
Subject to GDPR conditions, individuals may request access, correction, deletion, restriction, portability or objection, and may complain to the Finnish Data Protection Ombudsman. Contract and accounting records may be retained where legally required.
10. Changes and contact
We publish material changes and request renewed acceptance when appropriate. Privacy requests: info@punasaariresearch.fi.