Privacy Policy

In Finnish

Introduction

This privacy policy complements Lemonsoft’s security policy and defines how Lemonsoft collects, uses, stores, and protects personal data. The privacy policy ensures that the processing of personal data is lawful and that customers and staff can trust Lemonsoft’s operations.

Privacy Principles

Lemonsoft adheres to the following privacy principles in all personal data processing:

  • Lawfulness, fairness, and transparency: The processing of personal data is always based on a lawful basis, such as consent, contract performance, or legal obligation.
  • Data minimization: We collect only the personal data necessary for the processing purposes.
  • Accuracy: Personal data is kept accurate and up to date.
  • Storage limitation: Personal data is retained only as long as necessary for the processing purposes.
  • Data security: We protect personal data with appropriate technical and organizational measures.
  • Respect for privacy: We process personal data considering individuals’ rights, such as access and deletion requests.

Lemonsoft processes personal data for the following purposes:

1. Customers

  • Managing customer relationships, such as fulfilling orders, contracts, and customer service.
  • Collecting and analyzing customer feedback to improve business operations.
  • Managing customer access rights and personalizing services on the Lemonsoft platform.

2.Suppliers and Partners

  • Managing supplier relationships and partnerships, such as handling contracts and billing.
  • Communicating with suppliers and partners in coordinating joint projects and services.

3.Job Applicants

  • Managing recruitment processes, including processing applications, evaluating, and contacting job applicants.
  • Informing about the recruitment process and storing applicant data in accordance with legal requirements.

4.Processing Personal Data on the Lemonsoft Platform

  • Lemonsoft utilizes the Lemonsoft platform for storing and processing personal data. The platform is used for managing customer and supplier data, maintaining employee and job applicant information, and managing registered users’ access rights.
  • The data protection and security measures related to the use of the Lemonsoft platform are agreed upon in a contract with Lemonsoft, ensuring the lawful and secure processing of personal data.

5.Processing Employee Personal Data

  • Managing employment relationships, such as payroll, occupational health care, tax, and insurance information.
  • Tracking working hours and recording work-related tasks.
  • Example: Employee contact information (such as email and phone number) is stored to ensure correct payroll processing and to reach the employee regarding employment matters.
  • Information related to personnel development, such as training records and performance evaluations.

The processing of personal data for these purposes is always based on legislation, contracts, consents, or Lemonsoft’s legitimate interest, and the processing is guided by a strictly defined data security and privacy policy.

Data Disclosure and Processing

Lemonsoft may transfer personal data to service providers who process data on behalf of Lemonsoft. Data transfers always occur with appropriate agreements ensuring that the data is processed securely and lawfully. Personal data is not transferred outside the EU/EEA without appropriate safeguards and agreements.

Data Security Measures

Lemonsoft ensures the security of personal data with the following measures:

  • Access control: Access to personal data is restricted to those whose job duties require it.
  • Data encryption: Personal data is protected during transfer and storage. Database encryption is continuously developed.
  • Audits: Data protection audits Lemonsoft’s security regularly. Additionally, Lemonsoft’s security is audited regularly by an external party.
  • Risk management: Data security risks are regularly assessed, and a data breach management process is implemented.
  • Training: Regular data protection and security training is provided to staff.

Retention Period for Personal Data Personal data is retained only as long as necessary to fulfill the processing purposes or to comply with legal obligations.

Rights of Data Subjects

Individuals whose data Lemonsoft processes can exercise the following rights within the limits of the law:

  • The right to access their personal data.
  • The right to rectify data.
  • The right to delete data (“right to be forgotten”).
  • The right to restrict processing.
  • The right to object to data processing.
  • The right to data portability.

Data subjects can contact Lemonsoft’s Data Protection Officer to exercise these rights.

Data Protection Officer

Lemonsoft has appointed a Data Protection Officer responsible for overseeing personal data processing activities and developing data protection. The Data Protection Officer acts as a contact person for data protection-related questions.

Stakeholder Privacy Requirements

Lemonsoft considers the privacy requirements set by customers and partners to ensure that personal data processing also meets their expectations. This supports Lemonsoft’s strategy to operate as a responsible and customer-centric software company.

Maintenance of the Privacy Policy

The privacy policy is reviewed and updated annually and in accordance with changes in the operating environment, legislation, and business. The policy is approved by Lemonsoft’s management team.

Lemonsoft’s management team approved the security policy on December 17, 2024.