Processing of Personal Data in Lemonsoft Cloud Services (SaaS) and Mobile Applications

This appendix forms part of the service agreement between Lemonsoft Oyj and the Customer. It defines the rights and obligations relating to the processing of personal data in accordance with the EU General Data Protection Regulation (EU) 2016/679 ("GDPR").

Last updated: 22 July 2026.

 

1. Roles of the Parties

The Customer acts as the Controller with respect to the personal data that it stores and processes in the Lemonsoft Cloud Services.

Lemonsoft Oyj (Business ID: 2017863-1, Vaasanpuistikko 20 A, FI-65100 Vaasa, Finland) acts as the Processor on behalf of the Customer

2. Subject Matter, Nature and Purpose of the Processing

The processing covers the personal data of the Customer's employees and other individuals 
whose personal data is stored in the Lemonsoft Cloud Services.


The purposes of the processing include:

• providing SaaS and mobile services and their technical maintenance; 
• providing customer support; 
• ensuring information security and service availability; 
• backup and recovery; 
• logging and auditing; and 
• improving service quality. 


More detailed descriptions of the processed data are provided in the product-specific service 
descriptions.

Use of Location Data in Mobile Applications

If the user chooses to enable the feature, LemonTime may automatically calculate travel distance using the location data of the user's device. The feature is entirely optional, and travel expense claims can also be created without using location data.

When the feature is enabled, the detailed travel route is stored only on the user's own device for the duration of the trip and is not transferred to or stored in the service.

Only the departure location, destination location (coordinates and address), and the calculated travel distance are stored in the travel expense claim.

This information is used solely for the travel expense functionality, is not disclosed to third parties, and is permanently deleted when the trip or route is deleted.

3. Duration of Processing

Personal data is processed for as long as the Customer uses the Lemonsoft Cloud Services or mobile services.

Upon termination of the service agreement, Lemonsoft will, in accordance with the Customer's instructions, delete or return all personal data within 60 days, and backup copies within two years, unless mandatory legislation requires a longer retention period.

4. Sub-processors

Lemonsoft may use sub-processors (for example, cloud service providers).

Lemonsoft ensures that its sub-processors are contractually bound to data protection and information security obligations that are at least equivalent to those set out in this appendix.

Lemonsoft maintains an up-to-date list of sub-processors on its website and will notify the Customer in advance of any material changes. The Customer has the right to object to a new 
sub-processor on justified grounds.

5. Artificial Intelligence

Artificial Intelligence (AI) is used as an optional assistant to help users perform various tasks, such as creating travel expense claims.

The legal basis for this processing is the user's consent.

The AI processes only the information that the user voluntarily provides for the specific task being performed. For example, when preparing a travel expense claim, the AI processes only 
the information and personal data necessary for completing that claim.

User data is not stored within the AI service. Instead, all data is stored directly in Lemonsoft's information systems.

The AI service does not disclose customer data to third parties.

The AI functionality is based on Azure OpenAI. Customer-specific data is not retained within the Azure OpenAI service.

The use of AI also follows the fundamental principles of data protection, including:

• data minimisation; 
• purpose limitation; and 
• storage limitation.

The AI solution complies with applicable legislation, including:

• the EU Artificial Intelligence Act (AI Act); 
• the General Data Protection Regulation (GDPR); and 
• the Finnish Data Protection Act (1050/2018).

6. Data Location and Transfers

Customer data is primarily stored in the service provider's data centre located in Sweden.

Backup copies are stored in two physically separate locations within the EU/EEA.

Personal data will not be transferred outside the EU/EEA without the Customer's prior written consent and appropriate safeguards in accordance with the GDPR

7. Security Measures

Lemonsoft maintains an information security management system certified in accordance with ISO/IEC 27001:2022.

Lemonsoft implements appropriate technical and organisational measures to ensure the protection of personal data, including:

• use of cloud service providers compliant with ISO 27001; 
• access management, multi-factor authentication (MFA), and role-based access 
control; 
• encryption of data in transit using TLS 1.2/1.3 and encryption of data at rest; and 
• continuous security monitoring and logging.

8. Personal Data Breaches

Lemonsoft continuously monitors for security incidents and personal data breaches.

If Lemonsoft becomes aware of a personal data breach, it will notify the Customer without undue delay and no later than 48 hours after becoming aware of the breach.

The notification will include at least:

• a description of the incident 
• the estimated impact 
• the corrective measures taken.

Lemonsoft will assist the Customer in fulfilling its notification obligations under the GDPR.

9. Customer Rights and Audits

The Customer has the right to verify that Lemonsoft complies with the obligations set out in this appendix.

Upon request, Lemonsoft will provide information demonstrating such compliance.

Lemonsoft reserves the right to charge reasonable costs for such assistance.

Where necessary, the Customer may conduct an audit upon reasonable prior notice.

10. Compliance with the GDPR

Lemonsoft undertakes to assist the Customer in fulfilling its obligations as Controller, including:

• responding to data subject requests; 
• carrying out Data Protection Impact Assessments (DPIAs); and 
• cooperating with supervisory authorities.

Lemonsoft reserves the right to charge reasonable costs for such assistance.

11. Validity and Amendments

This appendix remains in force for the duration of the service agreement.

Lemonsoft may update this appendix due to changes in applicable data protection legislation or the acquisition of new certifications.

Customers will be notified in writing in advance of any material changes.

22 July 2026: Added a description of the use of location data to Section 2.