Back to home

Privacy Policy

Centro Cloud Oy

Last updated: 22 September 2026

This Privacy Policy describes how Centro Cloud Oy ("Centro Cloud", "we", "us") processes personal data when you visit our website, contact us, or use the Centro Cloud service.

Centro Cloud provides a cloud platform for intelligent asset and event management. The platform unifies asset management, event handling, team coordination, alerts, action lists, conversations, custom forms, reporting and optional AI features.

We comply with applicable data protection law, including the EU General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Finnish Data Protection Act.

1. Controller

Centro Cloud Oy

Business ID (Y-tunnus): 3326645-4

Registered office: Turku, Finland

Address: Latokarinkatu 3, 20200 Turku, Finland

Email: privacy@centrocloud.fi

Phone: +358 40 719 3449

Website: https://centrocloud.fi

Service login: https://secure.centrocloud.fi

2. Roles: when we are controller and when we are processor

2.1 Centro Cloud as data controller

We are the controller when we process personal data for our own purposes, including:

  • visitors to centrocloud.fi
  • sales, demo and quote requests
  • our customer and prospect contact persons
  • user accounts we administer for the service (name, email, role, login data)
  • billing and contract administration
  • security, abuse prevention and service operations on our own systems

2.2 Centro Cloud as data processor

When a customer organisation uses Centro Cloud, that organisation is typically the controller for the personal data it stores in the platform. This may include:

  • names and contact details of the customer's users and field workers
  • asset, site and event records that identify people
  • observations, action-list answers and visit logs
  • conversations, comments and attached files
  • data submitted through customer-created forms (including forms that can be filled without a Centro Cloud login)
  • inbound email or SMS content routed into the service
  • documents analysed with Centro AI, where the customer enables that feature

In this role we process data only on the customer's documented instructions and under a data processing agreement, to provide, secure and support the service.

If you are an individual whose data was entered into Centro Cloud by a customer organisation, please contact that organisation first. We will assist the customer in responding to your request.

3. Categories of personal data

Depending on how you interact with us, we may process:

Website and sales

  • name, email address, phone number and organisation
  • message content and demo or quote request details
  • communication history

Service accounts

  • name and email address
  • user credentials (passwords stored hashed/encrypted)
  • roles, permissions and asset-level access
  • language and other preferences
  • two-factor authentication data
  • billing and invoicing details of the customer organisation and its contact persons

Technical and security data

  • IP address
  • timestamps
  • browser, device and operating system information
  • log and activity data needed to operate and secure the service

Customer-controlled content (processor role)

  • any personal data the customer or its users enter into the platform, including form responses, files, conversations, event logs and alert content

We do not collect Finnish personal identity numbers (henkilötunnus) and do not require them to use the service.

4. Sources of personal data

  • you, when you contact us or create/use an account
  • your organisation, when it invites you as a user
  • use of the website and the service
  • public business sources, for B2B prospecting where applicable
  • third parties who fill a customer's shared form URL
  • inbound email or SMS channels configured by the customer

5. Purposes and legal bases

PurposeLegal basis (GDPR Art. 6)
Provide, maintain and support the contracted serviceContract (Art. 6(1)(b)); for customer content, processing on behalf of the customer (Art. 28)
Create and manage user accounts, roles and accessContract; legitimate interest in secure access control
Invoicing, bookkeeping and statutory recordsLegal obligation (Art. 6(1)(c)); contract
Customer support and service communicationsContract; legitimate interest
Sales, demos and B2B marketing to existing or potential business customersLegitimate interest (Art. 6(1)(f)); consent where required
Security, abuse prevention, troubleshooting and backupsLegitimate interest; legal obligation where applicable
Improve service functionality and understand aggregated usageLegitimate interest
Centro AI features enabled by the customerContract with the customer; the customer is responsible for its own lawful basis toward data subjects

You may object to processing based on legitimate interest. We will stop unless we have compelling legitimate grounds or the data is needed for legal claims.

6. Centro AI

Centro Cloud offers optional AI features.

  • Pro — AI for documents. Document analysis uses Google Gemini. Document content the customer submits for analysis is sent to Google for that purpose.
  • Enterprise. The customer may integrate its own language model so that analysis stays under the customer's control.

AI is used only to deliver the feature the customer has enabled. We do not use customer content to train general-purpose models for unrelated third parties.

The customer decides which documents AI is enabled. The customer must not submit special-category data or other data it is not entitled to process.

7. Recipients and sub-processors

Personal data is available only to Centro Cloud personnel who need it for their duties.

We use trusted service providers (sub-processors) to deliver the website and the service. All sub-processors are bound by written contracts that require GDPR-equivalent protection.

Current sub-processors:

ProviderRoleLocation
AkamaiHosting and infrastructure for the Centro Cloud service (secure.centrocloud.fi)Stockholm, Sweden (EU/EEA)
PostmarkTransactional and service email deliveryUnited States
Kajala Group OySMS delivery for alerts and inbound SMS channelsFinland (EU/EEA)
Procountor (Accountor)Monthly invoicing and financial administrationFinland (EU/EEA)
Google (Gemini)Optional Pro-plan AI for documentsProcessing may take place outside the EU/EEA

We do not currently use Vercel Insights or other website analytics tools.

We will provide customers with an up-to-date sub-processor list on request and, where the processing agreement so requires, notify customers of material changes.

We may disclose data if required by law, a competent authority, or to establish, exercise or defend legal claims. We do not sell personal data.

8. International transfers

Service data on secure.centrocloud.fi is hosted on Akamai infrastructure in Stockholm and is therefore processed in the EU/EEA. Invoicing (Procountor) and SMS delivery (Kajala Group Oy) are also provided from the EU/EEA.

Some providers process data outside the EU/EEA:

  • Postmark delivers email and is established in the United States.
  • Google Gemini, when a customer uses Pro-plan AI for documents, may process document content outside the EU/EEA.

Where personal data is transferred outside the EU/EEA, we use an appropriate safeguard, such as:

  • an adequacy decision of the European Commission (including, where applicable, the EU–US Data Privacy Framework), and/or
  • the Commission's Standard Contractual Clauses,
  • plus supplementary measures where needed.

9. Retention

DataRetention
Customer relationship and account dataFor the duration of the contract. After termination, customer content is retained for up to 180 days for recovery or export, then deleted, unless a longer period is required by law.
Invoicing and accounting recordsAs required by Finnish accounting and tax law (typically 6 years).
Sales and prospect contactsReviewed at least every 6 months; unnecessary data is deleted.
Support correspondenceAs long as needed to handle the matter and for a reasonable follow-up period.
Security and system logs that may contain identifiersUp to 2 years, unless a longer period is needed to investigate an incident.
BackupsUsed only for recovery and kept for a limited backup cycle.

10. Security

We implement appropriate technical and organisational measures, including:

  • encryption in transit and, where applicable, at rest
  • hashed or encrypted credentials
  • role-based access control and asset-level permissions
  • two-factor authentication for service login
  • logging and monitoring
  • backups and recovery processes
  • confidentiality obligations for personnel

No method of transmission or storage is completely secure. We work to reduce risk and to detect and respond to incidents.

11. Cookies and similar technologies

We do not use marketing, advertising or analytics cookies, and we do not currently use Vercel Insights or similar audience-measurement tools.

The service at secure.centrocloud.fi may use strictly necessary cookies or similar technologies for security, load balancing and authenticated sessions (including two-factor authentication). These are required to provide the service and do not require consent.

We do not sell browsing data to ad networks.

You can control cookies in your browser settings. Blocking necessary cookies may prevent login or parts of the service from working.

If we later enable optional analytics, we will update this section and request consent where the law requires it.

12. Data subject rights

You have the right to:

  • access your personal data
  • rectify inaccurate data
  • request erasure
  • restrict processing
  • object to processing based on legitimate interest, including B2B direct marketing
  • withdraw consent where processing is based on consent
  • data portability, where applicable
  • lodge a complaint with a supervisory authority

To exercise rights regarding data Centro Cloud holds as controller, contact us using the details in section 1. We may need to verify your identity.

To exercise rights regarding data a customer stores in the platform, contact that customer. We assist customers as required by GDPR Article 28.

We do not use solely automated decision-making that produces legal or similarly significant effects about you.

13. Personal data breaches

If we act as processor and become aware of a personal data breach affecting customer data, we notify the relevant customer without undue delay and, where possible, within 72 hours, with:

  • a description of the breach
  • the categories of data and approximate number of individuals affected, where known
  • likely consequences
  • measures taken or proposed

The customer, as controller, is responsible for notifying the supervisory authority and affected individuals when the law requires it.

If we act as controller, we will notify the Finnish Data Protection Ombudsman and, where required, the data subjects, in accordance with GDPR Articles 33 and 34.

14. Children

Centro Cloud is a business service. It is not directed at children. We do not knowingly collect personal data from children.

15. Supervisory authority

You may lodge a complaint with the authority in your EU/EEA country of residence or work, or with the Finnish authority:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)

Visiting address: Lintulahdenkuja 4, 00530 Helsinki, Finland

Postal address: P.O. Box 800, 00521 Helsinki, Finland

Phone: +358 29 56 66700

Email: tietosuoja@om.fi

Website: https://tietosuoja.fi

16. Changes

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change. Material changes will be indicated on this page or, where appropriate, by email to customer administrators.

17. Contact

Questions about this policy or our privacy practices:

Centro Cloud Oy

myynti@centrocloud.fi

+358 40 719 3449

Latokarinkatu 3, 20200 Turku, Finland

Questions about our privacy practices?

If you have any questions about how we handle your data, please contact us.