← Back to home

Folkuslab Cloud Privacy Policy

Here you can find information about the service's privacy protection, personal data processing and your own rights.

We may update the privacy policy as our operations develop or legislation changes, so we ask you to visit this page from time to time.

This document was last updated: 31 Oct 2025

1. Contact information

For questions related to this statement, you can contact the service provider:

Folkuslab Oy

Email: hello@folkuslab.com

2. What data is processed?

For survey participants, the service processes the following personal information:

  • Name
  • Email address
  • Other demographic information provided by the employer of the person
  • Answers to the survey
  • Timing information about the answers to the survey
  • Technical information about the device and browser used to access the service

For users of the platform, who conduct surveys, the service processes the following personal information:

  • Name
  • Email address
  • Other information entered by the user

In addition, the service processes network identification data generated from the use of the service (e.g. IP address).

The information is treated as confidential by default. Aggregated information may be used for research purposes and published.

3. Where does the information come from?

Most of the information is directly entered by the user.

For survey participants, some information is provided by the employer of the person.

In addition, the service provider's employees can add or update information when they notice the need for changes or are requested to do so by a user.

4. For what purpose is the information processed?

Personal information is processed e.g. for the following purposes:

  • Conducting surveys to a group of employees
  • Sending survey invites and reminders
  • Analyzing survey results
  • Creating reports and analyses based on survey results
  • Research based on survey results

As part of processing the information, it may be analyzed and further processed using automatic processes. Automatic processes support the decision-making of the service provider's employees, for example by separating certain types of information from the source material or modifying them in a more readable format, among other methods.

The use of the service generates usual network identification data (e.g. IP address, cookies) and log data (e.g. page downloads). The service provider can use this information for troubleshooting and analytics purposes, for example.

5. Is information handed over or transferred to third parties?

As part of the functionality of the service, the user's personal data can be disclosed to a partner of the service provider. Information will not be disclosed without the person's permission.

The service provider uses third-party services to provide the service. In this case, the information is handed over to the relevant parties for processing. The third-party services used have been chosen so that they guarantee the rights according to this privacy policy for the user of the service, e.g. so that they do not store data for longer than is defined in this privacy policy.

List of third-party services:

ServiceLocation
MicrosoftUSA
OpenAIUSA
PostmarkUSA
RenderEU

Information can be forwarded to different authorities if there is a legal basis for doing so. Information about the customer can be disclosed for the performance of the tasks referred to in the law without being hindered by confidentiality regulations and other restrictions on access to information. If there is no legal basis for the transfer of data, the data will only be forwarded with the customer's consent.

6. Where is the data stored?

Data is stored in EU/EEA area and in the USA.

7. Is data transferred outside the EU/EEA area or the USA?

Data is not transferred outside the EU/EEA area or the USA as part of data processing.

8. How long is the data kept?

The user's data is deleted in the following circumstances:

  • 6 months after their active relationship with the service ends. We periodically ask users if they wish to retain this relationship; if they do not respond or choose not to, their data will be deleted within this timeframe. The maximum period between these inquiries is 2 years.
  • If the user requests the deletion of their data, it will be promptly removed from our systems.

Online identification information is stored for a maximum of 1 year.

9. How is data protected?

Information stored in information systems is stored in a secure environment. Network traffic between the user's browser and the service provider's server is TLS protected.

Online identification information is stored in a secure environment to which only the service provider's personnel have access to the extent that it is necessary for the personnel.

10. The user's rights

Users have the following rights:

  • Reviewing information. Users can request a copy of their information by contacting the service provider.
  • Right for data correction. Users can request a change or a correction to their information by contacting the service provider.
  • Right for data erasure. Users can request the removal of their information by contacting the service provider.