Last updated: 9 April 2026

Privacy Policy

1. Who we are

ProductOS ("we", "our", "us") is a software-as-a-service product management platform operated from Finland. This Privacy Policy explains how we collect, use, and protect personal data when you use our website at productos.fi and the ProductOS application.

We act as the data controller for the personal data described in this policy. If you have questions, contact us at privacy@productos.fi.

2. What data we collect

We collect the following categories of personal data:

  • Account data — your name and email address when you register or join a workspace.
  • Waitlist data — your name (optional) and email address if you sign up for early access.
  • Workspace content — product plans, roadmap items, goals, opportunities, feedback, and other content you create inside the application. This data belongs to you and your organisation.
  • Usage data — pages visited, features used, and actions performed within the app. We use this to improve the product.
  • Technical data — IP address, browser type, and device information collected automatically when you access our services.

3. Why we collect it

We process your personal data on the following legal bases:

  • Contract performance — to provide, maintain, and support the ProductOS service you have signed up for.
  • Legitimate interests — to improve our product, prevent fraud, and ensure the security of our platform.
  • Consent — to send you marketing communications or product updates (you can withdraw consent at any time).
  • Legal obligation — to comply with applicable laws and regulations.

4. How we store your data

Your data is stored in a cloud-hosted PostgreSQL database provided by Neon (neon.tech), with servers located in the European Union. We apply encryption in transit (TLS) and at rest. Access to production data is restricted to authorised personnel only.

We retain account and workspace data for as long as your account is active or as needed to provide the service. Waitlist entries are retained until you request removal or until ProductOS is fully launched and the waitlist period ends.

5. Sub-processors

We use the following third-party services to operate ProductOS. Each acts as a data processor on our behalf under a Data Processing Agreement and is only permitted to process your data as instructed by us.

ProviderPurposeLocationTransfer basis
Vercel Inc.Application hosting & CDNUSAStandard Contractual Clauses
Neon Inc.Database hostingEU (Frankfurt, AWS eu-central-1)
Brevo (Sendinblue SAS)Transactional email deliveryEU (France)

6. Sharing your data

We do not sell your personal data. We share data only in the following limited cases:

  • Service providers — trusted third parties who help us operate the platform (cloud hosting, email delivery). These parties are bound by data processing agreements.
  • Your organisation — workspace administrators within your tenant can see member names and email addresses.
  • Legal requirements — if required by law or to protect our legal rights.

7. Cookies

We use a session cookie to keep you logged in. This cookie is strictly necessary for the service to function and does not require your consent. We do not use advertising or tracking cookies.

8. Your rights (GDPR)

As a resident of the European Economic Area, you have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your personal data ("right to be forgotten").
  • Restriction — request that we limit how we process your data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email us at privacy@productos.fi. We will respond within 30 days. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).

9. Security

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date at the top of this page. For significant changes, we will notify you by email or by a notice in the application.

11. Contact

For any privacy-related questions or requests, contact us at: privacy@productos.fi