Privacy Policy, HAI Social Agency

Version: 2.3 · Effective date: 19 August 2026 · Last updated: 14 August 2026 Languages: English (below) · Suomeksi (from "Tietosuojakäytäntö")

Who we are

HAI Social Agency Oy
Business ID (Y-tunnus): 3631226-8
Malminkaari 23, 00700 Helsinki, Finland
matti@haisocialagency.com

We are an AI coaching service that helps professionals write and publish LinkedIn posts. You talk to HAI on WhatsApp. HAI helps you shape your thoughts into posts and, when you approve them, publishes them to your LinkedIn.

This policy tells you what we collect, where it lives, who can reach it, and what you can ask of us. We have tried to write it so that every sentence is something we could prove on request.

What we collect

To provide the service

What Why
Your WhatsApp phone number It is how we recognise you. It is also your account identifier.
Your messages: text, voice notes, images The raw material for your posts.
Your drafts and published posts So you can come back to them, and so HAI learns your style.
Notes on your writing style AI-generated observations about how you write, so drafts sound like you.
Authorisation to post on LinkedIn Granted by you through LinkedIn's own permission screen.
A record of your consents When you accepted these terms, which policy version was in force, and whether you turned proactive messages on or off. Kept as a history that only accepts new entries, not just a current setting.

You give us during signup

Your name, company, job title, industry, LinkedIn profile URL, preferred language, and optionally a description of your brand voice.

At signup we also run a short background search on your name and company using public web sources, so that HAI's first message can name something true about you. It uses no data beyond what you have already given us, and it does not open your LinkedIn profile page.

If you join the waitlist

If you sign up on our website before becoming a user, we store your email address, where the signup came from, and the fact that you consented to marketing email. That is all. You can unsubscribe from any email we send, or write to us, and we will remove you.

Generated automatically

Timestamps, message counts, and operational records (how long a request took, whether it succeeded, what it cost us to run). These contain no message content.

Other people in your content

A photo or a voice note you send can include other people, like a colleague in a picture or a client you mention. We use that content only to draft your post. We never build profiles of those people, and the same retention and deletion rules apply to it as to everything else you send. Use your own judgment about what you share, as you would in any conversation.

We do not collect passwords, payment card details, or your LinkedIn password. We will never ask for your LinkedIn password, and you should never give it to anyone.

Why we use it

  1. To draft your posts.
  2. To sound like you, by learning your vocabulary and rhythm over time.
  3. To keep context, so you can say "make that shorter" without explaining again.
  4. To publish the posts you have approved.
  5. To keep the service working: spotting failures and watching costs.

We do not sell your data, run advertising, share your style notes with anyone, or use your content to train AI models for other customers.

  • Contract: the processing needed to deliver the service you asked for.
  • Consent: for the personal style profile that makes HAI feel like yours, for proactive messages, and for marketing email if you joined the waitlist. Each consent is recorded with its own timestamp and the policy version that was in force, and you can withdraw any of them at any time.
  • Legitimate interest: keeping the service reliable and secure, in a form that does not identify you.

How we protect it

Encryption. Everything you send travels encrypted (HTTPS), and our hosting provider encrypts the database at rest. Your LinkedIn authorisation sits in a separate secrets vault whose key is managed outside the database. A copy of the database alone would not contain a usable credential.

No public access to the database. The public API roles have no rights to any table. We checked this table by table, and we also changed the database defaults so that new tables get no rights either. Only our own backend can reach your data, using a server key that never leaves it.

Your LinkedIn credential never touches our automation layer. Publishing happens in one dedicated function. It checks the caller with a shared secret and refuses the request if the secret is missing. The automation platform only ever sends an instruction naming you and the post, never the credential.

A change log we cannot rewrite. Since 4 August 2026, every change to your profile or posts goes into an audit log that only accepts new entries. It records what changed, when, and by which system. It never stores the content itself, and no entry can be altered once written, not even by our own application. Entries expire after 12 months. Individual reads are not logged separately; those are covered by our hosting provider's platform logs.

Backups. Our hosting provider keeps daily backups for 7 days. Separately, every night we take our own encrypted copy and store it outside the platform, so your data survives even if we lost the whole hosting account. Those copies are encrypted with a key our storage provider never holds, which means what sits there is unreadable to anyone but us. Nightly copies are kept for 90 days and a snapshot on the first of each month is kept for 12 months, after which it is deleted automatically. When you delete your data, it disappears from live systems immediately and from backup copies as they expire.

Access. Your data is read by our automated backend to run the service, and by one person: our founder, for support and maintenance. No other founder, employee or contractor has access to the database, and no outside party has access for its own purposes. Our accounts with the services that hold your data are protected with two-factor authentication, so a stolen password on its own is not enough to reach anything.

An AI assistant helps with that maintenance work, and it can read your data. We would rather tell you than let you find out. From 19 August 2026 it connects to the database in read-only mode: it can look at what is there, and it cannot change it, delete it, or publish anything. Until that date it can also make changes, because it has been doing the development work that built this service, and we would rather say so than describe a limit that is not in place yet. Changes to the system are decided by a named person. Every change to your profile or posts is written to a log that cannot be rewritten, so if something had been altered, it would show. On the rare occasions the assistant needs to make a change once the restriction is in place, it is lifted deliberately and the change appears in that same record.

What we are still building. The database does not yet enforce per-user isolation internally. It is on our roadmap and recorded in the security architecture document we maintain internally. We tell you this rather than imply protections we have not finished.

Where it is stored

Our database is in Stockholm, Sweden, inside the European Union.

We have data processing agreements in place with our main providers, including the EU standard contractual clauses. Google transcribes your voice notes and describes your images under its paid API terms. Those terms forbid Google from using your content to train its models and from showing it to human reviewers. Google does not limit that processing to the EU, so we do not claim that your voice notes and images never leave the EU.

MailerLite, which sends our waitlist email, is a US company, so its data processing addendum includes the EU standard contractual clauses and took effect when we accepted its terms. The email addresses themselves sit in a Google Cloud data centre in the Netherlands, and MailerLite holds an ISO 27001 certification. If MailerLite discovers a breach affecting our data, it has to tell us within 48 hours.

Our nightly off-platform backup is stored on GitHub, a US company, under a data processing agreement that includes the EU standard contractual clauses. What GitHub holds is ciphertext: the file is encrypted before it leaves our systems, with a key GitHub never receives and cannot derive. The only file we store there unencrypted is a description of the database structure, which contains no personal data.

One thing is still open, and we would rather say so than imply otherwise. n8n, which runs our automation, has not yet confirmed in writing where it processes data. We asked on 4 August 2026 and will update this section when they answer.

We would rather tell you exactly how things are than claim more than we can prove.

How long we keep it

What How long
Conversation history Deleted automatically after 90 days. A job runs every day at 00:05 UTC and permanently removes anything older.
Your drafts Kept until you delete them or close your account.
Posts you published We keep our copy. The live post on LinkedIn is yours and stays until you remove it.
Your profile and style notes Kept while you are a user. Deleted when you ask.
Request records (no message content) 30 days.
Error records 90 days.
Usage, cost and audit records 12 months.
Data export files 7 days. Both download links expire and the files themselves are deleted by the same daily job.
Consent records and rights requests 24 months. These are the evidence that you gave permission and that we answered you, so they outlive the rest.
Waitlist email address Until you unsubscribe or ask us to remove it.

The same daily job also bounds every other table that holds your data, and reports back exactly how many rows it removed from each. Deleting your account does not remove posts already published to LinkedIn. Those are your property, live on LinkedIn's servers, and only you can take them down.

Your rights

Under GDPR you can:

Get a copy of everything. Ask HAI directly in the chat and you get two files. The first is a web page you can open on your phone and read as it is: who you are to us, what HAI has learned about your writing, your posts, your conversations, your consents, and a summary of the technical records we keep. The conversations on that page have HAI’s internal instructions stripped out of them, so what you read is the exchange itself rather than the machinery around it. The second file is the same information as machine-readable JSON, complete and unedited, including the consent history and operational records in full. Both are generated on the spot and delivered as private links that stop working after 7 days, so that a forwarded message cannot expose your data.

Have it deleted. We permanently delete your profile, drafts, scheduled posts, conversation history, style notes, pending messages, per-user records and your stored LinkedIn authorisation. Deletion is deliberately not automated: a request logs itself, starts the clock and goes to a human, because an irreversible action should not fire from a mistyped message. The deletion produces a report for each storage location, so when we confirm, we can show exactly what was removed. Two things survive on purpose. Aggregate reliability, cost and security records are kept, but stripped of any link to you. And your consent history and the record of your deletion request are kept, because they are how we prove you asked and we complied; they expire on their own after 24 months. We last tested the whole procedure with a test account on 4 August 2026.

Correct it. If something we hold about you is wrong, tell us and we will fix it.

Restrict processing. Ask us to stop using your data without deleting it. Useful if you want to pause and come back.

Take it elsewhere. The JSON file is yours to bring to any other service.

Object. You can object to the profiling we do to learn your writing style. That profiling is what makes HAI useful, so objecting may mean the service no longer works well for you. The choice is still yours.

How: tell HAI in the chat, or email matti@haisocialagency.com. Either way the request is logged with the time it arrived. We acknowledge within 5 days and act within 30 at the latest, usually much sooner. You never have to explain why.

Who else is involved

Building this alone would mean building a phone network, a speech recogniser and a language model from scratch. Here is every outside service and exactly what it receives.

Service What it receives Why
WhatsApp (Meta) Your messages, in transit It is the channel you talk to us through
Anthropic Your messages and recent conversation context. At signup, your name, company and title for a short public web search The AI that writes and edits your drafts, and the background search behind your first message. Under our commercial terms it does not train on your content. It retains inputs and outputs for 30 days for safety and security, after which they are removed. We asked Anthropic whether that window could be reduced to zero; it is offered only on enterprise contracts, which we are not yet large enough for, so we will revisit it as we grow
Google Your voice notes and images Transcription and image description. Paid API terms: not used to train models, no human review
Supabase Your stored data Hosts our database (EU, Stockholm)
n8n Message content, in transit. Successful runs store nothing; failed runs are kept briefly for debugging, then expire Runs the automation connecting these pieces
GitHub An encrypted nightly copy of the database, which it cannot read Stores our off-platform backup so your data survives the loss of our hosting account
MailerLite Your email address, only if you joined the waitlist Sends our waitlist email. Stored in the Netherlands. Receives nothing from the service itself
Vercel Your first name (shown on the signup success page) and standard technical logs Hosts our sign-up pages
LinkedIn The post text and image, when you publish Publishing your approved posts

None of these are advertising or behavioural analytics companies, and none of them receive your messages, drafts or style notes for their own purposes. One narrow exception is worth naming rather than glossing over: MailerLite and GitHub each reserve the right to use technical and account-level data about how we use their service for their own business purposes, such as support and product development. That covers our accounts with them, not the content of what you send us.

We used a separate search provider, Tavily, until 7 August 2026. It has been removed and now receives nothing.

Automated decision-making

HAI drafts and suggests. It does not decide.

  • Nothing is published without your explicit instruction. HAI will not post on its own or on a schedule you did not set.
  • If HAI is unsure which draft you mean, it stops and asks. Publishing the wrong thing under your name is the mistake we have worked hardest to prevent.
  • You can ignore anything it suggests, and you can always reach a human at the address above.

We do build an AI-generated profile of your writing style and professional context. It is used only to make your drafts sound like you.

Cookies and tracking

We use no third-party analytics, no tracking pixels, no advertising networks and no behavioural profiling services. Our sign-up pages set no tracking cookies.

We look at aggregate usage patterns, like how many messages and how many posts, to understand whether the service works. That analysis happens inside our own database and is never sent to an advertising or analytics company.

Children

HAI is not intended for anyone under 18. We do not knowingly collect data from children, and will delete it immediately if we discover we have.

Changes to this policy

We update this policy when the system changes. If a change is material, we tell you on WhatsApp rather than quietly editing the page. Every version carries a version number and date at the top.

Changed in version 2.2 (10 August 2026): We audited this policy line by line against the running system and corrected it where the two had drifted apart. Tavily was removed from the service on 7 August and is no longer a processor; the background search now runs through Anthropic. Version 2.1 implied Anthropic retained nothing, which was not accurate: it retains inputs and outputs for 30 days for safety and security, and we now say so. We asked whether that window could be reduced to zero and it cannot at our size, so the policy states the position rather than leaving the question open. MailerLite was added for waitlist email, and GitHub, which stores our encrypted off-platform backup, was never listed at all; both are now described along with the one thing each reserves for itself. Version 2.1 said our audit log could not be deleted by us; entries cannot be altered, but they do expire after 12 months, and the wording now reflects that. The retention table gives the real period for each category instead of one figure for all operational records. Consent records and rights requests now survive account deletion on purpose, because they are the proof that you asked and we complied. Data rights requests can be made directly to HAI in the chat: access requests are fulfilled immediately through a private link that expires in 7 days, while deletion goes to a human deliberately. And we have corrected who can reach your data: one person, not three.

Changed in version 2.3 (published 11 August 2026, takes effect 19 August 2026): We now say plainly that an AI assistant helps with development and maintenance and can read your data, and we describe the limits it works under. From 19 August it connects in read-only mode and cannot change, delete or publish anything; until then it can also make changes. That it can read your data was true before and was simply not written down, and a policy that describes who reaches your data should not leave one of them out. Alongside it we made the audit log genuinely unalterable at the database level rather than only for the application, so the claim in "How we protect it" is now enforced rather than promised.

Added to version 2.2 on 11 August 2026, before this version took effect: The data export now arrives as two files rather than one. Alongside the machine-readable JSON, which is unchanged and still complete, there is a readable web page organised into sections: who you are, what HAI has learned about your writing, your posts, your conversations, your consents, and a summary of the technical records. The conversations shown on that page have HAI’s internal instructions removed, so you read your own exchange rather than the scaffolding our system wraps around it. The JSON keeps the complete stored form, which is the one to take to another service. Both files expire together after 7 days.

Changed in version 2.1 (4 August 2026): The audit log that version 2.0 described as unfinished is now live, and we describe it as what it is: a log of changes, not of reads. Backups now exist and are described. The provider table now says precisely what each service receives; version 2.0 said too little. We also recorded that Google may not use your content for training.

Contact and complaints

Questions or requests: matti@haisocialagency.com Report a privacy concern: same address, subject "Privacy Incident"

If you believe we have mishandled your data, you can complain to the Finnish Data Protection Ombudsman:

Tietosuojavaltuutetun toimisto · tietosuoja.fi · +358 29 566 6700

In short

  • We collect your phone number, your messages, your drafts and notes on your writing style
  • Our database is in the EU. Google processes voice notes and images partly outside the EU, under terms that forbid training on them, and we say so openly
  • Conversations delete themselves after 90 days. Drafts stay until you remove them
  • No provider trains AI models on your content. Anthropic holds inputs and outputs for 30 days for safety checks, which is the shortest window available to a company our size
  • Your LinkedIn credential is encrypted in a separate vault and never passes through our automation layer
  • Our nightly backup leaves the EU, but it is encrypted with a key the storage provider never holds
  • One person can reach the database. Every change to your data is logged in a form nobody can rewrite
  • HAI never posts without your say-so, and asks when it is unsure
  • No tracking, no ads, nothing sold. Ever
  • Ask HAI, and we send you everything or delete everything


Tietosuojakäytäntö, HAI Social Agency

Versio: 2.3 · Voimassa: 19. elokuuta 2026 · Päivitetty: 11. elokuuta 2026

Keitä olemme

HAI Social Agency Oy
Y-tunnus: 3631226-8
Malminkaari 23, 00700 Helsinki
matti@haisocialagency.com

Olemme tekoälyavusteinen palvelu, joka auttaa ammattilaisia kirjoittamaan ja julkaisemaan LinkedIn-postauksia. Keskustelet HAIn kanssa WhatsAppissa. HAI muotoilee ajatuksesi postaukseksi ja julkaisee sen LinkedIniin, kun sinä hyväksyt sen.

Olemme pyrkineet kirjoittamaan tämän niin, että jokainen lause on sellainen, jonka pystymme pyydettäessä osoittamaan todeksi.

Mitä keräämme

Palvelun toimintaan

Mitä Miksi
WhatsApp-puhelinnumerosi Sillä tunnistamme sinut. Se on myös tilitunnuksesi.
Viestisi: teksti, ääniviestit ja kuvat Postaustesi raaka-aine.
Luonnoksesi ja julkaistut postaukset Jotta voit palata niihin ja HAI oppii tyylisi.
Muistiinpanot kirjoitustyylistäsi Tekoälyn havaintoja siitä, miten kirjoitat.
Lupa julkaista LinkedIniin Annat sen LinkedInin omalla lupasivulla.
Merkinnät antamistasi suostumuksista Milloin hyväksyit ehdot, mikä versio oli silloin voimassa ja oletko ottanut oma-aloitteiset viestit käyttöön. Säilytetään historiana, johon voi vain lisätä merkintöjä.

Annat rekisteröityessäsi: nimi, yritys, titteli, toimiala, LinkedIn-osoite, kieli ja halutessasi kuvaus brand voicestasi.

Rekisteröitymisen yhteydessä teemme lisäksi lyhyen taustahaun nimestäsi ja yrityksestäsi julkisista verkkolähteistä, jotta HAIn ensimmäinen viesti osaa mainita sinusta jotain todellista. Haku ei käytä muuta kuin sen, minkä olet meille jo antanut, eikä se avaa LinkedIn-profiiliasi.

Jos liityt jonotuslistalle: tallennamme sähköpostiosoitteesi, mistä ilmoittautuminen tuli ja sen, että annoit suostumuksen markkinointisähköpostiin. Ei muuta. Voit peruuttaa tilauksen mistä tahansa lähettämästämme viestistä tai kertoa meille, jolloin poistamme sinut.

Syntyy automaattisesti: aikaleimat, viestimäärät ja tekniset ajotiedot (kesto, onnistuiko, mitä maksoi). Näissä ei ole viestien sisältöä.

Muut ihmiset sisällössäsi. Lähettämässäsi kuvassa tai ääniviestissä voi näkyä tai kuulua muita ihmisiä, vaikkapa kollega kuvassa tai asiakas josta kerrot. Käytämme sisältöä vain postauksesi laatimiseen. Emme koskaan rakenna profiileja näistä ihmisistä, ja sisältöön pätevät samat säilytys- ja poistosäännöt kuin kaikkeen muuhunkin. Harkitse itse mitä jaat, kuten missä tahansa keskustelussa.

Emme kerää salasanoja, maksukorttitietoja emmekä LinkedIn-salasanaasi. Emme koskaan kysy LinkedIn-salasanaasi.

Miksi käytämme tietoja

Luonnosten kirjoittamiseen, oman äänesi jäljittelyyn, keskustelun muistamiseen, hyväksymiesi postausten julkaisuun ja palvelun toimivuuden varmistamiseen.

Emme myy tietojasi, tee mainontaa, jaa tyylimuistiinpanojasi kenellekään emmekä käytä sisältöäsi tekoälymallien kouluttamiseen muille asiakkaille.

Oikeusperuste: sopimus (palvelun toimittaminen), suostumus (henkilökohtainen tyyliprofiili, oma-aloitteiset viestit ja markkinointisähköposti jos liityit jonotuslistalle) sekä oikeutettu etu (palvelun luotettavuus ja tietoturva tunnistamattomassa muodossa). Jokainen suostumus kirjataan omalla aikaleimallaan ja sillä käytäntöversiolla, joka oli silloin voimassa, ja voit perua minkä tahansa niistä milloin tahansa.

Miten suojaamme tiedot

Salaus. Kaikki liikenne on salattua (HTTPS), ja palveluntarjoaja salaa tietokannan levytilan. LinkedIn-valtuutuksesi on erillisessä salaisuusholvissa, jonka avainta hallitaan tietokannan ulkopuolella. Pelkkä kopio tietokannasta ei siis sisällä toimivaa tunnistetta.

Tietokantaan ei pääse julkisesti. Julkisilla rajapintarooleilla ei ole oikeuksia yhteenkään tauluun. Tarkistimme tämän taulu taululta ja muutimme myös oletusasetukset niin, etteivät uudetkaan taulut saa oikeuksia. Tietoihin pääsee vain oma taustajärjestelmämme.

LinkedIn-tunniste ei kulje automaatiokerroksen läpi. Julkaisu tapahtuu yhden erillisen funktion kautta. Se tunnistaa kutsujan jaetulla salaisuudella ja kieltäytyy, jos salaisuus puuttuu. Automaatioalusta lähettää vain käskyn, ei koskaan tunnistetta.

Muutosloki, jota kukaan ei voi jälkikäteen muuttaa. 4.8.2026 alkaen jokainen muutos profiiliisi tai postauksiisi kirjautuu lokiin, johon voi vain lisätä merkintöjä. Loki kertoo mikä muuttui, milloin ja minkä järjestelmän toimesta. Itse sisältöä siihen ei koskaan tallenneta, eikä yhtäkään merkintää voi kirjoittamisen jälkeen muuttaa, ei myöskään oma sovelluksemme. Merkinnät vanhenevat 12 kuukaudessa. Yksittäisiä lukukertoja ei kirjata erikseen; ne kattaa palvelualustan oma loki.

Varmuuskopiot. Palveluntarjoaja säilyttää päivittäiset varmuuskopiot 7 päivää. Sen lisäksi otamme joka yö oman salatun kopion ja tallennamme sen alustan ulkopuolelle, jotta tietosi säilyvät silloinkin, jos koko hosting-tili menetettäisiin. Kopiot on salattu avaimella, jota tallennuspalvelu ei koskaan saa, joten siellä oleva tiedosto on muille kuin meille lukukelvoton. Yökopiot säilytetään 90 päivää ja kunkin kuukauden ensimmäisen päivän tilannekuva 12 kuukautta, minkä jälkeen se poistetaan automaattisesti. Kun poistat tietosi, ne katoavat käytössä olevista järjestelmistä heti ja varmuuskopioista niiden vanhetessa.

Pääsy tietoihin. Tietojasi lukee taustajärjestelmä palvelun pyörittämiseen sekä yksi ihminen: perustajamme, ylläpitoon ja tukeen. Kenelläkään muulla perustajalla, työntekijällä tai alihankkijalla ei ole pääsyä tietokantaan, eikä kukaan ulkopuolinen saa tietojasi omiin tarkoituksiinsa. Tilimme niissä palveluissa, joissa tietosi ovat, on suojattu kaksivaiheisella tunnistautumisella, joten pelkkä varastettu salasana ei riitä mihinkään.

Kehitys- ja ylläpitotyössä on apuna tekoälyavustaja, ja se pystyy lukemaan tietojasi. Kerromme sen mieluummin itse kuin annamme sinun huomata sen. 19.8.2026 alkaen avustaja on yhteydessä tietokantaan vain lukuoikeuksin: se voi katsoa, mitä siellä on, mutta se ei voi muuttaa, poistaa eikä julkaista mitään. Siihen asti se pystyy myös tekemään muutoksia, koska se on tehnyt sen kehitystyön, jolla tämä palvelu on rakennettu, ja kerromme sen mieluummin kuin kuvaamme rajoitusta, joka ei vielä ole voimassa. Järjestelmän muutoksista päättää nimetty ihminen. Jokainen muutos profiiliisi tai julkaisuihisi kirjautuu lokiin, jota ei voi jälkikäteen muuttaa, joten jos jotain olisi muutettu, se näkyisi. Niissä harvoissa tilanteissa, joissa avustajan on tehtävä muutos rajoituksen voimaantulon jälkeen, rajoitus poistetaan tarkoituksella ja muutos näkyy samassa merkinnässä.

Mitä vielä rakennamme. Tietokanta ei vielä eristä käyttäjiä toisistaan sisäisesti. Se on työn alla ja kirjattu sisäiseen tietoturva-arkkitehtuuridokumenttiimme. Kerromme tämän mieluummin kuin annamme ymmärtää, että kaikki on jo valmista.

Missä tiedot sijaitsevat

Tietokantamme on Tukholmassa Ruotsissa, EU:n alueella.

Tietojenkäsittelysopimukset ovat voimassa pääkumppaneidemme kanssa, EU:n vakiolausekkeet mukaan lukien. Google litteroi ääniviestisi ja kuvailee kuvasi maksullisen rajapintansa ehdoilla. Ehdot kieltävät sisältösi käytön mallien kouluttamiseen ja sen näyttämisen ihmisille. Google ei kuitenkaan rajaa käsittelyä EU:n alueelle, joten emme väitä, että ääniviestit ja kuvat eivät koskaan poistuisi EU:sta.

MailerLite, joka lähettää jonotuslistan sähköpostit, on yhdysvaltalainen yhtiö, joten sen tietojenkäsittelyliite sisältää EU:n vakiolausekkeet ja astui voimaan, kun hyväksyimme sen ehdot. Sähköpostiosoitteet itsessään sijaitsevat Google Cloudin konesalissa Alankomaissa, ja MailerLitellä on ISO 27001 -sertifikaatti. Jos MailerLite havaitsee tietojamme koskevan tietoturvaloukkauksen, sen on kerrottava siitä meille 48 tunnin kuluessa.

Yöllinen alustan ulkopuolinen varmuuskopio säilytetään GitHubissa, joka on yhdysvaltalainen yhtiö, tietojenkäsittelysopimuksella johon sisältyvät EU:n vakiolausekkeet. GitHubilla on hallussaan pelkkää salakirjoitusta: tiedosto salataan ennen kuin se lähtee järjestelmistämme, avaimella jota GitHub ei koskaan saa eikä voi päätellä. Ainoa salaamaton tiedosto siellä on kuvaus tietokannan rakenteesta, eikä se sisällä henkilötietoja.

Yksi asia on yhä auki, ja kerromme sen mieluummin kuin annamme ymmärtää toisin. n8n, joka pyörittää automaatiotamme, ei ole vielä vahvistanut kirjallisesti käsittelyn sijaintia. Pyysimme sen 4.8.2026 ja päivitämme tämän kohdan, kun vastaus saapuu.

Kerromme asiat mieluummin juuri niin kuin ne ovat kuin väitämme enemmän kuin voimme osoittaa.

Säilytysajat

Mitä Kuinka kauan
Keskusteluhistoria Poistetaan automaattisesti 90 päivän jälkeen (ajo joka päivä klo 00:05 UTC)
Luonnokset Kunnes poistat ne tai suljet tilisi
Julkaistut postaukset Säilytämme kopion; LinkedInissä oleva postaus on sinun
Profiili ja tyylimuistiinpanot Käyttäjyyden ajan, poistetaan pyynnöstä
Pyyntölokit (ei sisältöä) 30 päivää
Virhetiedot 90 päivää
Käyttö-, kustannus- ja muutoslokitiedot 12 kuukautta
Vientitiedostot 7 päivää. Molemmat latauslinkit vanhenevat ja tiedostot poistetaan samassa päivittäisessä ajossa
Suostumusmerkinnät ja tietopyynnöt 24 kuukautta. Nämä ovat todiste siitä, että annoit luvan ja että vastasimme sinulle, joten ne säilyvät muita pidempään
Jonotuslistan sähköpostiosoite Kunnes peruutat tilauksen tai pyydät poistoa

Sama päivittäinen ajo rajaa myös kaikki muut tietojasi sisältävät taulut ja raportoi tarkalleen, montako riviä kustakin poistettiin. Tilin poistaminen ei poista jo LinkedIniin julkaistuja postauksia. Ne ovat sinun, ja vain sinä voit poistaa ne.

Oikeutesi

Kopio kaikesta. Pyydä HAIlta suoraan keskustelussa, niin saat kaksi tiedostoa. Ensimmäinen on verkkosivu, jonka voit avata puhelimellasi ja lukea sellaisenaan: kuka olet meille, mitä HAI on oppinut kirjoittamisestasi, julkaisusi, keskustelusi, suostumuksesi ja yhteenveto säilyttämistämme teknisistä merkinnöistä. Sivulla näkyvistä keskusteluista on poistettu HAIn sisäiset ohjeet, joten luet itse keskustelun etkä sen ympärille rakennettua koneistoa. Toinen tiedosto on sama tieto koneluettavana JSON-muodossa, täydellisenä ja muokkaamattomana, suostumushistoria ja tekniset merkinnät kokonaisuudessaan mukaan lukien. Molemmat tehdään saman tien ja toimitetaan yksityisinä linkkeinä, jotka lakkaavat toimimasta 7 päivän kuluttua, jottei edelleen lähetetty viesti paljasta tietojasi.

Poisto. Poistamme profiilin, luonnokset, ajastukset, keskusteluhistorian, tyylimuistiinpanot, odottavat viestit, käyttäjäkohtaiset tiedot ja LinkedIn-valtuutuksen. Poistoa ei ole tarkoituksella automatisoitu: pyyntö kirjautuu, aikaraja alkaa kulua ja asia siirtyy ihmiselle, koska peruuttamaton toimenpide ei saa käynnistyä väärin kirjoitetusta viestistä. Poisto tuottaa erittelyn jokaisesta tallennuspaikasta, joten vahvistaessamme voimme näyttää tarkalleen mitä poistettiin. Kaksi asiaa säilyy tarkoituksella. Kootut luotettavuus-, kustannus- ja turvallisuustiedot säilyvät, mutta ilman yhteyttä sinuun. Lisäksi suostumushistoriasi ja merkintä poistopyynnöstäsi säilyvät, koska juuri niillä osoitamme että pyysit ja me toimimme; ne vanhenevat itsestään 24 kuukaudessa. Testasimme koko menettelyn viimeksi testitilillä 4.8.2026.

Oikaisu. Korjaamme virheelliset tiedot.

Käsittelyn rajoitus. Voit pyytää taukoa ilman poistoa.

Siirrettävyys. JSON-tiedosto on sinun.

Vastustaminen. Voit vastustaa tyyliprofilointia. Se on kuitenkin juuri se, mikä tekee HAIsta hyödyllisen, joten palvelu voi toimia huonommin. Valinta on silti sinun.

Miten: kerro HAIlle keskustelussa tai lähetä sähköpostia osoitteeseen matti@haisocialagency.com. Kummassakin tapauksessa pyyntö kirjataan saapumisaikoineen. Kuittaamme 5 päivässä ja toimimme viimeistään 30 päivässä, yleensä paljon nopeammin. Sinun ei tarvitse perustella.

Ketkä muut ovat mukana

Palvelu Mitä saa Miksi
WhatsApp (Meta) Viestisi siirron aikana Keskustelukanava
Anthropic Viestisi ja lähikonteksti. Rekisteröityessä nimesi, yrityksesi ja titteli lyhyttä julkista verkkohakua varten Tekoäly joka kirjoittaa luonnokset, ja ensimmäisen viestin taustahaku. Kaupallisten ehtojen mukaan sisältöäsi ei käytetä mallien kouluttamiseen. Syötteet ja vastaukset säilyvät 30 päivää turvallisuus- ja väärinkäyttötarkastuksia varten, minkä jälkeen ne poistetaan. Kysyimme Anthropicilta, voisiko tämän lyhentää nollaan; se on tarjolla vain yritystason sopimuksissa, joihin emme vielä kokomme puolesta yllä, joten palaamme asiaan kun kasvamme
Google Ääniviestit ja kuvat Litterointi ja kuvien kuvailu. Maksullisen rajapinnan ehdot: ei mallien koulutukseen, ei ihmistarkastelua
Supabase Tallennetut tiedot Tietokanta (EU, Tukholma)
n8n Viestisisältö siirron aikana. Onnistuneista ajoista ei tallennu mitään; epäonnistuneet säilyvät lyhyen aikaa vianetsintää varten Automaatio
GitHub Salattu yökopio tietokannasta, jota se ei pysty lukemaan Säilyttää alustan ulkopuolisen varmuuskopion, jotta tietosi kestävät hosting-tilin menetyksen
MailerLite Sähköpostiosoitteesi, vain jos liityit jonotuslistalle Lähettää jonotuslistan sähköpostit. Tallennettu Alankomaissa. Ei saa mitään itse palvelusta
Vercel Etunimesi (näkyy rekisteröitymisen valmis-sivulla) ja tavanomaiset tekniset lokit Rekisteröitymissivut
LinkedIn Postauksen teksti ja kuva Julkaisu

Yksikään näistä ei ole mainos- tai käyttäytymisanalytiikkayritys, eikä yksikään saa viestejäsi, luonnoksiasi tai tyylimuistiinpanojasi omiin tarkoituksiinsa. Yksi kapea poikkeus on parempi nimetä kuin sivuuttaa: MailerLite ja GitHub varaavat kumpikin oikeuden käyttää teknisiä ja tilitason tietoja siitä, miten me käytämme heidän palveluaan, omiin liiketoiminnallisiin tarkoituksiinsa, kuten tukeen ja tuotekehitykseen. Tämä koskee meidän tilejämme heillä, ei sitä sisältöä jonka sinä meille lähetät.

Käytimme erillistä hakupalvelua, Tavilya, 7.8.2026 asti. Se on poistettu käytöstä eikä saa enää mitään.

Automaattinen päätöksenteko

HAI ehdottaa, ei päätä.

  • Mitään ei julkaista ilman nimenomaista pyyntöäsi. HAI ei postaa omin päin eikä aikataululla, jota et ole itse asettanut.
  • Jos HAI ei ole varma, mistä luonnoksesta on kyse, se pysähtyy ja kysyy. Väärän postauksen julkaisu sinun nimissäsi on virhe, jonka estämiseen olemme nähneet eniten vaivaa.
  • Voit jättää ehdotukset huomiotta, ja tavoitat aina ihmisen yllä olevasta osoitteesta.

Rakennamme tekoälyn avulla profiilin kirjoitustyylistäsi ja ammatillisesta taustastasi. Sitä käytetään vain siihen, että luonnokset kuulostavat sinulta.

Seuranta ja evästeet

Emme käytä kolmannen osapuolen analytiikkaa, seurantapikseleitä, mainosverkostoja emmekä profilointipalveluita. Rekisteröitymissivumme eivät aseta seurantaevästeitä.

Katsomme koottuja käyttömääriä, kuten viestien ja postausten määriä, jotta ymmärrämme toimiiko palvelu. Analyysi tapahtuu omassa tietokannassamme, eikä sitä lähetetä mainos- tai analytiikkayrityksille.

Lapset

HAI ei ole tarkoitettu alle 18-vuotiaille. Emme tietoisesti kerää lasten tietoja, ja poistamme ne välittömästi jos niitä havaitaan.

Muutokset

Päivitämme käytäntöä, kun järjestelmä muuttuu. Olennaisista muutoksista kerromme WhatsAppissa emmekä vain hiljaisesti muokkaa sivua. Jokaisessa versiossa on versionumero ja päivämäärä.

Muutokset versiossa 2.2 (10.8.2026): Kävimme käytännön läpi rivi riviltä käytössä olevaa järjestelmää vasten ja korjasimme kohdat, joissa nämä kaksi olivat erkaantuneet toisistaan. Tavily poistettiin käytöstä 7.8. eikä ole enää käsittelijä; taustahaku kulkee nyt Anthropicin kautta. Versio 2.1 antoi ymmärtää, ettei Anthropic säilytä mitään, mikä ei pitänyt paikkaansa: se säilyttää syötteet ja vastaukset 30 päivää turvallisuustarkastuksia varten, ja nyt kerromme sen. Kysyimme, voisiko tämän lyhentää nollaan, mutta se ei meidän kokoisellemme yritykselle onnistu, joten käytäntö kertoo tilanteen sellaisena kuin se on eikä jätä kysymystä auki. MailerLite lisättiin jonotuslistan sähköposteihin, ja GitHub, joka säilyttää salatun varmuuskopiomme, puuttui aiemmin kokonaan; molemmat on nyt kuvattu samoin kuin se yksi asia, jonka kumpikin varaa itselleen. Versio 2.1 sanoi, ettemme voi poistaa muutoslokia; merkintöjä ei voi muuttaa, mutta ne vanhenevat 12 kuukaudessa, ja sanamuoto vastaa nyt sitä. Säilytystaulukko kertoo todellisen ajan kullekin tietoryhmälle yhden yhteisluvun sijaan. Suostumusmerkinnät ja tietopyynnöt säilyvät nyt tarkoituksella tilin poiston yli, koska ne ovat todiste siitä että pyysit ja me toimimme. Tietopyynnön voi tehdä suoraan HAIlle keskustelussa: kopiopyyntö toteutuu heti yksityisellä linkillä, joka vanhenee 7 päivässä, kun taas poisto siirtyy tarkoituksella ihmiselle. Lisäksi korjasimme sen, kuka pääsee tietoihisi: yksi ihminen, ei kolme.

Muutokset versiossa 2.3 (julkaistu 11.8.2026, voimaan 19.8.2026): Kerromme nyt suoraan, että kehitys- ja ylläpitotyössä on apuna tekoälyavustaja, joka pystyy lukemaan tietojasi, ja kuvaamme rajat joissa se toimii. 19.8. alkaen se on yhteydessä vain lukuoikeuksin eikä voi muuttaa, poistaa tai julkaista mitään; siihen asti se pystyy myös tekemään muutoksia. Se, että avustaja pystyy lukemaan tietojasi, oli totta jo aiemmin; sitä ei vain oltu kirjoitettu auki, eikä käytäntö joka kertoo kuka pääsee tietoihisi saa jättää yhtä heistä mainitsematta. Samalla teimme muutoslokista aidosti muuttumattoman tietokannan tasolla eikä vain sovelluksen osalta, joten kohdan "Miten suojaamme tiedot" lupaus on nyt teknisesti pakotettu eikä pelkkä lupaus.

Lisätty versioon 2.2 11.8.2026, ennen kuin tämä versio tuli voimaan: Tietojen vienti koostuu nyt kahdesta tiedostosta yhden sijaan. Koneluettavan JSON-tiedoston rinnalla, joka on ennallaan ja edelleen täydellinen, on luettava verkkosivu osioihin jaettuna: kuka olet, mitä HAI on oppinut kirjoittamisestasi, julkaisusi, keskustelusi, suostumuksesi ja yhteenveto teknisistä merkinnöistä. Sivulla näkyvistä keskusteluista on poistettu HAIn sisäiset ohjeet, joten luet oman keskustelusi etkä sitä rakennetta, jonka järjestelmämme kietoo sen ympärille. JSON säilyttää täydellisen tallennetun muodon, ja se on tiedosto, jonka voit viedä toiseen palveluun. Molemmat tiedostot vanhenevat yhtä aikaa 7 päivän kuluttua.

Muutokset versiossa 2.1 (4.8.2026): Versiossa 2.0 keskeneräiseksi kuvattu muutosloki on nyt käytössä, ja kuvaamme sen sinä mitä se on: muutosten lokina, ei lukemisen. Varmuuskopiot ovat nyt olemassa ja kuvattu. Palvelutaulukko kertoo nyt täsmällisesti, mitä kukin palvelu saa; versio 2.0 kertoi liian vähän. Lisäksi kirjasimme Googlen koulutuskiellon.

Yhteystiedot ja valitukset

Kysymykset ja pyynnöt: matti@haisocialagency.com Tietosuojahuoli: sama osoite, otsikko "Privacy Incident"

Valituksen voit tehdä tietosuojaviranomaiselle: Tietosuojavaltuutetun toimisto · tietosuoja.fi · +358 29 566 6700

Lyhyesti

  • Keräämme puhelinnumerosi, viestisi, luonnoksesi ja muistiinpanot tyylistäsi
  • Tietokanta on EU:ssa. Google käsittelee ääniviestit ja kuvat osin EU:n ulkopuolella ehdoilla, jotka kieltävät niillä kouluttamisen, ja sanomme sen suoraan
  • Keskustelut poistuvat 90 päivässä. Luonnokset säilyvät, kunnes poistat ne
  • Yksikään palveluntarjoaja ei kouluta tekoälymalleja sisälläsi. Anthropic säilyttää syötteet ja vastaukset 30 päivää turvallisuustarkastuksia varten, mikä on lyhin meidän kokoisellemme yritykselle tarjolla oleva aika
  • LinkedIn-tunnisteesi on salattuna erillisessä holvissa, eikä se kulje automaatiokerroksen läpi
  • Yöllinen varmuuskopio poistuu EU:sta, mutta se on salattu avaimella, jota tallennuspalvelu ei koskaan saa
  • Yksi ihminen pääsee tietokantaan. Jokainen muutos tietoihisi kirjautuu muotoon, jota kukaan ei voi jälkikäteen muuttaa
  • HAI ei julkaise ilman lupaasi ja kysyy, jos on epävarma
  • Ei seurantaa, ei mainoksia, ei myyntiä. Ei koskaan
  • Pyydä HAIlta, niin lähetämme kaiken tai poistamme kaiken