Privacy Policy
Valid from 6 August 2026 · Last updated 6 August 2026
1. Data controller
Mainetoimisto Kleos Oy
Company registration number (Finland): 3491352-9
Address: Lepolantie 96, 00660 Helsinki, FINLAND
Email: support@dotidydone.com
Website: www.dotidydone.com
Data Protection Officer:
Jaakko Hänninen
Email: dataprotection@dotidydone.com
This policy explains how we process personal data in connection with the DoTidyDone website, app, customer service, invoicing and marketing.
2. Roles of the data controller and data processor
DoTidyDone acts as either a data controller or a data processor in different situations.
We act as a data controller when we process:
- customer and user account data
- data relating to orders, invoicing and payments
- customer service communications
- usage and log data from the website and app
- data relating to the security of the service
- data relating to marketing and the referral programme
- statistics required for business development.
In such cases, we determine the purposes and means of processing personal data.
We act as a data processor when we process the following on behalf of the customer:
- information on cleaners and other users invited by the customer
- usernames added by the customer
- personal data relating to cleaning cards, tasks, comments and observations
- images added by the customer or a cleaner
- other personal data stored by the customer in the Service.
In these situations, the customer ordering the Service acts as the data controller. The customer is responsible for ensuring that they have the right to process the data and that data subjects are provided with the necessary information regarding the processing.
This privacy notice primarily describes processing in which DoTidyDone acts as the data controller. Processing carried out on behalf of the customer is also described in the terms of use and in any separate data processing agreement.
3. Whose data do we process?
We may process the data of individuals belonging to the following groups:
- Customers and account holders of the Servicecustomer contact personsService administratorscleaners, employees and subcontractorsindividuals who have started a free trialreferrers and referred customersindividuals who contact customer serviceusers of the website and the Servicesubscribers to newsletters and other marketing materialspotential partners.4. What personal data do we process?We only process data that is necessary for the purposes described below.4.1 Account and identification detailsWe do not receive the user’s password from Google or Apple.
- name
- email address
- username
- organisation name
- job title or role
- user account ID
-
-
-
- login method
- necessary identification data obtained via Google or Apple login
- language selection
- user account status
- account creation and update times.
- 4.2 Customer and subscription details
- Subscribed service and billing cycle
- Number of properties and access rights
- Trial period details
- Subscription start, renewal and end dates
- Details relating to price, discounts and account credits
- Billing name and address
- company registration number
- VAT number
- country and other information required for tax purposes
- invoice and payment history
- payment references and payment status
- the payment service provider’s customer or payment identifier.
- -
- As a rule, we do not store the full payment card number or the card’s security code. The payment service provider processes payment card details within its own system.4.3 Information relating to the use of the serviceWhen we process this data on behalf of the customer rather than for our own purposes, we act as a data processor.4.4 Customer service and communication data4.5 Referral programme dataWe do not disclose any unnecessary information to the referrer regarding the referred person’s account or payments. The referrer can, for example, see whether a referral eligible for a reward has been successful.
- personal referral code or link
- referrer’s user ID
- referred customer’s user ID
- date of referral
- status of trial and paid subscription
- credits awarded, used and remaining
- contact, device, payment and account details necessary to prevent misuse.
- contacts and messages
- support requests
- feedback and suggestions for improvement
- notes from calls or meetings
- images and files attached to messages
- times of communication
- actions taken by customer service.
- login times
- IP address
- browser and device details
- operating system
- session and cookie identifiers
- features used
- items, properties and tasks created or edited
- times of user actions
- start and end times of cleaning sessions
- tasks completed and skipped
- error, crash and performance data
- log data relating to security and suspected misuse.
4.6 Marketing information
- email address
- name and organisation
- marketing consents and opt-outs
- newsletter subscription
- information regarding messages sent
- message open and click-through data, if such tracking is used
- stated areas of interest
- campaign and source data.
4.7 Content stored by the Customer in the Service
The Customer may store the following in the Service, for example:
- cleaners’ names or ID numbers
- property addresses
- door codes and key locations
- images
- tasks and work instructions
- comments and observations
- information on defects, damage or work carried out.
With regard to this information, the Customer generally acts as the data controller and DoTidyDone as the data processor.
The Service is not intended to store data belonging to special categories of personal data, such as health data, nor personal identification numbers, images of payment cards, identity documents or other unnecessary sensitive material.
5. Where do we obtain personal data from?
We obtain data:
- from the individual themselves during registration, when placing an order and when contacting us
- from the customer’s organisation
- from an administrator invited by the customer to the Service
- from Google or Apple sign-in services
- from a payment service provider
- from technical logs generated automatically through the use of the Service
- through the use of cookies and similar technologies
- via referral links and campaigns
- from public sources of company and contact details, within the limits permitted by law.
Information about cleaners and other users added to the Service by the customer is primarily obtained from that customer.
6. Purposes and legal bases for the processing of personal data
6.1 Provision of the Service and user account
We process data:
- to create a user account
- to identify the user
- to enable login
- to provide the Service’s functions
- to manage access rights
- to manage bookings and accommodation.
Legal basis: performance of a contract or pre-contractual measures.
Where the Customer is an organisation and the user is acting on its behalf, processing may also be based on our legitimate interest in providing the Service to the Customer’s contact persons and users.
6.2 Invoicing, payment and taxation
We process data:
- to receive payments
- to issue invoices
- to monitor payments
- to calculate value added tax
- to fulfil accounting and tax obligations
- to prevent payment fraud and misuse.
Legal basis: performance of a contract, a legal obligation and a legitimate interest in preventing misconduct.
6.3 Customer service and communication
We process data:
- to respond to support requests
- to resolve issues
- to send notifications regarding the Service
- to carry out onboarding communications
- to process feedback.
Legal basis: performance of a contract and legitimate interest in providing customer service and developing the customer relationship.
6.4 Service security and prevention of misuse
We process data:
- to identify users and the Service
- to prevent unauthorised use
- to monitor failed login attempts
- to manage sessions
- to investigate technical faults
- to combat fraud, spam and misuse of the referral programme
- to establish, exercise or defend legal claims.
Legal basis: our legitimate interest in safeguarding the Service, users and our business, and, where necessary, compliance with legal obligations.
6.5 Service development and analytics
We process usage and technical data:
- to measure the Service’s performance
- to rectify errors
- to improve the user experience
- to understand how features are used
- to plan capacity
- to compile anonymised statistics.
Legal basis: our legitimate interest in developing and maintaining the Service.
If analytics are based on cookies or similar technologies other than those that are strictly necessary, processing is based on consent where required.
6.6 Referral programme
We process data:
- to match recommendations with the correct users
- to award rewards
- to manage refunds
- to monitor compliance with the terms and conditions
- to prevent fraudulent recommendations.
Legal basis: performance of a contract and our legitimate interest in running the programme securely.
6.7 Marketing
We may send messages to existing customers regarding the Service and similar products within the limits permitted by the law on electronic direct marketing.
Electronic direct marketing sent to other individuals is based on consent where such consent is required by law.
An individual may opt out of direct marketing at any time via the link provided in each marketing message or by contacting us.
Legal basis: consent or legitimate interest in accordance with applicable law.
6.8 Compliance with legal obligations
We process data, for example:
- to fulfil accounting obligations
- to respond to requests from public authorities
- to process consumer cancellation and complaint data
- to fulfil data protection and data security obligations.
Legal basis: a legal obligation.
7. Balancing test for legitimate interests
Where processing is based on a legitimate interest, we assess:
- whether the processing is necessary to fulfil the specified interest
- what kind of data is processed
- what the individual can reasonably expect
- what impact the processing may have on the individual
- whether the objective can be achieved in a way that has less impact on privacy
- what technical and organisational measures can be taken to mitigate the risks.
Our legitimate interests include, in particular, providing the Service to users of our organisational clients, managing customer relationships, developing the Service, ensuring data security, preventing misuse and preparing for legal claims.
The data subject may request further information on the balancing test by contacting the address mentioned in section 1.
8. Automated decision-making and profiling
We do not make decisions based on personal data that would have legal effects on the data subject or similarly significant effects solely on the basis of automated processing.
We may use automated rules, for example:
- to limit failed login attempts
- to identify suspicious payments or recommendations
- to prevent spam and misuse.
Such measures may result in a temporary lock or review. An individual may request a manual assessment of the situation by contacting customer service.
9. To whom do we disclose or grant access to data?
We may disclose data or grant access to data to the following recipients to the extent necessary:
Service providers and data processors
- hosting and cloud services
- database and file storage services
- Google and Apple sign-in services
- payment service providers
- email and messaging services
- customer service systems
- analytics and error-tracking solutions
- accounting and financial management services
- information security and technical experts.
Authorities and legal advisers
We may disclose information to authorities, courts, debt collection agencies, insurance companies or legal advisers when:
- it is required by law
- a public authority makes a lawful request
- it is necessary for the performance of a contract
- it is necessary for the establishment, exercise or defence of legal claims
- it is necessary to protect individuals, the Service or property.
Corporate transactions
If our business or part of it is sold, merged or reorganised, personal data may be disclosed to the parties to the transaction and their advisers to the extent necessary to evaluate and carry out the transaction.
Data will not be sold to advertisers or other third parties.
10. Data transfers outside the European Economic Area
We endeavour to use service providers that process data within the European Economic Area.
However, some service providers may process data outside the European Economic Area or grant access to such data from such a country.
In such cases, we ensure that the transfer is based on a legal ground in accordance with data protection legislation, such as:
- an adequacy decision by the European Commission
- standard contractual clauses approved by the European Commission
- other safeguards approved by legislation.
Where necessary, we will also assess the legislation of the recipient country and implement supplementary technical, contractual or organisational safeguards.
Further information on data transfers and the safeguards used may be requested from the contact address mentioned in section 1.
11. How long do we retain data?
We retain data only for as long as is necessary for the purpose of processing or to comply with a legal obligation.
The planned retention periods are:
User account data
For the duration of the account’s validity and for a maximum of 90 days after the account has been closed, unless a longer retention period is necessary due to legal claims or statutory obligations.
Free trial data
For the duration of the trial and for a maximum of 24 months after the trial ends, so that we can restore the account, prevent repeated trials and investigate any potential misuse.
Content processed on behalf of the customer
For the duration of the contract and for a maximum of 90 days after the contract ends, after which the data will be deleted or anonymised.
Accounting and payment data
For the period required by accounting legislation and other applicable legislation.
Customer service messages
As a general rule, for a maximum of 3 years from the resolution of the matter. Data relating to legal claims may be retained for longer in accordance with applicable limitation periods.
Usage and security logs
As a general rule, for a maximum of 24 months, unless a specific log is required for a longer period to investigate a data breach, misconduct or a legal claim.
Marketing data
For as long as the marketing consent remains valid or the individual has not objected to marketing. Information regarding a marketing opt-out may be retained permanently to ensure that no further marketing is sent.
Referral scheme data
For the duration of participation in the scheme and the customer relationship, and for a maximum of 3 years following the last referral event or the use of a reward. Data relating to payments and accounting is retained for the period required by law.
Backup copies
Deleted data may remain in backups for up to 90 days. Data in backups is not used in normal business operations and is deleted in accordance with the backup rotation schedule.
Once the retention period has expired, the data is deleted or anonymised so that the individual can no longer be identified.
12. Cookies and similar technologies
We use cookies and similar technologies to provide the Service.
Essential cookies
Essential cookies may be used without separate consent, for example:
- to maintain a logged-in status
- to secure the session
- to remember the language selection
- to ensure data security
- to process orders and the purchasing process
- to save cookie preferences.
Analytics and marketing cookies
Non-essential cookies are used only in accordance with applicable law and, where necessary, with the user’s consent.
These may include, for example:
- visitor analytics
- measuring user experience
- tracking campaign results
- advertising targeting.
For visitor analytics we use Google Analytics 4 (Google Ireland Limited). We use Google Consent Mode v2: before consent, no analytics or marketing cookies are set and only cookieless, coarse information about the page load is sent to Google. Once the user accepts analytics and marketing cookies, measurement continues normally.
Users can change their cookie preferences in the cookie settings.
Further details on the cookies in use, their providers, purposes and expiry dates are provided in the cookie policy or in the cookie settings.
13. How do we protect personal data?
We use technical and organisational security measures appropriate to the nature of the Service, the data being processed and the assessed risks.
These measures may include:
- encrypted network connections
- restriction of access rights
- database-level access control
- secure login methods
- limiting failed login attempts
- automatic session expiry
- confidentiality obligations for staff and subcontractors
- logging and monitoring of anomalies
- updating software and dependencies
- back-up
- assessment of subcontractors’ data protection and information security
- minimisation of personal data.
Access to personal data is granted only to individuals and service providers who require the data to carry out their duties.
Customers are responsible for ensuring that their own user IDs, as well as any links, door codes and other security information shared with cleaners, are properly protected.
14. Data breaches
We will investigate any suspected data breaches involving personal data without delay.
If a breach is likely to pose a risk to the rights and freedoms of natural persons, we will notify the supervisory authority in accordance with applicable legislation.
If the breach is likely to result in a high risk to the data subject, we will also notify the data subject without undue delay, unless an exception provided for by law applies.
When acting as a processor of a customer’s personal data, we will notify the customer without undue delay of any personal data breach affecting their data that we have detected.
15. Rights of the data subject
In situations covered by data protection legislation, the data subject has the right:
- to be informed about the processing of their personal data
- to obtain confirmation as to whether we are processing personal data relating to them
- to obtain a copy of their personal data
- to request the rectification of inaccurate or incomplete data
- to request the erasure of data
- to request the restriction of processing
- to object to processing based on a legitimate interest
- to object to direct marketing at any time
- to receive the data they have provided in a machine-readable format and to transfer it to another data controller, where the conditions are met
- to withdraw their consent at any time, without this affecting the lawfulness of processing carried out prior to withdrawal
- to lodge a complaint with a supervisory authority.
These rights are not absolute. For example, data cannot be erased if its retention is necessary to comply with a legal obligation or to establish, exercise or defend a legal claim.
According to the Data Protection Authority, the data subject’s rights include, amongst other things, the right to be informed about the processing, to access and rectify data, to request erasure or restriction of processing, and to object to processing.
16. Exercising your rights
A request regarding your rights may be sent to:
dataprotection@dotidydone.com
The request must specify in sufficient detail:
- who is making the request
- which right the request concerns
- which user account, organisation or data the request relates to.
We may request further information to verify your identity. We do not request unnecessary personal data.
We will respond to your request without undue delay and, as a rule, within one month. This time limit may be extended in accordance with data protection legislation if the request is complex or if there are multiple requests.
Exercising your rights is, as a rule, free of charge. In cases where a request is manifestly unfounded or unreasonably repetitive, we may, in circumstances permitted by data protection legislation, charge a reasonable fee or refuse to comply with the request.
If the request concerns data that we process on behalf of a client, we will forward the request to the client in question or assist the client in making the request.
17. Right to lodge a complaint
If a data subject considers that personal data has been processed in breach of data protection legislation, they may lodge a complaint with the competent supervisory authority.
In Finland, the supervisory authority is:
The Office of the Data Protection Ombudsman
Up-to-date contact details can be found on the Office of the Data Protection Ombudsman’s website.
We hope that the data subject will contact us first so that we can resolve the matter.
18. Children’s personal data
The Service is intended for adult hosts, businesses and employees. The Service is not aimed at children.
We do not knowingly collect children’s personal data for our own purposes.
If we become aware that a child’s personal data has been stored on the Service without a legitimate basis, we will take reasonable steps to delete the data.
19. Links and third-party services
The Service may contain links to external websites or services.
We are not responsible for the processing of personal data by third-party services. Users should familiarise themselves with the privacy policies of each third-party service.
20. Changes to the Privacy Policy
We may update this Privacy Policy if:
- the Service or its features change
- we introduce new service providers
- the processing of personal data changes
- legislation or official guidelines change.
The up-to-date policy will be published on the website.
If a change significantly affects data subjects’ rights or the purposes for which personal data is used, we will notify you in an appropriate manner, such as by email or via the Service, before the change takes effect.
The date of the most recent update is stated at the beginning of this policy.
21. Contact details
Questions and requests regarding data protection or the processing of personal data may be sent to:
dataprotection@dotidydone.com