knxsense
Suomi · English · Deutsch · Français · Español
Privacy Notice
Version 2026-09-22 · Deep Indigo Oy
Controller and contact details
Deep Indigo Oy (Business ID 3579661-9)
Tykistökatu 4, 20520 Turku, Finland
support@knxsense.com
No data protection officer has been designated. Data protection enquiries may be sent to the contact details above.
Controller or processor
The Service Provider is the controller in respect of account data. In respect of data collected from sites, the controller is the customer company and the Service Provider is the processor. The role determines to whom a data subject’s request must be addressed.
1. Account data
| Data | Source | Purpose |
|---|---|---|
| Company name, country, business ID / VAT identification number, address | The Customer and public registers | Identifying the Customer, invoicing, ensuring that the free trial is used only once |
| User’s e-mail address | The user, or the user who invited them | Sign-in and communications concerning the service |
| Password hash | The user | Sign-in. The password is not stored in plain text. |
| Two-step verification key and backup codes (optional) | Generated at set-up | Protecting sign-in. The key is stored encrypted and only a hash of each backup code is kept; deleted when two-step verification is turned off. |
| Session identifier (cookie) | Automatically | Keeping the user signed in. Valid for 30 days at a time and renewed on use; a session ends no later than 90 days after sign-in. |
| Sign-in attempts: e-mail address, IP address, whether successful | Automatically | Protecting accounts against password guessing. Deleted within 30 days. |
| Registration, password reset and verification attempts: IP address, hash of the e-mail address | Automatically | Preventing misuse |
| Acceptance of the terms: version, time, IP address, browser identifier | Automatically | Evidencing the conclusion of the contract |
| Setup and administration audit trail | Automatically | Troubleshooting and keeping a record of use of the administration view. Retained for 60 days. |
| Remote access sessions | Automatically | Record of who has connected to the site’s bus |
| Notifications sent by the service: recipient, time, whether successful | Automatically | Evidencing to whom each notification was sent. Retained for 365 days or 13 months depending on the type of notification. |
| Server access log: time, requested page or API endpoint, response code, browser identifier and network address in truncated form | Automatically | Troubleshooting and detection of misuse. Only the part of the network address that identifies the operator’s network is logged, not the individual subscriber connection, and the query string of the URL is not logged at all. Retained for 14 days. |
| Support requests and feedback | The user | Providing support and developing the service |
Legal bases for processing (Article 6(1) GDPR):
- Performance of a contract (b): account, sign-in, invoicing, service notifications, remote access and support.
- Legal obligation (c): bookkeeping and verification of VAT identification numbers.
- Legitimate interests (f): protecting the service and accounts against misuse (sign-in and registration attempts, audit trail, access log, ensuring that the free trial is used only once), evidencing acceptance of the terms, and developing the service on the basis of feedback.
Providing account data is a requirement for entering into the contract; without it the service cannot be used.
2. Data collected from sites
The KNX bus telegram traffic of a site is recorded: timestamp, addresses and telegram value. In addition, the Customer may store the site’s ETS project and the site’s identification details (address, location and contact person details) in the service.
Bus data is technical data about the devices in a building, but it indirectly reveals the presence and activities of people. Where the site is a dwelling, the data must be processed as personal data. This assessment is made by the customer company that connects the site to the service.
The data subjects are the residents and other users of the site, the site’s contact persons and the persons named in the ETS project.
Identifiable data may be found in particular in the ETS project (for example, personal names in the names of rooms and group addresses, and the names of the project’s authors) and in the site’s identification details. The site’s identification details are stored in encrypted form.
Conversations in the analysis feature are stored per site: the questions, the answers and the user’s ratings of the answers. Extracts of bus data retrieved to produce an answer are not stored in the conversation.
3. Retention periods
- Bus data collected from the site
- 400 days, and available throughout that period
- Metrics calculated from the data; ETS project
- For as long as the account remains active
- Conversations in the analysis feature
- For as long as the site remains in the service
- Sign-in attempts
- 30 days
- Setup and administration audit trail
- 60 days
- Server access log
- 14 days
- Invitations and password reset links
- An invitation link is valid for 7 days and a reset link for 1 hour. The record is deleted 30 days after the link has been used or has expired.
- Records of registration, password reset and verification attempts
- 30 days. The e-mail address is held here only as a hash.
- E-mail address verification codes
- Deleted within 24 hours after the code has expired or been used.
- Records of outage notifications
- 365 days
- Records of fault and price change notifications
- 13 months
- Remote access sessions
- For as long as the site remains in the service
- Feedback sent through the service
- 24 months
- Name and e-mail address of a closed user account
- 30 days from closure of the account
- Account data
- For as long as the account remains active. Accounting records are retained as required by the Finnish Accounting Act (kirjanpitolaki).
- Records ensuring that the free trial is used only once
- Permanently, only as a hash
4. Location of the data
The server is located in Finland. Backups are stored within the European Union. Some of the subcontractors named in section 5 are established outside the EU; the data transferred to each of them is specified there.
5. Subcontractors
| Subcontractor | Function and data transferred | Location |
|---|---|---|
| Hetzner Online GmbH | Server capacity and backups | Finland, EU |
| Google (Places and map images), independent controller | Address search: the text the user types into the address field. Maps: the user’s sites are shown to them on a map whose base layer is fetched from Google to the user’s browser; the area viewed and the user’s IP address are transferred to Google. The coordinates of sites are not sent to Google. | United States |
| Anthropic PBC | Language model for the analysis feature, only when the analysis feature is used. Only the minimum data necessary for the answer is disclosed. The site name is not sent. | United States |
| Norwegian Meteorological Institute (MET Norway) | Weather data for the site. The site’s location to three decimal places (approximately 100 metres). | Norway (EEA) |
| E-mail service (Resend, Inc.) | Messages sent by the service, such as invitations, password resets, outage notifications and fault notifications. The recipient’s address and the content of the message. | United States |
| Stripe Payments Europe Ltd. | Payment processing. The company’s billing details. Card details are provided directly to Stripe. | Ireland |
Transfers to the United States are based on the EU–US Data Privacy Framework (a Commission adequacy decision, Article 45 GDPR) or on the standard data protection clauses adopted by the Commission (standard contractual clauses, Article 46 GDPR). Information on the transfer mechanism used is available on request from the address above.
The customer company’s identifier is additionally checked against the authorities’ public registers (the EU’s VIES system and the YTJ business information system of the Finnish Patent and Registration Office).
6. Recipients of the data within the service
Only users to whom the customer company has granted access to the site in question can access that site’s data. The customer company may invite its own users and share an individual site with a user of another company. Sharing discloses the site’s data to the recipient, and the sharing company, as controller, is responsible for the legal basis of that disclosure. Sharing may be revoked at any time.
The Service Provider’s administrators cannot access a site’s bus data or ETS project without site-specific access rights. The administration view shows subscriptions, users and the names and status of sites and the device models used in them. There is one exception to this: the locations of sites on a map. The administration map shows the names and locations of sites across all customers to an accuracy of approximately ten metres, and nothing else. The map is available only to the Service Provider’s administrator, every access to it is logged, and the log is retained for 60 days. The coordinates of sites are not disclosed to any map service.
7. Rights of the data subject
The data subject has the right of access to data concerning them, the right to rectification of inaccurate data, the right to request erasure of the data, the right to restriction of processing, the right to data portability and the right to object to processing based on legitimate interests.
Requests must be addressed to the controller of the data in question. Requests concerning account data must be sent to the e-mail address above. Requests concerning a site’s data must be addressed to the customer company that connected the site to the service; the Service Provider assists it. Requests are answered within one month.
The data subject has the right to lodge a complaint with a supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi).
8. Security
- Traffic is encrypted. The device at the site verifies the server’s certificate and host name, and no unverified or unencrypted connection is ever opened.
- Site-specific access rights are checked on every request.
- Passwords are not stored in plain text, and sensitive fields are stored in encrypted form.
- Sign-in and registration attempts are rate-limited.
- Remote access is disabled by default and requires site-specific permission. It is limited to the KNX bus, and the device at the site initiates the connection outbound from the site. Every session is logged.
- Backups are taken automatically, and restoring from them is practised regularly.
9. Cookies
The service uses only one strictly necessary session cookie to keep the user signed in. The cookie is valid for 30 days at a time and is renewed on use; a session ends no later than 90 days after sign-in. No tracking, analytics or advertising cookies are used. The map in the site list loads Google’s map script and map images (see section 5).
10. Automated decision-making
The service does not make automated decisions concerning the data subject that would produce legal effects concerning them.
11. Changes to this notice
This notice is updated as the service develops. The Customer will be notified of material changes.
Language versions. This notice has been drawn up in Finnish. Its translations into English, German, French and Spanish have been prepared with the assistance of artificial intelligence. If a translation contains omissions or conflicts with the Finnish-language version, the Finnish-language version shall prevail. This does not restrict the rights of the data subject.
Language versions
This document is a translation of the original Finnish-language Privacy Notice. It has been prepared with the assistance of artificial intelligence. In the event of any omission, discrepancy or conflict between this translation and the Finnish-language version, the Finnish-language version shall prevail. This does not restrict the data subject’s rights under the General Data Protection Regulation or other applicable data protection law. If anything in this translation is unclear, please contact us at support@knxsense.com. The Finnish-language version is available at app.knxsense.com/tietosuoja.