knxsense

Suomi · English · Deutsch · Français · Español

Privacy Notice

Version 2026-09-22 · Deep Indigo Oy

Controller and contact details

Deep Indigo Oy (Business ID 3579661-9)
Tykistökatu 4, 20520 Turku, Finland
support@knxsense.com

No data protection officer has been designated. Data protection enquiries may be sent to the contact details above.

Controller or processor

The Service Provider is the controller in respect of account data. In respect of data collected from sites, the controller is the customer company and the Service Provider is the processor. The role determines to whom a data subject’s request must be addressed.

1. Account data

DataSourcePurpose
Company name, country, business ID / VAT identification number, address The Customer and public registers Identifying the Customer, invoicing, ensuring that the free trial is used only once
User’s e-mail addressThe user, or the user who invited them Sign-in and communications concerning the service
Password hashThe user Sign-in. The password is not stored in plain text.
Two-step verification key and backup codes (optional) Generated at set-up Protecting sign-in. The key is stored encrypted and only a hash of each backup code is kept; deleted when two-step verification is turned off.
Session identifier (cookie)Automatically Keeping the user signed in. Valid for 30 days at a time and renewed on use; a session ends no later than 90 days after sign-in.
Sign-in attempts: e-mail address, IP address, whether successful Automatically Protecting accounts against password guessing. Deleted within 30 days.
Registration, password reset and verification attempts: IP address, hash of the e-mail address AutomaticallyPreventing misuse
Acceptance of the terms: version, time, IP address, browser identifier AutomaticallyEvidencing the conclusion of the contract
Setup and administration audit trail Automatically Troubleshooting and keeping a record of use of the administration view. Retained for 60 days.
Remote access sessionsAutomatically Record of who has connected to the site’s bus
Notifications sent by the service: recipient, time, whether successful Automatically Evidencing to whom each notification was sent. Retained for 365 days or 13 months depending on the type of notification.
Server access log: time, requested page or API endpoint, response code, browser identifier and network address in truncated form Automatically Troubleshooting and detection of misuse. Only the part of the network address that identifies the operator’s network is logged, not the individual subscriber connection, and the query string of the URL is not logged at all. Retained for 14 days.
Support requests and feedbackThe user Providing support and developing the service

Legal bases for processing (Article 6(1) GDPR):

Providing account data is a requirement for entering into the contract; without it the service cannot be used.

2. Data collected from sites

The KNX bus telegram traffic of a site is recorded: timestamp, addresses and telegram value. In addition, the Customer may store the site’s ETS project and the site’s identification details (address, location and contact person details) in the service.

Bus data is technical data about the devices in a building, but it indirectly reveals the presence and activities of people. Where the site is a dwelling, the data must be processed as personal data. This assessment is made by the customer company that connects the site to the service.

The data subjects are the residents and other users of the site, the site’s contact persons and the persons named in the ETS project.

Identifiable data may be found in particular in the ETS project (for example, personal names in the names of rooms and group addresses, and the names of the project’s authors) and in the site’s identification details. The site’s identification details are stored in encrypted form.

Conversations in the analysis feature are stored per site: the questions, the answers and the user’s ratings of the answers. Extracts of bus data retrieved to produce an answer are not stored in the conversation.

3. Retention periods

Bus data collected from the site
400 days, and available throughout that period
Metrics calculated from the data; ETS project
For as long as the account remains active
Conversations in the analysis feature
For as long as the site remains in the service
Sign-in attempts
30 days
Setup and administration audit trail
60 days
Server access log
14 days
Invitations and password reset links
An invitation link is valid for 7 days and a reset link for 1 hour. The record is deleted 30 days after the link has been used or has expired.
Records of registration, password reset and verification attempts
30 days. The e-mail address is held here only as a hash.
E-mail address verification codes
Deleted within 24 hours after the code has expired or been used.
Records of outage notifications
365 days
Records of fault and price change notifications
13 months
Remote access sessions
For as long as the site remains in the service
Feedback sent through the service
24 months
Name and e-mail address of a closed user account
30 days from closure of the account
Account data
For as long as the account remains active. Accounting records are retained as required by the Finnish Accounting Act (kirjanpitolaki).
Records ensuring that the free trial is used only once
Permanently, only as a hash

4. Location of the data

The server is located in Finland. Backups are stored within the European Union. Some of the subcontractors named in section 5 are established outside the EU; the data transferred to each of them is specified there.

5. Subcontractors

SubcontractorFunction and data transferredLocation
Hetzner Online GmbH Server capacity and backups Finland, EU
Google (Places and map images), independent controller Address search: the text the user types into the address field. Maps: the user’s sites are shown to them on a map whose base layer is fetched from Google to the user’s browser; the area viewed and the user’s IP address are transferred to Google. The coordinates of sites are not sent to Google. United States
Anthropic PBC Language model for the analysis feature, only when the analysis feature is used. Only the minimum data necessary for the answer is disclosed. The site name is not sent. United States
Norwegian Meteorological Institute (MET Norway) Weather data for the site. The site’s location to three decimal places (approximately 100 metres). Norway (EEA)
E-mail service (Resend, Inc.) Messages sent by the service, such as invitations, password resets, outage notifications and fault notifications. The recipient’s address and the content of the message. United States
Stripe Payments Europe Ltd. Payment processing. The company’s billing details. Card details are provided directly to Stripe. Ireland

Transfers to the United States are based on the EU–US Data Privacy Framework (a Commission adequacy decision, Article 45 GDPR) or on the standard data protection clauses adopted by the Commission (standard contractual clauses, Article 46 GDPR). Information on the transfer mechanism used is available on request from the address above.

The customer company’s identifier is additionally checked against the authorities’ public registers (the EU’s VIES system and the YTJ business information system of the Finnish Patent and Registration Office).

6. Recipients of the data within the service

Only users to whom the customer company has granted access to the site in question can access that site’s data. The customer company may invite its own users and share an individual site with a user of another company. Sharing discloses the site’s data to the recipient, and the sharing company, as controller, is responsible for the legal basis of that disclosure. Sharing may be revoked at any time.

The Service Provider’s administrators cannot access a site’s bus data or ETS project without site-specific access rights. The administration view shows subscriptions, users and the names and status of sites and the device models used in them. There is one exception to this: the locations of sites on a map. The administration map shows the names and locations of sites across all customers to an accuracy of approximately ten metres, and nothing else. The map is available only to the Service Provider’s administrator, every access to it is logged, and the log is retained for 60 days. The coordinates of sites are not disclosed to any map service.

7. Rights of the data subject

The data subject has the right of access to data concerning them, the right to rectification of inaccurate data, the right to request erasure of the data, the right to restriction of processing, the right to data portability and the right to object to processing based on legitimate interests.

Requests must be addressed to the controller of the data in question. Requests concerning account data must be sent to the e-mail address above. Requests concerning a site’s data must be addressed to the customer company that connected the site to the service; the Service Provider assists it. Requests are answered within one month.

The data subject has the right to lodge a complaint with a supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi).

8. Security

9. Cookies

The service uses only one strictly necessary session cookie to keep the user signed in. The cookie is valid for 30 days at a time and is renewed on use; a session ends no later than 90 days after sign-in. No tracking, analytics or advertising cookies are used. The map in the site list loads Google’s map script and map images (see section 5).

10. Automated decision-making

The service does not make automated decisions concerning the data subject that would produce legal effects concerning them.

11. Changes to this notice

This notice is updated as the service develops. The Customer will be notified of material changes.

Language versions. This notice has been drawn up in Finnish. Its translations into English, German, French and Spanish have been prepared with the assistance of artificial intelligence. If a translation contains omissions or conflicts with the Finnish-language version, the Finnish-language version shall prevail. This does not restrict the rights of the data subject.

Language versions

This document is a translation of the original Finnish-language Privacy Notice. It has been prepared with the assistance of artificial intelligence. In the event of any omission, discrepancy or conflict between this translation and the Finnish-language version, the Finnish-language version shall prevail. This does not restrict the data subject’s rights under the General Data Protection Regulation or other applicable data protection law. If anything in this translation is unclear, please contact us at support@knxsense.com. The Finnish-language version is available at app.knxsense.com/tietosuoja.

← Registration  ·  Terms of Service