Privacy policy

This privacy notice explains how Tapaaminen.net processes personal data in accordance with the EU General Data Protection Regulation (GDPR). Last updated on 21 September 2026.

1. Data controller and contact details

Tapaaminen.net
help@tapaaminen.net

2. The register and how we use data

The Tapaaminen.net user and meeting register contains data about user accounts and meetings created in the service. We process this data to provide the service and its core functions.

We use data to create and manage meetings, process registrations, maintain user accounts, provide customer support and develop the service. We also process data to prevent misuse and security threats.

Creating an account is not required to use the service. A meeting creator can delete the meeting they created.

3. Why processing is allowed

When you create or use a user account or meeting, processing is necessary to provide the service and manage the service relationship.

For service security, misuse prevention and service development, processing is based on Tapaaminen.net's legitimate interests. We use necessary cookies to ensure the operation and security of the service.

We do not use data for automated decision-making or profiling.

4. Data we process

Depending on how you use the service, we process the following data:

  • user account name, email address, language preference, and account creation and confirmation information;
  • a securely hashed password when password sign-in is used; public passkey credential data and the user-provided name when passkeys are used;
  • a security log: the type and time of a security-setting change and, where applicable, the changed email address or passkey name. The log never stores passwords, confirmation codes, passkey private keys or IP addresses;
  • meeting, registration, comment and selected-time data, including names, email addresses, descriptions, location, messages and meeting settings;
  • technical data necessary for the service, such as session and security cookies, and the IP address of a server request temporarily for purposes such as rate limiting.

We do not store IP addresses in the user or security log. We use a self-hosted Plausible Analytics installation in Finland for aggregate service statistics. Plausible does not use cookies or persistent identifiers to identify individual visitors. See our cookie policy for more information.

5. Sources of data

Most data comes directly from you when you use the service, create a meeting or account, register for a meeting, or contact support. Usage statistics are generated from use of the website without individual tracking.

6. Retention periods

  • User account data is kept for as long as the account is in use or the data is otherwise needed.
  • Incomplete registrations that are not confirmed are deleted after one day.
  • The security log is kept for six months.
  • Deleted individual time slots are permanently removed after 30 days.
  • When a meeting creator deletes a meeting, the meeting and related data are marked as deleted and permanently removed after 90 days.
  • Backups are retained on a rolling basis for no more than 30 days. Data may remain in a backup until that period ends.

7. Disclosure and transfers of data

We do not sell or disclose personal data for commercial or marketing purposes. Data may be processed in the following situations:

  • Service providers: Hetzner processes data in Finland to provide hosting and the database. Amazon SES processes data needed to send service emails in the EU. Our self-hosted Plausible Analytics processes usage statistics in Finland. These providers act as processors on behalf of Tapaaminen.net.
  • Transfers outside the EU and EEA: data is currently processed within the EU or EEA. If a transfer outside the EU or EEA becomes necessary in the future, we will ensure that it has a lawful transfer mechanism, such as the European Commission's standard contractual clauses.
  • Legal obligations: we may disclose data to competent authorities when required by law.

8. Your rights

Under the GDPR, you have the following rights in relation to the processing of your personal data:

  • Right of access: you may request information about the data stored about you.
  • Right to rectification: you may request that inaccurate or incomplete data is corrected.
  • Right to erasure: you may request deletion of your data when there is no longer a basis for processing it.
  • Restriction of processing: you may request restriction of processing in certain situations.
  • Right to object: you may object to processing based on legitimate interests.
  • Data portability: you may request data processed on the basis of a contract or consent in a machine-readable format.
  • Withdrawal of consent: where processing is based on consent, you may withdraw it at any time.

Send requests to exercise your rights to help@tapaaminen.net. We aim to respond within one month. We may ask for further information to verify your identity.

Request your data using the online form.

You may also lodge a complaint with your data protection supervisory authority if you believe that your personal data has been processed unlawfully.

9. Data security

Connections to the service are encrypted. Passwords are not stored in readable form, and passkey authentication stores only public credential data. Access is limited to what is necessary for each task. The security log is available only to service administrators.

10. Cookies and consent management

We use only first-party cookies that are necessary for the operation and security of the service. You can open and change your cookie preferences at any time through the cookie policy.