Privacy policy

Last updated: 3 September 2026 · Controller: ID of Life Ltd.

This policy describes how ID of Life Ltd. collects, uses and protects your personal data under the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act. It covers the ID of Life service — your account, the files you store and the payments you make.

1. Controller

ID of Life Ltd., Business ID 3593234-2, Keilaranta 1, 02150 Espoo, Finland. Email info@idof.life. For privacy matters write to the same address.

2. What we process, and why

To run your account we process the email address and username you register with, your password as a cryptographic hash (never in readable form), and an optional postal address if you enter one. Legal basis: performance of a contract (Art. 6.1.b).

To store your files we process the files themselves, their names, sizes, types and version history, plus who shared what with whom. Legal basis: performance of a contract.

When you register, and again before you start a paid plan, you confirm that you have read this policy. We keep a record of that confirmation — which version, when, and where you ticked the box. Legal basis: our legitimate interest in being able to show that we informed you (Art. 6.1.f).

We keep no per-user activity log: no record of your sign-ins, uploads or downloads with your IP address. Our web server writes the usual access log (IP address, time, page, browser), which we use to run the service and to count visits (section 5) and which is deleted after 100 days at the latest. Legal basis: legitimate interest in a secure, working service (Art. 6.1.f).

Paid plans are not active yet: we collect no payment details, and no payment provider receives your data.

3. Where your files are stored

Your files are stored on a private storage network operated by ID of Life on servers in Europe. The network is closed: it is not connected to any public file-sharing network, so knowing a file identifier does not let an outsider retrieve it.

To be precise about what that does and does not mean: files are not individually encrypted with a key only you hold. They are protected by the closed network, by access control in the application and by the security of the servers. End-to-end encryption is on our roadmap and is not in place today. We would rather tell you that plainly than let a padlock icon imply otherwise.

4. Service providers we use

We do not sell your data. Our servers are hosted by OVH in the European Union under a data processing agreement; beyond that, only the people who operate the service come into contact with the systems, and only as far as running them requires.

5. Cookies and tracking

This service sets no tracking cookies, and there is no cookie banner because none is needed. Two kinds of cookie are used, both strictly necessary and therefore exempt from consent:

A session cookie that keeps you signed in, and a short-lived cookie that protects forms against being submitted from another site. Both disappear when you close the browser or sign out.

We count visits from our own server logs with Matomo, which runs on our own server: no tracking script, no cookie, nothing sent to a third party. Matomo keeps your IP address shortened, and its individual records are deleted after 100 days. There is no tag manager, no advertising pixel, and no social-media plug-in anywhere in the service. Web fonts and all other resources are served from our own servers, so simply visiting a page sends nothing to a third party.

6. How long we keep things

Your account data and files are kept for as long as your account exists. When an account or organisation is deactivated, a grace period of 30 days follows before it is removed for good — that window exists so an accidental or disputed closure can be reversed.

Accounting records, once paid plans exist, are kept for six years, as the Finnish Accounting Act requires.

Server access logs and the visit statistics derived from them are deleted after 100 days at the latest. The record of your privacy-policy confirmation is kept as long as your account exists and goes with it.

7. Your rights

You have the right to see what data we hold about you, to have inaccurate data corrected, to have your data deleted, to restrict or object to processing, and to withdraw any consent you have given.

A self-service export does not exist yet, so please write to info@idof.life and we will provide your data in a readable form.

If you believe we handle your data unlawfully you can complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu, tietosuoja.fi).

8. Security

Access to your data requires authentication, and every request is checked against the organisation you are working in. Passwords are stored only as hashes. Traffic between your browser and our servers is encrypted in transit. Administrative interfaces are not reachable from the open internet without authentication. Access to the servers is limited to the people who operate them.

9. Changes to this policy

When the service changes in a way that affects this policy, we update the page and move the date at the top. Substantial changes affecting you as a customer will be announced in the service.