Privacy Policy
Effective Date: April 17, 2026
Version: 1.0
1. Introduction
Rightware Oy, a Finnish company (Business ID 2307199-5) ("Rightware," "we," "us," or "our") is committed to protecting your privacy and is the data controller responsible for the processing of your personal data as described in this Privacy Policy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the Kanzi Portal ("Portal"), our websites, and related services.
By creating an account, accepting an invitation, using, or otherwise accessing the Portal, you agree to the terms of this Privacy Policy.
2. Legal Basis for Processing
We process your personal information on the following legal bases:
- Performance of a contract: to provide the Portal, manage your account, process license assignments, and deliver software downloads.
- Legitimate interests: to monitor usage trends, improve our services, and detect and prevent security incidents, where such interests are not overridden by your data protection rights.
- Legal obligation: to comply with applicable laws and regulations.
- Consent: where we rely on consent for any specific processing activity, we will inform you separately. You may withdraw your consent at any time by contacting us.
3. Information We Collect
3.1 Information You Provide
- Account Information: Name, email address, and company name when you register or are invited to the Portal.
- Organization Information: Company details, branch offices, and team structure as configured by your organization administrator.
- Support Requests: Information you provide when submitting support tickets or platform requests.
- Communications: Any correspondence you send to us.
3.2 Information Collected Automatically
- Usage Data: Pages visited, features used, and actions taken within the Portal.
- Device Information: Browser type, operating system, and device identifiers.
- Log Data: IP address, access times, and referring URLs.
- Authentication Data: Session tokens and authentication events managed by our identity provider.
3.3 Information from Third Parties
- Identity Provider: We use Clerk for authentication. Clerk may provide us with profile information associated with your account.
- License Systems: We receive license activation and host information from our licensing infrastructure.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Portal and our services.
- Manage your account, organization membership, and license assignments.
- Process support requests and platform license applications.
- Deliver software downloads authorized by your organization's licenses.
- Send service-related communications (e.g., license expiration notices).
- Monitor and analyze usage trends to improve user experience.
- Detect, prevent, and address security incidents and abuse.
- Comply with legal obligations.
We do not use your personal information for automated decision-making, including profiling, that produces legal effects or similarly significantly affects you.
5. How We Share Your Information
We do not sell your personal information. We may share your information with:
- Service Providers: Third-party services that assist us in operating the Portal, including:
- Clerk (authentication and identity management)
- Vercel (hosting and deployment)
- AWS (file storage and delivery)
- Zendesk (support ticket management)
- Upstash (rate limiting infrastructure)
- Your Organization: Organization administrators can view member information, license assignments, and usage within their organization.
- Legal Requirements: When required by law, regulation, or legal process.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. To request account deletion, send an email to support@rightware.com. We will delete or anonymize your personal information within 90 days of account removal, except where retention is necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
License activation records and audit logs may be retained for up to 3 years for compliance purposes.
7. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption in transit (TLS/HTTPS).
- Role-based access controls within the Portal.
- Rate limiting to prevent abuse.
- Security headers and Content Security Policy enforcement.
- Regular security assessments.
No method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please contact us immediately at privacy@rightware.com.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information.
- Export your data in a portable format.
- Object to or restrict certain processing activities.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority. For users in Finland, the competent authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), www.tietosuoja.fi.
To exercise these rights, please contact us at privacy@rightware.com.
9. International Data Transfers
Rightware is headquartered in Finland. Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws, including the use of standard contractual clauses approved by the European Commission, the EU–U.S. Data Privacy Framework, and other lawful safeguards.
9.1 Mainland China
The Portal and all associated services are hosted on infrastructure located outside mainland China. If you access the Portal from mainland China, all personal data described in this Privacy Policy will be transferred to and processed on servers located in the European Union and the United States. Please refer to Section 10 of our Terms of Use for further details on your responsibilities when accessing the Portal from mainland China.
10. Cookies and Tracking
The Portal uses essential cookies required for authentication and session management. We do not use advertising or tracking cookies. Analytics, if any, are processed in aggregate form.
11. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes are tracked via version control in our source repository. We will notify users of material changes through the Portal or by email.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact us at:
Rightware Oy
Porkkalankatu 3
00180 Helsinki, Finland
Email: privacy@rightware.com