Privacy Policy
Last updated: 25 September 2026
About Flenno
Flenno is a business analytics service operated by Tmi Lauri Koskensalo, Business ID 3361714-6, Viholankatu 12 A 16, 37120 Nokia, Finland.
This Privacy Policy explains how we handle information when you visit our website, use Flenno, sign in with Google, or connect Google Analytics.
For privacy questions and deletion requests, contact info@flenno.com.
We are responsible for personal information used to administer our business, website and user accounts. When we process personal data on behalf of a customer organisation, its instructions and our Data Processing Agreement govern that processing: https://flenno.com/data-processing-agreement. The customer organisation determines the purposes, or acts on the instructions of its own customer where it is itself a processor.
Information we collect
Depending on the features you use, we process:
Account information, including your name, email address, account identifiers and organisation membership.
Google account information provided during authorisation, connection permissions, and OAuth access and refresh tokens.
Google Analytics account and property information and reporting data, including traffic, engagement, acquisition, campaign and e-commerce performance.
Information you submit to Flenno, including messages, business context and questions, together with generated reports and AI responses.
Technical information, such as IP addresses, access events, timestamps and error logs, used to operate and secure the service.
Business contact and billing information, subscription and payment-status records, and correspondence that you provide when purchasing the service or contacting us.
We receive information directly from you, from your organisation and its authorised users, from connected Google services when you authorise access, and from your interaction with our service and website.
When we act as controller, our legal bases are:
Our legitimate interests in operating and securing the service, administering business customer accounts, answering enquiries, preventing abuse and establishing, exercising or defending legal claims, where those interests are not overridden by your rights.
Performance of a contract, or steps you request before entering one, where you are personally a party to that contract.
Compliance with legal obligations, including accounting and applicable responses to lawful requests.
Your consent for optional website analytics and tracking. You may withdraw that consent through the cookie controls at any time without affecting earlier lawful processing.
The customer organisation determines the legal basis for information we process on its behalf. Google authorisation controls access to your Google account; it does not authorise unrelated uses of your information. Account information needed to authenticate you and administer the service is necessary to provide those features. Optional tracking is not a condition of using Flenno.
Google sign-in and Google Analytics
Google sign-in allows us to authenticate you and associate your identity with your Flenno account. Authentication is handled using WorkOS. We do not receive your Google password.
Connecting Google Analytics is a separate authorisation. With your permission, Flenno reads information from the Google Analytics properties you connect to display reports, analyse performance and generate insights for your organisation.
The Google Analytics integration uses read-only access. It does not modify your Google Analytics configuration. This integration does not request access to Gmail messages, Google Drive files or Google Contacts.
We use Google user data only to provide the features described in this policy. We do not sell it, disclose it to data brokers, use it for advertising or retargeting, or use it to determine creditworthiness.
Flenno’s handling of information obtained through Google APIs follows the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. These restrictions also apply to information derived from Google user data.
AI processing
Flenno uses Amazon Bedrock, including Anthropic and Cohere models, to provide AI-assisted analysis and responses.
Information sent for this processing may include your questions, relevant conversation history, business context, saved insights and reporting data from your connected Google Analytics properties. Processing is limited to information relevant to the feature being provided.
We do not use Google user data to train or improve general-purpose AI or machine-learning models. AWS states that Bedrock inputs and outputs are not used to train AWS or third-party models. Customer-specific information saved within Flenno supports your organisation’s features and is separate from model training. Amazon Bedrock privacy information: https://aws.amazon.com/bedrock/faqs/.
Storage, service providers and access
We use AWS for application hosting, database storage and AI processing, and WorkOS for authentication. These providers process information needed to deliver their respective services. Google processes authorisation and API requests associated with your Google connection.
Application data and encrypted OAuth tokens are stored on AWS infrastructure. Our primary application database is configured in Stockholm, Sweden. The authorised Bedrock arrangement uses EU regions in Sweden, Germany, Ireland, France, Italy and Spain, depending on the model and inference profile. WorkOS authentication involves processing in the United States. AWS global delivery infrastructure and certain security logs also involve processing outside the European Economic Area. The service is therefore not limited to EU-only processing.
Annex 3 of our Data Processing Agreement identifies the authorised application subprocessors, processing functions and locations. AWS's published Service Terms incorporate its Data Processing Addendum, supplementary terms and applicable international-transfer Standard Contractual Clauses. WorkOS's published Data Processing Addendum forms part of its subscription terms and also provides for applicable Standard Contractual Clauses. These terms describe the providers' contractual data-protection and transfer safeguards:
https://aws.amazon.com/service-terms/
https://workos.com/legal/data-processing-addendum
Transfers outside the European Economic Area are subject to applicable data-protection law, using an applicable adequacy decision or appropriate safeguards, including Standard Contractual Clauses and supplementary measures where required. Flenno remains responsible for its own obligations; provider terms do not replace those obligations. Contact info@flenno.com for information about, or a copy of, the relevant transfer safeguards, subject to necessary protection of confidential information.
We use encryption, authentication and access controls to protect information. Within Flenno, technical administrative access to customer data is limited to the Head of Development. Customer content is not routinely read by personnel or used for unrelated purposes.
Human review of Google user data is permitted only with your affirmative agreement to review specific information, where necessary for security, or where required by law. Disclosures required by law or necessary to address security incidents are limited to the relevant information.
Retention, disconnection and deletion
We retain account information, customer analytics, conversations, saved context and generated insights for the active customer relationship and historical reporting, subject to valid deletion requests. These records do not have a single automatic expiry period. At the end of the service, we arrange return or deletion on the organisation's instructions under our Data Processing Agreement. Any necessary exit copy is restricted to returning the data, completing deletion, security or a specific legal requirement. Applicable retrieval rights take priority over deletion that would prevent a requested return.
Our production retention settings are:
Automated database backups: seven days.
Routine application, database, network and security logs: generally 90 days.
Content-delivery access logs: 90 days, with older stored versions retained for a further 30 days after becoming noncurrent.
Selected security and administrative audit records: 1,096 days, approximately three years, from the event. These records can contain account and organisation identifiers, IP addresses, timestamps and actions. They support investigation of security incidents and the establishment, exercise or defence of legal claims, and are not used for marketing.
Manual and final database recovery snapshots remain until explicitly deleted; they are outside the seven-day automated-backup cycle. We review them when handling deletion and retain them only while necessary for a documented recovery or legal purpose, with restricted access. They are deleted when that purpose ends. Deletion instructions are reapplied before restored data is returned to ordinary service.
When a request includes authentication information held by WorkOS, we arrange deletion through WorkOS's available procedures. Personal data retained in WorkOS backup and archival systems is deleted in accordance with WorkOS's applicable data retention schedule. Its Data Processing Addendum describes those retained copies: https://workos.com/legal/data-processing-addendum. Deleting information from Flenno does not itself confirm deletion from every external system or backup.
Account deletion does not automatically remove security audit records retained for the purposes above. We assess applicable erasure rights and objections individually and explain any justified retention. Billing and statutory business records are kept for the periods required by applicable law. Enquiry and support correspondence is kept for as long as needed to resolve the matter and address related contractual or legal obligations. These criteria do not permit indefinite retention for unrelated purposes.
You can disconnect a Google Analytics integration in Flenno to stop further synchronisation. Disconnecting an individual integration does not automatically delete previously imported data or the underlying Google authorisation.
The option to disconnect Google entirely removes the stored active OAuth tokens and initiates a request to revoke Google authorisation. You can also revoke Flenno’s access directly through your Google Account connections: https://myaccount.google.com/connections.
Revoking Google access does not automatically delete data already stored in Flenno. To request deletion of your account information or your organisation’s imported data and generated insights, contact info@flenno.com. We may verify your identity and authority to request deletion.
We handle valid deletion requests without undue delay and within applicable legal deadlines. Deletion may require manual steps and coordination with service providers. We may verify identity and authority proportionately; an internal approval step does not restart a statutory deadline. Our response identifies any remaining copies, their retention basis and the applicable deletion schedule or criteria.
Deleting an individual user account does not automatically delete the organisation's shared data. Our Data Processing Agreement describes secure CSV/JSON returns, subprocessor deletion, backup expiry and completion notices. We explain any lawful retention exception and distinguish completed deletion from copies still awaiting scheduled backup expiry.
Website cookies and analytics
Our public website is hosted using Framer and provides a cookie banner through Framer.
We use Google Analytics to understand website usage, Leadfeeder to identify visiting organisations and assess business interest, and Microsoft Clarity for heatmaps and session recordings. These services may process browsing activity, device information, online identifiers and, depending on the service, IP addresses and interactions with website content.
Microsoft acts as an independent controller for Clarity data. Its terms allow processing for its own services and advertising, and the use of non-personal data for research and AI development. See the Microsoft Privacy Statement: https://privacy.microsoft.com/en-us/privacystatement.
Website tracking is separate from the Google Analytics data that customers authorise Flenno to import. Customer Google API data is not provided to website tracking services for advertising.
Optional website analytics and tracking start only after consent. You can reject optional tracking or change and withdraw your choices through the website's cookie controls. Necessary storage used for authentication, security and remembering your choices operates as required to provide those functions. Application preferences may also be stored locally in your browser.
Website tracking does not capture authenticated customer content, OAuth credentials, imported customer reports or AI conversations. Cookie names, purposes and lifetimes are explained in the cookie information available through our website. Website analytics retention depends on the relevant service and configured settings; the application log periods in section 6 do not describe website analytics. Further information is available in our Cookie Policy: https://flenno.com/cookie-policy.
Your rights
Depending on applicable law, you may request access to, correction or deletion of your personal information, restriction of processing, or data portability, and may object to certain processing. You may withdraw consent where processing relies on consent.
Contact info@flenno.com to exercise these rights. We normally respond within one month. Where your organisation controls the relevant information, we may refer your request to it or assist it in responding.
You may also lodge a complaint with the Finnish Data Protection Ombudsman (https://tietosuoja.fi/en) or your local supervisory authority.
Changes to this policy
We may update this policy to reflect changes to Flenno or its data processing. We will publish the updated version on this page. If we introduce a new use of Google user data that requires additional authorisation, we will explain the change and obtain that authorisation before proceeding