Effective Date: June 2026 | Version: 1.0 | Contact: info@ruso.app
Effective Date: June 2026 | Version: 1.0 | Contact: info@ruso.fi
Cookie Policy
Cookie Policy
Introduction
This Cookie Policy explains how RUSO Oy, referred to as RUSO, we, or us, uses cookies and similar technologies on our website. It should be read together with our Privacy Policy.
What Cookies Are
Cookies are small text files placed on your device when you visit a website. They allow a website to recognize your device and remember certain information about your visit.
Types of Cookies We Use
Strictly necessary cookies. These are required for the website to function, such as maintaining your session and security settings. They cannot be switched off and do not require consent under Finnish and EU law.
Analytics cookies. These help us understand how visitors use our website, such as which pages are viewed and how long visitors stay. We use Firebase Analytics for this purpose, which processes data in the United States under Google's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. These cookies are only set with your consent.
Marketing cookies. [To define: list any advertising or remarketing tools in use, such as Google Ads, Meta Pixel, LinkedIn Insight Tag, or similar, along with what each one does.] These cookies are only set with your consent.
Managing Your Consent
When you first visit our website, you will be shown a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your preferences at any time through [insert: the consent management tool you use, or "the cookie settings link in our website footer"].
Third Party Cookies
Some cookies are placed by third party services we use, such as Google/Firebase for analytics. These third parties may also independently collect data according to their own privacy policies. [Add any additional third party tools here once marketing cookies are defined above.]
How Long Cookies Last
[To define: session cookies (expire when you close your browser) versus persistent cookies (remain for a set period). Specify actual retention periods once your analytics/marketing tools are finalized — Firebase Analytics defaults to 14 months unless configured otherwise, worth confirming your actual setting.]
Changes to This Policy
We may update this Cookie Policy as our use of cookies changes. Material changes will be reflected here with an updated effective date.
Contact us: info@ruso.app
1. Parties and Scope These Terms of Service ("Terms") govern the relationship between RUSO Oy, a company registered in Vantaa, Finland ("RUSO"), and any business entering into a subscription agreement with RUSO ("Customer") for use of the RUSO platform. These Terms apply together with the RUSO Data Processing Agreement ("DPA") and, where licensed, the general terms and conditions of IT2022 YSE. In case of conflict, these Terms take priority for matters they specifically address; IT2022 YSE governs matters not otherwise addressed here.
2. Definitions
"Platform" means the RUSO software service, comprising the web application, the Employee application, and the Scanner application.
"Authorized Users" means individuals the Customer grants access to the Platform, including Customer's own employees.
"Customer Data" means all data submitted to, or generated within, the Platform by or on behalf of the Customer, including operational data and personal data relating to Customer's employees and Customer's own customers.
"Aggregated Data" means Customer Data that has been processed such that it can no longer reasonably be used to identify an individual, a vehicle, or a specific Customer entity, in line with the anonymization standard described in Section 9.
3. The Platform The Platform is a cloud-based logistics management system comprising:
Management interface — used by Customer's supervisory and management staff (operations, finance, executive) to manage orders, fleet, staff, customer relationships, billing, and reporting.
Employee application — used by Customer's staff for shift-based task execution.
Scanner application (Android only) — used with Customer's compatible handheld scanning hardware for warehouse operations.
Each Customer receives an administrator account with full control over its own organization's configuration: onboarding and managing its employees, vehicles, and its own customers' access within the Customer's account. RUSO does not access, modify, or manage Customer Data except as instructed under the DPA or as required to provide support.
4. Fees and Invoicing Fees are billed according to the Customer's agreed subscription tier and billing cycle. Customers on a monthly contract are invoiced monthly in advance. Customers on an annual contract are invoiced annually in advance. Invoicing continues for the full duration of the agreed contract term. Late payment may result in a formal notice and, if unresolved, suspension of access until outstanding amounts are settled in full.
5. Data Protection and GDPR Compliance
5.1. Roles. With respect to Customer Data that constitutes personal data, RUSO acts as a data processor and the Customer acts as the data controller, as those terms are defined under the General Data Protection Regulation ("GDPR"). RUSO processes personal data only on the Customer's documented instructions, as set out in the DPA.
5.2. Customer responsibilities. The Customer is solely responsible for establishing a valid legal basis for all personal data processed through the Platform, including data relating to its employees, and for providing all legally required notices to its employees and other data subjects. Where local employment or privacy legislation (including the Act on the Protection of Privacy in Working Life) imposes additional obligations on employers using monitoring or tracking functionality, meeting those obligations — including necessity assessments, advance notice, and any required consultation with employee representatives — is the Customer's sole responsibility, not RUSO's.
5.3. Data subject rights. RUSO will provide reasonable assistance to the Customer in responding to data subject access, correction, or deletion requests, as set out in the DPA. RUSO will not withhold assistance on the basis that a request came from an individual rather than the Customer.
5.4. Aggregated Data. RUSO may use Aggregated Data for product improvement, benchmarking, and analytics offerings, including across multiple customers, provided the aggregation meets a minimum group-size threshold sufficient to prevent identification of any individual, vehicle, or specific Customer, as further described in the DPA. RUSO will not use identifiable Customer Data for these purposes without a separate, explicit agreement with the affected Customer.
5.5. International transfers. Any transfer of personal data outside the European Economic Area will be made subject to an approved transfer mechanism (such as Standard Contractual Clauses) as required under GDPR.
6. Data Security RUSO maintains technical and organizational security measures appropriate to the nature of the data processed, as detailed in the DPA's security exhibit. [Insert only measures/certifications RUSO actually holds — encryption standards, hosting location, access controls, sub-processor list, and any completed audits or certifications. Do not reference a certification RUSO has not obtained.]
7. Service Availability and Support RUSO provides customer support on a 24/7 basis. Customers experiencing an urgent issue may contact RUSO's on-call support team directly by phone rather than relying solely on email. [Insert defined response and resolution time targets by severity level — an unqualified "swift" commitment isn't enforceable and should be replaced with actual numbers before this is signed.]
8. Intellectual Property RUSO retains all right, title, and interest in the Platform, including its software, design, and underlying technology. Nothing in these Terms transfers ownership of the Platform to the Customer. The Customer retains ownership of Customer Data, subject to RUSO's rights regarding Aggregated Data under Section 5.4.
9. Confidentiality Each party will protect the other's confidential information with reasonable care and use it only for purposes of performing under these Terms, for the duration of the agreement and a reasonable period following termination.
10. Liability [This section needs specific figures agreed with legal counsel — a cap tied to fees paid over a defined period, carve-outs for gross negligence/willful misconduct and for GDPR-related fines caused by each party's own non-compliance, and exclusion of indirect/consequential damages, consistent with standard IT2022 liability structure.]
11. Term and Termination This agreement remains in effect for the contract term agreed at signing. Either party may terminate in accordance with the termination provisions set out in the signed contract. Termination takes effect on the first day of the calendar month following the applicable notice period. Following termination, Customer Data will be deleted within 14 working days, except where retention is required by applicable law.
12. Amendments RUSO may amend these Terms. Customers will be notified by direct phone contact and provided with the updated Terms in writing prior to the changes taking effect. Material changes affecting data processing will require the Customer's affirmative acknowledgment before taking effect.
13. Governing Law and Dispute Resolution These Terms are governed by the laws of Finland. Any dispute arising from these Terms will be finally resolved by arbitration administered by the Finland Chamber of Commerce, seated in Helsinki, Finland, to the exclusion of ordinary courts.
14. Force Majeure Neither party is liable for delay or failure to perform caused by circumstances beyond its reasonable control, including outages of third-party infrastructure providers.
This is now structurally complete but has several bracketed placeholders that need real numbers/facts before it's usable — liability caps, SLA response times, and the actual security measures/certifications RUSO holds. Those aren't things I should fill in with placeholder-sounding figures; they need to reflect what RUSO can actually commit to. Once you have those, this should go to a Finnish lawyer for a final pass, particularly Sections 5, 10, and 13, before it's used in any real customer contract.