Effective Date: June 2026 | Version: 1.0 | Contact: info@ruso.app

Effective Date: June 2026 | Version: 1.0 | Contact: info@ruso.fi

Privacy Policy

Privacy Policy

1. Introduction

RUSO Oy ("RUSO," "we," "us") provides a logistics management software platform. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with our website and the RUSO platform, and describes your rights regarding that data under the General Data Protection Regulation ("GDPR") and applicable Finnish law.

2. Who We Are

RUSO Oy is based in Vantaa, Finland. For any privacy-related inquiry, including requests to exercise your data protection rights, contact us at info@ruso.app.

3. Data We Collect and Why

We collect the following categories of data, limited to what is necessary for the stated purpose:

  • Website form submissions — name, company, email, and phone number, when you request a demo, pricing estimate, or contact us — used to respond to your inquiry and prepare a pricing proposal.

  • Website analytics and marketing data — collected via cookies and similar technologies, where you have given consent, used to understand site usage, score and prioritize leads, and run remarketing campaigns. See our Cookie Policy for full detail and to manage your preferences.

  • Email, phone, and video meeting interactions — when you contact us directly, used to respond to and document that interaction.

  • Platform account and usage data — for Customer employees and administrators using the RUSO platform, collected on behalf of, and at the instruction of, the Customer that employs you. See Section 4 for location data specifics, and see the relevant Customer's own employee privacy notice for how they use this data.

We do not collect data beyond what each of these purposes requires.

4. Location Data (Scanner and Employee Applications)

RUSO's Employee and Scanner applications collect location data only while a user is actively signed in within an assigned work geofence. Signing in requires being physically within the geofenced work area; a location sign-in action is required to begin tracking. Outside of an active, geofenced sign-in — including outside working hours, on breaks not requiring sign-in, or after sign-out — RUSO does not collect or have visibility into a user's location. This means the Customer (the employer) can see an employee's location only while that employee is actively performing an assigned, geofenced work task, not at other times.

5. Cookies

Our website uses cookies for essential site functionality, analytics, and (where consented to) marketing purposes. For full details and to manage your preferences, see our [Cookie Policy].

6. Where Data Is Stored and Who Processes It

Core platform data is hosted on Google Cloud Platform via Firebase, in Finland (Google Cloud region europe-north1, Hamina). Firebase Authentication and Firebase Analytics process data in the United States, under Google's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. As of 8 September 2026, Google Cloud Platform via Firebase is our sole sub-processor; this list will be updated as additional sub-processors are engaged. We take appropriate technical and organizational measures to protect the data described in this policy. Further detail on our security measures is available on request.

7. If There Is a Data Breach

If a personal data breach affecting your data occurs, we will assess it without undue delay and notify affected individuals and, where legally required, the Finnish data protection authority, in accordance with GDPR.

8. When We Share Data

We do not sell personal data. We may disclose personal data to third parties only in the following circumstances:

  • To service providers who process data on our behalf under a data processing agreement, for the purposes described in Section 3.

  • Where required by valid legal process — such as a court order or a formal, legally binding request from Finnish or EU law enforcement authorities — and only to the extent that request legally compels us to respond. We assess each request individually and disclose only what is legally required.

  • Where necessary to establish, exercise, or defend a legal claim, including disclosure to legal counsel involved in such a matter.

We do not knowingly collect personal data from children, and our services are not directed at children.

9. Changes to This Policy

We may update this Privacy Policy. Customers will be notified by direct phone contact and provided with the updated policy in writing before changes take effect, consistent with our Terms of Service.

1. Parties and Scope These Terms of Service ("Terms") govern the relationship between RUSO Oy, a company registered in Vantaa, Finland ("RUSO"), and any business entering into a subscription agreement with RUSO ("Customer") for use of the RUSO platform. These Terms apply together with the RUSO Data Processing Agreement ("DPA") and, where licensed, the general terms and conditions of IT2022 YSE. In case of conflict, these Terms take priority for matters they specifically address; IT2022 YSE governs matters not otherwise addressed here.

2. Definitions

  • "Platform" means the RUSO software service, comprising the web application, the Employee application, and the Scanner application.

  • "Authorized Users" means individuals the Customer grants access to the Platform, including Customer's own employees.

  • "Customer Data" means all data submitted to, or generated within, the Platform by or on behalf of the Customer, including operational data and personal data relating to Customer's employees and Customer's own customers.

  • "Aggregated Data" means Customer Data that has been processed such that it can no longer reasonably be used to identify an individual, a vehicle, or a specific Customer entity, in line with the anonymization standard described in Section 9.

3. The Platform The Platform is a cloud-based logistics management system comprising:

  • Management interface — used by Customer's supervisory and management staff (operations, finance, executive) to manage orders, fleet, staff, customer relationships, billing, and reporting.

  • Employee application — used by Customer's staff for shift-based task execution.

  • Scanner application (Android only) — used with Customer's compatible handheld scanning hardware for warehouse operations.

Each Customer receives an administrator account with full control over its own organization's configuration: onboarding and managing its employees, vehicles, and its own customers' access within the Customer's account. RUSO does not access, modify, or manage Customer Data except as instructed under the DPA or as required to provide support.

4. Fees and Invoicing Fees are billed according to the Customer's agreed subscription tier and billing cycle. Customers on a monthly contract are invoiced monthly in advance. Customers on an annual contract are invoiced annually in advance. Invoicing continues for the full duration of the agreed contract term. Late payment may result in a formal notice and, if unresolved, suspension of access until outstanding amounts are settled in full.

5. Data Protection and GDPR Compliance

5.1. Roles. With respect to Customer Data that constitutes personal data, RUSO acts as a data processor and the Customer acts as the data controller, as those terms are defined under the General Data Protection Regulation ("GDPR"). RUSO processes personal data only on the Customer's documented instructions, as set out in the DPA.

5.2. Customer responsibilities. The Customer is solely responsible for establishing a valid legal basis for all personal data processed through the Platform, including data relating to its employees, and for providing all legally required notices to its employees and other data subjects. Where local employment or privacy legislation (including the Act on the Protection of Privacy in Working Life) imposes additional obligations on employers using monitoring or tracking functionality, meeting those obligations — including necessity assessments, advance notice, and any required consultation with employee representatives — is the Customer's sole responsibility, not RUSO's.

5.3. Data subject rights. RUSO will provide reasonable assistance to the Customer in responding to data subject access, correction, or deletion requests, as set out in the DPA. RUSO will not withhold assistance on the basis that a request came from an individual rather than the Customer.

5.4. Aggregated Data. RUSO may use Aggregated Data for product improvement, benchmarking, and analytics offerings, including across multiple customers, provided the aggregation meets a minimum group-size threshold sufficient to prevent identification of any individual, vehicle, or specific Customer, as further described in the DPA. RUSO will not use identifiable Customer Data for these purposes without a separate, explicit agreement with the affected Customer.

5.5. International transfers. Any transfer of personal data outside the European Economic Area will be made subject to an approved transfer mechanism (such as Standard Contractual Clauses) as required under GDPR.

6. Data Security RUSO maintains technical and organizational security measures appropriate to the nature of the data processed, as detailed in the DPA's security exhibit. [Insert only measures/certifications RUSO actually holds — encryption standards, hosting location, access controls, sub-processor list, and any completed audits or certifications. Do not reference a certification RUSO has not obtained.]

7. Service Availability and Support RUSO provides customer support on a 24/7 basis. Customers experiencing an urgent issue may contact RUSO's on-call support team directly by phone rather than relying solely on email. [Insert defined response and resolution time targets by severity level — an unqualified "swift" commitment isn't enforceable and should be replaced with actual numbers before this is signed.]

8. Intellectual Property RUSO retains all right, title, and interest in the Platform, including its software, design, and underlying technology. Nothing in these Terms transfers ownership of the Platform to the Customer. The Customer retains ownership of Customer Data, subject to RUSO's rights regarding Aggregated Data under Section 5.4.

9. Confidentiality Each party will protect the other's confidential information with reasonable care and use it only for purposes of performing under these Terms, for the duration of the agreement and a reasonable period following termination.

10. Liability [This section needs specific figures agreed with legal counsel — a cap tied to fees paid over a defined period, carve-outs for gross negligence/willful misconduct and for GDPR-related fines caused by each party's own non-compliance, and exclusion of indirect/consequential damages, consistent with standard IT2022 liability structure.]

11. Term and Termination This agreement remains in effect for the contract term agreed at signing. Either party may terminate in accordance with the termination provisions set out in the signed contract. Termination takes effect on the first day of the calendar month following the applicable notice period. Following termination, Customer Data will be deleted within 14 working days, except where retention is required by applicable law.

12. Amendments RUSO may amend these Terms. Customers will be notified by direct phone contact and provided with the updated Terms in writing prior to the changes taking effect. Material changes affecting data processing will require the Customer's affirmative acknowledgment before taking effect.

13. Governing Law and Dispute Resolution These Terms are governed by the laws of Finland. Any dispute arising from these Terms will be finally resolved by arbitration administered by the Finland Chamber of Commerce, seated in Helsinki, Finland, to the exclusion of ordinary courts.

14. Force Majeure Neither party is liable for delay or failure to perform caused by circumstances beyond its reasonable control, including outages of third-party infrastructure providers.

This is now structurally complete but has several bracketed placeholders that need real numbers/facts before it's usable — liability caps, SLA response times, and the actual security measures/certifications RUSO holds. Those aren't things I should fill in with placeholder-sounding figures; they need to reflect what RUSO can actually commit to. Once you have those, this should go to a Finnish lawyer for a final pass, particularly Sections 5, 10, and 13, before it's used in any real customer contract.