Legal
Privacy policy
Updated 4 May 2026
This English translation is provided for convenience. If the versions differ, the Finnish version prevails.
This privacy policy covers the umasvoice.fi website and the Umasvoice service. The controller is Umas Oy (Business ID 3604932-4).
1. Controller
Umas Oy
Business ID 3604932-4
Espoo, Finland
Email: info@umasity.com
Data protection officer: Appointing a data protection officer is not mandatory under Art. 37 GDPR, given the nature and the scope of our operations. In data protection matters the contact person is founder Samu Sauvonsaari, info@umasity.com.
2. Purpose of the processing and legal basis
We process personal data in the following situations:
- Contact form: in order to answer your enquiries (legal basis: our legitimate interest in serving prospective customers, GDPR 6(1)(f)).
- Demo call booking (Cal.com): in order to reserve a time in the calendar (legal basis: steps preparatory to a contract, GDPR 6(1)(b)).
- Technical operation of the website: Cloudflare processes your IP address temporarily in order to safeguard the operation and the security of the service (DDoS protection, rate limiting). The processing is momentary and it does not produce identifiers that single you out (legal basis: our legitimate interest, GDPR 6(1)(f)).
- Umasvoice service: see the separate DPA concluded with every customer.
The website uses no analytics and no tracking: visitor counts, page views and behaviour are not measured.
3. Retention period
- Contact form: 6 months from the last contact.
- Demo call booking: 6 months from the booking, after which it is anonymised or deleted.
- Cloudflare technical IP processing: momentary, no permanent storage.
- Umasvoice call audio is never stored with us at any point. Call audio is processed in real time and it is discarded after the processing. Call metadata (time, duration, outcome) and the text summary requested by the customer are retained for the term of the customer subscription, after which they are deleted or anonymised within 90 days of the subscription ending.
4. Transfers of data and sub-processors
Art. 13(1)(e) GDPR requires that sub-processors are disclosed at least by category. Two classes of sub-processor are used for the website and the service.
4.1 Services used on the website (publicly named)
These providers are directly visible to visitors to the website, so we name them:
- Cloudflare, Inc. (United States / global EU edge): delivery of the website (CDN), DDoS protection and bot protection (Cloudflare Turnstile on the contact form). Where bot suspicion is triggered, Turnstile may set a short-lived verification cookie (
cf_chl_*), and that cookie expires at the end of the session. EU traffic is routed primarily through EU edges. Transfers outside the EU under the standard contractual clauses. Cloudflare privacy policy ↗ - Cal.com, Inc. (United States): providing the demo call booking through an external link at
cal.com/umasvoice/demo. Data is transferred to Cal.com only when a visitor clicks the "Book a demo" link on the /en/contact/ page. Transfers under the standard contractual clauses. Cal.com privacy policy ↗ - Simple Static Forms (Web3Forms) (EU): relaying the contact form to a mailbox. Data is transferred only when the form is submitted. Web3Forms privacy policy ↗
4.2 Technical composition of the Umasvoice service (by category)
The names of the technical sub-processors of the voice service are part of our competitive advantage, so they are disclosed as an up-to-date list in the DPA signed with every customer, and we also provide the list on request before a subscription. This covers the following categories:
- SIP and telephony connection routing, an international operator, EU routing as the primary option. Transfers outside the EU under the standard contractual clauses and with a Schrems II assessment.
- Speech synthesis (text to speech), real-time processing, no permanent storage. Transfers outside the EU under the standard contractual clauses.
- Speech recognition (speech to text), real time, no permanent storage.
- Language-model based response generation, real-time processing, according to the configuration of the customer. Transfers outside the EU under the standard contractual clauses.
- Transactional email, transfers outside the EU under the standard contractual clauses where necessary.
We notify active customers by email at least 30 days in advance before a new sub-processor is added or a current one is replaced.
5. Rights of the data subject
The GDPR gives you the following rights: access to your own data, rectification, erasure, restriction of the processing, data portability, and the right to object. Send your request to info@umasity.com and we will answer within 30 days.
Right to lodge a complaint: the Office of the Data Protection Ombudsman, Ratapihantie 9, 00520 Helsinki, tietosuoja.fi.
7. Security of the data
Data is encrypted in transit and at rest in line with standard industry practice. Access to the systems is behind two-factor authentication and restricted to the people who specifically need it. We will notify you of a data breach within 72 hours in accordance with the GDPR obligation.
8. Updates to this policy
This policy may be updated. The most recent update was made on 4 May 2026. Material changes are notified by email to active customers.