Privacy Notice
Mmx Solutions Oy
Translation notice. This English text is a translation provided for convenience. The Finnish original is the binding version; in case of any discrepancy, the Finnish text prevails.
Klippi is a video coaching tool for sports clubs and coaches: the club uploads its matches in the browser, the coach cuts the clips and shares them with the players.
This notice describes how Mmx Solutions Oy processes personal data as a controller in its own right.
Note. When Mmx Solutions Oy processes material that a customer has stored in the Klippi service (videos, Player data, user accounts), it acts as a processor of personal data on the customer's behalf. That processing is described in the data protection annex to the customer contract, not in this notice.
1. Controller
Mmx Solutions Oy
Business ID 3338794-2
Hippalankuja 2, 40270 Palokka
Contact person for data protection matters: Ismo Nybacka
Email: ismo.nybacka@mmx.fi
The company has no statutory obligation to appoint a data protection officer.
2. Whose data we process
- Contact persons of customer companies and organisations
- Prospective customers and persons who contact us
- Partners, such as intermediaries and resellers
- Contact persons of suppliers
- Visitors to the website
3. What data we process
Contact and customer data
Name, position or role, email address, telephone number, the organisation represented and its details.
Contract and invoicing data
Subscription details, licence tier, contract period, the time and version of the acceptance of the terms, invoices, payments made, and any payment defaults.
Transaction and communications data
Email communications, support requests, feedback, telephone calls and meeting notes. In connection with a support request, the sender's IP address and browser information are stored in order to prevent misuse.
Technical data concerning the maintenance of the service
The event log of administrative actions (invoicing, support functions, acting with a user's account) and technical application logs to the extent that they relate to the maintenance of the service, the investigation of errors and information security.
Website usage data
The cookies required for the operation of the service; see section 8.
We do not process data belonging to special categories of personal data in this role.
4. Where the data comes from
- From the data subject themselves: registration, contacts, contract negotiations
- From the customer organisation that the data subject represents
- From public sources, such as the Trade Register, the Business Information System (YTJ) and organisations' websites
- From log data accumulated automatically from the use of the service
5. Purposes and legal bases of the processing
| Purpose | Legal basis |
|---|---|
| Managing the customer relationship and performing the contract | Contract |
| Invoicing and monitoring of payments | Contract and legal obligation |
| Demonstrating the acceptance of the contractual terms | Contract and legitimate interest |
| Accounting and obligations relating to taxation | Legal obligation |
| Customer support and responding to contacts | Contract or legitimate interest |
| Technical maintenance of the service, investigation of errors and information security | Legitimate interest |
| Developing the service | Legitimate interest |
| Marketing and communications to existing and prospective customers by email, by telephone and at events | Legitimate interest |
| Establishing or defending legal claims | Legitimate interest |
| The cookies required for the operation of the service | Legitimate interest |
The basis for processing founded on legitimate interest is our business interests, such as managing customer relationships, ensuring the security and functioning of the service, developing the service, and marketing and protecting our business. We have assessed that the processing is necessary in order to achieve these purposes and that it does not override the rights and freedoms of the data subject. The processing concerns the data of the contact persons of organisations in the ordinary conduct of business.
6. Retention periods
| Data | Retention period |
|---|---|
| Customer and contact data | For the duration of the customer relationship and 24 months from its end |
| Invoices, vouchers and other accounting material | 6 years from the end of the year in which the financial period ends |
| Financial statements and accounting books | 10 years from the end of the financial period |
| Contracts and records of the acceptance of the terms | For the duration of the contract period and 10 years from its end |
| Support requests and transaction communications | 24 months from the most recent event |
| Administrative event log | 24 months |
| Technical application logs | 14 days |
| Notifications internal to the service | Read notifications 90 days, others 12 months |
| Viewing data (video, viewing position, watched marker) | 12 months from the most recent viewing |
| Login codes | Valid for 15 minutes; deleted upon use and at the latest one day after expiry |
| Marketing permissions and prohibitions | For as long as is necessary in order to comply with the data subject's choice |
| Data of prospective customers | 24 months from the most recent contact |
Some of the data that has become unnecessary is deleted by an automatic clean-up run daily: notifications internal to the service, viewing data, the administrative event log, support requests and login codes. Technical application logs rotate automatically on a 14-day cycle. The other retention periods are implemented manually in the manner described in section 11.
7. Recipients of the data
Personal data is not sold or disclosed to outside parties for marketing purposes.
Data is disclosed to the following recipients:
| Recipient | Purpose | Role | Location |
|---|---|---|---|
| UpCloud Oy | server and storage service | processor | Finland |
| Twilio Inc. (SendGrid) | transmission of emails | processor | United States / EU |
| Browser manufacturers' push delivery services (Google, Mozilla, Apple) | delivery of push notifications | processor | United States / EU |
| Holvi Payment Services Oy | transmission of invoices and payment transactions | independent controller in respect of its own statutory obligations | Finland / EU |
| AnnaK Consulting | accounting and financial statements | independent controller in respect of the obligations of accounting and tax legislation | Finland |
An agreement on the processing of personal data has been concluded with the processors. Recipients acting as independent controllers are responsible for their own processing and provide information about it in their own privacy notices.
In addition, data may be disclosed to the authorities where required by law, and to legal advisers where necessary.
8. Cookies
The service uses only those cookies that are strictly necessary for its operation:
- a session cookie, which keeps a logged-in user's session valid
- an XSRF token, which protects forms and requests against misuse
These cookies are necessary in order to provide the service and do not require consent. Cookies are set only for our own domain.
We do not use statistics, analytics or marketing cookies, and we do not load third-party tracking scripts into the service. For this reason there is no cookie consent notice on the site. Necessary cookies can be blocked in the browser settings, but in that case it is not possible to log in to the service.
9. Transfer of data outside the EU/EEA
Personal data is processed as a rule within the EU/EEA. The servers and the storage space are located in Finland.
SendGrid (Twilio Inc.), which is used for transmitting email communications, may process email addresses and the content of messages outside the EU/EEA. The same applies to the browser manufacturers' notification services used for delivering push notifications.
Transfers are carried out using transfer bases and appropriate safeguards in accordance with applicable data protection legislation, such as the standard contractual clauses approved by the European Commission.
10. Protection of the data
The data is protected by appropriate technical and organisational measures. These include, among others:
- Encrypted data transmission (TLS)
- Logging in with a single-use email code: the service has no passwords, so they cannot be leaked or reused
- Multi-factor authentication in those of Mmx Solutions Oy's own management systems that support it
- Restriction of access rights on a need-to-know basis, and the limitation of access rights by Club and by Team
- Backups once every 24 hours, with a retention period of 7 days
- Logging of administrative actions and monitoring of use
- Rate limiting of requests in order to prevent misuse
- Location of the servers in supervised data centres in Finland
Personal data is processed only by those persons whose duties require it.
11. Rights of the data subject
The data subject has the right:
- To know whether data concerning them is being processed, and to obtain a copy of it
- To request the rectification of incorrect data
- To request the erasure of data where there is no longer a basis for the processing
- To request the restriction of processing
- To object to processing based on legitimate interest on grounds relating to their particular situation
- To receive the data provided on the basis of a contract or of consent in a transferable format, where the conditions of applicable legislation are met
- To prohibit direct marketing at any time without giving a reason
Requests are to be addressed to ismo.nybacka@mmx.fi. We respond within one month. We may request identification before carrying out a request. Requests are carried out manually; the service has no self-service export or deletion function.
12. Automated decision-making
We do not make decisions concerning data subjects solely on the basis of automated processing, and we do not engage in profiling that would have legal effects on the data subject or similarly significant effects.
13. Right to lodge a complaint
The data subject has the right to lodge a complaint with the data protection authority if they consider that the processing of personal data is unlawful.
In Finland, the supervisory authority is the Office of the Data Protection Ombudsman. Up-to-date contact details and instructions for lodging a complaint can be found at tietosuoja.fi.
14. Changes to this notice
We develop our operations continuously and may update this notice. The up-to-date version is always available at https://klippi.pro/en/legal/privacy.html. We will inform data subjects of material changes in an appropriate manner, for example on our website or, where necessary, by email.
See also the subscription and delivery terms and their data protection annex, which covers the material a customer stores in the Service. Questions: ismo.nybacka@mmx.fi.