Privacy Policy
Version privacy-3 · Effective 4 September 2026
This Policy explains how Compassiome (the “Service”) processes your personal data and your rights over it.
1. Controller
RemedyBytes Oy (VAT FI33350365), c/o Terkko Health Hub, Building 14, Haartmaninkatu 4, 00290 Helsinki, Finland is the data controller. Contact contact@remedybytes.com.
2. Data we process
- Account data — username, name and email address.
- Authentication data — salted password hashes, passkey public keys and, where still present from an earlier setup, dormant recovery-code hashes. We do not store raw passwords.
- Session data — cookies needed to keep you securely signed in.
- Security logs — sign-in events, timestamps and source information such as IP address.
3. Purpose and legal basis
We process data to create and secure your account, sign you in and send verification or recovery email under performance of a contract (GDPR Art. 6(1)(b)). We prevent abuse and retain security logs under our legitimate interest in operating a secure service (Art. 6(1)(f)).
4. Connected applications
When you sign in to a connected application, our self-hosted identity service shares only the identity claims needed for that application to recognize you, such as your subject identifier, name and verified email address.
5. Processors
- Hetzner — EU hosting and infrastructure.
- Cloudflare — traffic routing, protection and email security.
- Amazon SES — account email delivery from an EU region.
6. International transfers
We process data within the EU/EEA where possible. Where a provider processes data outside the EEA, appropriate safeguards such as Standard Contractual Clauses apply.
7. Retention
Expired sessions are removed automatically. Sign-in and other user security events are retained for 30 days; administrative security events are retained for 90 days. Account data remains until the account is deleted or closed. Encrypted backups rotate out under the production retention policy.
8. Your rights
You may request access, correction, deletion, restriction or portability, object to certain processing, or withdraw consent. Contact us to exercise a right. You may also complain to Finland’s Office of the Data Protection Ombudsman.
9. Security
We use encrypted connections, password protections including temporary failed-login throttling, optional passkeys, a self-hosted identity service and encrypted off-site backups.
10. Children
An account for a minor should be created and managed by a responsible adult. If you are under 13, use the Service only with a parent or guardian.
11. Changes
We may update this Policy. For material changes we will notify you, for example by email or at sign-in.
12. Contact
Privacy requests: contact@remedybytes.com.