Skip to content
Compassiome

Privacy Policy

Version privacy-3 · Effective 4 September 2026

This Policy explains how Compassiome (the “Service”) processes your personal data and your rights over it.

1. Controller

RemedyBytes Oy (VAT FI33350365), c/o Terkko Health Hub, Building 14, Haartmaninkatu 4, 00290 Helsinki, Finland is the data controller. Contact contact@remedybytes.com.

2. Data we process

  • Account data — username, name and email address.
  • Authentication data — salted password hashes, passkey public keys and, where still present from an earlier setup, dormant recovery-code hashes. We do not store raw passwords.
  • Session data — cookies needed to keep you securely signed in.
  • Security logs — sign-in events, timestamps and source information such as IP address.

3. Purpose and legal basis

We process data to create and secure your account, sign you in and send verification or recovery email under performance of a contract (GDPR Art. 6(1)(b)). We prevent abuse and retain security logs under our legitimate interest in operating a secure service (Art. 6(1)(f)).

4. Connected applications

When you sign in to a connected application, our self-hosted identity service shares only the identity claims needed for that application to recognize you, such as your subject identifier, name and verified email address.

5. Processors

  • Hetzner — EU hosting and infrastructure.
  • Cloudflare — traffic routing, protection and email security.
  • Amazon SES — account email delivery from an EU region.

6. International transfers

We process data within the EU/EEA where possible. Where a provider processes data outside the EEA, appropriate safeguards such as Standard Contractual Clauses apply.

7. Retention

Expired sessions are removed automatically. Sign-in and other user security events are retained for 30 days; administrative security events are retained for 90 days. Account data remains until the account is deleted or closed. Encrypted backups rotate out under the production retention policy.

8. Your rights

You may request access, correction, deletion, restriction or portability, object to certain processing, or withdraw consent. Contact us to exercise a right. You may also complain to Finland’s Office of the Data Protection Ombudsman.

9. Security

We use encrypted connections, password protections including temporary failed-login throttling, optional passkeys, a self-hosted identity service and encrypted off-site backups.

10. Children

An account for a minor should be created and managed by a responsible adult. If you are under 13, use the Service only with a parent or guardian.

11. Changes

We may update this Policy. For material changes we will notify you, for example by email or at sign-in.

12. Contact

Privacy requests: contact@remedybytes.com.

Home · Terms