---
title: PlainRouter Privacy Policy
description: How Wudaku Oy processes personal data for PlainRouter's website, application, APIs, integrations, and support.
canonical: https://plainrouter.com/privacy
last_updated: 2026-08-26
---

# Privacy Policy

**Effective date: 8 August 2026**

This Privacy Policy explains how Wudaku Oy processes personal data in connection with PlainRouter's website, application, first-party signal collection, APIs, integrations, support, and related services (together, the **Service**).

## 1. Controller and contact details

The controller is:

**Wudaku Oy**, the company operating PlainRouter as its software-as-a-service product<br>
Business ID: 2838111-6<br>
Hermannin rantatie 3<br>
00540 Helsinki, Finland<br>
[Contact PlainRouter](#plainrouter-contact)

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.

Contact us at the address above for privacy questions or to exercise your rights.

## 2. When this policy applies

This policy applies when Wudaku Oy acts as a controller, including for account administration, billing, security, service communications, support, and our website.

Customers may use PlainRouter to process first-party advertising events, advertising-platform data, or other data on their own behalf. For personal data in that **Customer Content**, the customer normally determines the purposes and means of processing and is the controller; Wudaku Oy acts as its processor. In that situation, direct your request to the relevant customer. We will assist the customer as required by law and our agreement with it.

Third-party services such as Meta, Google, GitHub, and a customer-selected AI tool process data under their own privacy notices. This policy does not control their independent processing.

## 3. Personal data we collect

Depending on how you use the Service, we may process the following categories.

### Account and identity data

- name, business email address, password hash, and profile photo;
- email-verification and account status;
- organisation, team, workspace, membership, role, and invitation details; and
- settings, language, and communication preferences.

### Social sign-in data

If you choose Google or GitHub sign-in, we receive data permitted by that provider and your settings, such as provider ID, name, email address, profile image, access token, refresh token, scopes, and expiry information.

### Advertising-platform and integration data

- connected platform and business-account identifiers;
- advertising-account name, identifier, currency, time zone, status, and related metadata;
- OAuth credentials, granted permissions, scopes, and expiry information;
- collection domains, event schemas, destination configuration, consent and enforcement metadata, and delivery status;
- first-party event payloads and, when supplied under the customer's instructions, associated browser, click, or customer identifiers;
- campaign, audience, creative, reporting, configuration, and instruction data that you ask the Service to retrieve or act on; and
- tool calls, action proposals, approval decisions, execution evidence, results, and integration status.

Advertising-platform credentials are encrypted at the application layer before database storage and are excluded from ordinary application responses.

### Service and device data

- IP address, browser and device type, operating system, user agent, timestamps, session identifiers, and requested pages;
- login, security, audit, diagnostic, error, and performance events; and
- API-token name, permissions, use, and non-reversible token representation.

### Communications and commercial data

- messages, support requests, feedback, and other communications;
- company, role, billing contact, order, subscription, invoice, payment status, and transaction details; and
- participation in calls, product research, or surveys.

We do not need sensitive personal data to administer PlainRouter accounts. Please do not send it through support or other general-purpose fields.

## 4. How we obtain personal data

We obtain personal data:

- directly from you when you register, configure the Service, contact us, or use a feature;
- from your employer, organisation, teammates, or another customer that invites you or manages your access;
- from a sign-in or advertising platform when you authorise a connection;
- from customer websites, servers, or tools that send first-party events to a configured collection endpoint;
- from customer-selected tools that call the PlainRouter API on your behalf; and
- automatically from your browser, device, and use of the Service.

Where a customer instructs us to retrieve platform data, the source may be the customer's advertising platform, business portfolio, or connected data source.

## 5. Purposes and legal bases

We process personal data only where we have a legal basis under applicable law.

| Purpose                                                                                                           | Typical data                                                                         | Legal basis                                                                                                     |
| ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------- |
| Create accounts; authenticate users; provide workspaces, first-party measurement, integrations, APIs, and support | Account, identity, event, integration, platform, instruction, and communication data | Performance of our contract; steps requested before entering a contract                                         |
| Operate, troubleshoot, maintain, and improve the Service                                                          | Service, device, diagnostic, feature-use, feedback, and support data                 | Performance of our contract; legitimate interests in providing and improving a reliable business service        |
| Protect accounts, prevent abuse, investigate incidents, and enforce our terms                                     | Identity, access, session, IP, audit, integration, and security data                 | Legitimate interests in protecting the Service, customers, and third parties; compliance with legal obligations |
| Administer subscriptions, invoices, tax, and accounting                                                           | Account, organisation, order, invoice, payment-status, and transaction data          | Performance of our contract; compliance with legal obligations                                                  |
| Send verification, invitation, security, service, and legal notices                                               | Name, email address, account, and service data                                       | Performance of our contract; legal obligations; legitimate interests in administering the Service               |
| Send product news or marketing where permitted                                                                    | Name, business contact details, preferences, and engagement                          | Consent where required; otherwise legitimate interests in business-to-business marketing                        |
| Establish, exercise, or defend legal claims and respond to authorities                                            | Relevant account, transaction, communication, audit, and service data                | Legitimate interests; compliance with legal obligations                                                         |

Where we rely on legitimate interests, we balance those interests against the person's rights and reasonable expectations. You may object as described below. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.

## 6. How we use advertising and Customer Content

We process first-party events, advertising-platform data, and Customer Content to carry out the customer's instructions, show account context, prepare or execute approved actions, deliver configured conversion signals, return results, maintain auditability, and protect the Service.

We do not sell personal data. We do not use Customer Content to train general-purpose AI models unless the customer expressly agrees. PlainRouter does not make solely automated decisions about individuals that produce legal or similarly significant effects.

The customer is responsible for ensuring that its campaign, audience, customer-list, and other submitted data was collected lawfully and may be used for the requested advertising purpose.

## 7. Cookies and similar technologies

The application uses cookies or similar storage that are necessary to keep users signed in, protect requests, remember security-related state, and provide requested features. These essential technologies are used to perform the Service and protect it.

We do not currently use non-essential advertising cookies in the PlainRouter application. If we introduce optional analytics, advertising, or other non-essential technologies, we will update this policy and request consent where required.

You can control cookies in your browser. Blocking essential cookies may prevent account features from working.

## 8. Recipients and service providers

We disclose personal data only as needed to:

- cloud hosting, managed database, storage, backup, and infrastructure providers;
- network delivery, DNS, availability, and abuse-prevention providers;
- transactional email and customer-support providers;
- payment, accounting, and professional-adviser providers;
- identity providers you select, such as Google or GitHub;
- advertising platforms you connect, such as Meta;
- AI or developer tools that you choose to connect to PlainRouter;
- other members and administrators of your organisation as directed by the customer;
- a buyer, investor, lender, or adviser in a proposed corporate transaction, subject to appropriate confidentiality; and
- authorities or other parties where required by law or reasonably necessary to protect rights, security, and the integrity of the Service.

Our service providers may process data only for agreed purposes and under appropriate contractual and confidentiality obligations. Current high-level categories and processing locations are described on our [Security page](/security). Customers may request more detailed subprocessor information by contacting us.

## 9. International transfers

We aim to host the Service's primary application data and backups in the European Union. Some providers, connected platforms, or customer-selected tools may process personal data outside the European Economic Area.

Where Wudaku Oy transfers personal data to a country that has not been recognised as providing adequate protection, we use an approved transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. A connected platform or customer-selected tool may separately make its own transfers under its privacy notice.

You may contact us for more information about the safeguards relevant to your data.

## 10. Retention

We keep personal data only for as long as needed for the purposes described above. Typical retention periods are:

- **Account and workspace data:** while the account is active and normally up to 30 days after a valid deletion request or termination, subject to the exceptions below;
- **OAuth credentials:** until the connection is revoked, expires without renewal, or is deleted, plus a limited period needed for secure deletion and backups;
- **Customer Content and advertising data:** for the period configured in the Service or agreed with the customer, and otherwise only as long as needed to provide the requested operation;
- **Security, access, and audit logs:** normally up to 12 months, and longer when reasonably needed to investigate an incident or protect legal rights;
- **Support and business communications:** normally up to 3 years after the matter is closed or the customer relationship ends;
- **Contract, invoice, and accounting records:** for the period required by Finnish accounting, tax, and other applicable law; and
- **Backups:** removed through the ordinary backup-rotation cycle and protected from routine use in the meantime.

We may retain limited data longer where required by law, necessary to establish or defend legal claims, needed to prevent fraud or repeat abuse, or requested by the customer acting as controller. We delete or anonymise data when the applicable period ends.

## 11. Security

We use technical and organisational measures designed to protect personal data, including access controls, encryption in transit, application-layer encryption for platform credentials, password hashing, environment separation, backups, and security monitoring.

No method of transmission or storage is completely secure. You are responsible for using strong authentication, limiting permissions and API tokens, reviewing connected applications, and notifying us promptly about suspected compromise. See our [Security page](/security) for more information.

## 12. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

- obtain information about our processing and access your personal data;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict certain processing;
- receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests and object at any time to direct marketing; and
- withdraw consent at any time where processing is based on consent.

To exercise a right, [contact PlainRouter](#plainrouter-contact). We may need to verify your identity and clarify the request. We will respond without undue delay and generally within one month, as required by law.

You can also update much of your account data or delete your account from the profile settings. An organisation administrator may need to handle requests concerning organisation-controlled data. Deleting a PlainRouter account does not automatically delete data held independently by Meta, Google, GitHub, an AI tool, or another third party.

## 13. Complaints

Please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or place of the alleged infringement.

Our lead supervisory authority is the **Office of the Data Protection Ombudsman of Finland**. Contact information is available at [tietosuoja.fi](https://tietosuoja.fi/en/frontpage).

## 14. Children

The Service is intended for business users aged 18 or older and is not directed to children. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.

## 15. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service, our processing, or applicable requirements. We will post the updated policy with a new effective date and provide additional notice where a change is material or law requires it.

## 16. Contact

Privacy questions and requests may be sent to:

**Wudaku Oy / PlainRouter**<br>
Business ID: 2838111-6<br>
Hermannin rantatie 3<br>
00540 Helsinki, Finland<br>
[Contact PlainRouter](#plainrouter-contact)
