Tietosuoja, lyhyesti.
Sivulla on kaksi osaa. Ensin jonotuslista osoitteessa sparsom.ai, joka on ainoa tänään tapahtuva käsittely. Sen jälkeen Sparsom-sovelluksen tietosuojaseloste sanatarkasti.
OSA 1
Jonotuslista sivustolla sparsom.ai
Tämä sivu on jonotuslista, ei sovellus. Siksi tallennettavaa on vähän ja jaettavaa vielä vähemmän. Kaikki tämä kuvaa sitä, mitä tänään todella tapahtuu.
REKISTERINPITÄJÄ
Rekisterinpitäjä on Sparsom AS, norjalainen organisaatiotunnus 837 185 882. Käsittelyyn sovelletaan Norjan lakia.
Käsittelyä koskevat yhteydenotot osoitteeseen contact@sparsom.ai.
MITÄ TALLENNAMME
Kolme kenttää, ja ne kaikki tulevat juuri täyttämästäsi lomakkeesta:
Sähköpostiosoitteesi pienillä kirjaimilla. Kieli, jolla luit sivun (nb, sv, da, fi, is tai en). Ilmoittautumisen ajankohta. Jokainen rivi saa lisäksi teknisen tunnisteen.
Siinä kaikki. Emme tallenna nimeä, puhelinnumeroa, osoitetta, IP-osoitetta, pankkitietoja tai tapahtumia. Sovellusta ei vielä ole, eikä tämä sivu käsittele pankkidataa.
IP-osoitteesi luetaan sillä hetkellä kun lähetät lomakkeen, ja sitä käytetään vain yritysten laskemiseen minuutissa. Se on palvelimen muistissa eikä sitä koskaan kirjoiteta tietokantaan.
Lomakkeessa on myös piilotettu kenttä, jonka vain automaattiset botit täyttävät. Jos se on täytetty, mitään ei tallenneta.
MIKSI
Sähköpostiosoite: jotta voimme kertoa kun on sinun vuorosi. Se on ainoa käyttö.
Kieli: jotta viesti tulee sillä kielellä, jolla todella luit sivun.
Ajankohta: jotta tiedämme jonon järjestyksen.
IP-osoite: jotta kukaan ei voi ilmoittaa tuhatta osoitetta minuutissa.
OIKEUSPERUSTE
Suostumus, tietosuoja-asetuksen (GDPR) 6 artiklan 1 kohdan a alakohta.
Annat suostumuksen lähettämällä lomakkeen, ja voit perua sen milloin tahansa. Silloin rivi poistetaan.
KUKA NÄKEE SEN
Kolme käsittelijää, ei muita. Ei mainosverkostoja, ei seurantaa, ei edelleenmyyntiä.
Supabase: tietokanta, jossa jonotuslista on.
Resend: sähköpostin lähetys, alue eu-west-1 (EU).
Vercel: itse sivuston hosting. Vercel Analytics ja Speed Insights eivät ole asennettuina; sivu ei mittaa sinusta mitään.
KUINKA KAUAN
Julkaisuun asti. Kun jonotuslista on tehnyt tehtävänsä ja kaikki on kutsuttu sisään, se poistetaan kokonaan.
Jos pyydät poistoa sitä ennen, se tapahtuu heti.
EVÄSTEET
Tämä sivu ei aseta evästeitä. Ei yhtään.
Se ei myöskään tallenna mitään localStorageen tai sessionStorageen, eikä hae skriptejä, fontteja tai kuvia muilta verkkotunnuksilta. Fontit ladataan käännösvaiheessa ja tarjoillaan omalta verkkotunnukseltamme.
Siksi täällä ei ole myöskään suostumusbanneria. Ei ole mitään, mihin suostua.
OIKEUTESI
Sinulla on oikeus saada tietää mitä sinusta on tallennettu, oikaista virheet, saada tiedot poistetuiksi ja siirtää tiedot koneluettavassa muodossa.
Voit myös perua suostumuksesi milloin tahansa syytä ilmoittamatta.
Lähetä sähköpostia osoitteeseen contact@sparsom.ai. Saat vastauksen 30 päivän kuluessa, joka on tietosuoja-asetuksen määräaika. Käytännössä nopeammin, koska lista on lyhyt.
TIETOTURVA
Sivu tarjoillaan vain HTTPS:n yli, ja se lähettää HSTS-otsakkeen joka pyytää selainta olemaan koskaan yrittämättä httpta uudelleen.
Selain saa kuusi tietoturvaotsaketta: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy ja Strict-Transport-Security.
Sähköpostiosoite validoidaan ennen tallennusta, ja ohjausmerkkejä tai HTML:ää sisältävät osoitteet hylätään.
Kirjoitus tietokantaan tapahtuu palvelimelta avaimella, jota ei koskaan lähetetä selaimeen. Erillinen portti rakennusketjussa skannaa rakennusartefaktin avainten varalta ennen jokaista julkaisua.
Lomake ottaa vastaan viisi yritystä minuutissa IP-osoitetta kohden.
VALITUS
Jos katsot että käsittelemme tietojasi väärin, voit tehdä valituksen Norjan tietosuojaviranomaiselle.
Datatilsynet, www.datatilsynet.no
MUUTOKSET
Päivitämme tämän sivun kun käsittely muuttuu, esimerkiksi kun sovellukseen tulee pankkiyhteys. Silloin se kuvataan tässä ennen käyttöönottoa, ei jälkikäteen.
Viimeksi päivitetty:
OSA 2
Sparsom-sovelluksen seloste
Tämä on Sparsom-sovelluksen tietosuojaseloste sanatarkasti asiakirjasta. Se kuvaa sovellusta, ei yllä olevaa jonotuslistaa, eikä yhtäkään sen virkettä ole kirjoitettu uudelleen.
Seloste on olemassa norjaksi ja englanniksi. Sivuston neljällä muulla kielellä näkyy englanninkielinen teksti, koska konekäännetty tietosuojaseloste ei ole asiakirja, jonka joku olisi allekirjoittanut.
Sparsom Privacy Policy
Last updated: 16 August 2026
Reference translation of the Norwegian original («Personvernerklæring for Sparsom»). In case of any discrepancy, the Norwegian version prevails.
This Privacy Policy explains how Sparsom AS collects, uses and protects your personal data when you use the Sparsom app and the website sparsom.ai (together, the "Service"). We process personal data in accordance with the Norwegian Personal Data Act and the EU General Data Protection Regulation (GDPR).
1. Data controller
Sparsom AS (org. no. 837 185 882) is the data controller for personal data processed in the Service.
Contact: contact@sparsom.ai
2. What data we collect
2.1 Data you provide
- Account information: email address and login details when you create an account.
- Messages you send to the AI assistant in the app.
- Corrections you make to transaction categories.
2.2 Bank data via open banking (PSD2)
When you connect your bank, we retrieve account information via Neonomics AS, a licensed third-party provider (AISP) under the Payment Services Directive (PSD2), supervised by the Financial Supervisory Authority of Norway (Finanstilsynet). This includes:
- Account name, account number and balance.
- Transaction history: amount, date, merchant/counterparty and transaction description.
The connection is made with your explicit consent through your bank’s own authentication (e.g. BankID). Sparsom never has access to your bank login credentials or BankID. Consent must be renewed periodically in accordance with PSD2 requirements, and you can withdraw it at any time in the app.
2.3 Data collected automatically
- Technical information: device type, operating system, app version and language setting.
- Usage analytics: anonymised events about how the app is used (e.g. which screens are opened). Financial data is never included in analytics.
- Error reports: technical crash reports without personally identifiable content. Financial data is automatically scrubbed before reports are sent.
3. How we use your data
- Providing the Service: showing balances, transactions, categorisation, alerts, Sparsom Score and monthly summaries. Legal basis: contract (GDPR Art. 6(1)(b)).
- AI categorisation and AI assistant: transactions are categorised automatically, and the AI assistant answers questions about your finances. Legal basis: contract (Art. 6(1)(b)).
- Bank connection: retrieving account data via Neonomics. Legal basis: your explicit consent (Art. 6(1)(a)).
- Improving the Service: anonymised usage analytics and error reports. Legal basis: legitimate interest (Art. 6(1)(f)).
- Communication: important messages about your account, changes to terms or the Service. Legal basis: contract and legitimate interest.
We never sell your personal data, and we do not use it for third-party marketing.
4. Automated processing and AI
Sparsom uses artificial intelligence (AI models from Anthropic) to categorise transactions and power the AI assistant in the app. This means that transaction data and messages you send to the assistant are processed by the AI model to provide you with answers and insights.
- The AI provider does not use your data to train its models.
- AI responses are informational insights based on your data, not financial advice.
- No decisions with legal effect or similarly significant effect on you are made in a fully automated manner.
5. Data processors and third parties
We only share data with providers that are necessary to deliver the Service and that are bound by data processing agreements:
- Neonomics AS (Norway): licensed open banking provider. Retrieves account data from your bank with your consent.
- Anthropic (USA): AI models for categorisation and the AI assistant. Transfers to the USA are safeguarded through the EU-U.S. Data Privacy Framework and/or the EU Standard Contractual Clauses (SCC).
- PostHog (EU Cloud): usage analytics. Data is stored in the EU. Financial data is never collected, and screen recording (Session Replay) is disabled.
- Sentry (EU): error and crash reporting. Data is stored in the EU. Collection of personally identifiable information is disabled, and financial data is automatically scrubbed.
- Apple App Store / Google Play: process subscription payments. Sparsom never receives your payment card details. See Apple’s and Google’s own privacy policies.
6. Data retention
- Transaction data: stored in raw form for up to 13 months (12 complete calendar months plus the current month). Raw data is then deleted and replaced by monthly category aggregates linked to your account. The aggregates cannot be traced back to individual transactions, but they are pseudonymised personal data and are deleted when you delete your account.
- Account information: stored for as long as you have an active account.
- Upon account deletion: your personal data is deleted or anonymised without undue delay, unless statutory retention obligations (e.g. the Norwegian Bookkeeping Act) require otherwise.
- Usage analytics and error reports: stored in anonymised form.
7. Your rights
Under the GDPR you have the right to:
- Access the data we hold about you.
- Rectification of inaccurate data.
- Erasure ("the right to be forgotten").
- Restriction of processing.
- Data portability – receiving your data in a machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, without affecting the lawfulness of processing already carried out.
To exercise your rights, contact us at contact@sparsom.ai. We respond within 30 days at the latest.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, www.datatilsynet.no) if you believe our processing violates data protection law.
8. Security
We take the security of your financial data seriously. Measures include encryption of data in transit and at rest, access controls, and bank connections exclusively via licensed PSD2 infrastructure. Sparsom never stores your bank login credentials.
9. Age limit
The Service is intended for persons over 18 years of age. We do not knowingly collect data about persons under 18.
10. Changes to this policy
We may update this Privacy Policy as needed. In the event of material changes, we will notify you in the app or by email. The current version is always available at sparsom.ai.
11. Contact
Sparsom AS, org. no. 837 185 882
Email: contact@sparsom.ai