Privacy Policy

Last updated: January 1, 2026

Data Controller: Freimi Oy
Contact: aija@freimi.com

1. Introduction and Data Controller

Maker's Schedule is operated by Freimi Oy ("we," "our," "us," or "the Company"). We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) (EU) 2016/679.

Data Controller Information:

  • Company Name: Freimi Oy
  • Contact Email: aija@freimi.com
  • Service: Maker's Schedule

This Privacy Policy explains how we collect, use, process, disclose, and safeguard your personal data when you use our service. By using Maker's Schedule, you consent to the data practices described in this policy.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email address, password)
  • Profile information and preferences
  • Content you create (projects, tasks, notes, calendar entries)
  • Payment information (processed securely through Stripe)

2.2 Automatically Collected Information

  • Usage data and analytics
  • Device information and browser type
  • IP address and location data
  • Cookies and similar tracking technologies

3. Legal Basis for Processing and How We Use Your Information

Under GDPR, we process your personal data based on the following legal bases:

  • Contract Performance: To provide our services and fulfill our contractual obligations to you
  • Legitimate Interests: To improve our services, prevent fraud, and ensure security
  • Consent: For marketing communications and non-essential cookies (where applicable)
  • Legal Obligation: To comply with applicable laws and regulations

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and manage subscriptions
  • Send you important updates and notifications (service-related)
  • Respond to your inquiries and provide customer support
  • Detect and prevent fraud or abuse
  • Comply with legal obligations and enforce our terms
  • Analyze usage patterns to improve user experience

4. Data Storage, Retention, and Security

4.1 Data Storage

Your data is stored securely using Supabase, which provides enterprise-grade security and is GDPR-compliant. Data is stored in secure data centers within the European Economic Area (EEA) or in jurisdictions with adequate data protection laws.

4.2 Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Account Data: Retained while your account is active and for up to 30 days after account deletion (to allow account recovery)
  • Transaction Data: Retained for 7 years as required by accounting and tax laws
  • Marketing Data: Retained until you withdraw consent or unsubscribe
  • Support Communications: Retained for 3 years after the last interaction

After the retention period, data is securely deleted or anonymized.

4.3 Security Measures

We implement appropriate technical and organizational measures to protect your personal information:

  • Data is encrypted in transit (TLS/SSL) and at rest
  • Access controls and authentication are enforced (Row Level Security policies)
  • Regular security audits and monitoring
  • Payment information is processed by Stripe (PCI DSS compliant) and never stored on our servers
  • Regular backups with secure storage
  • Staff training on data protection

5. Data Sharing, Disclosure, and Third-Party Processors

We do not sell your personal information. We may share your data only in the following circumstances:

5.1 Service Providers (Data Processors)

We use the following third-party service providers who act as data processors on our behalf:

  • Supabase: Database and authentication services (GDPR-compliant, data stored in EEA)
  • Stripe: Payment processing (PCI DSS compliant, processes payments globally)
  • Resend: Email delivery services (GDPR-compliant)

All processors are contractually bound to:

  • Process data only as instructed by us
  • Implement appropriate security measures
  • Comply with GDPR requirements
  • Not use your data for their own purposes

5.2 Legal Requirements

We may disclose your data when required by law, court order, or governmental authority, or to protect our rights, property, or safety, or that of our users.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you of any such change and ensure the new entity continues to protect your data in accordance with this policy.

6. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

6.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether we process your personal data and to access that data, including:

  • The purposes of processing
  • The categories of personal data concerned
  • The recipients or categories of recipients
  • The retention period or criteria used

6.2 Right to Rectification (Article 16 GDPR)

You have the right to have inaccurate personal data corrected and incomplete data completed. You can update most information directly in your account settings.

6.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request deletion of your personal data when:

  • The data is no longer necessary for the original purpose
  • You withdraw consent and there is no other legal basis
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Note: We may retain certain data if required by law (e.g., transaction records for tax purposes).

6.4 Right to Restrict Processing (Article 18 GDPR)

You have the right to restrict processing of your data in certain circumstances, such as when you contest the accuracy of the data.

6.5 Right to Data Portability (Article 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

6.6 Right to Object (Article 21 GDPR)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

6.7 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

6.8 How to Exercise Your Rights

To exercise any of these rights, please contact us at:

Email: aija@freimi.com
Subject: "GDPR Data Request - [Your Request Type]"

We will respond to your request within one month (may be extended by two months for complex requests).

You can also delete your account directly through your profile settings, which will initiate the deletion process.

6.9 Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. For EU users, you can find your authority at: European Data Protection Board

7. Cookies and Tracking

We use cookies and similar technologies to enhance your experience, analyze usage, and assist with marketing efforts. You can control cookies through your browser settings, though this may affect functionality.

8. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

9. International Data Transfers

Your personal data is primarily stored and processed within the European Economic Area (EEA). However, some of our service providers may process data outside the EEA:

  • Stripe: May process payment data globally but maintains GDPR compliance through Standard Contractual Clauses (SCCs)
  • Supabase: Data is stored in EEA data centers
  • Resend: GDPR-compliant email service

When data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other legally recognized transfer mechanisms

You can request information about the specific safeguards applied to your data by contacting us at aija@freimi.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

10. Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and in any event within 72 hours of becoming aware of the breach, where feasible.

11. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. If this changes in the future, we will inform you and obtain your explicit consent where required.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • Posting the updated policy on this page
  • Updating the "Last updated" date
  • Sending you an email notification for significant changes

We encourage you to review this policy periodically to stay informed about how we protect your data.

13. Contact Us and Data Protection Officer

If you have questions about this Privacy Policy, wish to exercise your rights, or have concerns about our data practices, please contact us:

Data Controller:

Freimi Oy

Contact Email:

aija@freimi.com

Service:

Maker's Schedule

We will respond to your inquiry within one month. For complex requests, we may extend this period by up to two months and will inform you of the extension and reasons.