Last updated: 6 March 2026
This Privacy Policy explains how Ennen Oy (“Ennen”, “we”, “us”) processes personal data when you use our website and digital services (the “Service”), interact with us, or contact us.
1. Data Controller and Contact Details
Data Controller:
Ennen Oy
Business ID: 3455744-8
Metsotie 3, 90650 Oulu, Finland
Email:
info@ennen.fi
Data Protection Officer:
Mikko Katajamäki
mikko.katajamaki@ennen.fi
2. What Personal Data Do We Collect?
We only collect personal data that is necessary for providing and improving the Service. Data may be collected in three ways:
- information you provide directly,
- information generated through your use of the Service, and
- information we may receive from partners where needed to provide the Service.
2.1 Information You Provide
This may include:
- account information, such as your name or username, email address, encrypted password, language, and settings
- customer service and communication data, such as messages, feedback, and survey responses
- payment-related information, such as transaction details
Please note that payment card details are typically processed by the payment service provider, not by Ennen.
2.2 Information Collected During Use
This may include:
- usage data, such as which features you use, when you use them, how long you use them, and general service performance and usage metrics
- device and log data, such as browser type, app version, IP address, operating system, device identifiers, and error logs
2.3 Optional or Service-Specific Data
This may include:
- data produced by the camera or other sensors, such as measurements related to task performance, where the user has given permission and uses those features
- integration data, if you connect the Service with a third-party service, such as another wellbeing application; in those cases, we only receive the data you have authorized us to access
3. Why Do We Use Personal Data, and on What Legal Basis?
3.1 Biometric Data and Data Related to Cognitive Performance
The Service processes user performance and measurement data, which may include biometric data. This data is collected and generated when the user completes exercises and assessment tasks. It may include, for example:
- eye-movement-related metrics, such as gaze movement, delays, and fixation-related indicators
- facial expression or head movement metrics, such as micro-movements and indicators derived from facial features
- task performance metrics, such as reaction times, errors, and task-specific scores
We do not store image data of users. We only process measurement data derived from eye movements and facial features.
3.2 Cognitive Index and Longitudinal Monitoring
When a user enables eye-tracking and facial-feature monitoring features, biometric data is generated. This data consists of movement coordinate sequences produced during task performance, such as coordinate series related to eye, facial, or head movement, as well as analytical indicators derived from those coordinates, including delays, reaction times, task performance metrics, and other statistical measures.
Ennen does not store or retain raw video footage or photographs of users. The camera may only be used during the measurement event to generate coordinate data. After that, only the coordinate sequences described above and the derived indicators are stored in the Service.
This data is used for:
- longitudinal monitoring of the user's cognitive performance over time, and
- calculating and presenting Ennen Oy's cognitive index to the user.
This processing is based on the user's explicit consent under GDPR Article 6(1)(a) and Article 9(2)(a). Consent is requested when the user creates an account in the Service. The user may withdraw consent at any time through the Service settings. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
The cognitive index is an informative summary of the user's own performance and related indicators. The Service is not intended for diagnosing, predicting, or treating disease, and it must not be used as the sole basis for health-related decisions.
3.3 Service Delivery and Maintenance
We also process personal data for the following purposes:
Providing and maintaining the Service
For example, user login and service functionality
Legal basis: contract (GDPR Article 6(1)(b))
Customer service and communications
For example, support, responding to requests, and service notifications
Legal basis: contract and/or legitimate interest (GDPR Article 6(1)(b) and 6(1)(f))
Service development and quality assurance
For example, fixing errors, improving usability, and analytics
Legal basis: legitimate interest (GDPR Article 6(1)(f))
Payment processing and invoicing
Legal basis: contract (GDPR Article 6(1)(b)) and legal obligation (GDPR Article 6(1)(c))
Marketing communications
Legal basis: consent or legitimate interest, as permitted by applicable law
You may opt out at any time
Information security and prevention of misuse
Legal basis: legitimate interest (GDPR Article 6(1)(f)) and, where applicable, legal obligation
4. Who Do We Share Data With?
We may share personal data only to the extent necessary with:
- service providers, such as hosting, analytics, customer support, payment processing, and communication service providers
- professional advisers, such as accountants, lawyers, and auditors, subject to confidentiality obligations
- public authorities, where required by law
- parties involved in corporate transactions, such as mergers or acquisitions, where appropriate safeguards are in place
We do not sell personal data.
5. Cookies and Analytics
We use cookies and similar technologies to:
- ensure that the Service functions properly, including essential cookies
- support analytics and improve user experience, where consent is required under applicable law
You can manage cookies through your browser settings.
6. Transfers Outside the EU/EEA
If we use service providers located outside the EU or EEA, we ensure that appropriate safeguards are in place for such transfers, for example through:
- the European Commission's Standard Contractual Clauses (SCCs), or
- an adequacy decision of the European Commission
You may request more information about international data transfers using the contact details provided above.
7. How Long Do We Retain Data?
We retain personal data only for as long as necessary for the purposes for which it was collected, including:
- providing the Service and maintaining user accounts
- complying with legal obligations, such as accounting requirements
- resolving disputes and ensuring information security
When data is no longer needed, it is deleted or anonymized.
8. Data Security
We protect personal data through appropriate technical and organizational measures, such as access controls, encryption, logging, and contractual safeguards with service providers. No system is completely risk-free, but we take reasonable steps to reduce risks and protect the data we process.
9. Your Rights (EU/EEA)
Subject to applicable law, you have the right to:
- access your personal data and receive a copy of it
- correct inaccurate personal data
- request deletion of your data in certain circumstances
- request restriction of processing in certain circumstances
- object to processing where the legal basis is legitimate interest
- receive your data in a portable format in certain cases
- withdraw consent at any time, where processing is based on consent
To exercise your rights, please contact: info@ennen.fi
You also have the right to lodge a complaint with a supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman.
10. Children's Privacy
The Service is intended for adults only. We do not knowingly collect personaldata from children without the consent of a parent or legal guardian. If you believe such a situationhas occurred, please contact us.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date and, where appropriate, notify users of material changes through the Service or by email.