Lue tietosuojaseloste suomeksi

Laki.ai Privacy Policy

Version 5 – 3 September 2026

1.Controller, contact details and scope

The controller is Helsinki AI Labs Oy (Business ID 3296587-8), Sompasaarenlaituri 4 B 46, 00540 Helsinki, Finland. Privacy questions and data subject requests: info@laki.ai.

This policy covers the Laki.ai website and service, accounts, organizations, billing, support, MCP access and Laki.ai integrations used through supported hosts and clients. The provider of the user-selected MCP host or client processes data under its own terms and privacy policy. Deleting a conversation or local session in that host or client does not delete the Laki.ai OAuth connection, account, operational records or other retained records described here.

2.Roles and restricted inputs

Laki.ai is the controller for accounts, authentication, organizations, billing, security, communications and operational metadata. When Laki.ai processes personal data in a customer research input or output on the customer's behalf, the customer is the controller and Laki.ai is the processor under the Laki.ai Data Processing Addendum (DPA) incorporated into the Laki.ai General Terms of Use for every authenticated user of the research functions through any supported host or client, including free accounts. The customer must have an appropriate legal basis and, where applicable, an additional condition under Article 9 or Article 10 of the GDPR, minimise the material to what the legal task requires, and be entitled to disclose it through the selected host or client, Laki.ai and subprocessors.

Do not put PCI-regulated payment-card data, protected health information (PHI), government-issued personal identifiers, authentication credentials or other secrets into research inputs or model-generated tool calls. Other regulated sensitive data, including special categories of personal data under Article 9 of the GDPR and personal data relating to criminal convictions and offences under Article 10 of the GDPR, may be processed only when strictly necessary for the legal task and when the customer has ensured lawful control and a legally adequate consent. Special categories of personal data and data relating to criminal convictions and offences may be provided only to the extent that they do not fall within the categories prohibited above; the customer must remove personal identity codes, health information, and other prohibited data before submission. Laki.ai does not promise to detect or automatically classify prohibited material.

The applicable Data Processing Addendum and subprocessor list are available online.

3.Data categories and sources

We process account and contact details; user and organization roles; credential and audit attribution attached to MCP calls; subscription, invoice and tax details; hashed OAuth codes and tokens plus their client, resource, scope and timing metadata; support correspondence; and the bounded research inputs and outputs described below. Operational records may include tool name, MCP profile, status, duration, timestamp, and usage, model, provider, token and cost metadata. They exclude query, context, source-body and answer text. Stripe, rather than Laki.ai, handles full card numbers and card security codes.

For organization agreement and Microsoft Copilot administration, we also process the agreement release and locale, document and statement hashes, the rendered statement concerning the accepting person’s capacity and authority, acceptance time, organization identity and the authenticated accepting person's account and work-email snapshot. Acquisition, billing and capacity records may include quantities, prices, payment and schedule references, operation status, timestamps, actor and request digests, and immutable organization snapshots.

Tenant-administration records may include the precommitted Microsoft tenant identifier; catalog-app and verifier identity and configuration versions; request, revision and status identifiers; a non-reversible digest of the Microsoft administrator's subject; the accepted Microsoft directory-role class; proof, declaration and confirmation timestamps; the operational declaration release, locale, hash and rendered text; and the Laki.ai organization owner or administrator who initiated or confirmed the request. We do not retain the Microsoft administrator's raw token, claims payload, name, email address or raw subject identifier.

Transfer records may include source and destination organization and tenant snapshots, the authorizing and confirming actors, reason, status, timestamps and immutable evidence references. The sole exceptional source-organization-dissolution method may include a private reference to a current official-register record, its issuing authority, record identifier and date, private artifact locator and content hash. These data are not published in a listing or public reviewer material.

Microsoft capacity measurement uses a tenant-scoped, non-reversible pseudonymous actor identifier and first-seen, last-seen and retention timestamps. It does not store the person's name, email address, raw Microsoft identifier or a mapping to a Laki.ai user.

Website and service telemetry may include IP address, route, response status, browser, device and referrer data, coarse region, request timing, security and error data, and aggregate analytics. We use it to deliver and secure the service, prevent abuse, diagnose errors, measure reliability and aggregate usage, subject to the retention rows and the rights and controls below.

Data comes from users and customer organizations, their selected MCP hosts or clients, model-generated tool calls, Laki.ai services, Microsoft Entra, Stripe, Firebase, support and email services, browsers and network connections, and, for the narrowly limited dissolution-transfer exception, an official register and an authorized Laki.ai system administrator. Laki.ai also returns public legal and public-authority materials. Those public sources may themselves contain personal data, including personal data relating to criminal convictions and offences under Article 10 of the GDPR; public availability does not make the information risk-free or remove the user's duty to use it lawfully.

We process data to provide and secure the service, authenticate users, manage accounts and organizations, perform requested legal-source operations, administer subscriptions and billing, provide support, communicate, prevent abuse, diagnose faults and comply with law.

The applicable bases depend on the record and relationship:

Where processing relies on legitimate interests, the relevant interests are limited to operating and securing the requested professional service, proving authorization and agreement, administering paid capacity, preventing fraud and tenant takeover, and establishing, exercising or defending legal claims. We limit the data, use pseudonymous identifiers where possible, provide the controls described below, and do not use these records for advertising or unrelated profiling.

Record or processingPurposeLegal basis
Account, contact, organization and subscription administrationForm and perform the requested service relationship and manage authorized usersPerformance of a contract or steps before contract only where the individual is personally the contracting party; otherwise Laki.ai's and the customer's legitimate interests in administering the professional service
Organization agreement and accepting-person capacity or authority evidenceEstablish, evidence and defend the organization's agreement and the accepting person's personal contracting capacity or representative authorityLegitimate interests in reliable contract formation, fraud prevention and legal claims; performance of a contract where the accepting individual is the customer and personally a party
Acquisition, capacity and billing operationsQuote, purchase, increase, decrease, reconcile and account for one organization capacityPerformance of a contract or pre-contract steps only where the individual is personally the contracting party; otherwise legitimate interests in administering an organization's order; legal obligations only for accounting and tax records
Microsoft tenant proof, operational declaration, connection, reproof and disablementProve the precommitted tenant and accepted administrator role, prevent first-caller binding or tenant takeover, and maintain the customer-authorized connectionLegitimate interests of Laki.ai, the customer and its users in secure provisioning, authorization, service delivery and legal-claim evidence
Tenant transfer authorization and evidencePrevent unauthorized retargeting and document the source and destination authority for an exceptional transferLegitimate interests in secure continuity, fraud prevention and establishing, exercising or defending legal claims
Pseudonymous Microsoft actor capacity recordEnforce the organization's purchased capacity, prevent over-admission, operate and secure the service, and resolve capacity disputesLegitimate interests of Laki.ai and the customer in fair, secure and auditable capacity administration
Security, incident and abuse recordsProtect users, organizations and the service and respond to incidentsLegitimate interests in security, abuse prevention, service integrity and legal claims
Customer-controlled research materialPerform the requested legal-research operation on the customer's documented instructionsThe customer determines its legal basis; Laki.ai acts as processor under the DPA

5.MCP tool data flows

The rows below describe the MCP tool data flows used across Laki.ai integrations. MCP tool calls pass between the customer-selected MCP host or client, Laki.ai and Google Cloud infrastructure. The host or client sends inputs to Laki.ai, and Laki.ai returns outputs for the user's request. Vertex AI search, vector, embedding, model or relevance processing is conditional and occurs only where the relevant tool row says so. MCP calls are not retained as call logs. Separate operational records can contain attribution, but exclude query, context, source-body and answer text.

The document reader does not create a Laki.ai research session. Expansion, scroll and other local presentation state exists only in the widget instance. Fullscreen rehosting starts with a fresh local source list and does not persist or transfer a selected source. Display metadata is not legal evidence: source text must be read before it is relied on or cited.

ToolInputsOutput fieldsOutputsPurpose and recipientsPersistence and controls
search_legal_sourcesqueries, type, mode, inForceOnly, asOfDate, limitresultsA query-labelled group for each batched query, containing ordered source id, title, source type and optional snippet; no graph.Locate Finnish sources and European Union sources where enabled for the integration. Recipients: Laki.ai and the selected MCP host or client; Google search/vector processing only on configured semantic or hybrid paths.Queries last for the request only and are not stored. Identifiable operational records without query or source-body text are pseudonymised within 90 days; pseudonymised usage and cost metadata follows the retention table below.
read_documentids, includeRelatedSourceStubs, optional bounded contextdocuments, errorsDocuments and per-ID errors; source/content-block IDs, titles/types, text, citations and related leads.Read source text and optionally filter related leads. Recipients: Laki.ai and the selected MCP host or client; Google only for configured relevance filtering.Context lasts for this call only and is not cached between MCP tool calls. Identifiable operational records without context or source-body text are pseudonymised within 90 days; pseudonymised usage and cost metadata follows the retention table below.
get_statute_section_historyid, startFromIndexstatute, versions, startFromIndex, returnedCount, nextStartFromIndex, hasMore, scanTruncatedStatute citation, bounded versions/dates/text, amending acts, preparatory-work leads and paging.Read amendment history. Recipients: Laki.ai and the selected MCP host or client; no model or embedding processing in this tool.Identifiable operational records without source-body or answer text are pseudonymised within 90 days; pseudonymised usage and cost metadata follows the retention table below.
get_table_of_contentsids, depthdocuments, errorsDocument IDs/titles/types, nested section locators, totals and bounded per-ID errors.Navigate known documents. Recipients: Laki.ai and the selected MCP host or client; no model or embedding processing in this tool.Identifiable operational records without source-body or answer text are pseudonymised within 90 days; pseudonymised usage and cost metadata follows the retention table below.
search_within_documentsids, query, modematches, truncated, errorsOrdered matches with document/title/id/type/context/score, truncation and bounded per-ID errors.Locate passages in supplied documents. Recipients: Laki.ai and the selected MCP host or client; Google embedding/vector processing on semantic or hybrid paths.The query lasts for the request only and is not stored. Identifiable operational records without query or source-body text are pseudonymised within 90 days; pseudonymised usage and cost metadata follows the retention table below.
open_legal_sources_in_readerids (1–10; each no more than 256 characters)documents, errorsOrdered compact descriptors (id, title, citation text, source type), bounded per-ID errors and UI link; no document bodies.Display already-identified Laki.ai documents. Recipients: Laki.ai and the selected MCP host or client; no Google model or embedding processing.No research workflow or server-side selection-handoff record. Expansion, scroll and other local presentation state lasts only for the widget instance. Identifiable operational records excluding source-body and answer text are pseudonymised within 90 days; pseudonymised usage and cost metadata follows the retention table below.
get_source_coverageClosed input: {}coverageCurated model-readable source-coverage and search guidance in coverage; no live corpus count or service-health result.Explain the available Finnish and European Union source categories and search guidance. Recipients: Laki.ai and the selected MCP host or client; Google Cloud infrastructure, with no model or embedding processing for this tool.The tool receives no query, source identifier, or document text. Identifiable operational records without source-body or answer text are pseudonymised within 90 days; pseudonymised usage and cost metadata follows the retention table below.

6.Microsoft 365 Copilot organization path

For the administrator-deployed Microsoft 365 Copilot path, Microsoft Entra and Microsoft's Enterprise Token Store present signed authentication material with each tool request. Assigned users use their existing Microsoft session, do not create or sign in to a Laki.ai account, and do not complete a Laki.ai end-user OAuth consent flow. Laki.ai validates the material for the request and does not durably retain the raw token, claims payload, email address or display name.

An accepted request runs only as the eligible Laki.ai organization mapped through the immutable Microsoft Entra tenant-to-organization link. The individual Microsoft actor is represented in operational records only by a non-reversible pseudonymous audit identifier. The live tenant mapping remains while the organization connection is enabled. Immutable proof and declaration evidence follows the separate retention period below.

Microsoft sends the tool request needed for the customer's legal-source task and receives the Laki.ai output under Microsoft’s own terms and the terms agreed with the customer. In this path Microsoft is the customer-selected host, not a Laki.ai subprocessor merely because it sends requests or receives outputs. Laki.ai subprocessors used to provide the service are listed in the Laki.ai DPA.

Before self-service acquisition, Laki.ai presents a just-in-time link to this Privacy Policy alongside the applicable purchase and agreement information. Before a Microsoft administrator begins tenant proof or accepts the separate operational deployment-and-assignment declaration, the verifier page presents the same link and identifies the Laki.ai organization, precommitted tenant, catalog app and separate verifier application involved.

Tenant proof confirms the precommitted Microsoft tenant and one accepted administrator role from signed Microsoft material. It does not use Microsoft Graph, request Graph data permissions, or prove deployment or user assignment. The Microsoft administrator separately confirms the versioned operational declaration, and a Laki.ai organization owner or administrator makes the final activation confirmation. The declaration is operational configuration evidence, not Team Terms or DPA acceptance.

Microsoft capacity is measured by the number of distinct pseudonymous actors with valid research-tool activity during the preceding 30 days. That 30-day window determines current capacity only; it is not the record-retention period. Discovery, initialization, resource listing and reader presentation do not create or refresh Microsoft actor activity.

Laki.ai does not link the pseudonymous Microsoft actor to a Laki.ai user identity and does not use these records for advertising or unrelated profiling. The service does not make a decision based solely on automated processing that produces legal effects or similarly significant effects on a person within Article 22 of the GDPR. Automated eligibility and capacity controls may allow or deny technical access to the service based on the organization’s agreement, paid capacity and administrator-controlled configuration. An organization owner or administrator can correct the configuration, change capacity where available, disable the connection, or ask Laki.ai support to review an error; exceptional tenant transfers require the documented human authorizations described above.

Revocation for this path does not use a Laki.ai OAuth token family. Laki.ai can disable the server-side tenant link so every fresh request fails closed; the Microsoft administrator separately removes user or group assignment and, where appropriate, the app package. Re-enablement requires the organization entitlement, tenant mapping, provisioning, assignment policy and intended assignment to be revalidated, with fresh proof and declaration evidence where required.

7.Recipients and international transfers

Recipient categories are Helsinki AI Labs personnel with a task-based need, the customer and authorized users, the provider of the selected MCP host or client, Google Cloud infrastructure for every call, Vertex AI only where a tool row states conditional search, vector, relevance-filtering, model or embedding processing, and the authentication, billing, email, support, error-monitoring and analytics providers listed in the DPA or used for the controller activities described here. Microsoft provides the customer-selected host and signed Entra material for the Microsoft path. Stripe processes payment data for billing. We do not sell research inputs or use them to train general-purpose models.

Provider processing may occur outside Finland or the EEA. Transfers use an adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses, together with supplementary measures where required. Vertex AI model and embedding requests containing research inputs or outputs are configured for EU regional processing.

8.Retention and deletion

All cut-offs use UTC. A data deletion or transformation deadline is reached when the controlling timestamp is at or before the cut-off. A legal-preservation exception may apply only to identified records where preservation is necessary to establish, exercise or defend an identified legal claim or to comply with an identified legal obligation. The exception is narrow, documented and reviewed regularly; it does not act as a general retention switch. Accounting material remains subject to statutory six- or ten-year periods without expanding research-data retention.

DataMaximum retention or deletion rule
Search and within-document queriesRequest-lived; no durable Laki.ai storage.
read_document contextCall-only; never cached between MCP tool calls.
Reader expansion, scroll and other local presentation stateWidget-instance memory only; no research workflow or session record.
Legacy research records (historical widget data only; current tools create no research session)Delete 30 days after the last valid research-tool activity; historical widget polling does not extend retention.
Active OAuth refresh familyUntil disconnect or expiry; at most 365 days from initial family issuance. Rotation never extends the deadline.
Terminal OAuth recordsDelete within 30 days after the earliest consumed, rotated, revoked or expired event.
Organization agreement and accepting-person capacity or authority evidenceRetain while the applicable organization agreement is active and for 10 years after its termination. Then delete, subject only to the record-specific legal-preservation exception above. Deleting the accepting person's account or the relevant Laki.ai organization or Team does not erase the evidence before this period ends.
Microsoft tenant-connection setup request, verifier session and authentication attemptEligibility, proof-session and CSRF material is cleared when the request becomes terminal. A terminal setup request is deleted within 24 hours after its durable success fields have been copied to connection evidence. Successful or failed authentication attempts are deleted promptly; an abandoned attempt expires after 10 minutes and is deleted within 24 hours.
Microsoft Entra authentication and live tenant-to-organization mappingRaw Enterprise Token Store tokens and claims are request-lived and not durably retained; Laki.ai does not retain email or display name for this path. The operational mapping remains only while the connection is live.
Pseudonymous Microsoft actor capacity recordDelete 120 days after the actor's last valid research-tool activity. A later valid activity moves that actor's deadline; discovery, initialization, resources and reader presentation do not. This rule is separate from the pseudonymised usage-detail row below.
Tenant-administrator proof, operational declaration and connection evidenceRetain while the connection is live. When the connection terminates through disablement, retirement, a completed transfer, termination of the applicable organization agreement, or deletion of the relevant Laki.ai organization or Team, record the terminal event once and delete six years after that terminal date, subject only to the record-specific legal-preservation exception above.
Tenant-transfer authorization and transfer evidenceDelete six years after the authorization date or transfer event, as applicable, subject only to the record-specific legal-preservation exception above. This includes a private official-register reference used for the sole dissolution exception.
Copilot acquisition, capacity and billing-operation recordsKeep operational state while needed for the active subscription. Accounting source records are retained through the applicable statutory six-year period; a record that is itself a statutory financial statement or accounting book follows the applicable ten-year period.
Identifiable usage detail other than the Microsoft actor capacity recordPseudonymise within 90 days and immediately on verified account deletion.
Pseudonymised usage detail other than the Microsoft actor capacity recordRetain through six years after the relevant financial year, then delete.
Account, profile and organization dataWhile active; primary deletion within 30 days after verified deletion or termination, subject to agreement-evidence, accounting and other stated exceptions.
Support and email correspondenceDelete or irreversibly anonymise within 24 months after closure or delivery completion.
Incident and dispute evidenceThree years from closure, subject only to the record-specific legal-preservation exception above.
Routine provider operational metadataNo more than 90 days.
Cloud SQL deletion propagationUp to 15 retained daily backup generations; retention and deletion are reapplied after restore before traffic.

9.Security

We use access controls, encryption in transit, restricted production access, hashed storage for secret OAuth and API-key values, pseudonymous identifiers, one-time and expiring verification material, monitoring, backups, supplier controls and incident procedures appropriate to the service. No internet service is risk-free. Customers must manage host permissions and settings, minimise inputs and never submit the prohibited categories listed above.

10.Your rights and connection controls

Subject to applicable law, you may request access, correction, deletion, restriction or portability; object to processing; withdraw consent where consent is used; and complain to the Office of the Data Protection Ombudsman. Send requests to info@laki.ai. We may request information needed to verify identity and route requests concerning our role as processor to the customer acting as controller. Where a record is pseudonymous, we may need the relevant organization, tenant or request context to locate it without collecting an identity mapping that we otherwise do not keep.

You can revoke an OAuth connection through the relevant host's connection controls, where available. You may also request revocation at info@laki.ai. Revocation invalidates the matching Laki.ai access and refresh-token family. Disconnecting does not by itself delete the Laki.ai account or records that must be retained under this policy. Deleting only a host conversation or local client session does not revoke or delete them.

For the Microsoft organization path, the Laki.ai organization owner or administrator can disable the server-side tenant connection, and the Microsoft administrator can remove assignments and the application. You may ask Laki.ai to review an incorrect capacity, proof, connection or transfer status. A deletion or objection request does not require Laki.ai to create a Microsoft-to-Laki identity link, rewrite immutable evidence, or delete a record before an applicable contract or statutory period ends or while the record-specific legal-preservation exception above applies.

info@laki.ai · Office of the Data Protection Ombudsman

11.Changes

We update this policy when the service, processing or law changes. The current version is published with its version number and date. We give clear, appropriate notice of material changes in the service or to the account email when required by the applicable relationship and law.

Version 5 is a dated page update. Laki.ai presents a just-in-time link to it before self-service acquisition and before Microsoft administrator proof and the operational declaration. No separate email or other notification campaign is sent solely for this Version 5 publication.