Skip to content
ristna

Privacy policy

Last updated 26 Sept 2026

Who we are

SoftAccount OÜ (registry code 12607687, Estonia, Hiiumaa, Käina, Sõpruse põik 3-8, 92101) operates ristna and is the controller of the personal data described in this policy. The policy covers our website and the ristna app (together, the “Service”). If you have any questions about it, contact us at hello@ristna.app.

If you use ristna in a workspace set up by an organization, such as your employer, that organization controls the workspace content instead. We process that content on its behalf and under its instructions, so please send requests about workspace content to the organization first.

What we collect

  • Account details: your name, email address, password (never stored in plain text) and your role in each workspace.
  • Workspace content: anything you or your teammates create or upload in the Service, which may include personal data about you or other people.
  • Billing details: billing name and address, company name, VAT number and payment history. Card payments are handled by our payment provider, so we never see or store your full card number.
  • Usage data: information collected automatically when you use the Service, such as your IP address, browser and device type, the pages and features you use, timestamps and error reports.
  • Messages to us: what you send through our contact form or by email, including your name, email address and anything else you choose to include.

Most of this comes directly from you. If a teammate invites you to a workspace, we receive your email address from them. We need your account details to create your account, so without them you can’t use the Service.

How we use it

We use personal data for the following purposes, each with a legal basis under the EU General Data Protection Regulation (GDPR):

  • Providing the Service: running your account, storing and syncing workspace content, sending essential service emails and giving support. Legal basis: performing our contract with you.
  • Billing: taking payments, issuing invoices and keeping accounting records. Legal basis: performing our contract with you and complying with accounting and tax law.
  • Security: protecting accounts, preventing fraud and abuse, and diagnosing errors. Legal basis: our legitimate interest in running a secure and reliable service.
  • Improving the Service: understanding how features are used, mostly in aggregate. Legal basis: our legitimate interest in improving the product.
  • Answering your messages: replying to contact form and email enquiries. Legal basis: our legitimate interest in responding to you, or taking steps you asked for before entering into a contract.
  • Product news: occasional emails about ristna. Legal basis: your consent or, for existing customers, our legitimate interest where the law allows it. Every email has an unsubscribe link.
  • Legal compliance: meeting legal obligations, responding to lawful requests from authorities, and establishing or defending legal claims. Legal basis: legal obligation or our legitimate interests.

When we rely on legitimate interests, we have weighed them against your rights, and you can object at any time (see Your rights). We do not sell your personal data, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

Who we share it with

We share personal data only with:

  • Service providers that process it on our behalf, under contracts that require them to protect it and use it only on our instructions (listed below).
  • Stripe, our payment provider, which also uses payment data as an independent controller, for example to prevent fraud and meet its legal obligations (see Stripe’s privacy policy).
  • Other members of your workspace, who can see your name, email address and the content you share with them. Workspace admins can also manage your access.
  • Professional advisers, such as lawyers, accountants and auditors, who are bound by confidentiality.
  • Authorities, when the law requires it or when it is necessary to protect our rights, our users or others.
  • A buyer or successor, if we are involved in a merger, acquisition or sale of assets. We will tell you before your data becomes subject to a different privacy policy.

Our current service providers are:

  • Vercel Inc.: website and application hosting (US/global)
  • Heroku (Salesforce, Inc.): application server hosting (EU)
  • Neo4j, Inc.: database hosting and backups (EU)
  • Stripe Payments Europe, Limited: payment processing (EU/US)
  • Elkdata OÜ: account and service emails (EU)

International transfers

We store your data in the European Union. Some of our service providers may process it outside the European Economic Area. When they do, the transfer is covered by a European Commission adequacy decision or by Standard Contractual Clauses approved by the Commission, with additional safeguards where needed. You can ask us for details of these safeguards.

How long we keep it

  • Account details: until you ask us to delete your account, then deleted within 30 days.
  • Workspace content: until you or a workspace admin deletes it or the workspace is closed, then deleted within 30 days.
  • Billing records: 7 years, as required by accounting law.
  • Usage data and logs: up to 12 months.
  • Messages to us: up to 2 years after our last exchange.

Deleted data can remain in backups for up to 7 more days, until those backups expire. We may keep data longer where the law requires it or to establish, exercise or defend legal claims.

Cookies

We use cookies and similar technologies that are strictly necessary for the Service to work, for example to keep you signed in and to protect your account. These don’t require your consent.

Security

We protect personal data with technical and organizational measures suited to the risk, including encryption in transit and at rest, access limited to people who need it, and regular backups. No system is completely secure, but if a breach affects your data, we will notify you and the authorities as the law requires.

Your rights

Under the GDPR, you have the right to:

  • access your personal data and get a copy of it;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict how we use your data;
  • receive the data you gave us in a machine-readable format, or have it sent to another service;
  • object to processing based on our legitimate interests, and to direct marketing at any time;
  • withdraw your consent at any time, without affecting processing that happened before.

You can update your details in your account settings. For anything else, email us at hello@ristna.app. We will respond within one month, or tell you if a complex request needs up to two more months, and we may need to confirm your identity first. Some rights have exceptions, for example when the law requires us to keep billing records. If one applies, we will explain why.

You can also lodge a complaint with a data protection authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), but you can also contact the authority in the EU or EEA country where you live or work.

Children

ristna is not intended for children under 12, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. We will post the new version on this page and update the date at the top. If the changes are significant, we will also tell you by email or in the app before they take effect.