This policy describes how Friigo Oy processes personal data in the Amura Mobile app and the related Amura service. Everything described here corresponds to app version 1.1.1.
1. Controller
Friigo Oy (Business ID 3129114-6)
Sammonkatu 19H, 33540 Tampere, Finland
Email: asiakaspalvelu@friigo.fi
Phone: +358 45 635 3901
2. Contact for data protection matters
3. Name of the register
Amura service user and voucher register
4. What the app is for
Amura Mobile is an app for users of the Amura financial-management software. A company representative photographs the company’s receipts and other documents and delivers them to the company’s bookkeeping. Using the app requires Amura user credentials. The app is not intended for persons under 18 or for consumer use.
5. Data processed
User data
- Email address, name and user role (credentials created in the Amura service)
- Password (sent to the server over an encrypted connection at login; the app does not see it afterwards) and, where enabled, the two-factor authentication code
- Which companies the user has access to
Voucher data
- Images of receipts and vouchers that the user takes with the camera or selects from the device’s photo library
- Details recognised from the images and checked by the user: merchant, date, total, VAT, cost centre and any note
- The voucher’s processing status in bookkeeping
Receipts may contain personal data (for example the buyer’s name, the last digits of a card number or a loyalty-card number). These are processed as part of the company’s bookkeeping material.
Company data
Shown in the app, maintained in the Amura service.
- Company name and Business ID, cost centres
- The company’s sales invoices, customers and products (view only)
Technical data
- Login session token (valid for at most 8 hours), stored in the device’s secure storage
- If the user enables “Remember login on this device”: the email and password are stored in the device’s secure storage (iOS Keychain / Android Keystore), and using them requires confirmation with the device lock (Face ID, Touch ID, fingerprint or passcode). This data leaves the device only to log in to the Amura service. It is deleted when the user logs out or turns the option off.
- Language preference (stored on the device only)
- Server logs (IP address, timestamp, requested action) for security and troubleshooting. Logs are kept for 6 months.
What the app does not collect: the app contains no analytics, advertising, tracking identifiers or crash reporting. Location is not used. Only the image the user selects is read from the photo library.
6. Purpose and legal basis
- Receiving, recognising and archiving the vouchers of a company subject to accounting obligations — legal basis: the Amura service agreement with the customer company and the statutory obligations of the Finnish Accounting Act.
- Identifying the user and managing access rights — contract.
- Service security, prevention of misuse and troubleshooting — legitimate interest.
7. AI-based recognition
Details are recognised automatically from the uploaded receipt image with an AI model so the user does not have to type them. The result is always a suggestion that the user checks and corrects if needed before saving. Recognition uses Google’s Gemini model on Google Cloud Vertex AI in the EU/EEA region via the Amura service’s server; the app does not send images directly to Google, and Google does not use the images to train its models. Recognition is not used for automated decision-making.
8. Retention
- Vouchers and the data saved from them are part of the customer company’s bookkeeping material and are retained for the period required by the Finnish Accounting Act (vouchers 6 years and accounting books 10 years from the end of the financial year). The material is stored on a server located in Finland. When the customer relationship ends, the material is handed over to the customer company and then deleted from the service provider’s server.
- User credentials are retained for the duration of the customer relationship and access right.
- The session token expires within 8 hours at the latest. Login details stored on the device are removed on logout.
- The app keeps images on the device only for the duration of the upload; it saves nothing to the device’s own photo library.
9. Disclosures and processors
Data is not sold or disclosed for marketing purposes. Processors acting on Friigo’s behalf:
- Server environment: Adalia Oy, servers located in Finland.
- Google Cloud (Vertex AI, Gemini): AI recognition of the receipt image in the EU/EEA region, see section 7.
- Expo (Expo, Inc., USA): on launch the app checks Expo’s service for app updates. The request carries the app version, operating system and IP address — no user or voucher data.
- Apple and Google: app store distribution and the operating system’s secure storage. The stores may collect their own statistics under their own privacy policies.
- The customer company’s own accountant processes the vouchers as part of the bookkeeping service.
10. Transfers outside the EU/EEA
Voucher data is processed within the EU/EEA: the servers are located in Finland and AI recognition runs in the EU region of Vertex AI. Where a processor (for example Expo or Google) is located in the United States, the transfer is based on the standard contractual clauses approved by the European Commission and/or the EU–US Data Privacy Framework.
11. Security
All traffic between the app and the server is encrypted (HTTPS). Voucher images can be retrieved only with a logged-in user’s token. Tokens and login details kept on the device are in the operating system’s secure storage. Access to server data is limited to named persons bound by confidentiality.
12. Rights of the data subject
The data subject has the right to access their data, request rectification or erasure, restrict or object to processing, and receive their data in a portable format, to the extent permitted by law. Bookkeeping material cannot be erased during the retention period required by the Accounting Act. Requests are addressed to the contact in section 2. The data subject also has the right to lodge a complaint with the supervisory authority (Office of the Data Protection Ombudsman, tietosuoja.fi).
13. Changes
This policy is updated as the app evolves. The current version is always available at this address; material changes are announced in the app.