Suomeksi: Tietosuojaseloste
Last updated: 19 August 2026
Applies to: the Thispatch mobile application (com.thispatch.mobile) and the
Thispatch web console.
Thispatch is a field-service dispatch tool licensed to organisations (security, alarm-response, and health and social care service providers).
Your employer or contracting organisation is the data controller for all personal data in the service: your user account, service-recipient (customer) records, tasks, task notes and reports, photographs, unit location data, security and audit logs, and application diagnostics. It decides what is collected and why.
Heroic Oy is the data processor throughout. We host and operate the service and process personal data only on the documented instructions of the controlling organisation, under a data processing agreement concluded in accordance with Article 28 of the GDPR. We do not use the data for our own purposes, and we do not repurpose diagnostic or analytics data for product development or any other use of our own.
Because Heroic Oy is a processor and not a controller, requests to exercise your rights are handled by your organisation. Contact it first; we assist it in responding.
Contact details
| Controller | Your employer or contracting organisation — see its own privacy notice |
| Processor | Heroic Oy |
| Business ID (Y-tunnus) | 2946245-2 |
| Registered address | Hakatie 5, 01390 Vantaa, Finland |
| Privacy contact | Alberto Cruz, info@thispatch.fi |
| Data protection officer | Not appointed — see privacy contact above |
Accounts are created by your organisation's administrators. The app has no public sign-up.
Whether location is collected is controlled according to your organisation's policy, not as an individual preference. The setting is held against your user account rather than the handset, so it is the same on whichever device you sign in to, and collection is on unless your organisation has decided otherwise. Where the organisation's policy allows individuals to control it, the switch under Settings → Location is usable; otherwise it is shown but fixed, and a request to change it is made to your organisation.
Collection is not limited to the time the app is on screen. While you are signed in to a unit, position is reported by a background service that keeps running with the screen off and while other applications are in use. Android shows a permanent notification for as long as that service runs, and the notification states whether position is being shared. The app does not collect location when you are not signed in to a unit, and signing out stops it.
Where the organisation's policy has location collection switched off, that background service still runs — it is what allows the phone to be alerted about a dispatched task nobody has accepted — but no position leaves the device.
Location data relates to the unit and, through the unit, to the person signed in to it. Section 4.2 explains the Finnish rules that apply to this.
Depending on what your organisation records, task and customer records may contain:
Special category data. Where the controlling organisation uses Thispatch to support health or social care service delivery, these records may contain data concerning health within the meaning of Article 9 of the GDPR. Heroic Oy processes such data solely as a processor, on the controller's instructions. The controller is responsible for identifying its legal basis (typically Article 9(2)(h)) and for compliance with Finnish sectoral legislation, including the Act on the Processing of Client Data in Health and Social Care (703/2023).
We do not process payment card data, biometric data, or advertising identifiers, and the data is not used for advertising or profiling.
Data is obtained from you (entries you make in the app, photographs you take, your device's location sensor), from your employing organisation (account and role data), from the controller's own or integrated systems (customer and task records, alarm events), and generated by the service itself (audit and diagnostic records).
| Purpose | Legal basis |
|---|---|
| Providing dispatch, task management, and reporting functionality | Heroic Oy processes as processor under Article 28; the controller's own basis is typically Article 6(1)(b), (c), (e), or (f) |
| Account administration, authentication, and access control | The controller's basis, typically Article 6(1)(b) — performance of your employment or service contract |
| Security monitoring, audit logging, incident investigation, and abuse prevention | The controller's basis, typically Article 6(1)(c) — legal obligation to secure the data — or Article 6(1)(f) |
Unit location is processed for dispatch efficiency, task verification, and the safety of lone workers. The legal basis relied on by the controlling organisation is normally Article 6(1)(f) — its legitimate interest in operating the service and protecting its personnel.
Where the persons tracked are employees, the controlling organisation must in addition comply with Finnish law:
Heroic Oy makes location functionality available; the decision to enable it, the completion of co-operation negotiations, and the provision of information to employees are the controlling organisation's responsibility.
The product is supplied with location collection switched on, and the ability of an individual to switch it off is itself a permission the organisation grants to a role — reflecting that the necessity test under 759/2004 is answered by the organisation for the work being done, not by each person for themselves. An organisation that has not completed the co-operation procedure, or that concludes location is not necessary for a given group, is responsible for switching it off for the people concerned.
Crash diagnostics are necessary to keep the application working safely and are processed on the controller's behalf on the basis it relies on for operating the service, normally Article 6(1)(f). They are not linked to your account unless you enable usage analytics.
Usage analytics are optional and off by default. Under section 205 of the Act on Electronic Communications Services (917/2014), storing information on, or reading information from, a user's terminal equipment for purposes that are not strictly necessary requires consent. Analytics are therefore not collected unless you switch them on yourself:
There is no automated decision-making producing legal or similarly significant effects, and no profiling, within the meaning of Article 22 of the GDPR.
| Data | Retention |
|---|---|
| User account and role data | For the duration of the account; deleted or deactivated when your organisation removes the account |
| Session and device records | Until the session is terminated, plus 12 months for security investigation |
| Unit location history | 90 days, after which records are automatically and permanently deleted by a daily purge. The unit's current position is not history and is overwritten on each new report |
| Task, customer, and attachment data | Determined by the controlling organisation and its statutory obligations; Heroic Oy deletes or returns the data at the end of the processing agreement |
| Audit log | 7 years, after which entries are automatically anonymised |
| Crash diagnostics and analytics | Per Google Firebase retention settings — crash reports 90 days (Crashlytics); analytics user-level data 2 months (Google Analytics for Firebase default) |
| Support correspondence | 24 months from case closure |
We do not sell personal data and we do not disclose it for marketing purposes.
Data is disclosed to:
Sub-processors
| Provider | Function | Processing location |
|---|---|---|
| Microsoft Ireland Operations Ltd (Microsoft Azure) | Application hosting, database, file storage — for installations hosted by Heroic Oy | EU/EEA — European regions only |
| Google Ireland Limited | Firebase Crashlytics, Firebase Analytics, Firebase Cloud Messaging (push notifications) | EU, with onward processing by Google LLC in the United States |
Telephony and call handling run on service infrastructure operated by Heroic Oy within the hosting environment above; no external email, SMS, or telephony delivery provider is currently engaged. Where a customer installation runs on infrastructure procured by the customer organisation itself, that organisation's own processing agreement annex names the hosting provider instead. This list is updated before any new sub-processor is engaged.
Transfers outside the EU/EEA. Application data — your account, tasks, service-recipient records, photographs, location history, and audit logs — is stored and processed in the EU/EEA and is not transferred outside it.
Three functions are the exception. Crash diagnostics, usage analytics (only where you have enabled them), and push notification delivery run on Google Firebase, which involves processing by Google LLC in the United States. Those transfers are made under the European Commission's Standard Contractual Clauses together with Google's data processing terms and supplementary technical measures.
What is sent to Firebase is limited, and deliberately so:
| Sent to Firebase | Never sent to Firebase |
|---|---|
| Crash stack traces, device model, OS and app version | Service-recipient or customer records of any kind |
| A push notification registration token | Task descriptions, notes, reports, or custom field values |
| Analytics events (sign-in, sign-out, unit selection, screen views, push notification receipt) — only if you opted in | Photographs and their captions |
| Your account identifier — only if you opted in | Location coordinates and location history |
| Names, email addresses, telephone numbers, or free-text entered in the app | |
| Any health or other special-category data |
This data is still personal data. Device identifiers, IP addresses, and — where you have opted in — your account identifier make it attributable to you, so it is protected as personal data and covered by the safeguards above. What it does not contain is any content from the service: no service-recipient information, no task content, and no special-category data.
If a personal data breach occurs, we notify the affected controlling organisations without undue delay so that they can meet their obligations under Articles 33 and 34 of the GDPR.
Under the GDPR you have the right to:
How to exercise them. Address requests to your employing or contracting organisation, which is the controller for all data in the service. Heroic Oy acts on the controller's instructions and assists it in responding within the statutory time limit. If you are unsure who to contact, write to us at info@thispatch.fi and we will route the request to the correct controller — we cannot decide it ourselves.
The analytics setting is the one choice you make directly in the app: switch it off under Settings → Privacy at any time, without going through anyone.
Account deletion. Accounts are created and removed by your organisation's administrators; there is no in-app self-registration or self-deletion. Ask your administrator to deactivate your account.
Right to complain. You may lodge a complaint with the Finnish supervisory authority:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) Postal address: PL 800, 00531 Helsinki, Finland Visiting address: Lintulahdenkuja 4, 00530 Helsinki Telephone: +358 29 566 6700 Email: tietosuoja@om.fi https://tietosuoja.fi
The application requests the following permissions. Each may be declined; declining disables the corresponding feature but not the application as a whole.
| Permission | Why |
|---|---|
| Precise location | Reporting unit position for dispatch and worker safety while signed in to a unit, collected according to your organisation's policy. Also used, with no position leaving the device, to alert you about a dispatched task nobody has accepted |
| Camera | Photographing work sites and completed installations as task attachments |
| NFC | Reading an NFC tag to unlock the app quickly and to identify installed equipment |
| Notifications | Delivering new-task and escalation alerts |
Thispatch is a professional tool provided to organisations for use by their personnel. It is not directed at, or intended for use by, persons under 18.
We may update this policy as the service changes. The date at the top of the page indicates the latest revision. Material changes are communicated to controlling organisations in advance through the ordinary service-communication channels.
Heroic Oy (processor) — Hakatie 5, 01390 Vantaa, Finland Privacy enquiries: Alberto Cruz, info@thispatch.fi
For your rights as a data subject, contact your own organisation as controller. The address above is for routing and for the controller's own enquiries.
A Finnish-language version of this policy is available at docs/tietosuojaseloste.md. In the event of a discrepancy, the Finnish version prevails.