Who is responsible
Bröderna Saxin AB, operating as PineCore Systems, company no. 559379-4364, Lindesby 152, 713 94 Nora, Sweden, is the controller for PineKey account administration, service security and correspondence. Contact: [email protected].
When an organisation decides to put personal data in a team vault, it is normally the controller of that data and PineKey acts as its processor. The organisation must give its members the relevant information. Our DPA covers that relationship.
What we process and why
Your vault contents are encrypted on your device before reaching our servers. Your master password and decrypted vault fields are not sent to our application API. Encryption does not hide every piece of service metadata.
| Information | Purpose and basis |
|---|---|
| Email address, optional profile name, authentication verifier and protected encryption keys | Create and maintain the account and provide access. Contract, Article 6(1)(b) GDPR. |
| Encrypted vault items, folders, collections and workspace history; object identifiers, ownership and modification times | Store, synchronise and organise the vault you ask us to provide. Contract; organisation content is processed on the organisation’s instructions. |
| Organisation names, membership, invitations, roles and access permissions | Provide team sharing and manage authorised access. Contract and, for business contacts, our legitimate interest in providing the organisation’s service. |
| Device identifiers/names, session times, IP addresses, security events and technical error information | Prevent abuse, troubleshoot and protect the service. Legitimate interest in account and infrastructure security; essential session processing also supports the contract. |
| Support messages and transactional email addresses/content and delivery information | Answer requests and send account, invitation and security messages. Contract or legitimate interest in responding to enquiries. |
We do not use vault data for advertising, sell it, or use it to train AI models. We do not add advertising or behavioural analytics scripts to the website. Necessary account details are required to provide an account; the profile name is optional. There is no automated decision-making with legal or similarly significant effects.
Where information comes from
You provide account and support information. Your browser supplies technical connection information. An organisation administrator or trusted contact may give us your email address to invite you. Invitation emails identify the purpose; contact us if an invitation was unwanted.
Hosting, recipients and international processing
The application, primary vault database and routine server backups are hosted by Hetzner in Helsinki, Finland, in the EU. Service operators are based in Sweden. Access is restricted to people and providers who need it to operate the service.
Cloudflare provides network delivery and protection through its global network. Resend delivers transactional mail; the domain’s sending region is Ireland, but that setting does not restrict all Resend processing to the EU. MXroute hosts the support mailbox. These providers may process connection information, account metadata or correspondence outside the EEA. We do not claim that every data flow stays in the EU.
See the provider register for purposes and locations. International transfers require a valid mechanism, such as an applicable adequacy decision or standard contractual clauses with necessary supplementary measures. You can request information about the arrangements that apply to your data. Provider-region settings alone are not proof of EU-only processing.
How long information stays
| Category | Retention |
|---|---|
| Account and active encrypted vault | For the life of the account, until you delete the content or request account closure. Archived items stay until deleted; trash is configured for automatic deletion after 30 days. |
| Team activity | The service is configured to retain organisation events for 90 days. |
| Sessions | Up to 30 days, or earlier when expired or revoked. Expired session files are cleaned by the scheduled maintenance job. |
| Backups | Encrypted snapshots rotate through 30 daily, 8 weekly and 12 monthly restore points. Removed data can remain in historical backups until those points age out. Backups are restricted to recovery; deletions must be reapplied after restoration. |
| Support, security investigations and provider records | Kept while needed to handle the request, protect the service or resolve a dispute, then assessed for deletion. Provider retention depends on the service and contractual settings; ask us for details relevant to your request. |
| Optional offline copy | Stored on your device until removal, site-data clearing or sign-out. The app refuses to unlock a copy more than seven days old; expiry does not itself guarantee erasure of bytes from your device. |
Your rights and choices
You can request access, correction, erasure, restriction or portability where applicable, and object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it. Contact [email protected]; we may ask for proportionate proof of identity but never your master password.
We normally respond within one month. If an extension is permitted because a request is complex or numerous, we explain it within that month. You can complain to the Swedish Authority for Privacy Protection, IMY, or your local supervisory authority.
You can change your profile and email in Settings, review sessions in Security, and export your vault under Import and export. Account closure currently requires a support request. Requests about an employer’s shared content may need to be directed to that organisation. We cannot decrypt content for you or erase a copy another authorised recipient already saved.
Cookies and updates
The cookies and local storage notice describes browser storage. We publish dated updates here and communicate material changes affecting existing accounts through the service or service email. A new purpose requires its own appropriate legal basis.