Trust
Security
This page describes key security practices for Purnukka's SaaS service and the customer's own responsibility.
Updated: 26.6.2026
This is not legal advice. The terms can be reviewed by a lawyer before final use.
Stripe Connect
Stripe Connect may be used for technical payment routing. Stripe is responsible for the security of its own payment services and for processing payment data under its own terms.
Purnukka does not aim to store full payment card numbers in its own systems, but routes payment to secure components provided by the payment service.
SSL/TLS
Purnukka websites are intended to be provided over encrypted HTTPS connections. SSL/TLS encryption protects traffic between the browser and server in ordinary web use.
A certificate can be enabled for the customer's own domain as part of technical setup if the domain DNS and server environment allow it.
Backups
The service may use backups provided by hosting and database services. The exact coverage, retention period and recovery options depend on the provider and technical environment used.
Backups do not replace the customer's own duty to preserve essential business and accounting records appropriately.
Access rights
Admin panel access rights are intended to be limited by the user role and need. The customer is responsible for ensuring that their own users are the correct people and that unnecessary accounts are removed.
Purnukka may use technical maintenance accounts to provide the service, fix errors and support customers.
Updates
Purnukka maintains its own service code and aims to fix detected security issues within a reasonable time. Third-party services and libraries follow their own update and support models.
Changes may be made to the service for security, reliability or development reasons.
Processing data in the EU/EEA
Purnukka aims to process and store data in the EU/EEA where possible. Some providers, such as payment or email services, may also process data in other countries under their own terms and safeguards.
Actual providers and processing locations may change as the service develops.
Incidents
In incidents, Purnukka aims to investigate the impact, limit the issue and restore normal service within a reasonable time. An incident may also be caused by a third-party service, network connection, DNS or payment service.
If you notice an incident, contact info@purnukka.com.
Customer responsibility
The customer is responsible for the security of passwords, email accounts, their own devices and content entered into the service. The customer is also responsible for ensuring that unlawful, misleading or rights-infringing content is not added to the service.
Purnukka may restrict use of the service if it is used in a way that endangers security, service operation or other users' rights.