← Back to Legal Hub

Version: 1.2
Date: April 2026
Owner: Risto Anton Päärni, CEO
Compliance: GDPR, EU Data Act, NIS2, EU AI Act

1. Lifetime Oy Security Stack

Infrastructure Security

Lifetime Oy Security Stack:

Email Communication Security

All Business Email via Proton Mail

Lifetime Oy policy:

Email Classification

Email Type Proton Mail Features Security Level
CONFIDENTIAL E2EE to Proton recipients, password-protected to others 🔒🔒🔒 Highest
INTERNAL Standard encryption (TLS), no password needed 🔒🔒 High
PUBLIC Standard encryption (TLS) 🔒 Medium

Sending CONFIDENTIAL Data via Email

Option 1: Recipient has Proton Mail

  1. Compose email in Proton Mail
  2. Attach file or write sensitive content
  3. Send normally → Automatic E2EE
  4. ✅ Both sender and recipient encrypted end-to-end

Option 2: Recipient uses Gmail/Outlook/Other

  1. Compose email in Proton Mail
  2. Enable: "Encrypt for non-Proton users"
  3. Set password (share via SMS separately)
  4. Recipient clicks link → Enters password → Reads email
  5. ✅ Message encrypted, recipient cannot forward/copy (security mode)

Option 3: Use Proton Drive link (preferred for large files)

  1. Upload file to Proton Drive
  2. Create password-protected link
  3. Send link via Proton Mail
  4. Send password via SMS
  5. ✅ File never leaves encrypted environment

Email Retention

Classification Retention Period Archive Location
CONFIDENTIAL 7 years (GDPR/tax law) Proton Mail Archive (encrypted)
INTERNAL 3 years Proton Mail Archive
PUBLIC 1 year Proton Mail Archive

2. EU Compliance Requirements

GDPR (General Data Protection Regulation)

Lifetime Oy complies with EU GDPR requirements:

EU AI Act (Regulation 2024/1689)

DWS IQ 6 = Limited Risk AI system (Annex III: construction safety)

NIS2 Directive (EU 2022/2555)

Lifetime Oy = Essential entity (construction sector)

3. Data Residency

All production data is stored in EU regions:

4. Contact and Questions

Policy owner:
Risto Anton Päärni, CEO
Email: risto@lifetime.fi

Report security incident:
Email: security@lifetime.fi
Urgent: CEO directly (risto@lifetime.fi)


Document history:
2025-12-13: v1.0 — Initial policy created
2025-12-20: v1.1 — Updated with security stack, email communication, EU compliance
2026-04-01: v1.2 — Q2 2026 quarterly review; fixed region name (europe-north1 = Finland)
Next review: 2026-07-01 (quarterly)