Privacy Policy

Panda Capital Oy Ab (Finnish business ID 3297809-7) ("we", "us", "our") respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, and store personal data when you access or use the Saturn SQL service ("Service").

1. Data Controller

The controller responsible for data processing is Panda Capital Oy Ab, registered in Finland under business ID 3297809-7.

2. Scope

This Privacy Policy applies to personal data processed in connection with registration for and use of the Service, and any associated websites or communications.

3. Legal Basis for Processing

We process personal data as necessary to perform our contract with you, comply with legal obligations, and pursue legitimate interests such as improving the Service, maintaining security, and preventing fraud. Processing is performed in accordance with the GDPR and Finnish law.

4. What Personal Data We Collect

We may collect limited information necessary to operate and improve the Service:

CategoryDetails
Account informationDetails provided during signup and account management
Service usage informationTechnical and operational data generated through normal use of the Service
Authentication informationData required to verify identity and maintain secure sessions
Connection informationConfiguration data needed to establish and maintain access to external data sources
Billing and subscription informationPayment-related and plan-related data processed by trusted third-party providers
Support and communication recordsInformation shared with us when contacting support or providing feedback
Early access or waitlist informationContact details submitted to express interest before product availability

5. How We Use Personal Data

We use collected data to:

  • provide, maintain, and support the Service,
  • manage subscriptions and payments,
  • deliver updates and security alerts,
  • improve performance and functionality, and
  • prevent abuse and security incidents.

6. Data Disclosure and Sharing

We may share personal data with:

  • subprocessors providing hosting, payment, or analytics services,
  • authorities where required by law, and
  • entities necessary to protect rights or safety.

We do not sell personal data.

7. Transfers Outside the EEA

If data is transferred outside the EEA, appropriate safeguards such as EU Standard Contractual Clauses or adequacy decisions are applied.

8. Data Retention

We retain personal data only as long as necessary for providing the Service and meeting legal requirements. After account termination, data is deleted or anonymised unless retention is legally required or needed for legitimate business purposes such as resolving disputes or auditing.

9. Your Rights

Users have the right to:

  • access their data,
  • correct inaccuracies,
  • request erasure in certain cases,
  • restrict or object to processing,
  • receive data in portable form, and
  • withdraw consent where applicable.

Requests can be made through the contact form available in the Service.

10. Cookies and Similar Technologies

Cookies and similar technologies are used to operate, measure, and improve the Service. You can manage or disable cookies through your browser settings.

11. Security and Liability

We apply strong technical and organisational measures such as encryption, access control, and monitoring. Absolute security cannot be guaranteed. We are not liable for accidental loss or unauthorised access except where caused by gross negligence or willful misconduct. Any data breach will be notified as required by law.

12. Changes to This Privacy Policy

Updates will be published on the website with an updated effective date. Major changes may also be communicated in-app.

13. Subprocessors and Third-Party Service Providers

We rely on carefully selected third-party providers for infrastructure, hosting, analytics, and payment processing. Each provider is bound by a data processing agreement and required to maintain adequate technical and organisational measures to protect data. Updated information about subprocessors is made available through the Service.

Service ProviderServiceData ProcessedLocation
Vercel Inc.Application Hosting & DeploymentAccount data, session data, query metadata, server logsUnited States
Neon (Serverless Postgres)Database StorageAll user data, query history, account informationUnited States (AWS)
UpstashRedis Cache & Rate LimitingIP addresses, request metadata, rate limit countersUnited States
Stripe Inc.Payment ProcessingBilling information, subscription data, payment recordsUnited States

14. Data Processing Agreement

Enterprise customers may request a separate Data Processing Agreement consistent with this Privacy Policy and compliant with GDPR requirements.

15. Contact

Questions or requests regarding this Privacy Policy may be submitted through the contact form in the Service.