How it worksPricingReferencesResourcesFAQContact

Built for European teams

Strategy software with EU data residency

Suunta.ai stores core strategy, OKR, project and KPI data in the EU (AWS Stockholm) and is designed for GDPR-conscious teams. AI processing is transparent, covered by SCCs where needed, and includes an EU-only Mistral path.

  • EU data residency
  • GDPR-focused
  • No AI training on your data
  • AES-256 encrypted

The compliance gap

Most AI-powered tools were not built for European data rules

Many SaaS platforms store customer data outside the EU, use AI processing with unclear retention terms, or provide limited transparency about where information goes. For European teams, that creates legal and reputational risk.

The problem with US-first tooling

When your strategy discussions, OKRs and performance data live in tools built around non-European infrastructure, you face three concrete risks:

  1. Data residency: sensitive company data may require additional safeguards before it is processed outside the EEA.
  1. AI training: some AI-assisted tools reserve the right to use customer inputs to improve their models.
  1. Opaque subprocessors: complex vendor chains make it hard to know who actually handles your data.

What EU data residency means for you

Suunta.ai is built to reduce these risks. Core customer data - strategies, OKRs, project details and KPIs - is stored and processed in the EU (AWS Stockholm). AI processing is handled by disclosed sub-processors: some EU-based (Mistral; Google Vertex AI's EU region where available) and some US-based (Anthropic, OpenAI, Google), under GDPR Standard Contractual Clauses where required. We never use your inputs to train AI models, and an EU-only AI path via Mistral is available.

For your DPO, this means clearer answers for vendor review, subprocessor assessment and AI risk management. For your leadership team, it means you can connect strategy work without accepting vague data-handling promises.

Data protection by design

Built with GDPR in mind from the ground up

These are not badge claims. Privacy and data residency are part of the architecture.

Northern lights aurora borealis over mountain silhouettes at night
  1. 01

    EU data residency

    Core customer data (strategies, OKRs, projects, KPIs) is stored and processed in the EU (AWS Stockholm). AI processing uses disclosed sub-processors, some EU-based and some US-based, under GDPR SCCs where required. An EU-only AI path via Mistral is available.

  2. 02

    GDPR-focused controls

    Suunta.ai is designed to support GDPR requirements with a DPA, subprocessor disclosure, deletion support and GDPR-aligned data handling.

  3. 03

    No training on your data

    We don't keep separate logs of your prompts or responses, and we never use them to train AI models. Chat history is stored encrypted for continuity and can be deleted anytime; in-progress output is held transiently and auto-deleted.

  4. 04

    Encrypted in transit and at rest

    Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Role-based access controls and data export workflows support security reviews.

  5. 05

    Clear DPA

    A Data Processing Agreement is available for customers. It documents roles, processing purposes, subprocessors and retention periods.

  6. 06

    Strategy without surveillance

    Your plans, OKRs and KPIs stay private to your organisation. Suunta.ai does not analyse or benchmark your data against other customers.

For your DPO and legal team

What you get in writing

Compliance confidence should not depend on a vendor marketing page. Here is what is documented for procurement and vendor review.

Data Processing Agreement (DPA) - Available for customers. Covers roles (controller / processor), processing purposes, retention schedules and subprocessor disclosure.

Subprocessor list - A published list identifies third-party services that process customer data, along with their role and country of operation.

Data residency commitment - Core application data, including strategy, OKR, project and KPI data, is hosted in the EU/EEA. Where AI, payments or optional integrations involve non-EEA subprocessors, they are disclosed and covered with GDPR transfer safeguards such as SCCs.

Right to erasure - Suunta.ai supports data subject requests, including full account and data deletion on request.

Incident notification - In the unlikely event of a security incident, we notify affected customers within 72 hours in line with GDPR Article 33.

Kare Oja - President of Suunta.ai

From the founder

Strategy data is the most sensitive information a company holds

"Privacy and security have been a top priority for us since day one, shaping every architectural decision we have made. That is not a compliance checkbox, it is a commitment to our customers."

Kare Oja

Founder, Suunta.ai · CTO, Y4 Works

The full picture

Compliance and capability in one tool

Choosing a GDPR-focused tool should not mean settling for a lesser product. Suunta.ai gives you the full strategy stack alongside a transparent data-protection architecture.

Frozen lake surface with dramatic snow-covered rock cliffs in winter
  1. 01

    Strategy to execution in one place

    Connect long-term strategy with OKRs, projects and KPIs. No more copying targets between tools or losing context across documents.

  2. 02

    AI that respects your data

    Suunta.ai uses your goals and context to generate useful suggestions. We do not use your data for model training, chat history is encrypted for continuity, and an EU-only AI processing path is available via Mistral.

  3. 03

    Live KPI tracking

    Track progress against your goals as work moves. Spot misalignment early and redirect effort before it becomes a problem.

  4. 04

    Built for leadership teams

    Designed for 10–200-person organisations where the leadership team needs clarity, not complexity. Fast to set up, easy to maintain.

Common questions

Data protection — what people ask

Suunta.ai is designed for GDPR-conscious teams: core app data is hosted in AWS Stockholm, encrypted at rest with AES-256 and protected in transit with TLS 1.2+.

We do not keep separate logs of prompts or responses, and we never use customer data to train AI models. Chat history is stored encrypted for continuity and can be deleted; in-progress AI output is held transiently and deleted automatically soon after generation.

AI providers are disclosed as subprocessors and are covered by GDPR transfer safeguards where needed.

Yes. Suunta.ai supports single sign-on via Google and Microsoft (OIDC/OAuth2). Role-based access controls help separate owner, admin, member, viewer and consultant access across the organisation.

SAML SSO, including Okta and Azure AD federation, and SCIM provisioning are roadmap items, not current production features. Audit and activity data are available through data export workflows.

Core application data - strategies, OKRs, projects and KPIs - is hosted in AWS Europe (Stockholm), encrypted at rest with AES-256 and protected in transit with TLS 1.2+.

AI processing uses disclosed sub-processors: some EU-based (Mistral; Google Vertex AI's EU region where available) and some US-based (Anthropic, OpenAI, Google), under GDPR SCCs where required. An EU-only AI path via Mistral is available.

We can provide a DPA and subprocessor information for vendor review. Email privacy@suunta.ai.

Further reading

A practical GDPR guide for European teams using AI strategy tools

Choosing an AI-powered strategy platform as a European team raises specific questions: where does data go, who can access it, and how do you explain AI use to your DPO? This article guides you through the key considerations.

Our article covers:

  • What EU data residency actually means in practice and what it does not cover
  • How to assess AI subprocessors under GDPR (SCCs, data retention, training clauses)
  • The questions your DPO is likely to ask when reviewing a strategy SaaS vendor
  • What a GDPR-ready AI tool should document: DPA, subprocessor list, deletion rights and incident notification

If you are evaluating tools for your team or preparing a vendor review, the article is a practical starting point.

Read the article →

EU-hosted core app data

Run your strategy on infrastructure you can explain

EU-hosted core app data, encryption at rest and in transit, transparent subprocessors and a strategy tool your team will actually use.