Privacy

Privacy Policy

Updated 6 July 2026

Service: Digistartti
Controller: AI Velho Oy, Business ID 3616261-8, auxiliary business name Digistartti
Address: Kravatti 6, 90830 Haukipudas, Finland
Contact: [email protected]
Updated: 6 July 2026

This privacy policy explains how Digistartti processes personal data in the service, on the digistartti.fi website and in digital materials produced through the Digistartti service for customers.

1. Controller

The controller is AI Velho Oy (Business ID 3616261-8), whose registered auxiliary business name is Digistartti.

Contact details:

2. Purposes, data categories and legal bases

Digistartti processes personal data for the following purposes:

PurposeData categoriesData subjectsRoleLegal basisRetention
Customer account managementName, email, company name, Business ID, service tier, billing periodCustomersControllerGDPR 6(1)(b), contractDuring the contractual relationship + 30 days
Registration and management of .fi domainsDomain holder and contact details, company name, Business ID, domain name, management and change requestsCustomers and representatives of domain holdersControllerGDPR 6(1)(b), contract; GDPR 6(1)(c), legal obligationsAs long as the domain is under our management, active or in a grace period; deleted when the processing basis ends unless law or legal claims require longer retention
Hosting customer websitesCompany name, address, phone, email, service descriptions, images, logoCustomers and website visitorsController for customer company data; processor for end-user dataGDPR 6(1)(b); customer's legal basis for end-user dataDuring the contractual relationship; deleted within 7 days after termination
Contact formsName, email, phone, message contentCustomer's website visitorsProcessorCustomer's legal basis, usually GDPR 6(1)(f)According to customer's instructions, default 12 months
CRMName, email, phone, company, interaction history, notesCustomer's business contactsProcessorCustomer's legal basisAccording to customer's instructions
InvoicingBuyer name, address, VAT ID, company buyer Business ID, consumer buyer personal identity code encrypted only for invoice creation and possible debt collection transfer, invoice amount, payment status, reference numberCustomer's buyersProcessorCustomer's contract and legal obligationAccounting records 6 years; encrypted personal identity code is deleted or anonymised when invoice, collection, accounting or legal-claim handling no longer requires retention
Email deliveryRecipient email, name, message contentCustomers and end usersProcessor or controller depending on message typeContract or customer's legal basisDelivery logs 30 days
AI image and content generationCompany name, industry, service description, uploaded imagesCustomersControllerGDPR 6(1)(b), contractInputs are not retained by model providers; outputs during the contractual relationship
Content moderationTexts submitted by the userCustomersControllerGDPR 6(1)(f), legitimate interestFor the technical need
Payment processingPayment amount, payment status, order reference; card data is processed by MollieCustomersMollie is an independent controller for payment dataMollie's own legal basisAccording to Mollie's practices
Website analyticsAggregated page views, page URL, referrer, country, device data; no marketing cookiesWebsite visitorsControllerGDPR 6(1)(f), legitimate interest90 days in aggregated form
Google Business Profile integrationCompany name, address, category, opening hours, images, reviews, website URL, description, service contentCustomersProcessor under customer's instructionGDPR 6(1)(b), contract and customer's authorisationDuring the contractual relationship; Google connection technical access and refresh permissions are deleted when the account ends
Google Calendar integrationService name, location, time, customer's first name, dashboard link, free/busy time slots and Google account identifier for calendar entries created by DigistarttiCustomersProcessor under customer's instructionGDPR 6(1)(b), contract and customer's authorisationGoogle Calendar technical access permissions are retained while the connection is active; free/busy data is not used as a permanent mirror of calendar contents
Weekly digestsCustomer email, website performance data, number of contactsCustomersControllerGDPR 6(1)(a), consentUntil consent is withdrawn

.fi domain registration data

When we register or manage a .fi domain on your behalf, we process the domain holder and contact details for domain registration, maintenance, renewal, changes, transfer, termination and resolving possible domain matters.

Data may be transferred to the .fi domain register maintained by Traficom and may appear according to Traficom's rules in the .fi domain search, WHOIS service or other authority-maintained register services. Public visibility of data about private individuals is more limited than that of company data.

We retain personal data needed for domain management only as long as a processing basis exists, for example as long as the domain is under our management, active or in a grace period. When the processing basis ends, we delete the data from our systems unless law or handling a legal claim requires longer retention.

You have the right to access your data, request correction of inaccurate data, request restriction of processing and lodge a complaint with the Data Protection Ombudsman. You can submit a request to Digistartti support and, in matters concerning the .fi domain register, also to Traficom.

3. Google Business Profile integration

If a customer connects their Google Business Profile account to Digistartti, Digistartti uses Google's authorisation only to provide the Google Business Profile synchronisation requested by the customer. Technical access and refresh permissions (OAuth tokens) mean permissions granted by Google that allow Digistartti to use the Google Business Profile functions authorised by the customer without processing the Google password.

What we read from Google Business Profile:

  • company name
  • address
  • category
  • opening hours
  • images
  • reviews

What we write to Google Business Profile:

  • website address
  • company description
  • service content

Retention of Google connection access permissions (OAuth tokens): The Google connection technical access and refresh permissions are stored encrypted on the server side. They are not shown in the browser and are not disclosed to the customer or third parties.

Revocation: The customer can disconnect the Google Business Profile connection in Digistartti settings. The customer can also revoke Digistartti's access directly in the Google Account security settings.

Retention period: Google Business Profile data is retained for the duration of the contractual relationship. Google connection technical access permissions (OAuth tokens) are permanently deleted when the connection is disconnected or the customer account is closed.

Digistartti's use of Google APIs and transfer of information received from Google comply with the Google API Services User Data Policy, including the Limited Use requirements.

4. Google Calendar integration

At the customer's user's own request, Digistartti may connect the user's Google Calendar to Digistartti booking functions.

What the data is used for:

  • Digistartti may add the user's Digistartti bookings to the user's own Google Calendar.
  • Digistartti may update or delete only calendar events created by Digistartti itself when a booking changes, is cancelled or the Google connection is disconnected.
  • If the user enables the free/busy check, Digistartti reads from Google only busy time slots for calculating booking availability.

What Google Calendar data is processed:

  • The service name, location, time, customer's first name and link to the Digistartti dashboard for calendar events created by Digistartti.
  • For the free/busy check, only the times of busy slots.
  • The Google account identifier needed to show the connection to the user.

What Digistartti does not do:

  • Digistartti does not read the titles, descriptions, participants, locations or notes of the user's other Google Calendar events.
  • Digistartti does not import Google Calendar events into Digistartti.
  • Digistartti does not create Digistartti bookings based on Google Calendar events.
  • Digistartti does not request full calendar management access.

Disconnecting:

The user can disconnect the Google Calendar connection in Digistartti settings. The user can also revoke Digistartti's access directly in the Google Account security settings. When the connection is disconnected, Digistartti removes the connection's technical access permissions and no longer continues synchronising bookings to that Google Calendar.

Retention:

Google Calendar connection technical access permissions are retained only as long as the user keeps the connection active or the customer relationship requires it. Free/busy data is not used as a permanent mirror of calendar contents.

Google API Services User Data Policy:

Digistartti's Google Calendar integration use and transfer of information received from Google comply with the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google is used only to provide the calendar integration requested by the user, and it is not used for advertising, sold to third parties or used to train AI models.

5. Controller and processor roles

Digistartti acts as controller for its own customers' account data, contract data, service usage data, AI outputs, moderation, analytics and weekly digests.

Digistartti acts as processor when it processes, on behalf of the customer, data concerning the customer's website visitors, CRM contacts, invoice recipients, Google Business Profile profile or Google Calendar connection. In these situations the customer is the controller and Digistartti processes data according to the customer's instructions.

The personal identity code stored for consumer invoices is retained encrypted on the server side. It is not shown on the invoice PDF, invoice emails, e-invoice material or customer-view log and event texts; the code is used only as an identifier stored during invoice creation and later in a separately approved debt collection transfer if the customer's processing basis requires it.

Mollie B.V. acts as an independent controller for payment data. Digistartti does not process card data and does not determine the purposes or means of Mollie's payment processing.

6. Recipients, subprocessors and transfers

Digistartti uses subprocessors and other service providers to produce the service. Key recipient groups are:

  • Hetzner Online GmbH: EU server infrastructure and database
  • Cloudflare: DNS, CDN, object storage and cookie-free analytics
  • Resend: transactional emails
  • Google LLC: Google Business Profile API, Google Calendar API and Gemini API
  • OpenAI: content moderation
  • Mollie B.V.: payment processing as an independent controller
  • Traficom: .fi domain register and authority processing of domain matters

Some service providers are located outside the EU/EEA. In that case transfers are based on the EU Standard Contractual Clauses, the EU-US Data Privacy Framework or another transfer mechanism under the GDPR. Data is not disclosed to third parties for marketing purposes.

7. Cookies and tracking

Digistartti uses necessary session cookies to maintain login and security. The digistartti.fi website does not use third-party marketing cookies.

Customer-generated websites may use Cloudflare Web Analytics cookie-free measurement. The measurement collects aggregated page view and visitor statistics and does not store individual-level visitor profiles.

8. Data subject rights

Data subjects have the following rights under the GDPR:

  • right of access to their own data
  • right to rectification
  • right to erasure
  • right to restriction of processing
  • right to data portability
  • right to object to processing based on legitimate interest
  • right to withdraw consent when processing is based on consent

Requests are sent to [email protected]. We generally respond to requests within 30 days.

If a request concerns the customer's own end customers, Digistartti assists the customer as processor. The customer, as controller, responds to requests from its end customers.

9. Security

Digistartti protects personal data with technical and organisational measures. These include TLS-encrypted data transfer, server-side encryption for sensitive identifiers, access limitation, logging and production data access control.

Google OAuth refresh tokens, meaning the Google connection technical access permissions, are stored encrypted on the server side. Tokens are never shown in the browser-side application.

10. Changes to this policy

Digistartti may update this policy. Active customers will be informed of material changes by email before the change takes effect. The current policy is available at https://digistartti.fi/tietosuojaseloste.

11. Right to lodge a complaint

If a data subject considers that the processing of personal data violates data protection law, they have the right to lodge a complaint with the supervisory authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman:

  • https://tietosuoja.fi
  • PO Box 800, 00521 Helsinki, Finland
  • Phone +358 29 566 6700
Privacy Policy | Digistartti