Privacy
Privacy Policy
Updated 6 July 2026
Service: Digistartti
Controller: AI Velho Oy, Business ID 3616261-8, auxiliary business name Digistartti
Address: Kravatti 6, 90830 Haukipudas, Finland
Contact: [email protected]
Updated: 6 July 2026
This privacy policy explains how Digistartti processes personal data in the service, on the digistartti.fi website and in digital materials produced through the Digistartti service for customers.
1. Controller
The controller is AI Velho Oy (Business ID 3616261-8), whose registered auxiliary business name is Digistartti.
Contact details:
- AI Velho Oy / Digistartti
- Kravatti 6, 90830 Haukipudas, Finland
- [email protected]
- [email protected]
2. Purposes, data categories and legal bases
Digistartti processes personal data for the following purposes:
| Purpose | Data categories | Data subjects | Role | Legal basis | Retention |
|---|---|---|---|---|---|
| Customer account management | Name, email, company name, Business ID, service tier, billing period | Customers | Controller | GDPR 6(1)(b), contract | During the contractual relationship + 30 days |
| Registration and management of .fi domains | Domain holder and contact details, company name, Business ID, domain name, management and change requests | Customers and representatives of domain holders | Controller | GDPR 6(1)(b), contract; GDPR 6(1)(c), legal obligations | As long as the domain is under our management, active or in a grace period; deleted when the processing basis ends unless law or legal claims require longer retention |
| Hosting customer websites | Company name, address, phone, email, service descriptions, images, logo | Customers and website visitors | Controller for customer company data; processor for end-user data | GDPR 6(1)(b); customer's legal basis for end-user data | During the contractual relationship; deleted within 7 days after termination |
| Contact forms | Name, email, phone, message content | Customer's website visitors | Processor | Customer's legal basis, usually GDPR 6(1)(f) | According to customer's instructions, default 12 months |
| CRM | Name, email, phone, company, interaction history, notes | Customer's business contacts | Processor | Customer's legal basis | According to customer's instructions |
| Invoicing | Buyer name, address, VAT ID, company buyer Business ID, consumer buyer personal identity code encrypted only for invoice creation and possible debt collection transfer, invoice amount, payment status, reference number | Customer's buyers | Processor | Customer's contract and legal obligation | Accounting records 6 years; encrypted personal identity code is deleted or anonymised when invoice, collection, accounting or legal-claim handling no longer requires retention |
| Email delivery | Recipient email, name, message content | Customers and end users | Processor or controller depending on message type | Contract or customer's legal basis | Delivery logs 30 days |
| AI image and content generation | Company name, industry, service description, uploaded images | Customers | Controller | GDPR 6(1)(b), contract | Inputs are not retained by model providers; outputs during the contractual relationship |
| Content moderation | Texts submitted by the user | Customers | Controller | GDPR 6(1)(f), legitimate interest | For the technical need |
| Payment processing | Payment amount, payment status, order reference; card data is processed by Mollie | Customers | Mollie is an independent controller for payment data | Mollie's own legal basis | According to Mollie's practices |
| Website analytics | Aggregated page views, page URL, referrer, country, device data; no marketing cookies | Website visitors | Controller | GDPR 6(1)(f), legitimate interest | 90 days in aggregated form |
| Google Business Profile integration | Company name, address, category, opening hours, images, reviews, website URL, description, service content | Customers | Processor under customer's instruction | GDPR 6(1)(b), contract and customer's authorisation | During the contractual relationship; Google connection technical access and refresh permissions are deleted when the account ends |
| Google Calendar integration | Service name, location, time, customer's first name, dashboard link, free/busy time slots and Google account identifier for calendar entries created by Digistartti | Customers | Processor under customer's instruction | GDPR 6(1)(b), contract and customer's authorisation | Google Calendar technical access permissions are retained while the connection is active; free/busy data is not used as a permanent mirror of calendar contents |
| Weekly digests | Customer email, website performance data, number of contacts | Customers | Controller | GDPR 6(1)(a), consent | Until consent is withdrawn |
.fi domain registration data
When we register or manage a .fi domain on your behalf, we process the domain holder and contact details for domain registration, maintenance, renewal, changes, transfer, termination and resolving possible domain matters.
Data may be transferred to the .fi domain register maintained by Traficom and may appear according to Traficom's rules in the .fi domain search, WHOIS service or other authority-maintained register services. Public visibility of data about private individuals is more limited than that of company data.
We retain personal data needed for domain management only as long as a processing basis exists, for example as long as the domain is under our management, active or in a grace period. When the processing basis ends, we delete the data from our systems unless law or handling a legal claim requires longer retention.
You have the right to access your data, request correction of inaccurate data, request restriction of processing and lodge a complaint with the Data Protection Ombudsman. You can submit a request to Digistartti support and, in matters concerning the .fi domain register, also to Traficom.
3. Google Business Profile integration
If a customer connects their Google Business Profile account to Digistartti, Digistartti uses Google's authorisation only to provide the Google Business Profile synchronisation requested by the customer. Technical access and refresh permissions (OAuth tokens) mean permissions granted by Google that allow Digistartti to use the Google Business Profile functions authorised by the customer without processing the Google password.
What we read from Google Business Profile:
- company name
- address
- category
- opening hours
- images
- reviews
What we write to Google Business Profile:
- website address
- company description
- service content
Retention of Google connection access permissions (OAuth tokens): The Google connection technical access and refresh permissions are stored encrypted on the server side. They are not shown in the browser and are not disclosed to the customer or third parties.
Revocation: The customer can disconnect the Google Business Profile connection in Digistartti settings. The customer can also revoke Digistartti's access directly in the Google Account security settings.
Retention period: Google Business Profile data is retained for the duration of the contractual relationship. Google connection technical access permissions (OAuth tokens) are permanently deleted when the connection is disconnected or the customer account is closed.
Digistartti's use of Google APIs and transfer of information received from Google comply with the Google API Services User Data Policy, including the Limited Use requirements.
4. Google Calendar integration
At the customer's user's own request, Digistartti may connect the user's Google Calendar to Digistartti booking functions.
What the data is used for:
- Digistartti may add the user's Digistartti bookings to the user's own Google Calendar.
- Digistartti may update or delete only calendar events created by Digistartti itself when a booking changes, is cancelled or the Google connection is disconnected.
- If the user enables the free/busy check, Digistartti reads from Google only busy time slots for calculating booking availability.
What Google Calendar data is processed:
- The service name, location, time, customer's first name and link to the Digistartti dashboard for calendar events created by Digistartti.
- For the free/busy check, only the times of busy slots.
- The Google account identifier needed to show the connection to the user.
What Digistartti does not do:
- Digistartti does not read the titles, descriptions, participants, locations or notes of the user's other Google Calendar events.
- Digistartti does not import Google Calendar events into Digistartti.
- Digistartti does not create Digistartti bookings based on Google Calendar events.
- Digistartti does not request full calendar management access.
Disconnecting:
The user can disconnect the Google Calendar connection in Digistartti settings. The user can also revoke Digistartti's access directly in the Google Account security settings. When the connection is disconnected, Digistartti removes the connection's technical access permissions and no longer continues synchronising bookings to that Google Calendar.
Retention:
Google Calendar connection technical access permissions are retained only as long as the user keeps the connection active or the customer relationship requires it. Free/busy data is not used as a permanent mirror of calendar contents.
Google API Services User Data Policy:
Digistartti's Google Calendar integration use and transfer of information received from Google comply with the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google is used only to provide the calendar integration requested by the user, and it is not used for advertising, sold to third parties or used to train AI models.
5. Controller and processor roles
Digistartti acts as controller for its own customers' account data, contract data, service usage data, AI outputs, moderation, analytics and weekly digests.
Digistartti acts as processor when it processes, on behalf of the customer, data concerning the customer's website visitors, CRM contacts, invoice recipients, Google Business Profile profile or Google Calendar connection. In these situations the customer is the controller and Digistartti processes data according to the customer's instructions.
The personal identity code stored for consumer invoices is retained encrypted on the server side. It is not shown on the invoice PDF, invoice emails, e-invoice material or customer-view log and event texts; the code is used only as an identifier stored during invoice creation and later in a separately approved debt collection transfer if the customer's processing basis requires it.
Mollie B.V. acts as an independent controller for payment data. Digistartti does not process card data and does not determine the purposes or means of Mollie's payment processing.
6. Recipients, subprocessors and transfers
Digistartti uses subprocessors and other service providers to produce the service. Key recipient groups are:
- Hetzner Online GmbH: EU server infrastructure and database
- Cloudflare: DNS, CDN, object storage and cookie-free analytics
- Resend: transactional emails
- Google LLC: Google Business Profile API, Google Calendar API and Gemini API
- OpenAI: content moderation
- Mollie B.V.: payment processing as an independent controller
- Traficom: .fi domain register and authority processing of domain matters
Some service providers are located outside the EU/EEA. In that case transfers are based on the EU Standard Contractual Clauses, the EU-US Data Privacy Framework or another transfer mechanism under the GDPR. Data is not disclosed to third parties for marketing purposes.
7. Cookies and tracking
Digistartti uses necessary session cookies to maintain login and security. The digistartti.fi website does not use third-party marketing cookies.
Customer-generated websites may use Cloudflare Web Analytics cookie-free measurement. The measurement collects aggregated page view and visitor statistics and does not store individual-level visitor profiles.
8. Data subject rights
Data subjects have the following rights under the GDPR:
- right of access to their own data
- right to rectification
- right to erasure
- right to restriction of processing
- right to data portability
- right to object to processing based on legitimate interest
- right to withdraw consent when processing is based on consent
Requests are sent to [email protected]. We generally respond to requests within 30 days.
If a request concerns the customer's own end customers, Digistartti assists the customer as processor. The customer, as controller, responds to requests from its end customers.
9. Security
Digistartti protects personal data with technical and organisational measures. These include TLS-encrypted data transfer, server-side encryption for sensitive identifiers, access limitation, logging and production data access control.
Google OAuth refresh tokens, meaning the Google connection technical access permissions, are stored encrypted on the server side. Tokens are never shown in the browser-side application.
10. Changes to this policy
Digistartti may update this policy. Active customers will be informed of material changes by email before the change takes effect. The current policy is available at https://digistartti.fi/tietosuojaseloste.
11. Right to lodge a complaint
If a data subject considers that the processing of personal data violates data protection law, they have the right to lodge a complaint with the supervisory authority.
In Finland, the supervisory authority is the Office of the Data Protection Ombudsman:
- https://tietosuoja.fi
- PO Box 800, 00521 Helsinki, Finland
- Phone +358 29 566 6700