Sivustamo Oy
Effective: October 8, 2025
Last updated: October 8, 2025
Version: 1.0


1. Data Controller

Sivustamo Oy
Business ID: 2855506-7
Address: Ruissalontie 15, 20200 Turku, Finland
Email: tuki@sivustamo.fi
Phone: +358 40 187 6687
Website: www.sivustamo.fi


2. Contact Person for Data Protection Matters

Data Protection Officer:
Arttu Arojoki
Email: tuki@sivustamo.fi
Phone: +358 40 187 6687


3. Register Name

Sivustamo Oy Customer Register


4. Legal Basis and Purpose of Personal Data Processing

4.1 Legal Bases

We process your personal data based on the following legal grounds:

Contract (GDPR Article 6(1)(b))

  • Service delivery (domains, hosting, WordPress maintenance, marketing, content production)
  • Performance of customer agreement
  • Billing and payment processing

Legal Obligation (GDPR Article 6(1)(c))

  • Accounting legislation (6 years)
  • NIS2 Directive: maintenance of domain registration data
  • Tax legislation
  • Consumer Protection Act

Legitimate Interest (GDPR Article 6(1)(f))

  • Customer relationship management and development
  • Service improvement
  • Information security maintenance
  • Debt collection

Consent (GDPR Article 6(1)(a))

  • Newsletters and marketing messages
  • Analytics and cookies (if in use)

4.2 Purposes of Processing

We process your personal data for the following purposes:

  1. Service Delivery

    • Domain registration and maintenance
    • Hosting services
    • WordPress maintenance
    • Digital marketing
    • Content production
  2. Customer Relationship Management

    • Customer service and support
    • Contact management
    • Contract management
    • Order processing
  3. Billing

    • Invoice creation and sending
    • Payment processing
    • Debt collection
  4. Legal Obligations

    • Accounting
    • Taxation
    • NIS2 Directive obligations
    • Authority data requests
  5. Information Security

    • Detection and handling of security incidents
    • System monitoring
    • Prevention of abuse
  6. Marketing (with consent)

    • Newsletters
    • Offers and campaigns
    • Service development

5. What Data We Collect

5.1 Corporate Customers

Basic Information:

  • Company name
  • Business ID
  • Address
  • Contact person's name
  • Email address
  • Phone number

Service Information:

  • Domain names
  • Hosting packages
  • WordPress sites
  • Ordered additional services
  • Service usage data

Billing Information:

  • Billing address
  • Reference numbers
  • Payment information
  • Invoice history

Technical Information:

  • IP addresses
  • Login information (logged)
  • Server usage logs
  • Support requests and communications

5.2 Private Individuals

Basic Information:

  • Name
  • Address
  • Email address
  • Phone number

Service Information:

  • Domain names
  • Hosting packages
  • Ordered services

Billing Information:

  • Billing address
  • Payment information

Technical Information:

  • IP addresses
  • Login information
  • Support requests

5.3 Domain Registration Information (WHOIS)

In accordance with the NIS2 Directive, domain registration information includes:

  • Registrant's name
  • Contact information
  • Technical contact information
  • Administrative contact information
  • Billing contact information

Note: The publicity of WHOIS data depends on the domain extension (TLD). Data disclosure practices are described in section 7.


6. Data Sources

We collect data from the following sources:

Directly from You:

  • Registration forms
  • Order forms
  • Customer portal (oma.sivustamo.fi)
  • Email messages
  • Phone conversations
  • Support requests

Public Sources:

  • Finnish Business Information System (YTJ)
  • WHOIS databases

Automatically:

  • Server logs
  • Analytics tools (if in use)
  • Cookies (if in use)

7. Data Disclosure and Transfers

7.1 Regular Data Disclosures

We disclose your data in the following cases:

Domain Registries:

  • Louhi (.fi domains)
  • ICANN-accredited registries (.com, .net, .org, etc.)
  • Domain registration data is published in WHOIS service according to registry rules

Service Providers:

  • Server providers (hosting)
  • Backup services
  • Email services
  • Payment service providers

Authorities:

  • Tax authorities (accounting)
  • Police (criminal investigation, official request)
  • Traficom (NIS2 obligations)
  • Courts (legal proceedings)

7.2 Data Transfers Outside EU/EEA

Service Providers: Some of our service providers may be located outside the EU/EEA. We ensure that:

  • Data transfers comply with EU Commission decisions
  • Appropriate safeguards are in place (e.g., EU standard contractual clauses)
  • Information security is at an adequate level

Domain Registries: International domains (.com, .net, etc.) are registered with registries that may be located outside the EU (e.g., USA). ICANN-accredited registries comply with ICANN data protection rules.

7.3 WHOIS Data Publicity

Public Data (depending on TLD):

  • Domain name
  • Registrant's name (may be protected)
  • Registration date
  • Expiration date
  • Name servers

Restricted Access:

  • Contact information (email, phone, address)
  • Available only to authorized parties (e.g., law enforcement, data protection breaches)

Data Protection:

  • In accordance with GDPR, we limit WHOIS data publicity
  • Individual's data is automatically protected
  • WHOIS protection available as an additional service

8. Data Retention Periods

We retain your personal data as follows:

Data TypeRetention PeriodBasis
Active customer dataDuration of customer relationshipContract
Former customer data3 yearsLegitimate interest (potential continuation of customer relationship)
Billing information6 yearsAccounting Act
Domain informationDomain validity + 3 yearsNIS2 Directive
Support requests3 yearsLegitimate interest
Marketing consentsUntil withdrawalConsent
Log files14 daysInformation security
Backups14 daysBusiness continuity

Exceptions:

  • Litigation-related data is retained until the matter is finally resolved
  • Data required by authority order is retained according to the order

9. Data Protection

9.1 Technical Safeguards

  • Encryption: TLS/SSL encryption in data transmission (HTTPS)
  • Databases: In protected server environment
  • Firewalls: In use on all servers
  • Intrusion Prevention: IDS/IPS systems
  • Backups: Daily, in separate location
  • Access Control: Only authorized personnel
  • 2FA: Mandatory for administrators

9.2 Organizational Safeguards

  • Personnel Training: Annual information security training
  • Confidentiality Agreements: All employees sign
  • Access Rights Management: Need-to-know principle
  • Audits: Annual internal audits
  • Security Incidents: Documented handling process

9.3 Security Incidents

In case of a security incident:

  1. We notify the Data Protection Ombudsman within 72 hours
  2. We notify you if the incident affects your rights
  3. We take immediate corrective actions
  4. We document the incident and actions

10. Rights of the Data Subject

10.1 Right of Access

You have the right to check what data about you has been stored.

How: Send a request to tuki@sivustamo.fi
Response time: 30 days

10.2 Right to Rectification

You can request correction of incorrect data.

How:

  • Customer portal: oma.sivustamo.fi
  • Email: tuki@sivustamo.fi
    Processing time: Immediately or 14 days

10.3 Right to Erasure ("right to be forgotten")

You can request deletion of your data.

Limitations:

  • Legally required data (accounting 6 years)
  • Contract-related data (limitation period)
  • Legal claims

How: Send a request to tuki@sivustamo.fi
Processing time: 30 days

10.4 Right to Restriction of Processing

You can request restriction of processing your data in certain situations.

10.5 Right to Data Portability

You can request transfer of your data to another service provider in machine-readable format.

How: Send a request to tuki@sivustamo.fi
Format: CSV, JSON, or other agreed format

10.6 Right to Object

You can object to the processing of your data in situations based on legitimate interest.

10.7 Right to Withdraw Consent

You can withdraw your consent (e.g., marketing) at any time.

How:

  • Newsletter "Unsubscribe" link
  • Email: tuki@sivustamo.fi
  • Customer portal: oma.sivustamo.fi

10.8 Right to Lodge a Complaint

If you believe that the processing of your data violates data protection legislation, you can file a complaint:

Office of the Data Protection Ombudsman
Street address: Lintulahdenkuja 4, 00530 Helsinki, Finland
Postal address: P.O. Box 800, 00531 Helsinki, Finland
Email: tietosuoja@om.fi
Phone: +358 29 56 66700
Website: https://tietosuoja.fi


11. Cookies and Analytics

11.1 Use of Cookies

Our website uses cookies to improve user experience.

Essential Cookies:

  • Session management
  • Login
  • Shopping cart functionality

Analytics (with consent):

  • [If in use: Google Analytics, Matomo, etc.]
  • Usage statistics
  • Website development

How to Manage:

  • Cookie settings: [link to cookie settings]
  • Browser settings

Read more: [Link to cookie policy]

11.2 Analytics

We use analytics tools to understand how customers use our services.

Data Collected:

  • Page visits
  • Click behavior
  • Device type
  • Anonymized IP address

Purpose: Service development


12. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling.

All customer decisions (e.g., service approval, support requests) are made by humans.


13. Minors

Our services are intended for businesses and adults.

We do not knowingly collect personal data of individuals under 18 years of age without parental consent.


14. Changes to the Privacy Policy

We reserve the right to update this privacy policy.

Significant Changes:

  • We notify by email
  • We publish on our website
  • We update the version and date

Current Version: Always available at www.sivustamo.fi/privacy


15. Contact Information and Data Requests

Data Protection Matters:
Sivustamo Oy
Arttu Arojoki
Ruissalontie 15, 20200 Turku, Finland
Email: tuki@sivustamo.fi
Phone: +358 40 187 6687

Data Request Processing Time: 30 days


16. Applicable Legislation

This privacy policy and personal data processing comply with:

  • EU General Data Protection Regulation (GDPR) (EU) 2016/679
  • Finnish Data Protection Act (1050/2018)
  • NIS2 Directive (EU) 2022/2555
  • Act on Electronic Communications Services (917/2014)
  • Act on the Protection of Privacy in Electronic Communications (516/2004)
  • Accounting Act (1336/1997)

Version History:

VersionDateChangesApproved by
1.0October 8, 2025Initial versionArttu Arojoki

This privacy policy has been prepared in accordance with GDPR ((EU) 2016/679) and NIS2 Directive ((EU) 2022/2555) requirements.


Sivustamo Oy
www.sivustamo.fi
tuki@sivustamo.fi
+358 40 187 6687

Was this answer helpful? 0 Users Found This Useful (0 Votes)