Sivustamo Oy
Effective: October 8, 2025
Last updated: October 8, 2025
Version: 1.0
1. Data Controller
Sivustamo Oy
Business ID: 2855506-7
Address: Ruissalontie 15, 20200 Turku, Finland
Email: tuki@sivustamo.fi
Phone: +358 40 187 6687
Website: www.sivustamo.fi
2. Contact Person for Data Protection Matters
Data Protection Officer:
Arttu Arojoki
Email: tuki@sivustamo.fi
Phone: +358 40 187 6687
3. Register Name
Sivustamo Oy Customer Register
4. Legal Basis and Purpose of Personal Data Processing
4.1 Legal Bases
We process your personal data based on the following legal grounds:
Contract (GDPR Article 6(1)(b))
- Service delivery (domains, hosting, WordPress maintenance, marketing, content production)
- Performance of customer agreement
- Billing and payment processing
Legal Obligation (GDPR Article 6(1)(c))
- Accounting legislation (6 years)
- NIS2 Directive: maintenance of domain registration data
- Tax legislation
- Consumer Protection Act
Legitimate Interest (GDPR Article 6(1)(f))
- Customer relationship management and development
- Service improvement
- Information security maintenance
- Debt collection
Consent (GDPR Article 6(1)(a))
- Newsletters and marketing messages
- Analytics and cookies (if in use)
4.2 Purposes of Processing
We process your personal data for the following purposes:
Service Delivery
- Domain registration and maintenance
- Hosting services
- WordPress maintenance
- Digital marketing
- Content production
Customer Relationship Management
- Customer service and support
- Contact management
- Contract management
- Order processing
Billing
- Invoice creation and sending
- Payment processing
- Debt collection
Legal Obligations
- Accounting
- Taxation
- NIS2 Directive obligations
- Authority data requests
Information Security
- Detection and handling of security incidents
- System monitoring
- Prevention of abuse
Marketing (with consent)
- Newsletters
- Offers and campaigns
- Service development
5. What Data We Collect
5.1 Corporate Customers
Basic Information:
- Company name
- Business ID
- Address
- Contact person's name
- Email address
- Phone number
Service Information:
- Domain names
- Hosting packages
- WordPress sites
- Ordered additional services
- Service usage data
Billing Information:
- Billing address
- Reference numbers
- Payment information
- Invoice history
Technical Information:
- IP addresses
- Login information (logged)
- Server usage logs
- Support requests and communications
5.2 Private Individuals
Basic Information:
- Name
- Address
- Email address
- Phone number
Service Information:
- Domain names
- Hosting packages
- Ordered services
Billing Information:
- Billing address
- Payment information
Technical Information:
- IP addresses
- Login information
- Support requests
5.3 Domain Registration Information (WHOIS)
In accordance with the NIS2 Directive, domain registration information includes:
- Registrant's name
- Contact information
- Technical contact information
- Administrative contact information
- Billing contact information
Note: The publicity of WHOIS data depends on the domain extension (TLD). Data disclosure practices are described in section 7.
6. Data Sources
We collect data from the following sources:
Directly from You:
- Registration forms
- Order forms
- Customer portal (oma.sivustamo.fi)
- Email messages
- Phone conversations
- Support requests
Public Sources:
- Finnish Business Information System (YTJ)
- WHOIS databases
Automatically:
- Server logs
- Analytics tools (if in use)
- Cookies (if in use)
7. Data Disclosure and Transfers
7.1 Regular Data Disclosures
We disclose your data in the following cases:
Domain Registries:
- Louhi (.fi domains)
- ICANN-accredited registries (.com, .net, .org, etc.)
- Domain registration data is published in WHOIS service according to registry rules
Service Providers:
- Server providers (hosting)
- Backup services
- Email services
- Payment service providers
Authorities:
- Tax authorities (accounting)
- Police (criminal investigation, official request)
- Traficom (NIS2 obligations)
- Courts (legal proceedings)
7.2 Data Transfers Outside EU/EEA
Service Providers: Some of our service providers may be located outside the EU/EEA. We ensure that:
- Data transfers comply with EU Commission decisions
- Appropriate safeguards are in place (e.g., EU standard contractual clauses)
- Information security is at an adequate level
Domain Registries: International domains (.com, .net, etc.) are registered with registries that may be located outside the EU (e.g., USA). ICANN-accredited registries comply with ICANN data protection rules.
7.3 WHOIS Data Publicity
Public Data (depending on TLD):
- Domain name
- Registrant's name (may be protected)
- Registration date
- Expiration date
- Name servers
Restricted Access:
- Contact information (email, phone, address)
- Available only to authorized parties (e.g., law enforcement, data protection breaches)
Data Protection:
- In accordance with GDPR, we limit WHOIS data publicity
- Individual's data is automatically protected
- WHOIS protection available as an additional service
8. Data Retention Periods
We retain your personal data as follows:
| Data Type | Retention Period | Basis |
|---|---|---|
| Active customer data | Duration of customer relationship | Contract |
| Former customer data | 3 years | Legitimate interest (potential continuation of customer relationship) |
| Billing information | 6 years | Accounting Act |
| Domain information | Domain validity + 3 years | NIS2 Directive |
| Support requests | 3 years | Legitimate interest |
| Marketing consents | Until withdrawal | Consent |
| Log files | 14 days | Information security |
| Backups | 14 days | Business continuity |
Exceptions:
- Litigation-related data is retained until the matter is finally resolved
- Data required by authority order is retained according to the order
9. Data Protection
9.1 Technical Safeguards
- Encryption: TLS/SSL encryption in data transmission (HTTPS)
- Databases: In protected server environment
- Firewalls: In use on all servers
- Intrusion Prevention: IDS/IPS systems
- Backups: Daily, in separate location
- Access Control: Only authorized personnel
- 2FA: Mandatory for administrators
9.2 Organizational Safeguards
- Personnel Training: Annual information security training
- Confidentiality Agreements: All employees sign
- Access Rights Management: Need-to-know principle
- Audits: Annual internal audits
- Security Incidents: Documented handling process
9.3 Security Incidents
In case of a security incident:
- We notify the Data Protection Ombudsman within 72 hours
- We notify you if the incident affects your rights
- We take immediate corrective actions
- We document the incident and actions
10. Rights of the Data Subject
10.1 Right of Access
You have the right to check what data about you has been stored.
How: Send a request to tuki@sivustamo.fi
Response time: 30 days
10.2 Right to Rectification
You can request correction of incorrect data.
How:
- Customer portal: oma.sivustamo.fi
- Email: tuki@sivustamo.fi
Processing time: Immediately or 14 days
10.3 Right to Erasure ("right to be forgotten")
You can request deletion of your data.
Limitations:
- Legally required data (accounting 6 years)
- Contract-related data (limitation period)
- Legal claims
How: Send a request to tuki@sivustamo.fi
Processing time: 30 days
10.4 Right to Restriction of Processing
You can request restriction of processing your data in certain situations.
10.5 Right to Data Portability
You can request transfer of your data to another service provider in machine-readable format.
How: Send a request to tuki@sivustamo.fi
Format: CSV, JSON, or other agreed format
10.6 Right to Object
You can object to the processing of your data in situations based on legitimate interest.
10.7 Right to Withdraw Consent
You can withdraw your consent (e.g., marketing) at any time.
How:
- Newsletter "Unsubscribe" link
- Email: tuki@sivustamo.fi
- Customer portal: oma.sivustamo.fi
10.8 Right to Lodge a Complaint
If you believe that the processing of your data violates data protection legislation, you can file a complaint:
Office of the Data Protection Ombudsman
Street address: Lintulahdenkuja 4, 00530 Helsinki, Finland
Postal address: P.O. Box 800, 00531 Helsinki, Finland
Email: tietosuoja@om.fi
Phone: +358 29 56 66700
Website: https://tietosuoja.fi
11. Cookies and Analytics
11.1 Use of Cookies
Our website uses cookies to improve user experience.
Essential Cookies:
- Session management
- Login
- Shopping cart functionality
Analytics (with consent):
- [If in use: Google Analytics, Matomo, etc.]
- Usage statistics
- Website development
How to Manage:
- Cookie settings: [link to cookie settings]
- Browser settings
Read more: [Link to cookie policy]
11.2 Analytics
We use analytics tools to understand how customers use our services.
Data Collected:
- Page visits
- Click behavior
- Device type
- Anonymized IP address
Purpose: Service development
12. Automated Decision-Making and Profiling
We do not use automated decision-making or profiling.
All customer decisions (e.g., service approval, support requests) are made by humans.
13. Minors
Our services are intended for businesses and adults.
We do not knowingly collect personal data of individuals under 18 years of age without parental consent.
14. Changes to the Privacy Policy
We reserve the right to update this privacy policy.
Significant Changes:
- We notify by email
- We publish on our website
- We update the version and date
Current Version: Always available at www.sivustamo.fi/privacy
15. Contact Information and Data Requests
Data Protection Matters:
Sivustamo Oy
Arttu Arojoki
Ruissalontie 15, 20200 Turku, Finland
Email: tuki@sivustamo.fi
Phone: +358 40 187 6687
Data Request Processing Time: 30 days
16. Applicable Legislation
This privacy policy and personal data processing comply with:
- EU General Data Protection Regulation (GDPR) (EU) 2016/679
- Finnish Data Protection Act (1050/2018)
- NIS2 Directive (EU) 2022/2555
- Act on Electronic Communications Services (917/2014)
- Act on the Protection of Privacy in Electronic Communications (516/2004)
- Accounting Act (1336/1997)
Version History:
| Version | Date | Changes | Approved by |
|---|---|---|---|
| 1.0 | October 8, 2025 | Initial version | Arttu Arojoki |
This privacy policy has been prepared in accordance with GDPR ((EU) 2016/679) and NIS2 Directive ((EU) 2022/2555) requirements.
Sivustamo Oy
www.sivustamo.fi
tuki@sivustamo.fi
+358 40 187 6687
