Privacy Policy
Last updated: April 9, 2026This is a register and privacy policy in accordance with the EU's General Data Protection Regulation (GDPR) for DigiKaveri services.
1. Data Controller
Name: DigiKaveri
Address: Espoo, Finland
Email: [email protected]
Phone: 045 7833 8105
2. Contact Person for Registry Matters
Name: Abdurrahman Chatani
Email: [email protected]
3. Name of the Registry
DigiKaveri's customer and marketing register.
4. Legal Basis and Purpose of Processing
The legal basis for processing personal data is the contract between the company and the customer (service order) or the customer's consent (sending a contact form).
The purpose of processing personal data is:
- Responding to customer inquiries and communication.
- Implementation of IT support services (remote support and home visits).
- Billing and payment monitoring.
- Maintaining and developing the customer relationship.
Special Note on Remote Support: Connections established through remote support applications are one-time only and always occur with the customer's permission. DigiKaveri does not save files or browsing history on the customer's device to its own systems.
5. Data Content of the Registry and Retention Period
The following information is stored in the register:
- First and last name
- Phone number and email address
- Information provided by the customer regarding the device and problem description
- Service delivery address (for home visits to calculate travel fees and dispatch specialists)
- Billing information and service history
- Applicable promo or discount code metadata (e.g. single-use customer benefits)
Retention Period: Customer and billing data is retained for the period required by the Finnish Accounting Act (1339/1997, 6 years from the end of the financial year). Contact form submissions are retained for up to 12 months following completion of customer service, after which they are securely deleted.
6. Regular Data Sources
Information is obtained directly from the customer via the website contact form, interactive price estimator, WhatsApp messages, email, phone calls, or during in-person service appointments.
7. Regular Disclosure of Data & Sub-processors
Personal data is never sold or disclosed to third parties for direct marketing purposes. Data may be disclosed to public authorities where required by statutory law or to debt collection agencies in cases of payment default.
We work with trusted technical service partners (GDPR Data Processors) to deliver our services:
- Supabase Cloud Inc.: Cloud database infrastructure for single-use promo code validation (EU-hosted servers, ISO 27001 & SOC 2 Type II certified).
- Web3Forms: Encrypted, secure transmission of contact and booking requests.
- Google Workspace & Cloud: Secure customer communications and scheduling tools.
- OpenStreetMap & OSRM: Anonymous distance routing for travel fee calculations (no personal data stored).
Data is processed primarily within the EU/EEA. Where data is transferred outside the EU/EEA, European Commission Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework are strictly adhered to.
8. Cookies and Analytics (Consent Mode v2)
Our website uses cookies to ensure smooth technical performance and enhance the user experience:
- Strictly Necessary Cookies: Essential for core website operations, such as remembering your chosen color theme (light/dark) and cookie preferences. Always active.
- Analytics Cookies (Google Analytics 4): Collect anonymous visitor insights (IP anonymization enabled). These cookies only activate if you provide explicit consent in our cookie banner (Google Consent Mode v2 compliant).
You can adjust or withdraw your cookie preferences at any time via the "Cookie Preferences" link in the footer.
9. Principles of Registry Security
All personal data is processed with utmost care and modern security measures. All web traffic is encrypted with modern SSL/TLS protocols (HTTPS). Access to customer information is strictly restricted to designated, authorized specialists bound by confidentiality agreements, protected with multi-factor authentication (MFA).
10. Your Rights as a Data Subject
In accordance with GDPR Articles 15–22, you have the following rights:
- Right of access (Art. 15): Right to obtain confirmation of whether your data is being processed and view stored information.
- Right to rectification (Art. 16): Right to demand correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17): Right to request deletion of personal data ("right to be forgotten"), unless statutory obligations (e.g. Accounting Act) require retention.
- Right to restriction of processing (Art. 18): Right to restrict processing under certain statutory circumstances.
- Right to data portability (Art. 20): Right to receive your personal data in a structured, machine-readable format.
- Right to object (Art. 21): Right to object to processing on grounds relating to your particular situation.
- Right to withdraw consent: Right to withdraw previously granted consent at any time.
- Right to lodge a complaint: Right to lodge a complaint with the Finnish Data Protection Ombudsman (Office of the Data Protection Ombudsman, tietosuoja.fi/en).
All privacy requests should be sent in writing to [email protected]. We respond to all requests within one month.