Privacy Policy

oiva.dev · Effective date: 30 July 2026 · Governing jurisdiction: Finland

1. Data Controller

The data controller is Oiva Software Oy (Business ID: 3642400-8), a company registered in Finland and trading as oiva.dev. Registered office: Viipurinkatu 12 L 9, 00510 Helsinki, Finland. Phone: +358 41 328 9083. For privacy inquiries contact us at [email protected].

2. Data We Collect

Account data — name, email address, password hash, and optional profile information you provide on registration.

Company and domain data — organisation name and domain records you create inside the platform.

Survey and response data — survey configurations, steps, fields, and the end-user responses collected through embedded widgets on your websites. You are the data controller for this data; we process it on your behalf.

Technical data — IP address, browser type, referring URL, and timestamped access logs retained for security and debugging.

Performance monitoring data — if you consent via the cookie banner, aggregate, non-identifying data about page load times, API response times, and client-side errors (normalised page routes, numeric durations, and status codes only — never free-text error messages or page content). See our Cookie Policy for details.

Authentication data — if you sign in via Google OAuth, we receive your Google account email and name; no OAuth tokens are stored beyond the session.

3. Legal Basis for Processing

  • Contract performance (Art. 6(1)(b) GDPR) — processing your account data to provide the service.
  • Legitimate interest (Art. 6(1)(f) GDPR) — security monitoring, fraud prevention, and service improvement.
  • Consent (Art. 6(1)(a) GDPR) — marketing communications, analytics, and performance monitoring, if you opt in via the cookie banner.
  • Legal obligation (Art. 6(1)(c) GDPR) — retaining records where required by Finnish law.

4. How We Use Your Data

  • Provide, maintain, and improve the oiva.dev platform.
  • Authenticate you and manage your account.
  • Send transactional emails (email verification, password reset).
  • Detect and prevent abuse or unauthorised access.
  • Comply with legal obligations.

We do not sell your personal data to third parties.

5. Data Sharing and Sub-processors

We share data only where necessary. Current sub-processors and integrations:

  • Google LLC — optional OAuth sign-in. Google's privacy policy applies.
  • Hosting infrastructure — servers located within the European Economic Area.

We do not transfer personal data outside the EEA without appropriate safeguards.

6. Data Retention

  • Account data — retained for the duration of your account and deleted within 30 days of account deletion on request.
  • Survey and response data — retained per your subscription agreement; deleted promptly on contract termination.
  • Server logs — retained for up to 90 days.

7. Your Rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Request erasure (“right to be forgotten”).
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time without affecting prior processing.

To exercise these rights email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Finnish supervisory authority: Tietosuojavaltuutetun toimisto (tietosuoja.fi).

8. Security

We protect your data using TLS encryption in transit, hashed passwords (bcrypt), access controls, and regular security reviews. In the event of a personal data breach we will notify the supervisory authority within 72 hours and affected users without undue delay where required by GDPR Art. 34.

9. Changes to This Policy

We may update this policy. Material changes will be communicated by email or an in-app notice at least 14 days before they take effect.