Nettipoika Sites — privacy and cookies
Controller and contact Cloud Rift Oy, Business ID 3246185-6, Jäniksenpolku 11, 90850 Oulu, Finland, is the controller for product accounts, billing, support and platform security. Contact timo@nettipoika.fi or +358 44 973 4093. For personal data in a customer's hosted site, that customer normally decides the purposes and acts as controller; Cloud Rift acts as processor under section 8 of the service terms. Contact the site owner about that site's processing.
Data, sources, purposes and legal bases We receive your email, login verification and account identifier, order and billing details, country, optional business/tax details, permissions and consent records, and support correspondence from you and the identity/payment services. We process these to create your account, supply hosting, manage authorized agent connections and administer the subscription (GDPR Article 6(1)(b), contract). For a business representative's contact data, the basis is our legitimate interest in administering that business relationship. Tax, accounting and legally required records are processed for legal obligations (Article 6(1)(c)). Optional business verification uses Finnish public business registers and EU VAT validation when relevant to your order. IP addresses, authentication events, bounded technical logs, request identifiers and abuse reports support our legitimate interests in security, fraud prevention and diagnosing service failures (Article 6(1)(f)); we limit access and retention to what that purpose requires. We do not use account contents for advertising profiles or sell personal data. We do not make legally significant eligibility decisions solely by automated profiling. Automated operational controls enforce authorized scopes, payment state and resource limits; contact support to contest an error.
Recipients and locations Our authorized operators access data only as needed. Production hosting uses Hetzner infrastructure in Finland; Cloud Rift operates protected backups and monitoring in Finland. Logto authentication is self-hosted in this environment. Fastmail delivers verification and support email; its processing includes locations outside the EEA, including Australia and the United States, under its published Data Protection Agreement and EU Standard Contractual Clauses where applicable (fastmail.com/policies/dpa). Mollie independently processes payments, fraud checks and legally required payment records under its own privacy notice (mollie.com/privacy). We share only the billing and transaction data needed for that purpose. Cloudflare provides the public marketing edge and authoritative DNS; direct production product, authentication and tenant HTTPS traffic terminates on our hosting server. An agent you authorize receives the site information and capabilities within its granted scope; you separately choose and contract with that agent provider. Its processing and possible transfers are governed by its own terms. Ask us for information or a copy of applicable transfer safeguards.
Retention and security Account and operational data are kept while needed to supply the account, maintain consent and connection history, investigate security events and resolve documented claims. We review continued necessity when the account closes; data not required for those purposes is deleted or anonymized. Site suspension starts a 30-day primary-data retention period. Service-managed deletion snapshots expire within 35 additional days. Separate restricted disaster-recovery archives rotate through 7 daily, 4 weekly and 6 monthly restore points, so deleted data can remain there for approximately six months. These archives are used only for recovery, with deletion requests reapplied before restored data returns to ordinary use. A specific dispute or legal preservation duty can require restricted retention of relevant evidence, not unrestricted reuse. Finnish accounting material is kept for the applicable statutory period: supporting transaction records generally six years from the end of the year in which the financial year ended, and financial statements and accounting books ten years from financial-year end. A deletion request cannot erase records we must retain by law. We use tenant isolation, access controls, encrypted transport and restricted backup access. No system is risk-free; do not put credentials or sensitive data into source files or support messages.
Your rights Depending on the legal basis and circumstances, you can request access, correction, deletion, restriction, portability and object to legitimate-interest processing. If a separate optional activity relies on consent, you can withdraw it without affecting earlier lawful processing. Contact timo@nettipoika.fi; we verify identity proportionately and normally respond within one month. You may lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) or your competent EU supervisory authority. Essential account, order and payment data are needed for the service; without them we cannot complete signup or supply the paid subscription. Optional company details are not required for an individual customer.
Cookies and aggregate measurement The product uses necessary session, sign-in security, CSRF and language-preference cookies. Authentication involves the separate auth.nettipoika.fi origin and the chosen agent's OAuth return path. These cookies support the service you request; they are not advertising trackers. The marketing site uses its existing aggregate audience measurement. Referral measurement must exclude email addresses, access tokens and private account URLs. Your own published site's cookies and analytics are your responsibility. We explain material privacy changes before applying a new purpose.