Skip to content

Devella One- Privacy Notice

Näytä suomeksi

Last updated 4 September 2026

1. Data Controller

Devella Oy
Business ID: 3288286-1
Kokkola

2. Contact Person for Data Protection Matters

Panu Haaraniemi
Email: panu.haaraniemi@devella.fi

Requests and questions concerning data protection may be sent to the address above.

3. Scope of This Privacy Notice and Roles of the Parties

This privacy notice applies to the Devella One website and content management service and its maintenance, user accounts, AI assistant, forms, appointment booking, payments and integrations.

Devella Oy acts as the data controller when processing the data of its own customers and service users, for example for entering into agreements, managing user accounts, billing, customer service, service security and development.

Each Devella One customer is responsible for the privacy practices of its own website. When a customer collects visitor data through its website, for example via a form, appointment booking or payment process, the customer acts as the data controller and Devella Oy processes the data as a data processor in accordance with the customer's documented instructions.

The customer determines the purposes, legal bases and retention periods of the processing and is responsible for, among other things:

  • preparing and publishing its own up-to-date privacy notice and cookie notice
  • informing data subjects and ensuring the exercise of their rights
  • obtaining and managing any required consents
  • ensuring that the form and booking data collected is necessary
  • ensuring the lawful use of payment, calendar, analytics, marketing, CAPTCHA, embedded content and other third-party services it enables.

This Devella Oy privacy notice is not the privacy notice for the customer's own website and does not replace it. The technical privacy and cookie features provided by Devella One do not transfer the responsibilities of the data controller from the customer to Devella Oy.

4. Categories of Data Subjects

The service may process data relating to the following categories of individuals:

  • contact persons and other representatives of Devella One customer organisations
  • service administrators and developer users
  • visitors, persons making enquiries, persons making bookings and payers on customers' websites
  • persons contacting customer service or Devella Oy by other means
  • persons connecting a calendar or other integration account to the service.

5. Personal Data Processed

The data processed depends on the features being used.

User and Customer Data

  • name, email address, telephone number and language preference
  • company, Business ID, billing and address details, and customer relationship information
  • user roles, permissions, invitations and user account status
  • login, multi-factor authentication and account recovery information in protected form
  • customer service messages and other information provided by the user.

Website Content and Media Data

  • texts, images, files, contact details and metadata stored on the website
  • content version history, drafts, publishing information and persons responsible for changes
  • image-related filenames, captions, alternative text, author information and technical metadata.

The user must ensure that they have the right to store the personal data and materials they add to the service.

Form, Booking and Payment Data

  • information submitted through forms, which may include, for example, name, contact details, messages, selections and attachments
  • booking time, service, resource, status, additional selections, notes and information provided by the customer
  • payment amount, currency, tax information, products, payment service provider, transaction and reference identifiers, and payment status
  • email delivery status, protected recipient identifier, recipient domain, message subject and the service provider's message identifier.

Devella One does not store payment card numbers, online banking credentials or other confidential payment instrument credentials. These are processed by the payment service provider within its own service.

Technical, Security and Usage Data

  • a protected hash generated from the IP address, browser and device information, referring address and event timestamp
  • session, API identifier and security event information in protected form
  • login attempts, most recent login, logs, errors and audit information
  • cookie preferences and the related pseudonymous visitor identifier
  • information concerning service usage volumes, performance and error situations.

The raw IP address of a form submitter is not stored with the form submission. Instead, an HMAC-protected hash is generated from it for the prevention of misuse. The IP address may nevertheless appear for a limited period in the technical logs of the server infrastructure.

AI Assistant Data

  • user conversations, instructions and feedback
  • website content and settings selected for the conversation or retrieved by tools
  • attachments and screenshots provided by the user when required for the requested task
  • AI responses, tool calls, proposed changes and information on whether they were accepted or rejected
  • the model used, token and cost information, request identifiers, response time and error status.

Data required to provide the AI functionality is transmitted to OpenRouter and to the language model service provider selected by the user or the service. Users should not enter unnecessary sensitive or confidential personal data into AI conversations. The AI assistant is not used for automated decision-making concerning individuals that would have legal or similarly significant effects.

6. Calendar Integrations

A user may voluntarily connect their Google Calendar or Microsoft Outlook calendar to the Devella One booking feature.

The integration may process:

  • the email address of the connected account
  • calendar list identifiers, names and permission information
  • free/busy information from the calendar selected by the user
  • calendar events created from Devella One bookings and their identifiers
  • OAuth access and refresh tokens in encrypted form
  • granted permissions, token expiry information, and synchronisation status and error information.

For Google Calendar, the service retrieves the calendar list, reads free/busy information from the selected calendar, and creates, updates and deletes events generated from Devella One's own bookings. The service does not read the titles, descriptions or attendee information of other events for the purpose of free/busy checks. Personal data concerning the person making a booking is added to the calendar event only if the customer separately enables this setting; otherwise, the event contains only the general information required to manage the booking.

The calendar connection can be disconnected in the Devella One settings, and access can also be revoked in the settings of the user's Google or Microsoft account. Once the connection has been disconnected, no new calendar data is retrieved, and stored access and refresh tokens are deleted when the same account is no longer used for other calendar connections within the service. Events previously created in the external calendar may remain in that calendar until the user deletes them there.

Devella One's use of data received from Google API Services complies with the Google API Services User Data Policy, including its Limited Use requirements. Google Calendar data is not sold, used for advertising, used for creditworthiness assessments, or used to train general-purpose AI or machine learning models. Google Calendar data is reviewed by a human only with the user's explicit permission in connection with a support request, or when necessary for security purposes or to comply with the law.

7. Purposes and Legal Bases for Processing Personal Data

When Devella Oy acts as the data controller, data is processed for the following purposes:

PurposePrimary legal basis
Providing the service and user account, entering into agreements and managing the customer relationshipperformance of a contract or steps taken prior to entering into a contract
Billing, accounting and statutory obligationslegal obligation
Customer service, service communications and responding to customer requestsperformance of a contract or legitimate interest
Service security, prevention of misuse, troubleshooting and preparation for legal claimslegitimate interest
Improving the usability and operation of the servicelegitimate interest; consent in relation to any non-essential tracking
Providing voluntary integrations and AI featuresperformance of a contract and action requested by the user
Electronic direct marketingconsent or an existing customer relationship where permitted by applicable law

Devella Oy's legitimate interest is based on the need to maintain a secure and functional service, manage customer relationships and protect its rights. A data subject may object to processing based on legitimate interests on grounds relating to their particular situation.

When Devella Oy acts as a processor of a customer's personal data, the customer alone determines the purposes and legal bases of the processing. Devella Oy does not determine them on behalf of the customer. Submitting a form or making a booking does not in itself always constitute consent within the meaning of applicable data protection legislation. The legal basis may instead be, for example, performance of a contract, steps taken prior to entering into a contract, a legal obligation or the data controller's legitimate interest.

8. Sources of Data

Data is obtained:

  • from the data subject directly in connection with a user account, form submission, booking, payment, contact request or other use of the service
  • from a Devella One customer, for example when the customer invites a user to the service or maintains contact information
  • from Google or Microsoft services connected by the user, in accordance with permissions granted by the user
  • from payment, email, verification and other service providers to the extent required to provide the service
  • from technical events generated automatically through use of the service.

9. Recipients and Service Providers

Personal data is not sold. Data is processed only by persons authorised by Devella Oy and by service providers to the extent necessary to provide the service.

Depending on the features being used, data may be processed by the following services:

  • Google Cloud: server infrastructure and media file storage
  • Mailgun or an email service specified by the customer: delivery of system and form messages
  • OpenRouter and the selected language model service provider: processing AI assistant requests
  • Google and Microsoft: calendar services voluntarily connected by the user
  • Stripe and Paytrail: processing online payments
  • Cloudflare Turnstile or hCaptcha: prevention of form misuse, if enabled by the customer
  • analytics, marketing and content services selected by the customer, such as Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight, Matomo, Hotjar, Microsoft Clarity or third-party content embedded on the website.

Providers of payment, calendar, analytics, CAPTCHA and other external services may act as independent data controllers in respect of their own services. Their own privacy notices apply to the processing they perform. The customer is responsible for ensuring the lawful use of third-party services it selects for its website and for informing visitors about them.

Data may be disclosed to an authority or another party where required by law or by a binding order issued by a competent authority. Data may also be processed in connection with corporate restructuring to the extent permitted by applicable law.

10. Transfers of Data Outside the EU and EEA

The service's primary production infrastructure is located within the European Union. Some service providers or their subcontractors may process data outside the EU or EEA. This applies in particular to AI model services and may also apply to other external services enabled by the customer.

Transfers are carried out in accordance with applicable data protection legislation, for example on the basis of an adequacy decision by the European Commission, the EU Standard Contractual Clauses and, where necessary, supplementary safeguards. Further information about the service providers currently in use and the applicable transfer mechanisms is available from the contact person referred to in Section 2.

11. Data Retention

Data is retained only for as long as necessary for its purpose, contractual obligations, security, legal claims or statutory obligations.

  • Customer relationship, contract and user account data is retained for the duration of the customer relationship and thereafter for as long as required by statutory obligations or preparation for legal claims.
  • Accounting records are retained for the period required by accounting legislation.
  • An administration session remains valid for 30 days from its most recent renewal and for no more than 90 days from its creation. An expired session record is normally deleted within 24 hours after expiry.
  • The retention period for form submissions is determined by the customer separately for each form. The default is 365 days, and the selectable period is 0–3650 days. A value of 0 disables automatic time-based deletion, in which case the data is retained until the customer or Devella Oy deletes it in accordance with another agreed deletion procedure.
  • Email delivery logs related to forms are retained for no more than 180 days.
  • Website content, media files and their version history are retained for the duration of the customer relationship for the purpose of providing the service and recovery features. Soft-deleted content may remain in the version history until permanently deleted.
  • AI conversations, proposed changes and usage reports are generally retained for the duration of the customer relationship or until deleted at the request of the user or customer. AI conversations currently have no automatic time-based deletion.
  • Calendar OAuth tokens are retained for the duration of the calendar connection and deleted after disconnection as described in Section 6. Technical status and audit information relating to calendar synchronisation may be retained for as long as required for security and troubleshooting purposes.
  • Payment transaction data is retained for as long as required for payment processing, accounting, fraud prevention and legal claims. The payment service provider retains its own data in accordance with its own privacy notice.
  • Security and audit logs are retained for as long as reasonably necessary for service security, traceability of events and preparation for legal claims.

When data is deleted from the active system, any remaining copies are removed as part of the normal backup rotation cycle, unless there is a statutory basis for continued retention.

12. Cookies and Other Device Identifiers

Devella One uses essential cookies for the secure operation of the service. On customers' public websites, non-essential cookies and scripts are activated only based on the visitor's consent, provided that cookie consent has been enabled for the website and the integration has been designated as requiring consent.

The main cookies used by Devella One are:

Cookie or storage itemPurposeTypical validity period
__Host-dv_sessionadministration login session30 days at a time, maximum 90 days
__Host-dv_csrfprotection against cross-site request forgery30 days
dv_admin_localeadministration language preference365 days
dv_localepublic website language preferencevalidity period defined by the website
dv:consentpublic website cookie preferences180 days
__Host-dv_gateaccess authorisation for a password-protected website7 days
__Host-dv_payment_attemptsecurely linking a payment return to the original browser session30 minutes

In development environments and over unsecured local connections, the __Host- prefix is not used in cookie names. Website components may also use cookies, localStorage or sessionStorage for controlling display frequency for a period specified by the customer.

Analytics, marketing, CAPTCHA and embedded content services enabled by the customer may set their own cookies and process technical identifiers in accordance with their own terms. The customer is responsible for ensuring that these services, processing purposes, legal bases and retention periods are described in the cookie or privacy notice of its own website. The Devella One cookie banner is a technical tool, and enabling it alone does not fulfil the customer's obligations to provide information and obtain consent. Visitors can change their consent choices through the website's cookie settings or delete stored data through their browser.

13. Data Security

Data is protected using technical and organisational measures. These include, among other things:

  • encrypted HTTPS data transmission
  • role-based and website-specific access rights
  • strong one-way password hashing
  • storage of session and API identifiers using one-way hashes
  • encryption at rest of integration credentials, SMTP credentials and other secrets
  • support for multi-factor authentication
  • audit logs, abuse prevention controls and security monitoring
  • restricting access rights according to job responsibilities and need
  • secure server infrastructure and backups.

Although appropriate measures are used to protect data, no electronic service is completely risk-free.

14. Automated Decision-Making and Profiling

Devella Oy does not use personal data covered by this privacy notice for fully automated decision-making or profiling that would have legal or similarly significant effects on a data subject.

Technical spam and abuse assessment of forms may automatically flag a submission for review. Payment and CAPTCHA service providers may perform their own fraud prevention assessments in accordance with their own privacy notices.

15. Rights of the Data Subject

Under applicable data protection legislation, a data subject may have the right to:

  • obtain confirmation as to whether their personal data is being processed and obtain access to that data
  • request correction of inaccurate or incomplete data
  • request deletion of data
  • request restriction of processing
  • object to processing based on legitimate interests and to direct marketing
  • receive data they have provided in a structured, commonly used and machine-readable format where the right to data portability applies
  • withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal
  • lodge a complaint with a supervisory authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman: tietosuoja.fi.

If a request concerns form, booking or other data submitted through the website of a Devella One customer, the request should primarily be addressed to that customer, which acts as the data controller. Devella Oy assists the customer in fulfilling the request in its role as a personal data processor. Requests concerning data processed by Devella Oy in its own role as data controller should be addressed to the contact person referred to in Section 2.

The identity of the person making the request may be verified where necessary before the request is fulfilled. Rights may be restricted only on grounds provided for by law.

16. Changes to This Privacy Notice

This privacy notice is updated when the service, the processing of personal data or applicable requirements change. The current version is made available on Devella Oy's website. Material changes will be communicated through the service or by other appropriate means.