Privacy Policy: IterateWeb Oy

Published: 20 Apr 2026

Updated: 27 Apr 2026

This policy describes how IterateWeb Oy collects, processes and protects the personal data of its customers and website visitors in accordance with the EU General Data Protection Regulation (GDPR).

1. Data Controller

Company: IterateWeb Oy

Business ID: 3618449-7

Address: Kuninkaistentie 8a, Espoo 02610, Finland

Email: info@iterateweb.fi

Website: iterateweb.fi

2. Persons Responsible for Privacy Matters

The company founders are responsible for personal data processing and privacy-related requests:

Aki Dhadwal, aki.dhadwal@iterateweb.fi

Aleksi Koskela-Koivisto, aleksi.kk@iterateweb.fi

Both persons listed above act as contact persons for all questions related to data subject rights.

3. Purpose of Processing Personal Data

We process data for the following purposes:

Service delivery: Website design, domain registrations, hosting setup and email configuration.

Customer communication: Responding to contact requests and project management.

Invoicing and accounting: Billing for services (IterateWeb Oy is currently not registered for VAT).

Technical support: Support for possible booking systems or other integrations.

4. Legal Basis for Processing

Contract: Data is needed to deliver the service and fulfil the agreement.

Legal obligation: Requirements under accounting legislation.

Legitimate interest: Managing and developing customer relationships.

5. Personal Data Processed

The register may include the following data:

Basic information: Name, company name and contact details (phone, email, address).

Technical information: Domain names, required usernames and IP addresses.

Billing information: Billing address and completed payments.

6. Regular Sources of Data

Data is primarily received from the customer via the contact form, email, phone or when entering into agreements.

7. Data Disclosures and Transfers

Data is not sold or disclosed to third parties for marketing purposes. Data may be disclosed to:

Technical partners: For example domain registrars and hosting providers for service setup.

Authorities: Where required by law.

Payment processors: If integrations are used.

8. Transfers Outside the EU or EEA

We use services such as Lovable and potentially international hosting partners. We always ensure data transfers are handled securely and in accordance with applicable law, for example by using certified partners.

9. Data Retention Period

Personal data is retained only for as long as necessary to manage the customer relationship or fulfil legal obligations, such as accounting records for 6 years.

10. Rights of the Data Subject

You have the right to:

Access the data stored about you.

Request correction of inaccurate data.

Request deletion of your data (right to be forgotten).

Restrict or object to the processing of your data.

All requests must be submitted in writing to the email address mentioned in section 1.

11. Cookies

We use cookies on our website to improve user experience and track visitor statistics. Users can block cookies in their browser settings.

12. Right to Lodge a Complaint with an Authority

If you believe we are violating data protection legislation, you have the right to lodge a complaint with the Data Protection Ombudsman (www.tietosuoja.fi).