Suomeksi

Privacy Policy

Version 1.1 · Updated 23 August 2026 · EU General Data Protection Regulation (GDPR)

This policy describes how Luviamo (the “Service”) collects, uses, retains, and shares personal data. Luviamo is a marketing lifecycle platform for Nordic small and medium-sized businesses: ideation, planning, content creation, publishing, and analytics in a single application.

1. Data Controller

Innovasystems Oy
Business ID: 3639849-5
Postal address: Pilotinkatu 48, 33900 Tampere, Finland
Privacy contact: [email protected]
Contact person: Petri Korhonen

2. Personal data we process

We process the following data arising from use of the Service:

3. Purposes and legal bases

4. Google user data (Google Analytics 4 and Google Ads)

If you connect your own Google account, Luviamo reads your reporting data on a read-only basis. We never modify, create, or manage your accounts, campaigns, or settings.

What data is retrieved

How the data is used

The data is displayed back to the same user in their own analytics dashboard and PDF reports. It is not used for anything else and is not combined with other customers’ data (per-organization isolation).

Retention, sharing, and deletion

Luviamo's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Meta data (Facebook and Instagram)

If you connect your Facebook Page and its linked Instagram Business account, we process for publishing purposes:

When you remove the app from Facebook or request data deletion, Meta sends a signed request to our callback URL. We verify the signature (HMAC-SHA256) and delete the stored connection data (the encrypted Page access token and the account linkage). See data deletion.

6. AI (content creation)

We use Anthropic’s AI to assist with content creation. Only the following is sent to the AI:

We do not send Google or Meta raw data, email addresses, access tokens, or account identifiers to the AI. The AI produces suggestions that the user reviews and edits; this is not automated decision-making producing legal effects within the meaning of GDPR Art. 22.

7. Subprocessors

We use the following subprocessors. A data processing agreement (DPA) under GDPR Art. 28 is in place with each — click a subprocessor's name to open its DPA. Transfers outside the EU/EEA are covered by the EU Standard Contractual Clauses (SCC).

SubprocessorRoleData processedLocation / transfer
CloudflareHosting (Workers, Pages, D1, R2, KV)All application data, media, sessionsEU (Frankfurt, Germany)
AnthropicAI (content creation)Your own content input + de-identified index valueUSA · SCC
StripePayments and subscriptionsCustomer and subscription IDs (no card data with us)USA/Ireland · SCC
ResendTransactional and newsletter emailRecipient email + message contentUSA · SCC
MetaSocial publishing (on your initiative)Content and media to publishUSA/Ireland · SCC
GoogleSource of analytics data (read-only)We send no personal data; we receive reporting data
Google WorkspaceEmail, calendar and demo bookingsName, email, message content and meeting time from enquiries and bookingsEU/USA · SCC + EU–US DPF

8. Data location and transfers

Application data (database) and media files are stored on Cloudflare’s EU servers (Frankfurt, Germany). Some subprocessors (Anthropic, Stripe, Resend, Google) operate outside the EU; those transfers are covered by the EU Standard Contractual Clauses (SCC).

9. Retention periods

Data categoryRetention
Account and organization dataFor the life of the account. After your subscription ends the account remains, but if you don't sign in for 6 months the account and its data are deleted (signing in keeps the account active; you receive an email warning about 30 days before deletion). You can also delete the account yourself at any time — then data is removed immediately (from backups within 30 days)
Security log (audit log)12 months
Analytics aggregate metricsUp to 25 months; also removed on account deletion
Email delivery logs (opens, clicks, bounces)Removed on organization deletion
Sessions (refresh tokens)Time-based expiry (KV TTL)
Media (R2)Until you delete the file or disconnect
Integration tokens (OAuth)Deleted on disconnect or deauthorize/deletion request
Billing data7 years (accounting law)
Demo bookings and enquiriesUp to 24 months from the last contact, unless a customer relationship begins

10. Your rights

You have the rights under GDPR Art. 15–22: access, rectification, erasure, restriction, data portability, and objection.

To exercise your rights: [email protected].

11. Security

Access tokens and sensitive identifiers are encrypted (AES-256-GCM); passwords are stored as hashes. Application secrets reside only on the server, never in the browser. Organizations’ data is isolated from one another through three-layer tenant isolation (query-level scoping, static analysis, and an integration test).

12. Cookies, analytics and embedded content

The application itself (app.luviamo.app) uses only strictly necessary session tokens for sign-in.

This marketing website (luviamo.app) uses Google Analytics 4 for visitor analytics only if you consent in the cookie banner. Nothing is loaded before you make a choice. If you choose "Necessary only", no analytics are used at all. Your choice is stored in your browser's local storage (localStorage), and you can change it at any time via the Cookie settings link in the page footer.

When analytics is allowed, Google Analytics collects information about how the site is used (e.g. page views and visited pages) with IP anonymisation. The data is processed by Google Ireland Ltd; transfers are covered by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework.

The same consent also loads Google Tag Manager, through which the site may run marketing measurement tags such as Meta Pixel (Meta Platforms Ireland Ltd) and Google Ads and LinkedIn measurement. These measure advertising performance (e.g. which ad a visitor arrived from) and may set their own cookies. If you choose “Necessary only”, none of these are loaded.

Booking a demo

You can book a demo slot on this site. The booking calendar is provided by Google (a Google Workspace calendar appointment schedule), and the booking is stored in Luviamo’s Google Workspace environment. When booking you provide your name, email address and the time you choose, plus anything you write into the booking form fields. The meeting is held on Google Meet.

The legal basis is steps taken at your request prior to entering into a contract (GDPR 6(1)(b)). We use the data only to arrange the meeting, to remind you of it and for related correspondence — booking a demo does not add you to any newsletter.

The calendar is third-party content: when it opens, your browser connects to Google and Google may set its own cookies. On the front page the calendar loads only after you click “Book a demo”, and on the booking page it loads with the page, because booking is that page’s entire purpose. In both cases this is a service you requested yourself, not tracking. Google’s own processing is described in the Google privacy policy.

13. Right to lodge a complaint

If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority: the Office of the Data Protection Ombudsman (tietosuoja.fi), Finland.

14. Luviamo’s own marketing communication (newsletter)

When you subscribe to Luviamo’s own newsletter from the marketing website (luviamo.app), Innovasystems Oy acts as the controller — unlike our customers’ own newsletters, where Luviamo is a processor (see section 2).

15. Changes to this policy

We may update this policy. Changes are published on this page; the “updated” date and version number indicate the latest version.