Privacy Policy
Last updated: June 5, 2026
This Privacy Policy explains how Lovelyboost.ddd ("we," "us," or "our") collects, uses, stores, and protects your personal data when you visit our website or contact us. We comply with:
- Regulation (EU) 2016/679 — the General Data Protection Regulation (GDPR)
- The Finnish Data Protection Act (Tietosuojalaki 1050/2018)
- The Finnish Act on the Protection of Privacy in Working Life (Laki yksityisyyden suojasta työelämässä 759/2004), where applicable
- The Finnish Information Society Code (Laki tietoyhteiskunnan palvelujen tarjoamisesta 917/2014), Chapters 3 and 5
- The Finnish Act on Electronic Communications Services (Laki sähköisen viestinnän palveluista 917/2014), as amended
This policy fulfils our information obligation under GDPR Articles 13 and 14 and Section 10 of the Finnish Data Protection Act.
For mandatory service provider information under Finnish law, see our Legal Notice.
1. Data Controller and Contact Point
The data controller responsible for your personal data is:
- Business name: Lovelyboost.ddd
- Postal address: Aurakatu 22, 20100 Turku, Finland
- Email: business@lovelyboost.world
- Phone: +358 40 596 1585
- Country of establishment: Finland
We are not required to appoint a Data Protection Officer (DPO) under GDPR Article 37. For all data protection matters, contact us using the details above. We respond to requests without undue delay and within the statutory time limits.
2. Personal Data We Collect
2.1 Data You Provide Directly
When you use our contact form, we collect:
- Your name
- Your email address
- Your message content
- Your GDPR consent confirmation (timestamp and checkbox status)
2.2 Data Collected Automatically
When you visit our website, we may automatically collect:
- IP address (anonymized where analytics cookies are accepted)
- Browser type and version
- Device type and operating system
- Pages visited and time spent on each page
- Referring URL
- Cookie consent preferences stored in your browser (localStorage)
- Technical server log data (timestamp, request URL, HTTP status code)
2.3 Data We Do Not Collect
We do not intentionally collect special categories of personal data (GDPR Article 9), such as health data, biometric data, or information revealing racial or ethnic origin. We do not collect Finnish personal identity codes (henkilötunnus). Please do not include sensitive personal data in contact form messages.
2.4 Event Registration Data
If you register for a workshop or event via our contact form, we may additionally process your preferred attendance format (in-person or online) and any dietary or accessibility requirements you voluntarily provide.
3. Purposes and Legal Bases for Processing
We process your personal data only for specific, lawful purposes. Under the Finnish Data Protection Act (Section 6), processing is permitted only when a legal basis under GDPR Article 6 applies:
- Responding to inquiries and event registration — Legal basis: your consent (GDPR Art. 6(1)(a)); legitimate interest in handling communications directed to us (Art. 6(1)(f)).
- Website functionality and security (necessary cookies, server logs) — Legal basis: legitimate interest in operating a secure, functional website (Art. 6(1)(f)).
- Analytics (analytics cookies, only if accepted) — Legal basis: your explicit consent (Art. 6(1)(a)), as required by the Finnish Information Society Code and Traficom guidance on cookies.
- Marketing and content measurement (marketing cookies, only if accepted) — Legal basis: your explicit consent (Art. 6(1)(a)); you may object to direct marketing at any time under Section 31 of the Finnish Data Protection Act.
- Accounting and legal compliance — Legal basis: compliance with legal obligations under the Finnish Accounting Act (Kirjanpitolaki 1336/1997) and other applicable statutes (Art. 6(1)(c)).
Provision of data: Providing contact form data is voluntary. Without your name and email, we cannot respond to your inquiry. Failure to provide data does not have contractual consequences, as no contract is formed through website browsing alone.
4. Data Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with GDPR Article 5(1)(e) and Finnish Data Protection Act Section 8:
- Contact form submissions: Up to 12 months after your inquiry is resolved, then securely deleted — unless a longer period is required for legal claims or accounting records.
- Event registration records: Up to 6 months after the event concludes.
- Accounting-related correspondence: Up to 6 years from the end of the financial year, as required by the Finnish Accounting Act (Kirjanpitolaki 1336/1997, Section 2:10).
- Cookie consent records: Stored locally in your browser for up to 12 months; our server does not store a separate consent log unless analytics are enabled.
- Analytics data: Up to 26 months in anonymized or pseudonymized form, only if you have consented to analytics cookies.
- Server logs: Up to 90 days for security, troubleshooting, and abuse prevention.
When retention periods expire, data is securely deleted or irreversibly anonymized.
5. Recipients, Processors, and International Transfers
We do not sell your personal data. Categories of recipients may include:
- Hosting and infrastructure providers — EU/EEA-based servers where possible; bound by data processing agreements under GDPR Article 28.
- Analytics providers (e.g. Google Analytics) — only if you consent to analytics cookies; may involve transfers outside the EU/EEA.
- Embedded service providers (e.g. Google Maps on our Contacts page) — may process technical data (IP address, device data) under their own privacy policies when you interact with embedded content.
- Professional advisers — accountants or legal counsel, bound by confidentiality obligations.
- Public authorities — Finnish courts, police, or supervisory bodies, only when required by law or valid legal process.
5.1 International Data Transfers
Where personal data is transferred outside the EU/EEA (for example, to analytics providers in the United States), we ensure appropriate safeguards under GDPR Chapter V, including:
- European Commission adequacy decisions, where applicable
- EU Standard Contractual Clauses (SCCs, 2021/914)
- Supplementary technical measures (encryption, pseudonymization) where required by European Court of Justice guidance
You may request a copy of applicable safeguards by contacting us.
6. Data Security and Breach Notification
Under GDPR Article 32 and Finnish Data Protection Act Section 33, we implement appropriate technical and organizational measures, including:
- HTTPS/TLS encryption for all data transmission
- Access controls limiting data access to authorized personnel on a need-to-know basis
- Regular review of security practices and hosting configurations
- Secure deletion and anonymization when retention periods expire
- Staff awareness of data protection obligations
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) within 72 hours as required by GDPR Article 33, and inform affected individuals without undue delay where required by GDPR Article 34.
7. Automated Decision-Making and Profiling
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you, as defined in GDPR Article 22. Analytics tools, if enabled with your consent, may generate aggregated statistical reports that do not involve individual automated decisions.
8. Your Rights Under GDPR and Finnish Law
Under GDPR Articles 15–22 and the Finnish Data Protection Act (Sections 26–31), you have the following rights:
- Right of access (Art. 15) — Obtain confirmation of processing and a copy of your personal data.
- Right to rectification (Art. 16) — Request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17) — Request deletion where processing is no longer lawful or necessary.
- Right to restriction of processing (Art. 18) — Request limitation in defined circumstances.
- Right to data portability (Art. 20) — Receive data you provided in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Right to object (Art. 21) — Object to processing based on legitimate interests, including direct marketing at any time.
- Right to withdraw consent (Art. 7(3)) — Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. Withdrawal is as easy as giving consent — contact us or adjust cookie settings.
- Right not to be subject to automated decision-making (Art. 22) — Not applicable, as we do not conduct such processing.
To exercise any right, contact us at business@lovelyboost.world. We will respond without undue delay and within one month of receipt (GDPR Art. 12(3)), extendable by two further months for complex requests with notice to you.
We may request proof of identity before responding, to protect your data from unauthorized disclosure, in accordance with Finnish Data Protection Act Section 28.
9. Right to Lodge a Complaint with a Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
P.O. Box 800, FI-00521 Helsinki, Finland
Visiting address: Lintulahdenkuja 4, 00530 Helsinki
Website: tietosuoja.fi
Email: tietosuoja@om.fi
EU residents may also lodge a complaint with the supervisory authority in their country of habitual residence or place of work.
10. Children's Privacy
Under Section 10 of the Finnish Data Protection Act and GDPR Article 8, where information society services are offered directly to a child, parental consent is required for children under 13 years in Finland. Our website is intended for adults. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us immediately and we will delete it without undue delay.
11. Register of Processing Activities
As required by GDPR Article 30, we maintain an internal record of processing activities documenting purposes, categories of data, recipients, retention periods, and security measures. This register is available to the Data Protection Ombudsman upon request.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, or our practices. Material changes will be posted on this page with an updated revision date. Where required by law, we will seek renewed consent or provide additional notice before changes take effect.
13. Contact
For privacy-related questions or requests, contact us at:
Lovelyboost.ddd
Aurakatu 22, 20100 Turku, Finland
Email: business@lovelyboost.world
Phone: +358 40 596 1585