Privacy Policy
Rekisteriseloste / Privacy Policy
Data Controller
Toimii Digital
Private trader (sole proprietorship)
Business ID: 2501710-8
Vantaa, Finland
Email: support@toimii.io
What data we collect
Account data
When you sign up, we collect the following through Google or Apple sign-in:
- Email address
- Display name
- OAuth provider identifier
Component settings
Settings you create for your components: field definitions, look, and behavior options.
Submission data
Form responses submitted by visitors on your website through Toimii components:
- Form field values (name, email, message, etc. — as configured by you)
- Submitter's IP address
- Browser user agent
Why we collect this data
- To provide and run the Toimii service
- To deliver form submissions to you
- To send email notifications for new submissions
- To improve the service and fix bugs
Legal basis
- Contract performance — your account data is needed to provide the service
- Legitimate interest — submission data is processed on your behalf to deliver the service
Data storage
All data is stored in the EU. We use AWS Europe (Stockholm) for servers, database (PostgreSQL on RDS), and files (S3).
Data sharing
We don't share your data with anyone. No ads, no analytics tracking, no data selling. Your data is only used to run the Toimii service.
Cookies
Toimii uses one session cookie for sign-in. No marketing cookies, no analytics cookies, no third-party tracking.
Data retention
- Account data is kept while your account is active
- Submission data is kept per your preferences and can be deleted anytime
- All data is deleted within 30 days of account closure
Your rights
Under the GDPR, you have these rights:
- Right of access — request a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data
- Right to data portability — receive your data in a portable format
- Right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuojavaltuutettu)
Embedded components and data processing
When you embed a Toimii component on your site, you are the data controller for your visitors' submissions. Toimii acts as a data processor on your behalf and shows your visitors a standard privacy notice describing how their data is handled. You remain responsible for making sure your visitors are appropriately informed, and can add your own privacy policy if your use requires it.
Changes to this policy
We'll notify you of material changes via email. Minor clarifications may be made without notice.
Last updated: March 2, 2026