# Terms of engagement, and how data is handled

This page covers the terms under which turva.dev operates, the
privacy practices of the site, and the default terms for engagements.

## Operator

turva.dev is operated by Erik Rekola, Business ID 3600281-7,
registered in Finland as a sole proprietorship.
VAT-registered, VAT ID FI36002817.

Contact: <mailto:info@turva.dev>

## Terms of engagement

The following terms apply to all engagements (Shopify agent
storefront check, audit, advisory,
implementation, agent operations and MCP server design) unless
replaced by a written agreement.

**Scope.** Each engagement has a defined scope agreed in writing
before work starts. Scope changes require a new written agreement
and may affect price and timeline.

**Deliverables.** Audit deliverables are a written report.
Advisory deliverables are written reviews and a monthly summary.
Implementation deliverables are source code committed to the
agreed repository.

**Payment.** Payment terms are fourteen days net unless agreed
otherwise in writing. Late payment interest follows Finnish law.

**Confidentiality.** Information shared during an engagement is
treated as confidential. Your own non-disclosure agreement is signed
as it stands before any material moves, at no charge. Production
credentials are not requested at any stage.

**Liability.** Liability is limited to the value of the engagement.
turva.dev is not liable for indirect or consequential damages.

**Intellectual property.** The client owns the deliverables produced
for them. Generic methods, templates and reusable code remain with
turva.dev.

**Governing law.** Finnish law applies. Disputes are resolved in
the District Court of Pirkanmaa, Finland.

## Privacy

This site does not use analytics cookies, tracking pixels or
third-party scripts.

**Server logs.** The hosting provider (Cloudflare) records standard
request logs including IP address, user agent and requested path.
Logs are retained according to Cloudflare's standard retention policy.

**Email.** Email communication is stored in standard email
infrastructure for as long as needed to deliver the work and meet
accounting obligations under Finnish law (six years for invoice
records).

**Client data.** Data shared by a client during an engagement is
stored only on systems necessary to deliver the work, and deleted
within thirty days of engagement closure unless retention is
required by law. The workstation holding it uses full disk
encryption, credentials are held in an encrypted vault rather than in
files, and backups are encrypted on the machine before they are
uploaded anywhere.

**AI tools.** AI tools are used in the work, on a local workspace
holding the files a task needs. Those files are processed by the
provider of the tool in use. No secret reaches a tool in the clear,
because credentials are held in an encrypted vault that scripts read
at runtime, and the tools have no access to client systems. Material
a client wants excluded from AI tooling is named in the
non-disclosure agreement and excluded.

No data is sold. Data reaches a third party only through the
providers needed to deliver the work: hosting, email, encrypted
backup storage and the AI tool in use.

## Rights under GDPR

You have the right to access, correct or request deletion of personal
data held about you. Send the request to <mailto:info@turva.dev>.

The supervisory authority in Finland is the Data Protection
Ombudsman (tietosuojavaltuutettu.fi).

## Cookies

This site sets no cookies of its own. Cloudflare may set cookies
required for bot management and security. These are technical
cookies and do not require consent under EU law.

## Updates

This page is updated when the terms change. The current version
applies to engagements started after the date below.

Terms last updated: 2026-08-11.
