Privacy Policy

This privacy policy describes how we process the personal data of people who have visited Villa Ankkalinna and those who subscribe to our newsletter.

1 REGISTRAR

Data controller: Villa Ankkalinna
Finesco Hospitality Oy, 2765399-2

Contact person: Kari Järvenpää, kari@finesco.fi

2 LEGAL BASIS AND PURPOSE OF PROCESSING

We process your personal data for the purpose of providing and implementing accommodation and restaurant services. The processing is necessary for the implementation of the contract and compliance with legal obligations. Processing situations may include:

  • making reservations

  • communication about reservations and changes

  • invoicing

  • online shopping

  • maintenance of the passenger information system

We also process data based on legitimate interest to improve services and for marketing, such as customer surveys. Newsletters and electronic direct marketing are only sent with your consent.

Your information will not be used for automated decision-making.

3 PERSONAL DATA PROCESSED

  • passenger declaration information (e.g. name, social security number, passport number)

  • contact information (email, phone number)

  • newsletter and marketing consents

  • special diets and allergies

  • payment information

  • age groups for discounts

  • camera surveillance information (public spaces)

4 PERSONAL DATA RETENTION PERIODS

  • Completion of service + 3 years

  • Direct marketing consents: until you cancel

  • Camera surveillance: 3 months

  • Passenger declarations: 1 year

  • Accounting records: 6 or 10 years

5 HOW DATA IS COLLECTED

Information is obtained from:

  • in connection with a reservation, purchase or newsletter subscription

  • through transactions with the customer's consent

6 DATA TRANSFERS AND TRANSFERS

Data may be processed by outsourced service providers (e.g. payment services, marketing partners). In legal situations, data may be disclosed to authorities, such as the police.

7 TRANSFER OF DATA OUTSIDE THE EU/EEA

Data is generally not transferred outside the EU/EEA.

8 PRINCIPLES OF REGISTRY PROTECTION

  • Access only for employees who need it

  • Physical material is kept locked away

  • Electronic systems protected by usernames and passwords

9 RIGHTS OF THE DATA SUBJECT

You have the following rights under the EU Data Protection Regulation:

  • Right to access information

  • Right to rectify data

  • Right to request deletion of data

  • Right to restrict processing

  • Right to object to processing

  • The right to transfer data from one system to another

  • Right to withdraw consent

  • Right to lodge a complaint with a supervisory authority

Cookie Policy