Registry and privacy statement

Registry and privacy statement

This is Villa Klubiranta Ltd’s register and data protection statement in accordance with the Personal Data Act (Sections 10 and 24) and the EU’s General Data Protection Regulation (GDPR). The report was prepared on 30 June 2022. Villa Klubiranta Ltd operates in the accommodation and catering sector providing accommodation and restaurant services to its customers. This data protection statement describes the principles of personal data processing and protection, with which Villa Klubiranta Ltd, as the data controller, protects personal data in various situations.

1. Registrar

Villa Klubiranta Ltd
Haukilahdentie 10
35600 Halli, Finland
[email protected]

Company ID-number: 3263601-1

2. Person responsible for the register

Jenni Kunnas
+358 50 345 0487
[email protected]

3. Name and purpose of the register

The name of the customer register is Villa Klubiranta Oy’s customer register. The purpose of personal data processing is communication with customers, maintaining customer relations and marketing.


According to the EU’s General Data Protection Regulation, the legal basis for processing personal data is the person’s consent (documented, voluntary, individualized, informed and unambiguous)

4. Data content of the register

Information stored in the register includes: person’s name, position, company/organization, contact information (phone number, e-mail address, address), website addresses, IP address of the network connection, credentials/profiles in social media services, information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services.

The information is stored for two years from the moment when the information was last changed.

5. Regular information sources

The information stored in the register is obtained from messages sent by the customer using www forms, by e-mail, by phone, via social media services, contracts, customer meetings and other situations where the customer discloses their information.

The website collects anonymous visitor information via Google Analytics. This means that when the page is opened, the visitor is given a token identifier, i.e. a cookie, which Google Analytics uses to record visitors’ visits to the site. If you return to the pages later from the same device after accepting the cookie, Google Analytics registers this as well, but the visitor information is not linked to the person.

The server of the website also collects anonymous information about visitors, such as IP address, browser type, operator, starting page, exit page, time and the path of the visit to the site. Anonymous server information can be sent to the site administrator.

Personal data is processed when the website visitor buys accommodation services on the page and in its reservation system. Personal data is also processed when filling out contact forms and other possible forms. Information from the reservation system is only used to provide accommodation services and information from the forms to provide customer service.

Anonymous visitor data from Google Analytics is used for reporting and statistics on page visitors, as well as for measuring marketing measures such as newsletters.

6. Regular transfer of data and transfer of data outside the EU or EEA

Information is not regularly disclosed to other parties. Information can be published to the extent agreed with the customer. Data can also be transferred by the controller outside the EU or EEA.

Information may be disclosed to the following parties:

– Facebook
– Google
– MailChimp

The reason for the transfer of information is better and targeted marketing.

7. Principles of registry protection

Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.

8. Right of inspection and right to demand correction of information

Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

9. Other rights related to the processing of personal data

A person in the register has the right to request the removal of his personal data from the register (“right to be forgotten”). Data subjects also have other rights according to the EU General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests must be submitted in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).