Privacy policy
This is the register and privacy statement of Hiekkarannan Lomat in accordance with the Finnish Personal Data Act (sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Drawn up on 17 August 2026. Last modified on 17 August 2026.
1. Data controller
Hiekkarannan Lomat
Hiekkarannantie 110
FI-43300 Kannonkoski, Finland
Tel. +358 40 064 0675
info@hiekkarannanlomat.fi
2. Contact person responsible for the register
Kari Liimatainen (contact details in section 1).
3. Name of the register
Hiekkarannan Lomat customer and marketing register
4. Legal basis and purpose of processing personal data
The purpose of this register is to store the traveller information required by the Finnish Act on Accommodation and Food Service Operations (2006/308, section 6), to enable the contacts required by customer service and to maintain the customer relationship. Direct marketing is carried out when the customer has not prohibited it. The data is not used for automated decision-making or profiling.
5. Content of the register
The information stored in the register includes: the person’s name, position, company or organisation, business ID, contact details (telephone number, email address, postal address, social media addresses), website addresses, user names and profiles in social media services, invoicing details and other information related to the customer relationship and the services ordered.
In addition, information related to the user’s device is collected, such as the device type, IP address, operating system and browser (cookies).
Depending on the customer relationship, the data is stored for as long as necessary. A customer may request that their data be deleted.
6. Regular sources of information
The information stored in the register is received from the customer, for example through web forms, chat, email, telephone, social media, customer meetings and other situations in which the customer provides their information.
7. Regular disclosures of data and transfers outside the EU or EEA
The data is not disclosed to other parties but remains in the use of the data controller. Traveller information is disclosed to the authorities as required by law. The data is not transferred outside the EU or the European Economic Area.
8. Principles of protecting the register
The register is handled with care and the data is protected appropriately. The physical and digital security of the data stored on internet servers is taken care of appropriately.
The data controller ensures that the data is processed confidentially and only by those employees whose work includes it.
Manual material: printed material is kept in a locked space, and only the data controller and the authorities defined by law have access to it.
9. Right of access and right to demand correction of data
The data subject has the right to check their own data and to demand that incorrect data be corrected or completed. The request must be made in writing to the data controller.
If necessary, the data controller may ask the data subject to verify their identity, and will respond to the request as a rule within one month.
10. Other rights related to the processing of personal data
The data subject has the right to request the deletion of their data (the right to be forgotten) and the right to restrict the processing of their data in certain situations.
Requests must be made in writing to the data controller. If necessary, the data controller may ask the data subject to verify their identity, and will respond to requests as a rule within one month.
Cookies
This website uses cookies to improve the user experience. Cookies are small files that are saved on the user’s device.
The website uses both session cookies and persistent cookies. Cookies make it possible to analyse the user’s activity and to develop the service.
Browsers usually accept cookies automatically, but the user can prevent their use in the browser settings. This may affect the functionality of the website.
Third parties such as Google may use cookies and web beacons to optimise advertising. The information collected in this way is not combined with an individual person.
