Privacy Policy
Ranta-Keurula Register and Privacy Policy
This register and privacy policy has been prepared in accordance with the EU General Data Protection Regulation (GDPR), Sections 10 and 24 of the Finnish Personal Data Act, Section 7 of the Act on Accommodation and Food Service Activities, and applicable marketing legislation.
This policy describes Ranta-Keurula’s customer register and the processing of customer data for compliance with legal obligations and public duties, customer relationship management, sales and marketing.
Our website address is: https://ranta-keurula.fi
1. Data controller
Ranta-Keurula, Rantakeurulantie 159, 41550 Hannula, Finland (Y 1162794-1, VAT 11627941)
Phone +358405818893 ja +358415452461
Email info(a)ranta-keurula.fi
2. Contact person responsible for the register
Mirja Riipinen, owner/entrepreneur
3. Name of the register
Ranta-Keurula customer register
4. Legal basis and purposes of processing personal data
Ranta-Keurula collects and maintains customer data in accordance with applicable legislation for the performance of legal and public duties; the management and development of customer relationships; the provision of services and events; verification of customer transactions; the development of customer service and business operations; and the management of invoicing and credit control.
The data is also used to advertise and market the company’s services and products, conduct market research, and target direct marketing at data subjects who have given their consent or where a contractual relationship provides a lawful basis. Electronic communications identification data may be used for information, sales and marketing purposes as permitted by law. The data is not used for automated decision-making or profiling.
Under the EU General Data Protection Regulation, the legal basis for processing personal data includes the traveller register required by the Finnish Act on Accommodation and Food Service Activities (MaRaL 308/2006), for the purposes of submitting traveller notifications, maintaining public order and safety, preventing and investigating crime, and compiling statistics (legal obligation and performance of a public duty).
Other legal bases include a customer relationship arising from an accommodation, venue or service booking or purchase (legitimate interest), as well as consent to direct marketing, opinion and market research, and newsletter subscriptions (consent).
5. Data content of the register
The following data may be collected and stored depending on the customer relationship and the choices made by the customer:
Customer data
Private customers/travellers: First and last name, customer number, contact details (telephone number, home address, email address and any billing address), language code and country of departure. The names of adults and children staying with the registered guest.
Company/organisation contacts: The details of the organisation’s contact person or persons, as described for private customers; the name of the company or organisation; contact details (email address, telephone number and address); website addresses; the location of the company; information about ordered services and changes to them; invoicing details; and other information relating to the customer relationship and ordered services.
Information relating to the customer relationship: Information about the use, purchase, booking and cancellation of services and products, including past and future booking history. Information on where the service was purchased or discovered. Payment method, payment behaviour and invoicing details. Customer feedback and contacts. Information relating to the customer’s wishes and choices, such as preferred services or room category. Information concerning participation in any relevant agreement, such as a corporate agreement, loyalty programme or cooperation agreement.
Sales and marketing data
The customer’s consent to direct marketing by email, text message and other digital systems. Records of objections to direct marketing, distance selling and other marketing as required by law. Any profiling and interest information supplied by the customer. Information concerning the use of services, such as browsing and search data collected through cookies. Other information collected with the customer’s consent.
Information supplied by the customer that is necessary to provide the requested service safely and smoothly, such as mobility limitations, injuries or illnesses. Traveller notification data for private customers/travellers is retained manually for one year. Data held in systems is retained for the duration of the customer relationship or agreement, or until the customer requests otherwise.
An agreement or customer relationship ends when the customer notifies us or when the customer record has remained inactive in our systems for three years.
6. Regular sources of data
Customer data is obtained from the data subject when requesting a quotation, making an accommodation or service booking, making a purchase and/or completing a traveller notification, and from the data controller’s traveller register. Data is also obtained directly from customers when they provide information in connection with marketing campaigns, trade fairs, public events, competitions or other interactions through various channels and consent to its use.
Contact details may also be obtained from service providers that maintain company and customer registers. Calls may be recorded in customer service situations, and other communications, such as email messages, may be stored. We consider it important that customer data remains accurate and up to date. For this reason, data may be collected, stored and updated from registers maintained by data controllers providing generally and freely available information services.
Google Analytics is used on the website to monitor visitor activity.
A cookie is a small text file stored on the user’s device by an internet browser. Cookies are used, for example, to retain user information when the user moves from one page of an online service to another. The use of cookies always requires the user’s consent. (Finnish Communications Regulatory Authority)
7. Regular disclosures of data and transfers outside the EU or EEA
Customer data is not regularly disclosed to third parties. Data may be disclosed to the extent agreed with the customer or where it is essential for safety. Data may be disclosed to subcontractors and service-provider networks, such as activity providers, catering services and event producers, to the extent required by each party or by law. These disclosures are intended to ensure customer safety during the provision of services and flexibility in customer service.
Data included in the traveller register may be disclosed to authorities for the purposes and to the extent prescribed by the Finnish Act on Accommodation and Food Service Activities. As a rule, traveller data is not transferred outside the EU or EEA. This privacy policy is available on the Ranta-Keurula website.
8. Principles of register protection
Only persons whose duties require them to process customer data are authorised to use systems containing customer information. The register is handled with due care. Data is stored in databases protected by firewalls, passwords and other technical safeguards. Access to the databases is restricted to specifically designated persons.
Manual material is stored in an archive. Manual registration forms are destroyed immediately after the data has been entered into the system unless their retention is required by law or the performance of a public duty, in which case they are retained accordingly. Digital material is stored in databases. Ranta-Keurula complies with the principles of privacy protection and personal data legislation. All data is processed carefully and confidentially.
9. Right of access and right to request rectification
Under Section 26 of the Finnish Personal Data Act, data subjects have the right to inspect the personal data concerning them in the register and to request the correction of inaccurate data or the completion of incomplete data. Requests for access must be made in writing, signed and sent to the address specified in Section 2. The data controller may also correct such data on its own initiative. The data controller may ask the person making the request to verify their identity.
The data controller will respond within the period prescribed by the EU General Data Protection Regulation, normally within one month.
10. Other rights relating to the processing of personal data
A person included in the register has the right to request the deletion of their personal data from the register, also known as the “right to be forgotten”. Data subjects also have the other rights provided by the EU General Data Protection Regulation, including the right to restrict processing in certain circumstances. Requests must be submitted to the data controller in writing. Where necessary, the data controller may ask the person making the request to verify their identity.
The data controller will respond within the period prescribed by the EU General Data Protection Regulation, normally within one month.
Updated 20 July 2026 — MR
