Privacy Policy
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Website and services. By accessing or using our Website, you agree to the practices described in this policy. We encourage you to read this policy thoroughly to understand your rights and how your data is handled.
1. Definitions
For the purposes of this Privacy Policy:
- Personal Data: Information that identifies, relates to, or describes you, such as your name, email address, or phone number.
- Processing: Any operation or set of operations performed on personal data (e.g., collection, storage, modification, use).
- Data Controller: The entity that determines the purposes and means of processing your personal data, which in this case is [Your Company Name].
- Data Processor: Any entity that processes data on behalf of the Data Controller.
- Cookies: Small data files placed on your device to track activity and preferences.
- Third-Party Services: External service providers we engage to process your data (e.g., payment gateways, analytics providers).
2. Information We Collect
We collect both personal and non-personal information from you:
2.1 Personal Data
We collect personal information that you provide directly, such as:
- Identity Data: Full name, email address, phone number, and postal address.
- Payment Data: Financial information required for processing payments (e.g., credit card details).
- Service Data: Information provided during the booking of transportation, tours, or travel services.
2.2 Automatically Collected Information
When you use our Website, we collect certain information automatically, including:
- Device Information: IP address, browser type, operating system, and device type (desktop, mobile).
- Usage Data: Pages visited, time spent on the Website, links clicked, and other interaction data.
- Geolocation Data: For users who consent, we may collect location data to offer nearby services.
2.3 Third-Party Data
We may receive personal data about you from third-party partners (e.g., travel aggregators, marketing platforms, analytics services). This may include demographic data, preferences, and interests for marketing purposes.
3. How We Use Your Data
We use your personal data for several purposes:
- Service Provision: To provide transportation, tour, and travel services, including booking confirmations and customer support.
- Personalization: To offer personalized services based on your preferences, such as tour recommendations.
- Marketing Communications: With your consent, we may send newsletters, special offers, and updates.
- Legal Compliance: To comply with legal obligations under Finnish law and international regulations.
- Fraud Prevention: To protect against fraudulent activity and ensure secure transactions.
- Analytics: To monitor Website performance, understand user behavior, and improve our services.
4. GDPR Compliance (European Economic Area)
If you are located in the European Economic Area (EEA), we process your data in accordance with the General Data Protection Regulation (GDPR).
4.1 Data Subject Rights
Under the GDPR, you have the following rights:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure: You can request the deletion of your personal data (Right to be Forgotten).
- Right to Restrict Processing: You can request a restriction on processing under certain circumstances.
- Right to Data Portability: You can request a copy of your data in a machine-readable format and transfer it to another service provider.
- Right to Object: You can object to the processing of your data, particularly for direct marketing purposes.
- Right to Withdraw Consent: Where consent is the legal basis for processing, you can withdraw it at any time.
4.2 Legal Basis for Processing
We rely on the following legal bases for processing your data:
- Consent: Where you have provided explicit consent (e.g., for receiving marketing communications).
- Contractual Obligation: Processing is necessary for fulfilling a contract (e.g., booking services).
- Legal Compliance: Processing is required to comply with our legal obligations under Finnish and EU law.
- Legitimate Interests: Processing is necessary for our legitimate business interests, such as enhancing our services or ensuring security.
4.3 Data Retention
We retain personal data for as long as necessary to fulfill the purposes for which it was collected or as required by law. Specific retention periods include:
- Transactional Data: Retained for the duration of the contract and for the legally required period thereafter (e.g., for tax and accounting purposes).
- Marketing Data: Retained until you opt-out or withdraw your consent.
- User Account Data: Retained as long as your account is active or until deletion is requested.
5. CCPA Compliance (California Residents)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Request Information: Ask for details about the personal information we collect, including categories of data and purposes for collection.
- Request Deletion: Request the deletion of your personal data.
- Opt-Out of Sale: We do not sell your personal data. However, you have the right to opt-out of the sale of your data if our policies change in the future.
- Non-Discrimination: We do not discriminate against users who exercise their CCPA rights.
6. Data Security
We implement robust security measures to protect your personal data, including:
- Encryption: We use SSL/TLS encryption to secure data during transmission.
- Access Control: Personal data is only accessible to authorized personnel who need it for processing purposes.
- Firewalls and Intrusion Detection Systems: We use these technologies to monitor and block unauthorized access to our systems.
- Regular Security Audits: We conduct audits and vulnerability testing to identify and address potential threats.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience. Cookies help us:
- Remember Preferences: Store your language, location, and other preferences.
- Track User Behavior: Monitor how users navigate through the Website.
- Provide Targeted Advertising: Show you relevant advertisements based on your browsing behavior.
7.1 Types of Cookies We Use
- Essential Cookies: Required for basic functionality (e.g., to stay logged in).
- Performance Cookies: Collect data on user behavior to improve the Website.
- Targeting Cookies: Used by third-party advertisers to show you personalized ads.
8. Third-Party Service Providers
We may share your personal data with third-party service providers, including:
- Payment Processors: To handle transactions securely (e.g., Stripe, PayPal).
- Analytics Providers: To analyze Website performance and user behavior (e.g., Google Analytics).
- Marketing Platforms: To send newsletters and promotional content (e.g., MailChimp).
Each third-party provider has its own privacy policy, and we ensure that they comply with applicable privacy laws.
9. Data Transfers in Case of Business Change
If our company is involved in a merger, acquisition, or sale of assets, your personal data may be transferred to the new entity. In such cases, you will be notified, and the new entity will continue to handle your personal data according to the terms of this Privacy Policy.
10. Data Retention Policy
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific data retention periods include:
- Transactional Data: Retained for the duration of the contract and any legally mandated retention period (e.g., for tax reporting).
- Customer Support Data: Retained until the support case is resolved and archived.
- Marketing Data: Retained until you opt-out of marketing communications or request deletion.
Once data is no longer needed, we ensure secure deletion or anonymization.
11. Children’s Privacy
Our services are not intended for individuals under the age of 13. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected data from a child under 13, we will take steps to delete that data. If you believe that we may have collected information from a child, please contact us immediately.
12. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. Any changes we make will be posted on this page with an updated Effective Date at the top of the policy. We encourage you to review this page periodically for the latest information on our privacy practices. Continued use of our services after changes have been implemented constitutes acceptance of the revised policy.
13. Your Rights and Control Over Your Data
You have control over your personal data and can exercise the following rights under applicable data protection laws:
- Right to Access: You can request details about the personal data we hold on you.
- Right to Correction: You can ask us to update or correct your personal data if it is inaccurate.
- Right to Deletion: You can request that we delete your personal data in certain situations, such as if the data is no longer necessary for the purposes for which it was collected.
- Right to Object: You can object to the processing of your personal data, especially for direct marketing purposes.
- Right to Data Portability: You can request a copy of your data in a structured, machine-readable format for transfer to another service provider.
- Right to Withdraw Consent: If we rely on your consent to process your data, you can withdraw that consent at any time.
To exercise these rights, or if you have any questions or concerns about how we handle your data, please contact us at the information provided below.
14. Dispute Resolution and Complaints
If you have any concerns or disputes regarding our privacy practices, we encourage you to first reach out to us directly to resolve the issue. If you believe we have violated your data protection rights, you also have the right to lodge a complaint with your local data protection authority. In Finland, the Office of the Data Protection Ombudsman is responsible for overseeing GDPR compliance.
Contact the Data Protection Ombudsman:
- Website: https://tietosuoja.fi/en
- Phone: +358 29 566 6700
- Email: tietosuoja@om.fi
15. How We Handle International Data Transfers
As part of our services, your personal data may be transferred and processed outside of your home country, including to countries outside the European Economic Area (EEA) that may have different data protection laws than your country. In cases where personal data is transferred to countries that have not been deemed by the European Commission to provide an adequate level of protection, we use appropriate safeguards, such as Standard Contractual Clauses (SCCs), to protect your personal data.
You have the right to request further information about the safeguards we have implemented for international transfers. Please contact us if you have any questions regarding this.
16. Links to Other Websites
Our Website may contain links to other third-party websites. Please note that this Privacy Policy does not apply to any third-party websites, and we are not responsible for the privacy practices of those sites. We recommend reviewing the privacy policies of any third-party websites you visit to understand how they collect, use, and protect your data.