Privacy policy
This policy explains how Tiirismaan Liikenne Oy processes the personal data of Villa Hollola guests and people who contact us. It is based on the EU General Data Protection Regulation.
Updated 24 September 2026
Controller
- Tiirismaan Liikenne Oy, business ID 2440027-9
- Kirsikkatie 6, 15870 Hollola, Finland
- info@villahollola.fi
Please send any questions or requests about data protection to the same e-mail address.
What data we process
- Contact details: name, e-mail address and phone number.
- Quote and booking details: dates, number of guests, the room or villa booked, and your requests and messages.
- Company billing details: company name, business ID, e-invoice address, reference and contact person.
- Payment details: amount, status and time of payment. We do not process card details ourselves; the payment provider does.
- Door codes: the door code created for your booking and its validity period.
- Traveller notification: name, Finnish personal identity code or date of birth and nationality, home address, passport or ID card number for foreign nationals, arrival and departure dates, accompanying spouse and minor children, and signature.
- Technical data: IP address and browser details stored in the website server logs.
Where the data comes from
- From you, when you contact us, request a quote or make a booking.
- From Airbnb or Booking.com, when you book through them. They pass on the details needed to handle your booking.
Purposes and legal bases
- Answering quote requests and handling bookings, including door codes and arrival instructions. Legal basis: preparing and performing a contract, Article 6(1)(b) GDPR.
- Invoicing and bookkeeping. Legal basis: legal obligation, Article 6(1)(c), and the Finnish Accounting Act.
- Traveller notification. Legal basis: legal obligation, Article 6(1)(c), and the Finnish Act on Accommodation and Food Service Activities 308/2006.
- Asking for feedback after your stay, website security and preventing misuse. Legal basis: legitimate interest, Article 6(1)(f).
We do not use your data for direct marketing or profiling, and we make no automated decisions.
Retention
- Quote requests that do not lead to a booking: 12 months.
- Booking details: 2 years from the end of the stay.
- Bookkeeping records: vouchers 6 years and books of account 10 years from the end of the financial year, as required by the Finnish Accounting Act.
- Door codes are removed from the locks when the booking ends.
- Traveller notifications: one year from signing, after which they are deleted automatically.
- Server logs: up to 30 days.
Recipients
We use service providers who process data on our behalf and according to our instructions:
- MBGO Oy: development and maintenance of the website and booking system.
- Louhi Networks Oy: e-mail service, Finland.
- Vercel Inc.: website hosting.
- Supabase Inc.: database, data stored in the EU.
- Payment provider: card payments.
- Lock and messaging service providers: door codes and booking messages.
- Accountant: bookkeeping and invoicing.
Airbnb and Booking.com are independent controllers for bookings made through them, and their own privacy policies apply.
By law, we pass the traveller notification details of foreign nationals to the police. We disclose data to other authorities only when required by law.
Transfers outside the EU and EEA
Our service providers Vercel Inc. and Supabase Inc. are US companies, so data may be processed in the United States. Transfers are protected by safeguards required by the GDPR, such as the European Commission's standard contractual clauses.
Cookies
The website uses no cookies and no analytics or marketing tools.
Your rights
- You can request access to your data and have it corrected or erased.
- You can request restriction of processing and object to processing based on legitimate interest.
- You can request the data you have provided in a machine-readable format.
Send your request to info@villahollola.fi. We will reply within one month.
If you believe your data is processed unlawfully, you can lodge a complaint with the Office of the Data Protection Ombudsman in Finland at tietosuoja.fi.
Security
Data is stored in services that only those who need it for their work can access. The connection to the website is encrypted.
Changes
We update this policy when our processing changes. The date of the latest update is shown at the top of the page.