Lietsu Services Ltd. /Lietsu Boutique Aparthotel
Rantakatu 26, 80100 Joensuu, Finland
2. Person responsible for the register /Data protection officer
Helena Puhakka-Tarvainen, CEO
+358 50 541 7289
3. Name of the register
The customer register of Lietsu Services Ltd /Lietsu Boutique Aparthotel.
4. Purpose and legal basis of the processing of personal data
We process the personal information of our customers for the following purposes:
- handling customer relationships and reservations
- Payment, control of payments and collection of payments
- marketing of hotel products and services
- registration of services and benefits purchased by customers.
The legal basis for the processing of personal data under the EU General Data Protection Regulation is the individual’s consent. As a precondition for making a reservation, the customer must provide to the hotel at least one valid contact information (email address, telephone number).
5. Data content of the register
The following information about the customers is collected and stored:
- Customer Information: Person’s name, customer number, company / organization, contact information (eg. telephone number, email address, address), web site addresses, IP address of the internet connection, IDs / profiles on social media services, any other relevant customer relationship information.
- Customer feedback information: customer satisfaction information, comments on the registrar’s services, and other information obtained with the customer’s consent (anonymously).
- Booking information: Customer’s past and future bookings, number of adults and children staying at hotel, information and the changes on the services ordered, other information related to the customer relationship and services reserved.
- Payment information: Customer’s payment and payment behaviour information (including late payment information) and billing information. Your payment and credit card details are processed by your payment agent.
- Other Information: Information collected with the customer’s consent and necessary to provide the service requested.
Customer records are retained for a minimum of one year and a maximum of two years from the date of the last change to the information. The customer has the possibility to prohibit the storage of his / her data in the customer register after the completion of the accommodation service.
6. Regular sources of information
Information stored in the register can be obtained from the customer eg. by messages sent via web forms, email, telephone, social media services, contracts, customer meetings and other situations where the customer discloses his or her consent.
7. Disclosure of customer information and transfer of information outside the EU or EEA
Information is not routinely disclosed to anyone other than the statutory handing over of accommodation cards to the authorities. The information may be published to the extent agreed with the customer. Data may also be transferred by the controller outside the EU or the EEA.
Information may be disclosed to:
- Property Management System (PMS) providers
- Communication and marketing service providers
- Producers of social media marketing services
The reason for disclosure is better and more targeted marketing.
8. Register protection principles
The records shall be handled with care and the data processed by the information systems shall be appropriately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is properly taken care of. The data controller shall ensure that the stored information, as well as server access and other information critical to the security of the personal data, is treated confidentially and only by the employees whose job description it is included in.
The amount of material in manual format is minimized and locked in the premises of Lietsu Services Ltd. /Lietsu Boutique Aparthotel.
9. Right of inspection and the right to have the data corrected
Every person in the register has the right to verify their data stored in the register and to request the correction of any inaccurate or incomplete information. If a person wishes to check or rectify the information stored about him / her, the request must be sent in writing to the registrar. If necessary, the registrar may require the applicant to prove his identity. The registrar will respond to the client within the time limit set by the EU Data Protection Regulation (as a rule within one month).
10. Other rights related to the processing of personal data
A person on the register has the right to request that personal data relating to him / her be removed from the register (“the right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as restricting the processing of personal data in certain situations. Requests should be sent in writing to the registrar. If necessary, the registrar may ask the applicant to prove his identity. The registrar will respond to the client within the time limit set by the EU Data Protection Regulation (as a rule within one month).
This is a register and privacy statement of Lietsu Services Ltd. in accordance with Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Created 1.9.2019.