Privacy Policy
Last updated: January 2026
Paperplaydabbl Oy ("we", "us", "our") respects your privacy and is committed to safeguarding the personal information of every guest, prospect, and visitor who interacts with paperplaydabbl.com or our partner properties. This Privacy Policy explains what data we collect, why we collect it, how we use it, and the rights available to you under the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.
1. Data Controller
The data controller responsible for your personal information is:
Paperplaydabbl Oy
Pohjoisesplanadi 21, 00100 Helsinki, Finland
Business ID: FI-2026-PPD
Email: [email protected]
Phone: +358 9 4245 8870
2. Information We Collect
2.1 Information you provide directly
- Identification data: full name, salutation, date of birth (where required for booking compliance).
- Contact data: email address, postal address, telephone number.
- Reservation data: hotel preference, dates of stay, number of guests, room/suite preferences, dietary or accessibility requirements.
- VIP profile data: lifestyle preferences, prior stays, special-occasion notes (only with your consent).
- Communication data: any messages, enquiries, complaints, or feedback you send to us.
2.2 Information collected automatically
- Technical data: IP address, browser type, device type, operating system, language settings.
- Usage data: pages visited, click paths, session duration, referring source.
- Cookie data: see our Cookie Policy for full details.
2.3 Information from third parties
We may receive information from partner hotels (booking confirmations, on-property preferences) and from analytics providers, payment processors, and marketing platforms acting on our behalf.
3. How We Use Your Information
We process personal data only for clearly defined purposes, each with a lawful basis under Article 6 of the GDPR:
- To respond to enquiries and process reservations — basis: performance of a contract / pre-contractual steps.
- To coordinate stays with partner hotels — basis: performance of a contract.
- To send service communications (booking confirmations, updates, concierge follow-ups) — basis: contract / legitimate interest.
- To send marketing communications (offers, seasonal newsletters, VIP invitations) — basis: consent. You may withdraw consent at any time.
- To improve our website and services via aggregated analytics — basis: legitimate interest.
- To comply with legal obligations (accounting, tax, anti-fraud, regulatory reporting) — basis: legal obligation.
- To protect our rights, guests, and property — basis: legitimate interest.
4. Data Sharing & Recipients
We share personal data only with parties who need it to deliver the service you have requested or to fulfil a legal duty:
- Partner hotels in Helsinki, Savonlinna, and Rovaniemi (booking enquiries only).
- Trusted service providers: hosting (EU-based), email delivery, CRM, analytics, payment processing.
- Professional advisors: auditors, lawyers, insurers (under confidentiality).
- Public authorities, when required by Finnish or EU law.
We never sell, rent, or trade your personal data.
5. International Transfers
Your data is primarily processed within the European Economic Area (EEA). Where any processor is located outside the EEA, we rely on EU Standard Contractual Clauses (SCCs) and conduct transfer impact assessments to ensure equivalent protection.
6. Cookies & Tracking Technologies
We use a limited set of cookies for site functionality and analytics. Detailed information, including categories, durations, and opt-out controls, is available in our Cookie Policy.
7. Data Security
We apply administrative, technical, and physical safeguards aligned with ISO 27001 principles, including:
- TLS 1.3 encryption for all data in transit.
- AES-256 encryption for sensitive data at rest.
- Role-based access controls and multi-factor authentication for staff.
- Regular penetration testing and vulnerability scanning.
- Documented incident-response and breach-notification procedures (within 72 hours where required).
8. Data Retention
We retain personal data only as long as necessary for the purposes set out above:
- Enquiry data without booking: up to 24 months.
- Booking and stay records: up to 6 years (Finnish accounting requirement).
- Marketing data: until consent is withdrawn or after 36 months of inactivity.
- Web analytics data: anonymised after 14 months.
9. Your Rights Under the GDPR
If you are located in the EU/EEA you have the following rights, free of charge:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete information.
- Erasure ("right to be forgotten") — request deletion where applicable.
- Restriction — limit how we process your data in certain situations.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest or direct marketing.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) or your local supervisory authority.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
10. Children's Privacy
Our services are not directed at children under 16. We do not knowingly collect data from minors without parental consent. If you believe a child has provided us with personal data, please contact us for prompt removal.
11. Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.
12. Changes to This Policy
We may update this Privacy Policy to reflect operational, legal, or regulatory changes. The "Last updated" date at the top of this page indicates the latest revision. Significant changes will be communicated by email or a website notice.
13. Contact Us
For any privacy-related question, request, or complaint, please contact our Data Protection Officer:
Email: [email protected]
Phone: +358 9 4245 8870
Post: Data Protection Officer, Paperplaydabbl Oy, Pohjoisesplanadi 21, 00100 Helsinki, Finland