Privacy Policy
1. Controllers and contact
Lapland Boutique Resorts (LBR) is a brand under which different legal entities provide travel and hospitality services. The controller responsible for your personal data depends on the property or service concerned:
- Hilltop Hotel Iso-Syöte: Jepetron Oy, Business ID 3434075-9. Contact address: Isosyötteentie 246, 93280 Syöte, Finland.
- Ruka Safaris, Iisakki Village and Oivanki Resort: Ruka Experiences Oy, Business ID 3238982-3. Address: Myllylahdentie 4, 93830 Rukatunturi, Finland.
Where an itinerary contains services provided by more than one Lapland Boutique Resorts company, each legal entity is responsible for the personal data it processes in connection with the services it provides.
Jepetron Oy operates the shared LBR website and technical itinerary platform. It is the account holder for Cloudflare, OpenAI API, ChatGPT Workspace/Sites and Resend.
In this notice, references to LBR or “we” refer to the relevant companies operating under the brand, rather than to a separate legal entity.
For privacy questions and requests, contact sales@isosyote.fi.
2. Scope, information and sources
This notice covers www.laplandboutiqueresorts.fi, enquiries and forms relating to the services listed above, and the customer itinerary service.
Website enquiries and forms may contain your name, email address, telephone number, company name and information provided when requesting a quotation or making a booking. Website use may generate IP addresses, technical identifiers, and cookie or analytics information.
For itineraries, information may include customer and group names, booking references, travel dates, accommodation and room or unit types, board basis, activities, meals, transfers, pickup details, participant counts, relevant age categories, language preferences and necessary operational notes. Booking screenshots and uploaded files may contain this information.
Information may come from you, another member of your travelling party, a tour operator, travel agency, reseller, affiliate, or booking and operational systems. We may therefore receive information indirectly. Please contact us if information is inaccurate.
We limit the information used to what is relevant to the requested services.
3. Purposes and legal bases
We use personal data to respond to enquiries, prepare quotations, handle bookings, maintain customer relationships and organise requested services.
The itinerary service includes extracting relevant booking information, preparing and translating programmes, updating activities and practical arrangements, generating Word and PDF documents, providing an online itinerary, sending itinerary and update emails, and maintaining necessary delivery history.
Where you are a party to the contract, necessary processing is based on performance of that contract or steps taken at your request before entering it.
Where another party arranges your travel, our legitimate interests include coordinating the booked services and keeping authorised recipients informed. Legitimate interests also support necessary security, troubleshooting, proportionate delivery records and service improvement. These interests must be balanced against your rights and freedoms.
Consent is used where required for marketing communications and optional cookies or analytics. You may withdraw consent without affecting the lawfulness of processing before withdrawal. Operational itinerary communications are separate from marketing.
We also process information where necessary to fulfil applicable legal obligations, including responding to data-protection requests.
Providing necessary booking information is generally required to deliver the requested service. Without it, we may be unable to prepare an accurate itinerary or complete the arrangements. Optional information is voluntary.
4. Recipients, providers and international transfers
Access is limited to authorised personnel and providers who need the information for their duties. Relevant information may be shared with the companies delivering booked services. Itineraries may be sent to you and authorised recipients associated with your booking.
Website services may involve hosting, booking and payment systems, form and email services, analytics such as Google Analytics, and maps such as Google Maps, where used.
LBR uses service providers such as Cloudflare, OpenAI API and Resend to operate and deliver the itinerary service. Some processing may take place outside the European Economic Area. Where this occurs, LBR relies on the transfer mechanisms and safeguards applicable under EU data protection law and the relevant data processing agreements, such as an adequacy decision or Standard Contractual Clauses, where applicable. Information about the safeguards used and how to obtain a copy can be requested from LBR using the privacy contact details below.
Personal data is not disclosed without a lawful basis.
5. Cookies and website analytics
The website uses cookies and similar technologies for essential functions, preferences, analytics and improving the user experience. Consent is requested where required for optional cookies, analytics and third-party content.
You can review or change your choices through the website’s privacy or cookie preferences. Declining optional cookies does not prevent you from contacting us about our services.
The separate cookie notices linked from the website provide further information about the cookies used, their purposes and duration. This privacy notice complements those notices.
Marketing communications based on consent can be stopped by withdrawing consent or using the unsubscribe option provided.
6. Online itineraries and security
Your online itinerary is accessible through a private link containing a secure access token. Anyone holding the link may be able to view its contents. Share it only with intended recipients.
The viewer is not a public directory of customer itineraries. Links can be disabled, and expired tokens no longer provide access.
We use appropriate technical and organisational measures and access controls to protect personal data.
Automated extraction and translation assist staff in preparing itineraries. Staff can review and correct the information. The itinerary service does not make solely automated decisions producing legal or similarly significant effects on you.
7. Retention and deletion
Website enquiries, form submissions and customer records are retained for as long as necessary for their purposes, including relevant follow-up and applicable legal obligations.
For the itinerary service, scheduled cleanup removes source screenshots and files and disables public itinerary links after 30 days from departure. Identifiable itinerary records, generated documents and personal sending-history information are deleted or anonymised after 90 days from departure. These actions are carried out by scheduled runs. Anonymous operational information may remain.
These periods do not replace separate statutory requirements for records held in other systems, such as accounting records.
Disabling an online link does not remove documents already downloaded or emails already received. Copies held by recipients and records retained by providers outside the Builder are subject to their applicable retention arrangements.
8. Your rights
Subject to the applicable conditions, you may request access to your personal data, correction, erasure, restriction of processing or data portability. You may object to processing based on legitimate interests and withdraw consent where processing relies on it. You may object to direct marketing at any time.
Send questions or requests to sales@isosyote.fi. We may request proportionate information to verify your identity.
You may lodge a complaint with the Finnish Data Protection Ombudsman at https://tietosuoja.fi/en, or another competent supervisory authority.
9. Privacy contact
Email: sales@isosyote.fi
Website: https://www.laplandboutiqueresorts.fi