Privacy Policy

This is the GoPark.fi website's registration and privacy policy in accordance with the Personal Data Act and the EU General Data Protection Regulation (GDPR).

Last updated on July 4, 2026.

REGISTRAR

Name: Viasetti Oy
Business ID: 1068186-6
Address: Kangassaarentie 14, 37800 Akaa

The contact person for the data controller is Mikko Lammasaitta, info@gopark.fi, tel. 0400 881 999

REGISTER NAME

GoPark.fi's customer and marketing register.

PURPOSE OF PROCESSING PERSONAL DATA

We process personal data for the following purposes:

  • Processing accommodation reservations and customer relationship management
  • Fulfilling the statutory passenger notification obligation (Act 308/2006 on Accommodation and Catering Activities)
  • Processing, shipping and invoicing of online store orders
  • Sending a newsletter to subscribers
  • Responding to messages from customers
  • Analysis of website activity and usage (cookies)
  • Fulfilling legal obligations (including accounting)

BASIS FOR PROCESSING PERSONAL DATA 

We process personal data on the following grounds:

  • Fulfilling contractual obligations, including accommodation reservations and online shopping purchases
  • Fulfilling legal obligations, including passenger declaration and accounting
  • Consent of the interested party, including newsletters and website analytics and marketing cookies
  • The legitimate interest of the controller, including essential cookies on websites and the use of passenger data for customer service and direct marketing

REGISTER INFORMATION CONTENT

The information stored in the register includes: the person's name, contact information (telephone number, email address, address), information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services. Data is only kept for as long as necessary.

REGULAR INFORMATION SOURCES

The information stored in the register is obtained from the customer. when making a reservation, order, newsletter subscription or contact us or through website cookies and analytics tools.

ROUTINE DATA TRANSFERS AND DATA TRANSFER OUTSIDE THE EU OR EEA

The information is not routinely disclosed to other parties. The information is not disclosed to external parties for marketing purposes without consent. The information may be published to the extent agreed with the customer.

Data may be transferred by the controller outside the EU or EEA. The transfer of personal data outside the European Union or the European Economic Area is always based on the applicable legislation on the processing of personal data and is carried out in accordance with that legislation. 

PRINCIPLES OF REGISTER PROTECTION

The register is handled with care and the data processed by the information systems are protected appropriately. When the register data is stored on Internet servers, the physical and digital security of their equipment is appropriately ensured. The controller ensures that the stored data, as well as the access rights to the servers and other information critical to the security of personal data, are handled confidentially and only by employees whose job description requires it.

RIGHTS OF THE DATA SUBJECT

Every person in the register has the right to check their data stored in the register, to demand the correction of any incorrect data or the completion of any incomplete data, and to request the deletion of their data, unless this is prevented by statutory obligations. Data subjects also have other rights. Rights under the EU General Data Protection Regulation, such as restricting the processing of personal data in certain situations.

If a person wishes to check the information stored about them or to request a correction, the request must be sent in writing to the controller. The controller may, if necessary, ask the person making the request to prove their identity. The controller will respond to the customer within the time period set out in the EU Data Protection Regulation (generally within one month).

Note! The mandatory passenger notification and the collection and processing of related information under the Accommodation and Catering Act cannot be objected to, nor can the deletion of the information be requested within the retention period required by law (1 year), as the processing is based on a statutory obligation. Instead, the passenger can at any time prohibit the use of their information for customer service and direct marketing.

CHANGES TO THIS DISCLOSURE

This privacy policy may be updated as necessary, for example, due to changes in legislation or the development of the company's business. The latest update date is shown at the beginning of the policy.

Shopping Cart
Scroll to Top