Privacy Policy
Last updated: June 2025
This Privacy Policy describes how collects, uses, stores, and protects your personal data when you visit or use our website vorovihotelhaven.com or interact with our hotel and casino services. We are committed to protecting your privacy and processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the Finnish Data Protection Act (1050/2018), and other applicable data protection legislation.
Please read this Privacy Policy carefully before using our services. By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The data controller responsible for your personal data is:
| Company Name | |
|---|---|
| Registration Country | Finland (Suomi) |
| Business ID (Y-tunnus) | 3647185-2 |
| VAT Number | FI36471852 |
| Registered Address | Satamakatu 9 B, 33200 Tampere, Finland |
| Website | vorovihotelhaven.com |
| Privacy Contact Email | info@vorovihotelhaven.com |
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our data protection practices and ensure compliance with applicable data protection legislation. You may contact our DPO for any questions or concerns relating to the processing of your personal data or the exercise of your rights.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | Satamakatu 9 B, 33200 Tampere, Finland |
| info@vorovihotelhaven.com |
3. Personal Data We Collect
Depending on how you interact with Vorovi Hotel Haven, we may collect and process the following categories of personal data:
3.1 Identification and Contact Data
- Full name
- Date of birth
- Gender
- Nationality and country of residence
- Passport, national identity card, or other government-issued identification number (required by Finnish law for hotel registration)
- Postal address (home or billing address)
- Email address
- Telephone number
3.2 Reservation and Stay Data
- Booking reference numbers and reservation history
- Check-in and check-out dates
- Room type and preferences (e.g., accessibility requirements, dietary requirements)
- Number and details of accompanying guests
- Special requests and service preferences
- Loyalty programme membership number and activity
3.3 Payment and Financial Data
- Payment card type (e.g., Visa, Mastercard) and masked card number (last four digits)
- Billing address associated with payment method
- Invoice and receipt data
- Transaction identifiers and payment confirmation references
Full payment card details are processed exclusively by our certified payment service provider and are not stored on our own systems.
3.4 Casino and Gaming Data
In connection with our casino operations, we are required by Finnish law and anti-money laundering (AML) regulations to collect and retain additional personal data, including:
- Government-issued identification documents verified at casino entry
- Gaming activity records, including visit dates, time spent, and gaming history
- Transaction records related to cash exchanges, buy-ins, and pay-outs
- Self-exclusion status and responsible gambling declarations
- Data collected in fulfilment of obligations under the Finnish Lotteries Act (Arpajaislaki 1047/2001) and AML legislation
3.5 Website and Technical Data
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Pages visited, click paths, and time spent on pages
- Referral URLs
- Cookie identifiers and similar tracking technologies (see our Cookie Policy for further details)
3.6 Communications Data
- Content of emails, messages, or correspondence sent to us
- Records of telephone calls where legally permitted and where you have been notified
- Customer service interaction logs and complaint records
- Survey and feedback responses
3.7 Marketing and Preferences Data
- Marketing communication preferences and opt-in/opt-out records
- Interests and preferences inferred from your interactions with our services
- Participation in competitions, promotions, or loyalty schemes
3.8 Special Categories of Personal Data
We generally do not seek to collect special categories of personal data (sensitive data) as defined under Article 9 GDPR. However, where you voluntarily provide information relating to health or disability (for example, accessibility requirements or dietary needs for medical reasons), we will process such data solely on the basis of your explicit consent and only to the extent necessary to fulfil your request. You are under no obligation to provide this information.
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so under Article 6 of the GDPR. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
When you make a reservation, stay at our hotel, or use our casino or other services, we process your personal data to the extent necessary to perform the contract with you or to take steps at your request prior to entering into a contract. This includes:
- Processing your booking and managing your reservation
- Providing accommodation, dining, casino, and other on-site services
- Processing payments and issuing invoices
- Managing loyalty programme membership and rewards
- Communicating with you about your booking or stay
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We are subject to various legal obligations that require us to process certain personal data. These include:
- Guest registration obligations under Finnish law (Act on Accommodation and Catering Operations, 308/2006), which require us to collect and retain identification data for all guests
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations arising from the Finnish Act on Preventing Money Laundering and Terrorist Financing (444/2017) and related EU directives, applicable to our casino operations
- Obligations under the Finnish Lotteries Act (1047/2001), including identity verification and responsible gambling requirements
- Tax and accounting obligations under Finnish law
- Obligations to respond to lawful requests from competent public authorities
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
Where it does not override your rights and freedoms, we may process your personal data on the basis of our legitimate interests, including:
- Ensuring the security of our premises, guests, staff, and property (including CCTV surveillance in public areas, subject to appropriate notices)
- Preventing, detecting, and investigating fraud, theft, or other unlawful activity on our premises
- Improving and developing our services and website based on usage patterns and feedback
- Managing and protecting our IT systems and network security
- Sending direct marketing communications to existing customers about similar services (subject to your right to object at any time)
- Handling and resolving complaints and disputes
- Conducting internal business analytics, reporting, and planning
When we rely on legitimate interests, we carry out a balancing test to ensure that our interests are not overridden by your rights and interests. You have the right to object to processing based on legitimate interests at any time (see Section 8).
4.4 Consent (Article 6(1)(a) GDPR)
In certain circumstances, we will ask for your explicit, freely given, specific, informed, and unambiguous consent before processing your personal data. This applies to:
- Sending you marketing communications where you are not an existing customer
- Placing non-essential cookies and similar tracking technologies on your device
- Processing special categories of personal data (e.g., health information you voluntarily share for accessibility or dietary reasons)
- Any other processing activities for which we expressly seek your consent
Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before your withdrawal. To withdraw consent, please contact us at info@vorovihotelhaven.com or use the unsubscribe link in any marketing email.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data to protect your vital interests or those of another natural person — for example, in a medical emergency occurring on our premises. This legal basis will only be relied upon where it is not possible to rely on another legal basis and where processing is strictly necessary to protect life.
4.6 Public Task (Article 6(1)(e) GDPR)
This legal basis is not routinely relied upon by us in the course of our normal operations. However, where we act in collaboration with public authorities in the performance of a task carried out in the public interest, this basis may apply to the extent required by applicable law.
5. How We Use Your Personal Data
We use your personal data for the following purposes:
5.1 Provision of Hotel and Casino Services
- Processing and confirming reservations and bookings
- Managing check-in and check-out procedures
- Providing room service, dining, spa, casino, and other on-site services
- Fulfilling special requests and accommodating preferences
- Processing payments and managing billing
5.2 Guest Registration and Legal Compliance
- Maintaining mandatory guest registration records as required by Finnish law
- Verifying identity for casino access and gaming activities
- Fulfilling AML/CTF obligations
- Cooperating with law enforcement and regulatory authorities when lawfully required
5.3 Customer Communications
- Sending booking confirmations, pre-arrival information, and post-stay follow-up
- Responding to enquiries, complaints, and requests
- Notifying you of changes to bookings or services
5.4 Marketing and Personalisation
- Sending promotional offers, newsletters, and event invitations where you have consented or where we have a legitimate interest to do so
- Personalising your experience on our website and during your stay based on your preferences and history
- Administering loyalty programmes and rewards schemes
5.5 Security and Safety
- Operating CCTV and access control systems to protect guests and staff
- Investigating incidents, security breaches, or suspected unlawful activity
- Implementing responsible gambling measures, including enforcing self-exclusion requests
5.6 Website Operation and Improvement
- Operating and maintaining our website and digital services
- Analysing website usage to improve user experience
- Managing cookies and tracking technologies in accordance with your preferences
- Preventing and detecting fraud and cyber attacks
5.7 Business Administration
- Maintaining internal records, accounts, and business administration
- Conducting audits, assessments, and quality control
- Managing legal claims and disputes
- Complying with insurance obligations
6. Sharing Your Personal Data
We do not sell your personal data to third parties. We may share your personal data with third parties only in the following circumstances and to the extent strictly necessary:
6.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf as data processors, bound by data processing agreements in accordance with Article 28 GDPR. These include:
- Payment processing and card transaction service providers
- IT infrastructure, hosting, and cloud service providers
- Reservation and property management system (PMS) providers
- Email marketing and customer relationship management (CRM) platforms
- Website analytics providers
- Security and CCTV monitoring service providers
- Accounting, audit, and legal service firms
6.2 Public Authorities and Regulatory Bodies
We may disclose your personal data to competent public authorities where we are required to do so by law or in response to a lawful request. This includes:
- The Finnish Police (Poliisi) for guest registration and security purposes
- The Finnish Financial Intelligence Unit (Rahanpesun selvittelykeskus) in fulfilment of AML/CTF reporting obligations
- The Finnish Tax Administration (Verohallinto) for tax compliance purposes
- The National Police Board of Finland (Poliisihallitus) in connection with casino licensing and supervision
- Other regulatory authorities as required by applicable law
6.3 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of all or part of our business assets, your personal data may be transferred to the relevant third party as part of that transaction. We will take reasonable steps to ensure that your data remains protected and that you are notified of any such transfer where required by law.
6.4 Professional Advisers
We may share personal data with lawyers, accountants, insurers, and other professional advisers where necessary to obtain professional advice or to manage legal claims, subject to obligations of confidentiality.
6.5 With Your Consent
We may share your personal data with other third parties where you have given us your explicit consent to do so.
7. International Transfers of Personal Data
We are based in Finland and primarily process your personal data within the European Economic Area (EEA). However, some of our third-party service providers may be located outside the EEA or may process personal data on servers located outside the EEA.
Where personal data is transferred to a country outside the EEA, we ensure that appropriate safeguards are in place to protect your data in accordance with GDPR Chapter V. Such safeguards may include:
- Transfers to countries that have received an adequacy decision from the European Commission
- The use of Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (BCRs) where applicable
- Other appropriate safeguards as permitted under Article 46 GDPR
You may request a copy of the safeguards in place for international transfers by contacting us at info@vorovihotelhaven.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following retention periods generally apply:
| Category of Personal Data | Retention Period | Basis |
|---|---|---|
| Guest registration records (hotel) | 1 year from date of departure | Finnish law (Act on Accommodation and Catering Operations) |
| Casino identity verification records | 5 years from the date of the relevant transaction or business relationship | Finnish AML legislation (444/2017); Lotteries Act |
| Financial and accounting records (invoices, payments) | 7 years from the end of the relevant financial year | Finnish Accounting Act (1336/1997) |
| Reservation and booking data | 3 years from date of check-out | Legitimate interests; statutory limitation periods |
| Marketing preferences and communications | Until you withdraw consent or object; records of opt-outs retained indefinitely to honour preferences | Consent; legitimate interests |
| Website cookies and analytics data | As specified in our Cookie Policy (typically up to 24 months) | Consent; legitimate interests |
| CCTV footage | Up to 30 days unless retained for an ongoing security or legal matter | Legitimate interests; legal obligation |
| Customer service and complaint records | 3 years from resolution of the matter | Legitimate interests; statutory limitation periods |
| Self-exclusion and responsible gambling records | Duration of the self-exclusion period plus 5 years | Legal obligation; legitimate interests |
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised so that it can no longer be associated with an identified or identifiable individual. Where data is retained beyond these periods due to an ongoing legal claim, regulatory investigation, or dispute, it will be retained only for as long as necessary to resolve such matter.
9. Your Rights Under GDPR
As a data subject, you have the following rights in relation to your personal data under the GDPR and Finnish data protection law. We aim to respond to all valid requests within one month of receipt. This period may be extended by a further two months where requests are complex or numerous, in which case we will notify you accordingly.
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that data together with information about the purposes of processing, the categories of data processed, recipients, retention periods, and your other rights.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete personal data completed.
9.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where you withdraw consent (and there is no other legal basis for processing), or where processing is unlawful. This right is subject to limitations where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data, where processing is unlawful but you prefer restriction to erasure, or where we no longer need the data but you require it for a legal claim.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit that data directly to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests (Article 6(1)(f)) or where processing is for direct marketing purposes. Where you object to processing for direct marketing, we will cease processing your data for that purpose without further assessment. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for legal claims.
9.7 Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at info@vorovihotelhaven.com or use the unsubscribe link in any marketing communication.
9.8 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects or similarly significantly affects you. We do not currently make solely automated decisions that produce legal effects. Where any such processing is introduced in the future, we will inform you and provide you with an opportunity to request human review, express your point of view, and contest the decision.
9.9 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to:
- Email: info@vorovihotelhaven.com
- Post: The Data Protection Officer, , Satamakatu 9 B, 33200 Tampere, Finland
We may ask you to verify your identity before responding to your request. This is to ensure that personal data is not disclosed to or amended on behalf of unauthorised individuals. We will respond to your request free of charge. However, we may charge a reasonable fee if your request is manifestly unfounded or excessive, or if you request further copies of data already provided.
11. Security of Your Personal Data
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 GDPR. These measures include:
- Encryption of data in transit using TLS/SSL protocols
- Encryption of sensitive data at rest
- Access controls and authentication measures limiting access to personal data to authorised personnel only
- Regular security assessments and penetration testing
- Staff training on data protection and information security
- Secure disposal and destruction procedures for data and physical media
- Data breach detection, response, and notification procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) without undue delay and, where required, no later than 72 hours after becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
12. Third-Party Links
Our website may contain links to third-party websites, plug-ins, or services. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit when you leave our website.
13. Children and Minors
Our casino services are strictly available only to individuals who are 18 years of age or older, in accordance with Finnish law. We do not knowingly collect personal data from individuals under the age of 18 in connection with casino activities. Our website is not directed to children. If we become aware that we have inadvertently collected personal data from a child under the age of 18 without appropriate parental consent where required, we will take steps to delete such data promptly. If you believe that we may have collected personal data from a minor, please contact us at info@vorovihotelhaven.com.
15. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable legislation, or our services. We will publish any updated version on this page with a revised "Last updated" date. Where changes are significant, we will provide you with a more prominent notice (for example, by email or a prominent notice on our website). We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data.
16. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please do not hesitate to contact us:
| Company | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Address | Satamakatu 9 B, 33200 Tampere, Finland |
| info@vorovihotelhaven.com | |
| Website | vorovihotelhaven.com |