GDPR POLICY

 

Personal Data Protection law

Henkilötietolaki (523/99) 10 §

Applied since 20.04.2018



1. DATABASE HOLDER/REGISTRANT

Timetravels Incoming Ltd.

Mechelininkatu 10 A 4, 00100 Helsinki

customerservice@timetravels.fi



2. PERSON RESPONSIBLE OF THE DATABASE

Mikko Koistinen

Mechelininkatu 10 A 4, 00100 Helsinki

mikko.koistinen@timetravels.fi



3. NAME OF THE DATABASE

Customer database of Timetravels Ltd.



4. PURPOSE OF THE DATABASE

Database consists of customer information gathered through Timetravels Ltd.'s online reservation system for purchasing and arranging travel services. Customer information can be used in marketing purposes of Timetravels Ltd., but only with customer´s permission.

Customer information will be deleted from Timetravels customer database within reasonable period of time.

Information is collected also through Timetravels web pages and social media from people attending competitions or lotteries for conducting over mentioned events. Information collected will be deleted after the event is conducted (if not announced otherwise).

With customer´s permission, use of Timetravels online reservation system, web pages and social media pages can be monitored from time to time to survey and improve their functionality.



5. INFORMATION COLLECTED TO THE DATABASE AND UPDATING INFORMATION

Timetravels customer database collects the following information from customers: name, accommodation at destination, phone number and email address. Also purchase information will be collected (reservation date, travel date, payment information).

For surveying and improving Timetravels customer service the customer messages/conversations are documented. Information given by the customer, such as name, address, phone number, e-mail or other personal information may come up in these recordings and documentations, but they cannot be searched or identified from there.

Furthermore, Timetravels Ltd. holds seasonal photograph contests where customers are encouraged to take photographs at Timetravels' destination areas. These photographs, if submitted to Timetravels, are used in online promotional material on Timetravels' website and social media, and also in physical marketing material such as leaflets.



6. SOURCE OF INFORMATION

Information is collected directly from the customer when they register to Timetravels' reservation system, web pages or social media pages.



7. INFORMATION SUBMISSION

Information from customer database is submitted to service providers, such as, airlines, ferry or other transport companies and border officials, when necessary.  



8. INFORMATION SUBMISSION OUTSIDE EU

Information from customer database is submitted outside EU only to service providers or border officials, when necessary.



9. DATABASE SECURITY

Customer database of Timetravels is protected by standard technical means of protection. Database servers are secured by firewalls, anti-virus programs are used and database is protected by logins and passwords. Access to the database is given only to workers, whose position and work assignments require it. Database registers all actions conducted.



10. RIGHT OF ACCESS

Person registered in the online reservation system, web pages or social media pages of Timetravels Ltd. has a right to check what information is collected from him/her to Timetravels customer database. Customers should be prepared to prove their identity before receiving the information from Timetravels Ltd.



11. RIGHT OF CORRECTION

Persons registered in the online reservation system, web pages or social media pages of Timetravels Ltd. have a right to ask Timetravels to correct information collected from them in the Timetravels customer database.



12. RIGHT TO BE FORGOTTEN

Persons registered in the online reservation system, web pages or social media pages of Timetravels Ltd. have a right to ask their information to be removed from the Timetravels customer database. We will attempt to accommodate your request unless we are legally obligated to retain your information. Customers should be prepared to prove their identity before the request can be fulfilled.