Privacy Policy & Registration Statement


Privacy Policy & Registration Statement
Shillinki Hosting Oy (trading as Hosta) & Shillinki Rentals Oy
1.9.2026
REGISTERS
Shillinki Hosting Oy (Business ID 3388855-2), trading under the auxiliary business name Hosta
Shillinki Rentals Oy (Business ID 2889484-3)
MANAGING THE REGISTER
Tuomas Välimäki
hello@hosta.fi
NAME AND CONTENT OF THE REGISTER
Shillinki Hosting Oy’s & Shillinki Rentals Oy’s customer register (hereinafter “Customer Register”), covering guests, property owners, tenants and other counterparties as described below.
LEGAL FRAMEWORK
The processing of personal data described in this notice complies with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Finnish Data Protection Act (1050/2018), and other applicable Finnish and EU legislation on the processing of personal data.
CRITERIA FOR THE PROCESSING AND RECORDING OF PERSONAL DATA
General information
Purpose of collection and processing of personal data:
1. Contractual, customer or similar relationship
The purpose of the Customer Register is for the registrar to:
  • maintain a contractual or customer relationship with the other party to the transaction (e.g. a guest, a property owner, or — for Shillinki Rentals Oy’s long-term rental contracts — a tenant or lessor);
  • fulfil the service in relation to other parties involved (e.g. a member of the guest’s or tenant’s household);
  • carry out marketing communications the customer has authorised, e.g. by email, online, telemarketing or mail.
The Registrar may also collect information from other persons present in a managed property in order to prevent, monitor and investigate crime or misconduct, or to identify potential customer interest or establish a future customer relationship.
These persons are referred to in this document as a “Customer”.
2. Statutory anti-money-laundering control
Where applicable — including in relation to the management of owners’ rental income through the Registrar’s client funds account, and the identity and politically-exposed-person (PEP) verification carried out when a service agreement is signed — customer identification and other personal data are collected, stored and used pursuant to Chapter 3, Section 3 of the Act on the Prevention of Money Laundering and Terrorist Financing (444/2017), for the purpose of preventing and investigating money laundering and terrorist financing. Such data will not be used for any incompatible purpose.
3. Data storage based on consent
Where the processing described above does not apply, the Customer will be asked separately for consent to the storage and processing of their personal data, including for profiling of customer behaviour for marketing purposes where relevant.
If the Registrar does not receive the information described in this notice, the customer relationship may not be able to start or continue, and other agreements or proceedings involving the Customer may not be possible.
ROLES: CONTROLLER AND PROCESSOR
Where Shillinki Rentals Oy provides long-term rental services, it is itself the landlord toward its tenants and is the controller of tenants’ personal data in that relationship.
For Shillinki Hosting Oy’s (Hosta’s) co-hosting services, the property owner is the host toward guests. Shillinki Hosting Oy is never itself a party to, or in a direct contractual relationship with, the guest — it processes guest personal data as processor, on the property owner’s behalf, under a separate Data Processing Agreement available at hosta.fi/dpa.
For personal data relating to property owners themselves (identity verification, PEP screening, billing, contract administration), Shillinki Hosting Oy and Shillinki Rentals Oy are controllers, as described throughout this notice.
INFORMATION CONTAINED IN THE CUSTOMER REGISTER
Shillinki Hosting Oy and Shillinki Rentals Oy process information in their reservation/property management system (Hostaway), guest-experience and messaging platforms, and customer contact records. Depending on the nature of the relationship, this may include:
  • basic identification data: full name, address, language, date of birth
  • personal identity number or, for company representatives, business ID, where needed for reliable identification
  • billing and collection information, including bank account (IBAN)
  • for a corporate Customer, the beneficial owners’ names, dates of birth and nationalities
  • politically exposed person (PEP) status and international sanctions/freezing-list screening results, collected as part of Money Laundering Act identity verification
  • details of the contractual relationship: services used, dates of use, purchase/acceptance of services, and similar
  • marketing authorisations and prohibitions
  • information on customer interests
  • other transaction information relating to services provided
  • complaints and their handling
  • for long-term tenants, credit information relevant to assessing ability to pay rent
  • a copy of the Customer’s identity document (see Data Retention Periods below for the specific, shorter retention rule that applies to these copies)
  • other information provided by the Customer, or collected under the Money Laundering Act where applicable
  • for a foreign Customer without a Finnish personal identity code, citizenship and a copy of their travel document
DATA RETENTION PERIODS
Identity document / passport copies
Copies of a guest’s or customer’s identity document are deleted no later than 12 months after the end of the relevant stay or rental period, and typically earlier once they are no longer needed for check-in, safety or statutory registration purposes. This is a shorter, specific retention period that overrides the general period below for this category of data.
General customer data
All other information described above is retained for ten (10) years from the end of the service, lease or customer relationship, unless a shorter period is stated for a specific category of data in this notice.
Money Laundering Act data
Where applicable, data collected under the Money Laundering Act is retained for five (5) years, unless further retention is necessary to safeguard a criminal investigation, pending proceedings, or the rights of the controller or its employees. The need for further retention is reviewed no later than three (3) years after the previous review (444/2017, Section 4).
Other data
Other personal data is deleted once there is no longer a need to retain it. Where collection and storage was based solely on the Customer’s consent, the data is deleted at the Customer’s request.
REGULAR SOURCES OF INFORMATION
Personal data is collected from the data subject when they use, or plan to use, the Registrar’s services (e.g. booking a property or registering as a customer), including through contact forms, email enquiries, newsletter subscriptions, or customer satisfaction surveys. Data may also be collected or updated from the population register, other authority registers, and credit data registers.
DISCLOSURE OF INFORMATION AND SUBCONTRACTORS
Access to personal data is limited to those who need it to maintain the register or to carry out tasks related to the Registrar’s services. Personal data may be disclosed to authorities, service partners, and, in the event of a dispute, legal advisers, to the extent permitted by law.
Personal data may also be transferred outside the European Union / European Economic Area, including in connection with cloud services and outsourced staff — see “International Data Transfers” below for the specific safeguards that apply.
In connection with outsourcing of information management, personal data may be processed by the Registrar’s subcontractors, acting only on the Registrar’s behalf. Shillinki Hosting Oy’s and Shillinki Rentals Oy’s current subcontractors/processors include:
  • Hostaway (property management / channel manager) — https://www.hostaway.com/privacy-policy/
  • PriceLabs (dynamic pricing) — https://hello.pricelabs.co/privacy-policy/
  • EnsoConnect (guest experience / check-in) — https://ensoconnect.com/company/privacy-policy
  • Conduit (guest and owner messaging, AI knowledge-base chatbot) — https://conduit.psiphon.ca/fi/conduit-privacy-policy/
  • Pipedrive (CRM) — https://www.pipedrive.com/en/privacy
  • Fennoa (accounting and invoicing) — https://fennoa.com/tietosuojaseloste
  • Pacho (daily operations management) — https://pacho.io/privacy
  • Google Workspace (documents, drive, calendar, email) — https://workspace.google.com/intl/en/trust/
  • Notion (internal SOPs and operations records) — https://www.notion.so/privacy
  • Todoist (task tracking) — https://todoist.com/privacy
  • Framer (website hosting) — https://www.framer.com/legal/privacy-statement
INTERNATIONAL DATA TRANSFERS
Some of the Registrar’s staff and contracted personnel — including virtual assistants engaged as freelancers — are based outside the European Union / European Economic Area.
Where personal data is accessed from, or transferred to, a country outside the EU/EEA that the European Commission has not recognised as providing an adequate level of data protection, the transfer is safeguarded by the European Commission’s Standard Contractual Clauses (SCCs) under Article 46 GDPR, included in the relevant contractor/freelancer agreement, together with confidentiality obligations and role-based access limits.
Access for such personnel is limited by role: virtual assistants may access booking, communication, performance-related data, and — where necessary to carry out their assigned tasks, such as guest check-in verification — copies of identity documents. Access to accounting and ledger records (e.g. Fennoa) is not given to virtual assistants. All access is subject to confidentiality obligations and, where the assistant is based outside the EU/EEA, the Standard Contractual Clauses described above.
PRINCIPLES FOR THE PROTECTION OF THE REGISTER
Access to the register requires a user ID issued by the register administrator, who also determines each user’s access level. Only Registrar partners, employees and subcontractor personnel who need the data for their work have access to it. Data is stored electronically in databases protected by firewalls, passwords and other technical measures. Personal data containing a personal identity code is not sent by email or other unencrypted means without the data subject’s permission — such permission may be given, for example, as part of signing a service agreement with the Registrar.
CUSTOMER RIGHTS
1. Access, correction and data portability
The Customer may check what data about them is held in the Customer Register by submitting a written, signed request (including by email) to the controller. The Registrar will respond within 30 days.
The Customer is not entitled to inspect information collected to fulfil a Money Laundering Act reporting obligation (444/2017, Section 4:3), though the Data Protection Officer may, at the Customer’s request, verify that such processing is lawful.
The Customer has the right to receive their data in a structured, commonly used, machine-readable format for transfer to a third party. The controller retains a copy of the transferred data in accordance with this notice.
2. Correction of inaccurate data
The Customer has the right to have inaccurate personal data corrected.
3. Objection to, or restriction of, processing, and erasure
The Customer has the right to object to processing for direct marketing, remote marketing and other direct-marketing, market or opinion research, and business-development purposes, and to request restriction of processing already registered for those purposes.
4. Withdrawal of consent
Where processing is based on consent, the Customer may withdraw it at any time by contacting the controller. On request, all data that is not otherwise required to be retained by law will be deleted.
5. Exercising these rights
Requests for access, correction, objection or erasure should be sent to the contact details in this notice.
6. Complaints
If the Customer believes the Registrar has not complied with their request, they may lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
PROFILING AND AUTOMATED DECISION-MAKING
The Registrar does not make decisions producing legal effects or similarly significant effects concerning an individual based solely on automated processing. Dynamic pricing (via PriceLabs) is based on market and property-level data, not on individual customers’ personal data or behaviour.
As part of guest and tenant communication, the Registrar uses AI-assisted messaging tools (via Conduit) that can draft or send responses to routine guest/tenant enquiries based on the message content and available booking information. This assists, and does not replace, human customer service, and does not constitute automated decision-making about the individual within the meaning of Article 22 GDPR.
COOKIES AND WEBSITE ANALYTICS
hosta.fi does not use cookies to identify visitors. The site uses Framer’s built-in, cookieless site-analytics feature to understand aggregate visitor traffic, and stores the visitor’s selected display language in the browser’s local storage. No advertising or third-party tracking cookies are set.
CHANGES TO THIS NOTICE
This notice may be updated to reflect changes in the Registrar’s processing activities or in applicable law. The current version is dated at the top of this document.