Privacy Policy & Registration Statement
Privacy Policy & Registration Statement
Shillinki Hosting Oy (trading as Hosta) & Shillinki Rentals Oy
1.9.2026
REGISTERS
Shillinki Hosting Oy (Business ID 3388855-2), trading under the auxiliary business name Hosta
Shillinki Rentals Oy (Business ID 2889484-3)
MANAGING THE REGISTER
Tuomas Välimäki
hello@hosta.fi
NAME AND CONTENT OF THE REGISTER
Shillinki Hosting Oy’s & Shillinki Rentals Oy’s customer register (hereinafter “Customer Register”), covering guests, property owners, tenants and other counterparties as described below.
LEGAL FRAMEWORK
The processing of personal data described in this notice complies with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Finnish Data Protection Act (1050/2018), and other applicable Finnish and EU legislation on the processing of personal data.
CRITERIA FOR THE PROCESSING AND RECORDING OF PERSONAL DATA
General information
Purpose of collection and processing of personal data:
1. Contractual, customer or similar relationship
The purpose of the Customer Register is for the registrar to:
maintain a contractual or customer relationship with the other party to the transaction (e.g. a guest, a property owner, or — for Shillinki Rentals Oy’s long-term rental contracts — a tenant or lessor);
fulfil the service in relation to other parties involved (e.g. a member of the guest’s or tenant’s household);
carry out marketing communications the customer has authorised, e.g. by email, online, telemarketing or mail.
The Registrar may also collect information from other persons present in a managed property in order to prevent, monitor and investigate crime or misconduct, or to identify potential customer interest or establish a future customer relationship.
These persons are referred to in this document as a “Customer”.
2. Statutory anti-money-laundering control
Where applicable — including in relation to the management of owners’ rental income through the Registrar’s client funds account, and the identity and politically-exposed-person (PEP) verification carried out when a service agreement is signed — customer identification and other personal data are collected, stored and used pursuant to Chapter 3, Section 3 of the Act on the Prevention of Money Laundering and Terrorist Financing (444/2017), for the purpose of preventing and investigating money laundering and terrorist financing. Such data will not be used for any incompatible purpose.
3. Data storage based on consent
Where the processing described above does not apply, the Customer will be asked separately for consent to the storage and processing of their personal data, including for profiling of customer behaviour for marketing purposes where relevant.
If the Registrar does not receive the information described in this notice, the customer relationship may not be able to start or continue, and other agreements or proceedings involving the Customer may not be possible.
ROLES: CONTROLLER AND PROCESSOR
Where Shillinki Rentals Oy provides long-term rental services, it is itself the landlord toward its tenants and is the controller of tenants’ personal data in that relationship.
For Shillinki Hosting Oy’s (Hosta’s) co-hosting services, the property owner is the host toward guests. Shillinki Hosting Oy is never itself a party to, or in a direct contractual relationship with, the guest — it processes guest personal data as processor, on the property owner’s behalf, under a separate Data Processing Agreement available at hosta.fi/dpa.
For personal data relating to property owners themselves (identity verification, PEP screening, billing, contract administration), Shillinki Hosting Oy and Shillinki Rentals Oy are controllers, as described throughout this notice.
INFORMATION CONTAINED IN THE CUSTOMER REGISTER
Shillinki Hosting Oy and Shillinki Rentals Oy process information in their reservation/property management system (Hostaway), guest-experience and messaging platforms, and customer contact records. Depending on the nature of the relationship, this may include:
basic identification data: full name, address, language, date of birth
personal identity number or, for company representatives, business ID, where needed for reliable identification
billing and collection information, including bank account (IBAN)
for a corporate Customer, the beneficial owners’ names, dates of birth and nationalities
politically exposed person (PEP) status and international sanctions/freezing-list screening results, collected as part of Money Laundering Act identity verification
details of the contractual relationship: services used, dates of use, purchase/acceptance of services, and similar
marketing authorisations and prohibitions
information on customer interests
other transaction information relating to services provided
complaints and their handling
for long-term tenants, credit information relevant to assessing ability to pay rent
a copy of the Customer’s identity document (see Data Retention Periods below for the specific, shorter retention rule that applies to these copies)
other information provided by the Customer, or collected under the Money Laundering Act where applicable
for a foreign Customer without a Finnish personal identity code, citizenship and a copy of their travel document
DATA RETENTION PERIODS
Identity document / passport copies
Copies of a guest’s or customer’s identity document are deleted no later than 12 months after the end of the relevant stay or rental period, and typically earlier once they are no longer needed for check-in, safety or statutory registration purposes. This is a shorter, specific retention period that overrides the general period below for this category of data.
General customer data
All other information described above is retained for ten (10) years from the end of the service, lease or customer relationship, unless a shorter period is stated for a specific category of data in this notice.
Money Laundering Act data
Where applicable, data collected under the Money Laundering Act is retained for five (5) years, unless further retention is necessary to safeguard a criminal investigation, pending proceedings, or the rights of the controller or its employees. The need for further retention is reviewed no later than three (3) years after the previous review (444/2017, Section 4).
Other data
Other personal data is deleted once there is no longer a need to retain it. Where collection and storage was based solely on the Customer’s consent, the data is deleted at the Customer’s request.
REGULAR SOURCES OF INFORMATION
Personal data is collected from the data subject when they use, or plan to use, the Registrar’s services (e.g. booking a property or registering as a customer), including through contact forms, email enquiries, newsletter subscriptions, or customer satisfaction surveys. Data may also be collected or updated from the population register, other authority registers, and credit data registers.
DISCLOSURE OF INFORMATION AND SUBCONTRACTORS
Access to personal data is limited to those who need it to maintain the register or to carry out tasks related to the Registrar’s services. Personal data may be disclosed to authorities, service partners, and, in the event of a dispute, legal advisers, to the extent permitted by law.
Personal data may also be transferred outside the European Union / European Economic Area, including in connection with cloud services and outsourced staff — see “International Data Transfers” below for the specific safeguards that apply.
In connection with outsourcing of information management, personal data may be processed by the Registrar’s subcontractors, acting only on the Registrar’s behalf. Shillinki Hosting Oy’s and Shillinki Rentals Oy’s current subcontractors/processors include:
Hostaway (property management / channel manager) — https://www.hostaway.com/privacy-policy/
PriceLabs (dynamic pricing) — https://hello.pricelabs.co/privacy-policy/
EnsoConnect (guest experience / check-in) — https://ensoconnect.com/company/privacy-policy
Conduit (guest and owner messaging, AI knowledge-base chatbot) — https://conduit.psiphon.ca/fi/conduit-privacy-policy/
Pipedrive (CRM) — https://www.pipedrive.com/en/privacy
Fennoa (accounting and invoicing) — https://fennoa.com/tietosuojaseloste
Pacho (daily operations management) — https://pacho.io/privacy
Google Workspace (documents, drive, calendar, email) — https://workspace.google.com/intl/en/trust/
Notion (internal SOPs and operations records) — https://www.notion.so/privacy
Todoist (task tracking) — https://todoist.com/privacy
Framer (website hosting) — https://www.framer.com/legal/privacy-statement