AcademyHotel

Policies

Privacy Policy

Temporary draft placeholder — authorized for interim online booking use. Not final legal copy. Last updated 27 August 2026.

This interim notice explains how personal data is handled when you visit the Academy Hotel website, contact us or make a booking.

1. Data controller

The data controller is Kemijärvi Insider Oy(Business ID 3522178-6, VAT ID FI35221786), Korkalonkatu 36 L 1, 96200 Rovaniemi, Finland. The hotel address is Seminaarinkatu 9, 98120 Kemijärvi. General booking enquiries can be sent to info@academyhotel.com.

2. Data we process

  • Booking and guest details, such as names, contact details, dates, party composition, room and service selections, and special requests you choose to provide.
  • Booking, payment and fulfilment records, including totals, transaction status and provider references. Academy Hotel does not receive your full payment-card number.
  • Messages sent through the contact form or directly to the hotel, together with the information needed to answer them.
  • Essential technical and security data, including booking-session cookies, timestamps, request records and information needed to prevent duplicate or fraudulent transactions.

Please do not place unnecessary health, identity-document or other sensitive information in a free-text field. If an activity supplier requires such information, it is requested only for that activity and handled under the supplier's displayed requirements.

3. Why we use the data

  • To search availability, create and administer a booking, collect payment, provide the stay and communicate arrival information. The legal basis is performing the booking contract or taking steps at your request before entering it.
  • To keep statutory accommodation, accounting and tax records. The legal basis is compliance with legal obligations.
  • To answer enquiries, protect the booking service, prevent abuse, recover interrupted payments and resolve complaints. The legal basis is our legitimate interest in operating a reliable service and protecting guests and the business.

4. Systems and recipients

We disclose only the data needed for the relevant service. Nitesoft processes hotel availability, reservations and the hotel payment flow. Bókun and the selected activity supplier process an optional activity request or booking. Hosting, database, email, security and payment service providers may process data for us under contractual confidentiality and data-protection duties. Authorities receive data only where the law requires it.

If a service provider processes data outside the European Economic Area, we require an applicable lawful transfer mechanism and safeguards. A guest can ask us for current information about the processors and transfer safeguards relevant to their booking.

5. Retention

Booking, payment and accounting records are retained for the periods required by Finnish law. Operational booking details and correspondence are kept only as long as needed to provide the stay, handle claims and meet those obligations. Short-lived booking and security records are removed or anonymised when they are no longer needed for those purposes.

6. Your rights

Subject to the conditions in data-protection law, you may request access to your data, correction, deletion, restriction of processing or data portability, and may object to processing based on legitimate interests. You may also ask for information about the source, recipients and retention of your data. We may need to verify your identity before acting on a request.

Until a dedicated privacy email address is published, send a written privacy request to Kemijärvi Insider Oy, Korkalonkatu 36 L 1, 96200 Rovaniemi, Finland. You also have the right to lodge a complaint with the Office of the Data Protection Ombudsman in Finland.

7. Cookies and security

The booking flow uses essential cookies to bind the browser to its live room hold, preserve checkout integrity and recover a confirmed payment safely. These cookies are not used for advertising. We use access controls, limited data exposure and provider-side security measures appropriate to the service, but no internet service can be guaranteed completely risk-free.

8. Changes and booking terms

We will replace this temporary draft with reviewed final copy and update the date above. Material changes will apply prospectively unless law requires otherwise. See the Booking Terms & House Rules for the contract and stay rules.