Privacy Policy — Aarni Lapland
Last updated: 15 June 2026
1. Who we are
Aarni Lapland, a sole trader (private trader) registered in Finland ("Aarni Lapland", "we", "us", "our"), is the data controller for the personal data described in this policy.
- Business ID: 3631181-2
- Business address: Sairaalakatu 4 A 9, 96100 Rovaniemi
- Privacy contact (our main inbox): niko.killstrom@aarnilapland.com · +358 45 112 2331
We plan tailor-made trips to Finnish Lapland for travellers from abroad and, where you ask us to, make bookings in your name with local suppliers, whom you pay directly. This policy explains what personal data we collect, why, how we use and share it, and the rights you have. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (1050/2018).
We are a small business and are not required to appoint a Data Protection Officer; for any privacy matter, please use the contact above.
2. The personal data we collect
a) Information you give us through our website. When you contact us or send an enquiry through our website, we collect your name, email address and, optionally, your phone number. Our enquiry form also includes a free-text "special requests" field, where you can tell us about things such as anniversaries or other occasions, mobility needs, dietary needs, or the kind of experience you are dreaming of. You decide what to write there; if it includes health, dietary or accessibility details, please see clause 4.
b) Information you give us as we plan your trip (by email and other correspondence). Once we begin planning, we collect what we need to plan your trip and, for Aarni Full Journey, to make bookings in your name. This may include: the names and, where required by a supplier, the ages or dates of birth of everyone in your party; your contact details; your flight and arrival details; your preferences and special requests; and any dietary, accessibility, health or fitness information you choose to share so that suitable activities, meals and services can be arranged (see clause 4).
c) Payment information. You pay your travel-service providers directly; we do not collect, hold or process payments for your travel services. We do collect our own planning/service fee from you, through a secure invoice or payment link provided by our payment service provider, which processes that payment under its own privacy terms. We do not collect or store your card or bank details.
d) Information collected automatically (cookies and analytics). When you use our website, we and our analytics provider collect technical and usage information through cookies and similar technologies — for example the pages you view, the date and time, your approximate location, and your device and browser type. See clause 6 (Cookies).
3. Where your data comes from
We collect most data directly from you. If you book as the lead traveller for a group or family, you provide us with the personal data of the other travellers in your party. Please make sure they are aware of this policy; they have the same rights set out in clause 10. Where your party includes children, we process their data only as needed to plan and arrange the trip, and on the basis that the booking adult provides it.
4. Special category data (health, dietary and accessibility information)
Some of the information you may share with us — whether in the "special requests" field on our website or later by email — can be a special category of personal data under the GDPR. This includes anything that reveals a health condition, a mobility or accessibility need, an allergy, or a dietary requirement that may indicate your health or beliefs. We use it only to plan and arrange suitable parts of your trip (for example to recommend or book suitable activities or meals) and we share it with the relevant supplier only so far as necessary.
We process this information on the basis of your explicit consent, which you give by choosing to provide it to us for this purpose, and which you can withdraw at any time (clause 10). You do not have to give us this information, but without it we may be unable to arrange certain activities or services safely. Please do not share more sensitive information than your trip requires.
5. Why we use your data and our legal bases
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Respond to your enquiry and prepare a proposal/quotation | Name, email, phone; enquiry details | Steps taken at your request before a contract, and our legitimate interest in answering enquiries (Art. 6(1)(b) and (f)) |
| Plan your trip and, for Aarni Full Journey, make bookings in your name | All planning and traveller data | Performance of our contract with you (Art. 6(1)(b)) |
| Share details with the suppliers you will contract with | Names, dates, preferences and necessary requirements | Performance of the contract / our legitimate interest in delivering it (Art. 6(1)(b) and (f)) |
| Arrange suitable activities and meals from health, dietary or accessibility information | Special category data (clause 4) | Your explicit consent (Art. 9(2)(a)) |
| Keep accounting and tax records | Fee and correspondence records | Legal obligation (Art. 6(1)(c)) |
| Handle complaints and establish, exercise or defend legal claims; keep our website secure | Relevant data | Our legitimate interests (Art. 6(1)(f)) |
| Measure and improve our website using analytics | Cookie and usage data (clause 6) | Your consent (Art. 6(1)(a)) |
Providing the data needed to plan and arrange your trip is a requirement of using our service; if you do not provide it, we will not be able to plan or arrange your trip.
We do not make decisions that have a legal or similarly significant effect on you by solely automated means, and we do not use your data for profiling of that kind.
6. Cookies
Our website uses cookies and similar technologies. Cookies fall into two groups:
- Strictly necessary cookies, which are needed for the website to work. These do not require your consent.
- Analytics cookies, which we use only with your consent given through our cookie banner. We use Google Analytics (provided by Google) to understand how visitors use our site — for example which pages are viewed and for how long. Google Analytics collects this information through cookies and processes it on our behalf. According to Google's documentation, Google Analytics 4 does not log or store IP addresses.
You can give or withdraw your consent to non-essential cookies at any time through the cookie settings on our website, and you can block or delete cookies through your browser settings. Withdrawing consent does not affect any processing carried out before you withdrew it. More information on Google's handling of data is available in Google's own privacy and cookie policies.
7. Who we share your data with
We share your personal data only as needed to plan and arrange your trip, with:
- Travel-service suppliers — for example accommodation providers, activity and excursion operators, transfer companies and restaurants. For Aarni Full Journey we make bookings in your name with these suppliers, and you contract with them directly; we share only the details needed to make and hold those bookings. These suppliers are generally located in Finland or elsewhere in the European Economic Area (EEA).
- Service providers that process data on our behalf, such as our website platform (Squarespace), our email and IT service providers, our payment service provider (for our own fee), and our analytics provider (Google). These act on our instructions or under their own terms, with appropriate data-protection agreements in place.
- Public authorities, where we are required to share data by law.
We do not sell your personal data, and we do not use it for third-party advertising.
8. International transfers
Some of our service providers — including Google (analytics) and Squarespace (website) — are based in or may process data in the United States, and some of our other service providers may also process data outside the EEA. Where data is transferred outside the EEA, it is protected by appropriate safeguards: the EU–US Data Privacy Framework (an adequacy decision adopted by the European Commission) where the provider is certified under it, and/or the European Commission's Standard Contractual Clauses. If you would like details of the safeguards used for a particular provider, please contact us.
9. How long we keep your data
- Enquiries that do not lead to a booking: deleted within 12 months of our last contact.
- Planning and traveller data: kept for as long as needed to plan and arrange your trip and then for up to 3 years afterwards, to handle any complaints or claims, unless a longer period is required by law.
- Accounting and tax records: kept for at least 6 years from the end of the relevant accounting year, as required by the Finnish Accounting Act.
- Consent-based data (such as analytics): kept until you withdraw consent or in line with our analytics retention settings (up to 14 months).
When we no longer need your data, we delete or anonymise it securely.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- ask us to correct inaccurate or incomplete data;
- ask us to erase your data ("right to be forgotten") in certain circumstances;
- ask us to restrict or object to our processing in certain circumstances, including processing based on our legitimate interests;
- receive certain data in a portable format (data portability); and
- withdraw your consent at any time, where we rely on consent (for example for analytics cookies or special category data) — this does not affect processing carried out before withdrawal.
To exercise any of these rights, contact us using the details in clause 1. We will respond within one month (this may be extended for complex requests, in which case we will tell you). Exercising your rights is free of charge in normal cases.
11. Complaints
If you have a concern about how we handle your data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Finnish supervisory authority:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
If you live in another EU/EEA country, you may also contact the data protection authority where you live.
12. Security
We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access, and we require our service providers to do the same.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "last updated" date.
14. Contact
Questions about this policy or your data? Contact:
Aarni Lapland · Sole trader · Business ID 3631181-2 · Sairaalakatu 4 A 9, 96100 Rovaniemi · niko.killstrom@aarnilapland.com · +358 45 112 2331 · aarnilapland.com
