Privacy policy
Last updated 2 October 2026
This privacy policy describes how Gáldu Hotel & Spa processes the personal data of its guests and partners, in accordance with the EU General Data Protection Regulation (GDPR) and Finnish data protection legislation.
1. Controller
Gáldu Lapland Oy
Business ID 3433672-5
Viskitie 1, 99830 Saariselkä, Finland
contact@galdu.fi
For any question concerning your personal data, please contact us at contact@galdu.fi.
2. Personal data we process
- Basic details: name, address, email address, telephone number
- Booking details: arrival and departure dates, room type and special requests such as bed configuration
- Information required by the Finnish Accommodation and Catering Act: nationality, date of birth and identity document details, which accommodation businesses are required by law to collect
- Payment information. Card details are never stored in our own systems; they are processed directly by our payment provider.
- Activity and additional service bookings
- Correspondence between you and us, such as emails and messages
- For business customers: company details and contact person details
Health-related information
If you tell us about food allergies, dietary restrictions or a health condition relevant to your stay or to an activity, that information is classified as a special category of personal data under Article 9 of the GDPR. We process it only on the basis of your explicit consent, given when you provide it to us, and solely in order to serve you safely. You may withdraw that consent at any time, and we will delete the information unless we are required to retain it.
3. Why we process your data, and on what legal basis
- Delivering your booking and accommodation, and serving you during your stay — performance of a contract
- Invoicing and bookkeeping — legal obligation
- The traveller registration required of accommodation businesses — legal obligation
- Handling feedback and complaints — legitimate interest
- Allergies, dietary restrictions and other health information — explicit consent
- Marketing communications, where you have asked to receive them — consent
- Developing our services and keeping them secure — legitimate interest
4. Where the data comes from
Most of the data comes from you, when you make a booking through our website, by telephone or by email. We also receive booking data from the online travel agencies and tour operators we work with, such as Booking.com and Expedia, and from travel agents making bookings on your behalf.
5. Who we share data with
We use the following service providers, which process personal data on our behalf:
- Our property management system. We currently use Moder and will move to Mews from 29 October 2026.
- Stripe for card payments.
- FareHarbor and the independent activity providers themselves, when we reserve an excursion on your behalf. Your name and contact details are passed to the provider so that they can run the activity.
- Microsoft (Microsoft 365), where our email and internal booking records are held.
- Google (Google Analytics), for website statistics, as described in section 10.
- Our accounting firm.
- Authorities, where the law requires it, including the traveller registration.
We do not sell personal data, and we do not disclose it to third parties for their own marketing purposes.
6. Transfers outside the EU and EEA
Some of our service providers, including Google and Stripe, may process data outside the European Economic Area. Where that happens, the transfer is protected by appropriate safeguards, such as the European Commission’s standard contractual clauses or an adequacy decision.
7. How long we keep your data
We keep personal data only for as long as the purpose requires, or for as long as the law obliges us to:
- Accounting records: six years from the end of the financial year, as required by the Finnish Accounting Act.
- Traveller registration records: for the period required by the Accommodation and Catering Act, after which they are destroyed.
- Booking and guest history: for as long as needed to serve you and to handle any claims arising from the stay.
- Health-related information you have given us: deleted after your stay, unless you ask us to keep it for a future visit.
- Data processed on the basis of consent: until you withdraw that consent.
8. Your rights
You have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have your data erased, where the law does not require us to keep it
- restrict or object to the processing
- withdraw a consent you have given, at any time
- receive your data in a portable form
- lodge a complaint with the Office of the Data Protection Ombudsman in Finland, if you believe your data is being handled unlawfully
Requests can be sent to contact@galdu.fi. We may need to verify your identity before acting on a request.
9. Security
We protect personal data with appropriate technical and organisational measures against unauthorised access, loss and misuse. Access to guest data is limited to those members of staff who need it to do their work.
10. Cookies and website analytics
Our website, www.galdu.fi, uses cookies. Strictly necessary cookies keep the site working. Analytics cookies, through Google Analytics, help us understand how the site is used — which pages are read, how visitors arrive and where they leave.
Analytics and other non-essential cookies are set only after you have given your consent in the cookie banner. You can change or withdraw your choice at any time through the cookie settings on the site. Our consent management is provided by Cookiebot, and the detailed cookie declaration is shown there.
11. Automated decision-making
We do not use your personal data for automated decision-making or profiling that would produce legal effects for you.
12. Changes to this policy
We may update this privacy policy when our services or the systems we use change. The date of the latest update is shown at the top of the page.
13. Contact
Gáldu Hotel & Spa
Viskitie 1, 99830 Saariselkä, Finland
contact@galdu.fi
+358 400 250 838