This privacy policy explains how Fisafe Oy processes personal data on its website fisafe.fi and in related communications. The policy has been prepared in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (2016/679).
1. Data controller
Fisafe Oy
Business ID 3476646-9
Mestarintie 11, 01730 Vantaa
Phone 020 710 9174
sales@fisafe.fi
Fisafe Oy is part of the Fisplay Group.
2. Contact person for data protection matters
Tommi Sutinen, CEO
sales@fisafe.fi | 020 710 9174
All questions and requests regarding this privacy policy and the processing of your personal data can be directed to the contact information above.
3. Scope of the privacy statement
This statement applies to the personal data that we process when
• you use the fisafe.fi website
• you submit a contact request using the website's form
• you contact us by email or phone regarding sales or support
This privacy policy does not apply to personal data processed in the customer's access control system — for example, visitor access codes, staff access rights, or access events. In those cases, the data controller is Fisafe's customer and Fisafe acts as the data processor. See section 13.
4. Personal data processed
4.1 Contact Form
On the website at fisafe.fi/ota-yhteytta, we collect your name, email address, phone number, number of doors at the property, current booking system, and the content of your message. The name, email address, number of doors, booking system, and message content are mandatory; the phone number is optional.
The form also includes fields that are not visible to the user. These are used solely for automatic spam detection: no information is collected from the user in these fields, and if they are filled in, the submission is interpreted as being made by an automated bot. This is known as the honeypot technique.
4.2 Email and telephone contact
Contact information that you provide yourself, as well as the content of the communication.
4.3 Visitor Data
The website uses two different visitor tracking tools. They differ from each other substantially, and are therefore described separately.
Framer Visitor Statistics — does not require consent
The website platform's built-in statistics do not use cookies or any other identifier stored in the browser, and do not identify the visitor. The data collected includes the page opened, the referring website, rough location to country level, browser and device type, and the time of the visit. The data is compiled into statistics and is not combined with contact information.
Google Analytics 4
Google Analytics tracks pages opened and time spent on them, referring website or search engine, rough location at city or region level, browser, operating system and device type, session duration, and events on the site, such as form submissions. Data can be combined into visits from the same browser using a randomly generated identifier.
Google Analytics does not store the IP address. The address is only used to roughly determine location, after which it is discarded. We have not enabled Google signals or advertising features, so visitors are not tracked across devices and data is not combined with Google advertising profiles. We do not attempt to identify individual visitors from statistical data, nor do we combine it with contact details obtained through the contact form.
4.4 Server logs
The service provider responsible for the technical maintenance of the site records log data, which may include the IP address, timestamp, requested address, and browser identifier. Logs are used to maintain information security and to investigate disruptions.
5. Where the information is obtained from
All personal data we process is obtained from you directly or generated technically in connection with your use of the website. We do not buy, rent, or collect personal data from external sources.
6. Purpose and legal basis of processing
We process information received via the contact form, email, and telephone to respond to contacts and to prepare offers, based on legitimate interest and, regarding requests for offers, steps prior to entering into a contract. Managing the customer relationship and providing support are based on a contract. Framer's cookie-free statistics, as well as data security and the prevention of abuse, are based on legitimate interest. The use of Google Analytics is based on consent, and the storage of cookies is additionally governed by Section 205 of the Act on Electronic Communications Services. Accounting and statutory obligations are based on a legal obligation.
When processing is based on legitimate interest, we have assessed that the processing does not infringe upon the rights of the data subject: the data is minimal, the use is expected, and the processing is limited to the purposes described above. When processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. See section 7.
7. Cookies
A cookie is a small text file that a website stores on your browser.
Cookies used
The Google Analytics _ga cookie distinguishes visitors. Its duration is 2 years. The Google Analytics _ga_<id> cookie maintains session state. Its duration is 2 years.
You can delete cookies and prevent them from being saved in your browser settings. Blocking cookies may affect the functioning of the website.
8. Retention periods
Contacts that do not result in a customer relationship: 24 months from the contact.
Contacts and communication that led to a customer relationship: for the duration of the customer relationship and 24 months after its termination.
Accounting records: 6 years from the end of the financial year (Accounting Act 2:10).
Google Analytics event-level data: 14 months.
Google Analytics aggregated reports and Framer visitor statistics: stored in statistical form, no identifying information.
Server logs: period specified by the service provider, up to 12 months. Cookies: see the table in section 7.
We delete or anonymise data when the retention period expires or when the basis for processing ceases.
9. Recipients and processors
We do not sell or rent personal data. The data is processed on our behalf by the following service providers, with whom a data processing agreement has been concluded:
Framer B.V., Netherlands — website platform, content delivery and cookie-free visitor statistics.
Google Ireland Limited, Ireland — Google Workspace: email routing and storage. Google Analytics: visitor analytics.
Fisplay Oy and the Fisplay group companies — technical support and maintenance.
Google's processing is agreed upon in Google's Cloud Data Processing Addendum, which covers both Workspace and Analytics. Data may be disclosed to authorities if there is a legal obligation to do so.
10. Transfers outside the EU and EEA
The website is produced from servers located within the EU.
Our contract partner for both the email service and visitor analytics is Google Ireland Limited, located in the EU. However, Google may use sub-processors outside the EU and EEA in the provision of the services, including Google LLC in the United States. For these transfers, the safeguards in place are the standard contractual clauses approved by the European Commission as well as the EU-US Data Privacy Framework, under which Google LLC is certified.
For other service providers we use, any transfers outside the EU or EEA are based on an adequacy decision on data protection approved by the European Commission, the Commission's standard contractual clauses, or another safeguard in accordance with Chapter V of the General Data Protection Regulation.
11. Data protection
• The connection to the site is always encrypted (HTTPS, HSTS enforcement).
• Access to contacts and emails is restricted to those individuals who need the information for their duties.
• Access to analytics tools is restricted to designated individuals.
• User accounts are personal, and Google Workspace has two-factor authentication enabled.
• We do not maintain physical paper-based registers of personal data for the information covered by this statement.
• Service providers' data security is agreed upon in data processing agreements.
12. Your rights
According to the General Data Protection Regulation, you have the right to obtain confirmation as to whether or not personal data concerning you are being processed, and to receive a copy of the data; to rectify inaccurate or incomplete data; to request the erasure of data when there is no longer a legal basis for processing; to restrict processing when the conditions of the GDPR are met; to object to processing based on legitimate interest; to transmit the data from one system to another when the processing is based on consent or a contract and is automated; as well as to withdraw consent at any time. Regarding visitor analytics, this is most easily done from the website's cookie settings, see section 7.
Requests shall be addressed to the address mentioned in section 2. We may request you to verify your identity before fulfilling the request. We will respond within one month of receiving the request. If the request is complex, the deadline may be extended by up to two months, in which case we will inform you.
We do not make automated decisions or carry out profiling based on the data.
13. Access control service personal data
When Fisafe provides an access control service to a customer, personal data is processed in the system: access rights, access codes, and access events.
In these data, the controller is Fisafe's customer — for example, a hotel, a holiday village, or a property owner. The customer decides on the purposes and means of the processing. Fisafe acts as a personal data processor and processes the data only in accordance with the customer's documented instructions.
The processing is agreed with the customer in a data processing agreement in accordance with Article 28 of the General Data Protection Regulation, which defines the subject matter, duration, nature and purpose of the processing, the categories of personal data processed, the subprocessors, and the data security measures. The data used to provide the service is located in Finland.
If you are a guest or employee of an accommodation facility and want to know how access data concerning you is processed, please contact the facility in question. It is the controller of the data and is responsible for fulfilling the data subject's rights. We will forward the request to our customer if necessary.
14. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data violates the General Data Protection Regulation (GDPR), you can file a complaint with the supervisory authority:
Office of the Data Protection Ombudsman
P.O. Box 800, FI-00531 Helsinki
Street address: Lintulahdenkuja 4, FI-00530 Helsinki
Telephone: +358 29 566 6700
tietosuoja@om.fi
tietosuoja.fi
We hope you will contact us first — most matters are resolved more quickly directly.
15. Changes to this statement
We are constantly developing our service, and the notice may change. The up-to-date version is always available at fisafe.fi/tietosuoja. We will inform you of material changes on the website.
This version was updated on 1 September 2026.