Privacy Notice
This notice describes what personal data we process in Rentsa's boat trip booking service, on what basis and for how long, and how you can exercise your rights. This notice has been prepared in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (2016/679, "GDPR") and the Finnish Data Protection Act (1050/2018).
- Version
- 1.0
- Last updated
- 31 July 2026
1.Data controller and contact details
The data controller is responsible for how your personal data is processed for the purposes described in this notice.
- Data controller
- Patakymppi Oy (auxiliary trade name/service: Rentsa)
- Business ID
- 3255077-9
- Visiting address
- c/o Tilitoimisto Ekomia Oy, Oppilaankatu 4, 53100 Lappeenranta, Finland
- info@rentsa.fi
- Data protection contact person
- Marko, Skipper, reachable at info@rentsa.fi
- Data Protection Officer
- Our operations do not require the appointment of a Data Protection Officer under Article 37 of the GDPR, as we do not carry out large-scale regular monitoring or large-scale processing of special categories of personal data. For data protection matters, you can contact the contact person mentioned above.
2.Name of the register
Rentsa's customer and booking register.
The register contains personal data related to booking boat trips, carrying out the rental agreement, safely conducting the trips, and customer service.
3.What personal data is collected
We only process data that is necessary to fulfil the booking and to ensure the safety of the trip. The data is mostly obtained from you directly through the booking form; technical log data is generated automatically when the service is used.
Booking data
- booking number and booking status
- the selected trip, departure location, date, departure time, and duration
- number of passengers, including adults and children
- the selected equipment level
- a description of your own route plan, if you provide one
- acceptance of the rental agreement and the time of acceptance
Contact details
- first and last name
- email address
- phone number
- any marketing consent and the time it was given
Payment-related data
- the booking price, any add-ons, and VAT
- payment status, payment method, and the time of payment
- invoicing and accounting records
- We do not process payment card numbers or bank credentials. Payment card and online payment data is processed by our payment service provider, SumUp, in its own system.
Customer service data
- communication related to the booking conducted by email or phone
- notes on booking changes, cancellations, and weather reservations
- feedback and complaints and their handling
Technical log data
- a hashed IP address and a hashed email address, used to prevent misuse
- browser identification information (user agent) and the time of the booking request
- the log of the booking path's risk assessment: the outcome of the assessment and the reasons behind it
- the sending log of emails sent by the system and any error messages
- single-use confirmation tokens for email confirmation
Experience survey data
In the experience survey, we only ask for information that is essential for safety, so that we can assess whether the boat can be handed over safely and what equipment is needed for the trip:
- swimming ability
- weight class, for correctly sizing life jackets
- an assessment of whether passengers can safely board a low-freeboard boat
- boating experience, engine handling skills, and navigation skills
- answers related to safety awareness, such as assessing weather and acting in exceptional situations
- a score calculated from the answers by category, as well as a summary of the answers recorded in connection with the booking
We do not process health data.
We do not request or process information concerning health or other special categories of personal data referred to in Article 9 of the GDPR (for example, illnesses, medication, disabilities, ethnic origin, religion, or trade union membership), unless there is a separate legal basis for doing so. The questions in the experience survey relate to functional capacity and skills, not the reasons behind a person's state of health. We ask that you do not write information about your health or other sensitive matters in free-text fields. If such information reaches us, we will delete it without undue delay.
Information about passengers under the age of 18 is provided by the adult responsible person making the booking, who is responsible for the minor passengers during the trip.
4.Purposes of processing personal data
We process personal data for the following purposes:
- receiving, processing, confirming, and changing bookings, and handling cancellations
- concluding and performing the rental agreement, and verifying compliance with the contract terms
- identifying the customer when handing over the booking and communicating about matters related to the trip, such as weather-related changes
- customer service, and handling feedback and complaints
- assessing boating safety based on the experience survey
- selecting correctly sized life jackets and other safety equipment
- assessing whether the boat can be safely handed over to the customer and whether the selected trip is suitable for the customer's skill level
- preventing double bookings and misuse of the booking process
- technical maintenance of the service, resolving errors, and ensuring information security
- fulfilling statutory obligations, in particular accounting and tax obligations and reporting to authorities
- preparing, presenting, and defending potential legal claims, for example in cases of equipment damage
- marketing communications about new trips, only if you have given separate consent to this
We do not make automated decisions based on personal data that would have legal effects on you. The result of the experience survey narrows down the trip options presented, but the final assessment of whether the boat can be handed over is always made by a person on the day of the trip.
5.Legal basis for processing
The legal bases for processing, by purpose, are as follows:
| Purpose | Legal basis |
|---|---|
| Processing the booking, performing the rental agreement, communication related to the booking | Performance of a contract (GDPR Art. 6(1)(b)) |
| Accounting, invoicing, taxation, and other statutory obligations | Legal obligation (GDPR Art. 6(1)(c); Finnish Accounting Act 1336/1997) |
| Experience survey, life jacket sizing, and assessment of safe boat handover | Performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)): protecting the life and health of passengers and bystanders, and the safe handover of the equipment |
| Prevention of misuse and double bookings, technical logging, and information security | Legitimate interest (Art. 6(1)(f)): operational reliability of the service and prevention of misuse |
| Preparing and defending legal claims, for example equipment damage | Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) |
| Marketing communications and non-essential cookies | Consent (Art. 6(1)(a); Act on Electronic Communications Services 917/2014, Section 200) |
**Legitimate interest and balancing test.** For safety assessment, prevention of misuse, and technical logging, we have assessed that the processing is necessary for safely organising our operations, that the data processed is limited to the minimum necessary, that identifying data is stored in hashed form in the logs, and that retention periods are short. The processing is foreseeable to a customer of the booking service and does not override the rights of the data subject. You can object to processing based on legitimate interest at any time, as described in section 9.
We do not use consent as the legal basis for the booking or the safety assessment, because this data is necessary for performing the contract and providing it is not, in practice, voluntary. Without this data, a booking cannot be made and the boat cannot be handed over.
6.Data retention periods
We retain personal data only for as long as is necessary to fulfil the purpose of processing, or for as long as the law requires. When the retention period ends, the data is deleted or anonymised.
| Data category | Retention period and basis |
|---|---|
| Accounting records and payment transactions | 6 years from the end of the calendar year in which the financial period ends (Finnish Accounting Act, Chapter 2, Section 10) |
| Booking data and rental agreement, including damage cases | 3 years from the date of the trip (Act on the Statute of Limitations for Debt 728/2003, Section 4). If a dispute or claim is pending, retention continues until the matter is finally resolved. |
| Experience survey answers and scores | Deleted as soon as there is no longer a justified need to retain them: 24 months from the date of the trip. Data is retained longer only if required by law or a pending legal claim. |
| Unconfirmed bookings and email confirmation tokens | 30 days from the time the booking was made, after which the booking and token are deleted and the reserved slot is released |
| Technical logs, risk assessment logs, and email sending logs | 12 months from when the event was recorded. Logs related to an ongoing misuse or security incident investigation are retained for the duration of the investigation. |
| Customer service communications | 24 months from the last message, unless the communication relates to the accounting or contract records mentioned above |
| Marketing consent and marketing register | Until consent is withdrawn; the withdrawal is recorded and retained for 2 years for accountability purposes |
7.Disclosure of data
Personal data is processed only by those individuals whose duties require it. We also use external service providers who process data as processors on our behalf, under a written data processing agreement (GDPR Art. 28):
- the platform, database, and hosting service for the booking system and website (an application platform and managed database where booking and customer data are stored)
- the email sending service we use to send booking confirmations and customer messages
- the payment service provider SumUp, which processes payment transactions as an independent data controller and complies with SumUp Business EU's data protection regulation
- the accounting firm and bookkeeper: Tilitoimisto Ekomia Oy
- the analytics service, if you give your consent to it: Google Analytics
- authorities and courts, when required by law or when necessary to handle a legal claim, for example a maritime rescue or police authority in the event of an accident
**We do not sell, rent, or disclose personal data to third parties for marketing purposes, nor do we use the data to target external advertisers.**
8.Transfers of data outside the EU or EEA
We aim to process and store personal data within the EU or EEA. The service's database and file storage are configured to be located in the EU.
However, some of the cloud, email, and analytics services we use may process data or provide technical support from outside the EU or EEA. In these cases, the transfer is based on one of the following safeguards:
- a European Commission adequacy decision (GDPR Art. 45), for example a service provider certified under the EU–US Data Privacy Framework
- standard contractual clauses approved by the European Commission (GDPR Art. 46(2)(c); Implementing Decision (EU) 2021/914), supplemented by a transfer impact assessment and additional technical safeguards such as encryption
The location of data and any transfer mechanisms for our service providers are determined separately for each provider. Where necessary, we use European Commission adequacy decisions (GDPR Art. 45) and standard contractual clauses approved by the European Commission (GDPR Art. 46(2)(c); Implementing Decision (EU) 2021/914), supplemented with a transfer impact assessment and additional technical safeguards such as encryption.
You can request more information about the safeguards used and a copy of the standard contractual clauses at info@rentsa.fi.
9.Rights of the data subject
Under the GDPR, you have the following rights:
- **Right of access (Art. 15)** — the right to find out whether we process your data and to obtain a copy of the data being processed.
- **Rectification (Art. 16)** — the right to have inaccurate or incomplete data corrected or completed.
- **Erasure (Art. 17)** — the right to have your data deleted when there is no longer a basis for processing it. This right does not apply to data that we are required by law to retain, such as accounting records.
- **Restriction of processing (Art. 18)** — the right to request the restriction of processing, for example when you contest the accuracy of the data.
- **Objection (Art. 21)** — the right to object to processing based on legitimate interest on grounds relating to your particular situation, and to object to direct marketing at any time.
- **Data portability (Art. 20)** — the right to receive the data you have provided in a machine-readable format and to transfer it to another controller, when processing is based on contract or consent and is carried out by automated means.
- **Withdrawal of consent (Art. 7(3))** — the right to withdraw consent you have given at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- **Right to lodge a complaint with a supervisory authority (Art. 77)** — you can lodge a complaint with the Office of the Data Protection Ombudsman if you believe we are processing your data unlawfully.
How to exercise your rights
Send a request to info@rentsa.fi or in writing to the data controller's address. We may ask you to verify your identity before fulfilling the request. We will respond to your request within one month. If the request is complex or there are multiple requests, this period may be extended by up to two further months, of which we will notify you. Handling requests is free of charge.
Supervisory authority: Office of the Data Protection Ombudsman, P.O. Box 800, FI-00531 Helsinki, tel. +358 29 566 6700, tietosuoja.fi.
10.Information security
We protect personal data with appropriate technical and organisational measures (GDPR Art. 32):
Technical measures
- all traffic between the website and the user is encrypted with a TLS connection
- data is stored in a managed database with row-level access rules: each user can only access the data they are authorised to access
- the administration view is protected with personal authentication and role-based access rights
- identifying data in logs, such as IP addresses and email addresses, is stored in hashed form
- regular backups are taken of the database, and recovery capability is tested
- system usage and anomalies are monitored through logging and misuse-prevention functions
Organisational measures
- access rights are granted on the principle of least privilege and only to the extent required by job duties
- access rights are reviewed regularly and removed immediately when duties end
- staff and subcontractors are bound by confidentiality obligations
- data processing agreements in accordance with GDPR Article 28 have been concluded with service providers
- paper documents are stored in a locked location
If a data breach occurs, we will notify the Data Protection Ombudsman within 72 hours of becoming aware of it, and data subjects without undue delay if the breach is likely to result in a high risk to your rights.
11.Cookies and analytics
A cookie is a small text file stored on your device. We use cookies to ensure the service functions properly and to track visitor numbers.
Necessary cookies and browser storage
- maintaining the session of a logged-in administrator
- remembering the state of the user interface, such as the position of a menu
- storing the details of an incomplete booking in the browser's session storage, so the booking is not lost when navigating between pages
The use of these is based on Section 200 of the Act on Electronic Communications Services (917/2014): they are necessary to provide the service you requested, and consent is not required for them.
Analytics
We use visitor analytics to develop the service and to monitor how the site is used. Analytics is only enabled once you have given your consent, and you can withdraw your consent at any time from the cookie settings or by clearing your browser's cookies.
- Analytics service used: Google Analytics (Google Ireland Limited)
- Data collected: page views, referring page, approximate location, device and browser information, and an anonymous visitor identifier
- Retention period for cookies and analytics data: 24 months
- Legal basis: consent (GDPR Art. 6(1)(a))
You can also block cookies entirely from your browser settings. In that case, some of the service's functions, such as retaining incomplete booking details, may not work.
12.Changes to this notice
We continuously develop our service, so we may update this privacy notice. The updated notice will be published on this page, and the top of the page shows the current version and the update date. If a change is material, for example a new purpose of processing or a new legal basis, we will notify you personally by email before the change takes effect. We recommend checking the content of this notice from time to time.
Questions about this notice: info@rentsa.fi
