Privacy policy
Effective from 26 May 2026 · Version 1.0
This policy explains how Resaco Oy processes personal data in the ResaHost service, in accordance with Articles 13 and 14 of the EU General Data Protection Regulation.
1. Controller
Resaco Oy · Finnish business ID 3259870-5 · VAT number FI32598705.
Visiting address: Hallituskatu 26, second floor, 96100 Rovaniemi, Finland. Postal address: Evakkotie 48 A 5, 96100 Rovaniemi, Finland.
Data protection contact: Olli Junes, [email protected], +358 45 671 7116.
2. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Customer relationship management, billing, support and service delivery | Performance of a contract, Article 6(1)(b) |
| Accounting and statutory reporting | Legal obligation, Article 6(1)(c) |
| Direct marketing to existing customers, improving security and service operation, preventing misuse | Legitimate interests, Article 6(1)(f) |
| Marketing to non-customers and non-essential cookies | Consent, Article 6(1)(a) |
3. Information processed
We process contact information such as names, email addresses and telephone numbers; business names, identifiers and billing addresses; and contract information such as the selected plan, order date and billing history.
Technical information includes IP addresses, user agents, server logs and session identifiers. Usage information includes activity in the customer portal and the content of support requests. Marketing records include consent, newsletter subscriptions and objections to marketing.
4. Sources of information
Information comes from customers when ordering, using the portal or contacting support; logs collected automatically by servers and applications; cookies and similar technologies; and public registers, such as Finland's Business Information System for checking business identifiers.
5. Retention
| Information | Retention period |
|---|---|
| Customer data | Six years after the contract ends, under section 2:10 of the Finnish Accounting Act |
| Server logs | 90 days, unless a security investigation requires longer retention |
| Support conversations | 24 months after the last contact |
| Marketing information | 12 months after the last customer contact if consent has not been renewed |
| Marketing objections | Indefinitely, so that the objection can be respected |
6. Recipients and location
ResaHost discloses personal data to the following processors to deliver the service. Data processing agreements under Article 28 GDPR have been concluded with them.
- Hetzner Online GmbH, Germany/Finland: server infrastructure.
- Visma Pay, Visma Solutions Oy: payment processing.
- Cookiebot, Usercentrics A/S: consent management.
- Google Ireland Limited: Google Analytics 4.
- Dealfront Finland Oy, Leadfeeder: identifying business visitors.
Personal data is not transferred outside the EU or EEA. Processing takes place in Hetzner data centres within the EU, primarily Helsinki.
7. Security
Measures include TLS 1.3 encryption in transit, encrypted backups, two-factor authentication, role-based access with least privilege, logging and regular audits. Staff are bound by confidentiality.
8. Your rights
Under GDPR, you have rights of access, rectification, erasure, restriction, portability and objection to processing based on legitimate interests. Where processing relies on consent, you may withdraw it.
Send requests to [email protected]. We respond within one month and verify identity before carrying out the request.
You may complain to the Office of the Data Protection Ombudsman in Finland if you believe personal data is being processed unlawfully.
9. Automated decisions
ResaHost does not make automated decisions based on personal data that produce legal or similarly significant effects for individuals.
10. Changes
ResaHost may update this policy following changes to operations or legislation. Customers receive notice of material changes by email at least 30 days before they take effect.
Manage website consent through cookie settings. For processing carried out on behalf of customers, see the Data Processing Agreement.