Privacy Policy
Privacy Policy
Jepetron Oy / Hilltop Hotel Iso-Syöte
Last updated: 16 September 2026
1. Controller and contact details
Jepetron Oy (Business ID 3434075-9)
Isosyötteentie 246, 93280 Syöte, Finland
Telephone: +358 201 476 400
Email: myyntipalvelu@isosyote.fi
For privacy matters, contact us using the email address above. We may request reasonable additional information to verify identity where this is necessary to handle a request securely.
2. Data we process
- name, contact details, language and other basic information you provide;
- accommodation, restaurant, spa and activity reservations, dates, party size, requests and customer-service communications;
- billing and payment-transaction data. Full card details are handled by the payment provider and are not stored in the hotel’s own systems;
- consents, marketing preferences and cookie choices;
- technical website data such as IP address, device and browser data, event logs and information about use of the website;
- feedback, reviews and other information you choose to provide.
Special requests may reveal dietary, health or accessibility information. We process this only to arrange the requested service and, where required, on the basis of explicit consent. Data about children is processed only as needed to make and fulfil a reservation, normally as provided by a parent or guardian.
3. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Reservations and customer service | Making, changing and fulfilling reservations, communicating with guests and providing requested services | Contract and steps taken before entering into a contract |
| Payments and accounting | Taking payments, invoicing, refunds, fraud prevention and statutory accounting | Contract, legal obligation and legitimate interests |
| Security and service development | Information security, abuse prevention, troubleshooting and service improvement | Legitimate interests; consent for optional analytics |
| Marketing and personalisation | Newsletters, targeted advertising, campaign measurement and other optional marketing | Consent; for existing customers, where applicable, legitimate interests and electronic-marketing rules |
| Legal duties and claims | Compliance with authority requirements and establishing, exercising or defending legal claims | Legal obligation and legitimate interests |
Non-essential analytics and marketing technologies are activated only with consent. Consent can be withdrawn at any time through the Cookie settings link on the website.
4. Sources of data
We mainly obtain data from you when you make a reservation, contact us, pay, submit feedback or choose cookie settings. Data may also come from the person booking for your party, a corporate or tour-operator customer, and the booking, payment and analytics services we use.
5. Providers and recipients
We use processors and technical providers only to the extent necessary. The website’s current or potential services include:
- Mews for accommodation reservations and hotel operations and Stripe for payment processing;
- FareHarbor for activity reservations;
- Complianz for managing consent choices;
- Google Tag Manager and Google Analytics for optional measurement and Google reCAPTCHA for form protection;
- Meta/Facebook for optional advertising measurement and targeting;
- HubSpot for customer, form or marketing functions when enabled;
- Trustmary for displaying reviews and trust content;
- Adobe Fonts for web fonts;
- WordPress, WPML, YOOtheme and LiteSpeed, together with hosting, CDN, backup, security and IT-maintenance providers, for operating the website.
Reservation and payment data may also be disclosed to banks, payment providers, accountants, authorities and other parties where necessary to provide the service or comply with law. We do not sell personal data.
6. Transfers outside the EU or EEA
Some providers may process data outside the EU or EEA, particularly in the United States. Depending on the circumstances, transfers are protected by a European Commission adequacy decision, the EU–US Data Privacy Framework, the European Commission’s Standard Contractual Clauses and any necessary supplementary safeguards. The exact provider-specific mechanism depends on the current contract and service configuration.
7. Retention
- reservation, contract, payment and billing data is kept for as long as needed to provide the service and meet applicable accounting, tax and accommodation obligations;
- customer-service messages and feedback are normally kept for no more than 24 months after the matter is closed, unless a longer period is needed for a contract or legal claim;
- direct-marketing data is kept until consent is withdrawn or the marketing relationship ends; suppression records may be retained to respect an objection;
- technical logs are retained only for as long as needed for security, troubleshooting and service maintenance;
- cookie and similar-technology lifetimes are described in the Cookie Policy.
Data is deleted or anonymised when no longer needed, unless retention is required by law or necessary for a legal claim.
8. Security
Access is limited according to job duties. We use appropriate technical and organisational measures such as access controls, encrypted connections, backups, updates and contractual instructions for providers.
9. Your rights
Subject to applicable law, you may request access, correction or deletion; restrict processing; object to processing based on legitimate interests; receive data you provided in a portable format; and withdraw consent without affecting processing carried out before withdrawal. You may always object to direct marketing.
Exercise your rights by emailing myyntipalvelu@isosyote.fi. A signed paper request is not required. We respond without undue delay and within the statutory time limit.
10. Right to complain
If you believe that your personal data is processed unlawfully, you may lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman.
11. Automated decisions and changes
We do not use the website to make decisions based solely on automated processing that produce legal or similarly significant effects. We update this policy when services, processing practices or the law change materially.











