LegalPrivacy & GDPR

Privacy & GDPR

Last updated · 13.07.2026 — Effective · 01.08.2026

Data location
EU · Frankfurt
Transfers outside EU
none
Backups
daily, EU
Your rights
access, export, erasure

Draft — pending legal review

This text is a working draft and has not yet been reviewed by legal counsel. Bracketed items are placeholders. The final, binding version will be published before the effective date.

In shortNon-binding summary

For your account and billing, Pakkia decides how data is used — we're the controller. For the guest counts your campsite records, your campsite is the controller and we only process them on its behalf.

1.Controller & contact

The Pakkia service (the Service) is operated by [Company name — to be added] (Pakkia, “we”, “us”), a company registered in Finland. Business ID: [Business ID — to be added]. Registered address: [Registered address — to be added]. For anything in this policy, write to hello@pakkia.fi.

Two GDPR roles matter here, and the split is deliberate because Pakkia is a business tool:

  • Pakkia is the controller — the party that decides why and how personal data is processed — for the data described in sections 2.1–2.5: your account, usage logs, billing, support correspondence and this website.
  • For the overnight-stay records a campsite enters into the Service, the campsite is the controller and Pakkia is the processor— we process those records only on the campsite’s documented instructions, under the Data Processing Agreement described at the end of this page.

In shortNon-binding summary

Your name, email and role; the nightly counts your site records; ordinary usage logs; billing details; and support emails. Pakkia stores counts, not guests — no guest names, ever.

2.What we collect

We process the following categories of data:

  • Account data (2.1) — name, email address, and role at your campsite (Admin, Staff, or Pitch holder).
  • Usage & log data (2.2) — sign-ins, actions taken in the Service (the audit trail), and technical logs such as IP address and browser type.
  • Billing data (2.3) — organisation name, business ID, billing address and email, and invoicing history.
  • Support correspondence (2.4) — emails you send to hello@pakkia.fi.
  • Cookies (2.5) — strictly necessary cookies only, as listed in section 9.
  • Overnight-stay records(2.6) — the counts your campsite logs: how many people stayed on which pitch on which night, processed on the campsite’s behalf.

One thing the Service deliberately does not store: your guests. Overnight-stay records are numbers per pitch per night — no guest names, no ID numbers, no dates of birth, no contact details. A statistics report never needed identities, so Pakkia never collects them.

In shortNon-binding summary

Everything is stored in the EU, in Frankfurt, Germany — on Supabase infrastructure — and backed up daily inside the EU. We transfer no personal data outside the EU.

4.Where data lives

The Service’s database, authentication, and file storage run on Supabase in the EU · Frankfurt region (AWS eu-central-1, Germany). The application itself is served from EU infrastructure in the same region. Encrypted backups are taken daily and stored in the same EU region.

We transfer none of your personal data outside the EU/EEA. If that ever had to change, we would name the recipient and its safeguards in the sub-processor table below and give you notice before the change takes effect.

In shortNon-binding summary

Two companies help us run Pakkia — Supabase for the database and Vercel for serving the application — both operating for us in the EU, in Frankfurt.

5.Sub-processors

We use the following sub-processors. The list is kept current on this page, and we give notice before adding or replacing one (for example, a transactional-email provider once the Service sends email).

Sub-processors: name, purpose and processing region
NamePurposeRegion
SupabaseDatabase, authentication, and file storageEU · Frankfurt (AWS eu-central-1)
VercelApplication hosting and content deliveryEU · Frankfurt (fra1)

[Safeguard wording for sub-processors whose parent entities are established outside the EU — to be confirmed with counsel before the effective date].

In shortNon-binding summary

Your data stays as long as your account does. After closure you have 30 days to export everything; then we delete it, and daily backups roll it off within 35 days. Only bookkeeping records must stay longer — the law says 6 years.

6.Retention

Retention periods per data category
DataKept for
Account datalife of the account + 30-day export window
Overnight-stay recordswhile the account is active (campsite-controlled), then the same export window
Usage & log datasame cycle as the account it belongs to
Billing & bookkeeping records6 years (Finnish Accounting Act)
Support correspondence24 months after the case is closed
Backupsdaily, EU · rolling 35-day cycle

When your account is deleted — by you, or after the 30-day export window that follows termination — your data is deleted from production systems within 30 days. Because backups are kept on a rolling 35-day cycle, deleted data also disappears from every backup within 35 days of deletion. Backups are never restored in a way that resurrects deleted data.

In shortNon-binding summary

Encrypted in transit and at rest, access separated by role down at the database level, and every change to a record written to an audit trail.

7.Security

  • All traffic between you and the Service is encrypted in transit (TLS); stored data is encrypted at rest.
  • Access is separated per campsite and per role (Admin, Staff, Pitch holder) and enforced at the database level with row-level security (RLS) — not just in the user interface.
  • Every change to an overnight-stay record is written to an audit trail: what changed, when, and by whom.
  • Internal access follows least privilege: our staff access customer data only when needed to provide support you asked for or to keep the Service running.

If a personal-data breach ever occurs, we notify the affected customers and the supervisory authority as GDPR Articles 33–34 require.

In shortNon-binding summary

You can see, correct, export, and erase your data — export is built into the product as CSV, no request needed. And you can always complain to the Finnish data protection authority.

8.Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • rectification — have inaccurate data corrected;
  • erasure — have your data deleted, within the limits of section 6;
  • portability — receive your data in a machine-readable format. CSV export is built into the Service, so you can exercise this yourself at any time without asking us;
  • restriction of and objection to processing based on legitimate interests;
  • withdraw any consent you have given, at any time.

To exercise a right, email hello@pakkia.fi from your account address. We respond within one month. If you are unsatisfied, you may lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi. For overnight-stay records, requests are handled together with your campsite, which is the controller of that data.

In shortNon-binding summary

Only the cookies needed to keep you signed in. No analytics cookies, no marketing cookies, no third-party trackers — which is why you don't see a cookie banner.

9.Cookies

The Service sets strictly necessary cookies only:

Cookies: name, purpose and lifetime
CookiePurposeLifetime
sign-in sessionKeeps you signed in to your account (set by our authentication provider, Supabase)session · refreshed while you use the Service

We use no analytics, advertising, or social-media cookies, and no third-party trackers — so no consent banner is needed. If we ever introduce cookies that require consent, we will ask for it first and list them here before they are set.

In shortNon-binding summary

When this policy changes in a way that matters, account admins hear about it by email 30 days ahead — nothing changes quietly.

10.Changes

We may update this policy as the Service evolves. Material changes — anything that affects what we collect, where it lives, or your rights — are announced by email to account admins and in the Service at least 30days before they take effect. Minor clarifications are published on this page with an updated “Last updated” date.

Dated versions of this policy are kept available on request.