Privacy & GDPR
Last updated · 13.07.2026 — Effective · 01.08.2026
- Data location
- EU · Frankfurt
- Transfers outside EU
- none
- Backups
- daily, EU
- Your rights
- access, export, erasure
Draft — pending legal review
This text is a working draft and has not yet been reviewed by legal counsel. Bracketed items are placeholders. The final, binding version will be published before the effective date.
In shortNon-binding summary
For your account and billing, Pakkia decides how data is used — we're the controller. For the guest counts your campsite records, your campsite is the controller and we only process them on its behalf.
1.Controller & contact
The Pakkia service (the Service) is operated by [Company name — to be added] (Pakkia, “we”, “us”), a company registered in Finland. Business ID: [Business ID — to be added]. Registered address: [Registered address — to be added]. For anything in this policy, write to hello@pakkia.fi.
Two GDPR roles matter here, and the split is deliberate because Pakkia is a business tool:
- Pakkia is the controller — the party that decides why and how personal data is processed — for the data described in sections 2.1–2.5: your account, usage logs, billing, support correspondence and this website.
- For the overnight-stay records a campsite enters into the Service, the campsite is the controller and Pakkia is the processor— we process those records only on the campsite’s documented instructions, under the Data Processing Agreement described at the end of this page.
In shortNon-binding summary
Your name, email and role; the nightly counts your site records; ordinary usage logs; billing details; and support emails. Pakkia stores counts, not guests — no guest names, ever.
2.What we collect
We process the following categories of data:
- Account data (2.1) — name, email address, and role at your campsite (Admin, Staff, or Pitch holder).
- Usage & log data (2.2) — sign-ins, actions taken in the Service (the audit trail), and technical logs such as IP address and browser type.
- Billing data (2.3) — organisation name, business ID, billing address and email, and invoicing history.
- Support correspondence (2.4) — emails you send to hello@pakkia.fi.
- Cookies (2.5) — strictly necessary cookies only, as listed in section 9.
- Overnight-stay records(2.6) — the counts your campsite logs: how many people stayed on which pitch on which night, processed on the campsite’s behalf.
One thing the Service deliberately does not store: your guests. Overnight-stay records are numbers per pitch per night — no guest names, no ID numbers, no dates of birth, no contact details. A statistics report never needed identities, so Pakkia never collects them.
In shortNon-binding summary
We process data to run the service you signed up for, to keep it secure, to meet bookkeeping law — and beyond that only with your consent.
3.Why & legal bases
Each processing purpose rests on a GDPR legal basis:
- Contract performance (Art. 6(1)(b)) — providing the Service: accounts, logging, reports, exports, support, and billing.
- Legitimate interests (Art. 6(1)(f)) — keeping the Service secure, maintaining the audit trail, preventing abuse, and improving the product from aggregate usage.
- Consent (Art. 6(1)(a)) — only where we ask for it separately, such as product news by email. Consent can be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)) — retaining billing records under Finnish bookkeeping law (section 6).
For overnight-stay records we act as processor; the legal basis is the campsite’s own — typically its statutory reporting duty to Statistics Finland.
In shortNon-binding summary
Everything is stored in the EU, in Frankfurt, Germany — on Supabase infrastructure — and backed up daily inside the EU. We transfer no personal data outside the EU.
4.Where data lives
The Service’s database, authentication, and file storage run on Supabase in the EU · Frankfurt region (AWS eu-central-1, Germany). The application itself is served from EU infrastructure in the same region. Encrypted backups are taken daily and stored in the same EU region.
We transfer none of your personal data outside the EU/EEA. If that ever had to change, we would name the recipient and its safeguards in the sub-processor table below and give you notice before the change takes effect.
In shortNon-binding summary
Two companies help us run Pakkia — Supabase for the database and Vercel for serving the application — both operating for us in the EU, in Frankfurt.
5.Sub-processors
We use the following sub-processors. The list is kept current on this page, and we give notice before adding or replacing one (for example, a transactional-email provider once the Service sends email).
| Name | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, and file storage | EU · Frankfurt (AWS eu-central-1) |
| Vercel | Application hosting and content delivery | EU · Frankfurt (fra1) |
[Safeguard wording for sub-processors whose parent entities are established outside the EU — to be confirmed with counsel before the effective date].
In shortNon-binding summary
Your data stays as long as your account does. After closure you have 30 days to export everything; then we delete it, and daily backups roll it off within 35 days. Only bookkeeping records must stay longer — the law says 6 years.
6.Retention
| Data | Kept for |
|---|---|
| Account data | life of the account + 30-day export window |
| Overnight-stay records | while the account is active (campsite-controlled), then the same export window |
| Usage & log data | same cycle as the account it belongs to |
| Billing & bookkeeping records | 6 years (Finnish Accounting Act) |
| Support correspondence | 24 months after the case is closed |
| Backups | daily, EU · rolling 35-day cycle |
When your account is deleted — by you, or after the 30-day export window that follows termination — your data is deleted from production systems within 30 days. Because backups are kept on a rolling 35-day cycle, deleted data also disappears from every backup within 35 days of deletion. Backups are never restored in a way that resurrects deleted data.
In shortNon-binding summary
Encrypted in transit and at rest, access separated by role down at the database level, and every change to a record written to an audit trail.
7.Security
- All traffic between you and the Service is encrypted in transit (TLS); stored data is encrypted at rest.
- Access is separated per campsite and per role (Admin, Staff, Pitch holder) and enforced at the database level with row-level security (RLS) — not just in the user interface.
- Every change to an overnight-stay record is written to an audit trail: what changed, when, and by whom.
- Internal access follows least privilege: our staff access customer data only when needed to provide support you asked for or to keep the Service running.
If a personal-data breach ever occurs, we notify the affected customers and the supervisory authority as GDPR Articles 33–34 require.
In shortNon-binding summary
You can see, correct, export, and erase your data — export is built into the product as CSV, no request needed. And you can always complain to the Finnish data protection authority.
8.Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectification — have inaccurate data corrected;
- erasure — have your data deleted, within the limits of section 6;
- portability — receive your data in a machine-readable format. CSV export is built into the Service, so you can exercise this yourself at any time without asking us;
- restriction of and objection to processing based on legitimate interests;
- withdraw any consent you have given, at any time.
To exercise a right, email hello@pakkia.fi from your account address. We respond within one month. If you are unsatisfied, you may lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi. For overnight-stay records, requests are handled together with your campsite, which is the controller of that data.
In shortNon-binding summary
When this policy changes in a way that matters, account admins hear about it by email 30 days ahead — nothing changes quietly.
10.Changes
We may update this policy as the Service evolves. Material changes — anything that affects what we collect, where it lives, or your rights — are announced by email to account admins and in the Service at least 30days before they take effect. Minor clarifications are published on this page with an updated “Last updated” date.
Dated versions of this policy are kept available on request.