We want to explain clearly what information we need and why. This notice applies to our website, bookings, customer accounts, payments, gift cards, wristbands, newsletter, feedback and visits to Löylykontti locations.
Löylykontti Oy (Business ID 3145066-1)
Rajatorpantie 41 C, 01640 Vantaa, Finland
+358 45 234 6960
Depending on the service, we process:
We receive data mainly from you. We also receive necessary data from sign-in, payment and access-control services, your browser, our staff and CCTV at our locations.
If you use Find my location on a map, your precise location is processed in your browser and by Mapbox only after you grant device permission. We do not store your precise location in your customer account.
With Analytics consent, we process limited page and booking-funnel events in PostHog Cloud EU and Google Analytics 4. General analytics events do not contain contact details, booking or payment IDs, codes, raw errors or query strings.
With Analytics consent, PostHog Cloud EU may also record a sample of website sessions as a technical reconstruction of interactions such as page transitions, clicks, scrolling and interface state. It is not a camera, audio or conventional screen-video recording. Form fields and page text are masked, URL query strings are removed, and payment-provider, booking-confirmation, customer-account and administration pages are not recorded. We use recordings to investigate usability problems and technical errors.
With Marketing consent, Google Ads and Meta may receive limited page and purchase events, campaign, click and browser identifiers and, for enhanced matching, a normalized and hashed email address or phone number. Hashed data is still personal data.
Pricing may vary by time, location and demand, but it is not personalized using your personal data. We do not make decisions about you with legal or similarly significant effects based solely on automated processing.
We use the following providers only for the purposes needed to perform their respective tasks:
Maps, payment-service terms and some externally delivered technical content may send ordinary request data, such as IP address and browser information, to the provider when loaded. If you follow a link from our website to an external service, that service processes data under its own privacy notice.
We may also disclose data to our accountant, advisers, insurer, debt-collection service or an authority where necessary for a contract, legal claim or legal obligation. We do not sell personal data.
The application and primary business database are hosted in the EEA. Brevo stores newsletter data in the EU, and we use PostHog's EU cloud.
Some international providers may also process data outside the EEA. Depending on the provider, a transfer is based on a European Commission adequacy decision, transfer to a participant in the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses with additional safeguards where needed. Contact us for more information about the safeguard applicable to a particular transfer.
We use necessary cookies and similar local storage for purposes such as sign-in, session security, language selection and remembering consent choices. Optional analytics and advertising measurement are off by default until you consent. You can select Analytics and Marketing independently from Cookie settings in the footer.
PostHog session replay starts only after Analytics consent and only on approved public pages. Withdrawing consent stops recording and future analytics. Analytics consent is not required to make a booking.
Withdrawing consent stops future optional measurement, removes accessible browser identifiers for that purpose and cancels unsent optional events where possible. Data already received cannot be recalled; you can ask for its deletion under your data-protection rights.
We retain customer, booking, payment and communication data for as long as needed to provide the service, manage the customer relationship, meet accounting duties, handle complaints and establish or defend legal claims. When data is no longer needed, it is deleted or anonymized. Newsletter data is kept while you subscribe; we may retain a limited suppression record so a cancelled subscription is not accidentally reactivated.
Specific retention periods include:
Consent evidence is kept only for as long as needed to demonstrate consent and compliance. Payment and accounting records are retained for the period required by applicable law.
Access to personal data is limited by work duties. We protect data using measures including encrypted connections, access controls, backups, logging, rate controls and retention monitoring. Limited advertising-attribution data is also encrypted at rest.
Subject to applicable law, you can:
Send requests to [email protected]. We may ask for more information to verify your identity. Withdrawing consent does not affect processing carried out lawfully before the withdrawal.
We update this notice when the service or our processing of personal data changes. We communicate material changes on the website or by email where appropriate.
Last updated: 11 August 2026