Privacy Policy
This privacy policy has been prepared in accordance with Finnish data protection legislation (Personal Data Act, Sections 10 and 24) and the EU General Data Protection Regulation (GDPR).
Originally drafted 1 May 2020. Last updated 15.6.2026.
Data Controller
Juhan safari ja lomamatkat (hereinafter Safarisuomi), operating also under the trade name SFB Motorcycle Tours
Jyrkäntaival 13 89140 KOTILA, Finland
Phone: +358 44 748 6667
Contact Person
Juha Haanela Jyrkäntaival 13 89140 KOTILA, Finland Phone: +358 44 748 6667 ([email protected])
Name of the Register
Customer register
Purpose of Processing Personal Data
The personal data provided is used to carry out the tours, programs, and equipment rentals organized by Safarisuomi / SFB Motorcycle Tours, and for marketing future similar events. Following a tour, rental, and/or event, customers may also be sent surveys and newsletters.
After a tour and/or event, a customer’s basic information (name, email address, and company/organization name) is retained for five years, unless the data subject exercises their right to erasure.
Contents of the Register
- first and last name
- address details
- phone number
- email address
- campaign history
- direct marketing prohibitions and consents
Tour-Specific Additional Information
Organizing a tour often requires hotel, flight and/or ferry bookings and border crossings. Depending on the tour, the register may therefore also include:
- booking details for package tours and additional services, such as destination, travel dates, booking date, hotel details, ferry details, flight details, price, discounts and the basis for discounts, sales channel and responsible staff member
- travel group composition and additional services related to the tour
- loyalty program numbers
- passport number and validity period — required for hotel and flight bookings and for border crossings on international tours
- gender (where required for accommodation and transport bookings)
- a unique customer identifier
Credit Check for Invoiced Customers
- for business customers: company name and business ID
- for private customers: date of birth and personal identity code
Web Store and Payment Processors
Our online store operates on the WooCommerce platform. The following service providers act as data processors when processing orders:
Stripe — payment processing (card payments, Apple Pay, Google Pay). Stripe processes card details directly; card data is not stored on our own systems. Stripe may transfer data outside the EU/EEA (to the United States) in accordance with transfer mechanisms approved by the European Commission (e.g. the EU–US Data Privacy Framework or Standard Contractual Clauses). More information: stripe.com/privacy
Klarna — alternative payment method (invoice/installment payment). Klarna processes payment-related personal and credit data as an independent data controller, and may receive the order and payment information necessary to complete the payment. More information: klarna.com/privacy-policy
Marketing and Analytics Processors
Meta / Facebook Pixel — this site uses the Facebook Pixel, which collects information about visitor behavior for advertising targeting and measurement purposes. Data is transferred to Meta, which acts as an independent data controller. More information and management options: facebook.com/privacy/policy
Google Analytics — we use Google Analytics to analyze website traffic and usage, which collects anonymized or pseudonymized usage data. More information: policies.google.com/privacy
Klaviyo — Klaviyo is used or planned for use for email marketing and customer communications, processing contact details (email, name, purchase history) for targeted direct marketing and customer communication. More information: klaviyo.com/legal/privacy
The above-mentioned service providers may process data outside the European Union and European Economic Area. In such cases, we require that the transfer be based on a transfer mechanism approved by the European Commission (such as Standard Contractual Clauses or the Data Privacy Framework) in accordance with applicable data protection legislation and the GDPR.
For more information on the use of cookies and consent management, please see our separate Cookie Policy.
Regular Sources of Information
A person participating in a tour and/or event provides the participants’ information at the time of registration, with their own consent and that of any other participants.
Regular Disclosure of Data
Personal data provided is shared with partners relevant to carrying out the tour and/or event, such as hotels, airlines, and ferry operators, as well as the payment and marketing service providers listed above. Personal data is not otherwise disclosed to third parties, except in connection with credit checks.
Transfer of Data Outside the EU or EEA
Data may be transferred outside the European Union and European Economic Area where this is required for the technical implementation of a service requested by the user (e.g. Stripe, Meta, Google, Klaviyo as described above), or where otherwise necessary under applicable data protection legislation. Partners outside the EU are required to apply transfer mechanisms ensuring an adequate level of data protection.
To provide our services, necessary information is disclosed to service providers such as ferry operators, airlines, and hotels. Customer data is not disclosed to third parties for sales or marketing purposes without the customer’s separate consent. Personal data may also be disclosed to authorities to the extent permitted or required by applicable law.
Principles of Register Protection
Manual Material
No manual participant register is maintained.
Electronically Processed Data
The participant register is stored and maintained in systems designated for that purpose (e-commerce platform, payment processing, and marketing services). Staff of Safarisuomi / SFB Motorcycle Tours access these systems using personal credentials.
Particularly sensitive data, such as passport numbers and personal identity codes, is processed only to the extent necessary for completing a tour, booking, or border crossing, and is accessed only by personnel whose duties require it.
Right of Access
Data subjects have the right to review the data stored about them in the customer register. Requests to review personal data should be sent to ([email protected]).
Requests regarding personal data are free of charge once per year. A reasonable fee covering administrative costs may be charged for additional requests.
Right to Rectification
Data subjects have the right to request the correction of inaccurate data stored in the customer register. Requests for correction should be sent to [ ([email protected]).
Other Rights Relating to the Processing of Personal Data
Data subjects have the right to request the erasure of their data from the customer register. Requests for erasure should be sent to ([email protected]).
Please note that certain data (such as billing information) must be retained for the period required by accounting legislation, even if a data subject requests erasure of their other data.
Suggested text: Visitor comments may be checked through an automated spam detection service.