Privacy Policy

1. Controller

Ahvi Oy (Business ID 2724580-9). Email: info@cityhomefinland.com. Phone: +358 50 3110631.

2. Personal data we process

When you search availability, we process selected dates and the number of guests. For a direct online booking and its payment, we process your name, email, phone number, language, apartment, stay dates, number of guests, quoted amount and currency, and booking reference. After payment, the reservation is entered into Smoobu manually.

If payment is enabled, Stripe processes payment information. Ahvi Oy does not receive or store full card details. Payment identifiers, status, amount and currency may be processed to manage bookings and payments.

We store the name, email, optional phone number and message submitted through the contact form and use Resend to notify us by email. The website and server may also process technical operational and security logs to prevent abuse and investigate faults.

3. Purposes and legal bases

Checking availability and taking steps requested before entering into a contract.

Creating, administering and fulfilling a booking and processing any payment on the basis of the accommodation contract.

Complying with applicable accounting and other legal obligations.

Protecting the service, preventing misuse and investigating incidents on the basis of our legitimate interests.

4. Recipients and service providers

We disclose data only as needed to provide the service. Stripe processes any payments. Smoobu processes availability and booking data when a reservation is transferred to the reservation system. Resend processes contact submissions for email delivery. Technical hosting providers may process limited necessary information.

Providers process data under their applicable terms and data protection arrangements. Details of any processing outside the European Economic Area and the safeguards used must be confirmed from current provider agreements.

5. Retention

We delete contact form data from the website database 12 months after receiving the message. Staff handle copies received by email separately.

Ordinary customer and booking data is generally retained for 12 months after the stay to administer accommodation, resolve booking or service matters, and protect the parties’ rights. Paid direct bookings on this website are then reviewed manually and deleted from the database when there is no longer a reason to retain them; deletion is not automatic. An interrupted payment can also leave a database record, which is manually reviewed and deleted when no longer needed. Payment, invoicing and accounting records are not necessarily deleted after 12 months and are retained as required by applicable legal obligations. Data held in Smoobu, Stripe and Resend, and copies in staff email, are handled separately under their respective retention and deletion practices. Technical and security logs are retained only as long as reasonably needed.

6. Security

Access to data is limited to those who need it. Connections to payment and booking services are protected, and sensitive authorization or cookie headers are not recorded in application logs. No online service can be guaranteed completely secure.

7. Your rights

Subject to applicable law, you may request access to, correction or deletion of your data, restriction or portability, or object to processing based on legitimate interests. You may complain to the competent data protection authority. Contact us using the details above; we may need to verify your identity.

8. Cookies and analytics

The website does not use analytics or advertising systems. This policy will be updated before new processing activities are introduced.