Privacy Policy
Last updated: August 23, 2026
Virtual Realm / DM Services (“Virtual Realm”, “we”, “us”, or “the data controller”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we process it, how we protect it, and what rights you have regarding your personal data.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection legislation.
1. Data Controller
Data controller: DM Services
Business name: Virtual Realm
Business ID (Y-tunnus): 3146956-5
Address: Pikkupiiankatu 1 A 9, 33580 Tampere, Finland
Email: asiakaspalvelu@virtualrealm.fi
2. What Personal Data We Collect
Depending on how you use our services, we may collect and process the following personal data:
- Name
- Email address
- Phone number, if you provide it
- Information related to a reservation or enquiry
- Other information that you voluntarily provide to us when contacting us or making a reservation
When you use our website, certain technical information may also be processed automatically, such as your IP address, browser type, device type, and information relating to your use of the website.
We do not intentionally collect or process special categories of personal data, such as health information, political opinions, religious beliefs, or other sensitive personal information.
3. How We Use Personal Data
We may process personal data for the following purposes:
- Receiving and managing reservations
- Responding to enquiries and contact requests
- Communicating with customers regarding reservations and our services
- Providing and managing our services
- Maintaining and improving our website and services
- Ensuring the security and proper functioning of our website
- Detecting and resolving technical problems or misuse
- Complying with legal obligations
We do not use your contact information for direct marketing without an appropriate legal basis under applicable law.
4. Legal Basis for Processing
Depending on the circumstances, we process personal data on the following legal bases under the GDPR:
- Performance of a contract: for example, when personal data is required to process a reservation and provide the requested service.
- Legitimate interests: for example, to maintain the security and functionality of our website and to develop and improve our services.
- Legal obligation: when processing is necessary for us to comply with a legal obligation.
- Consent: when processing requires your consent under applicable law.
Where providing personal data is necessary for processing a reservation or responding to a request, failure to provide the necessary information may prevent us from processing the reservation or responding to your enquiry.
5. Where We Obtain Personal Data
Personal data is generally obtained directly from you, for example:
- Through a contact or reservation form on our website
- By email
- By telephone
- Through other communication between you and Virtual Realm
We may also receive limited technical information automatically when you use our website.
6. Sharing Personal Data
We do not sell your personal data to third parties.
Personal data may be shared with or processed by service providers when necessary for operating our website, handling communications and reservations, providing IT services, or otherwise delivering our services.
These service providers may include:
- Website hosting providers
- Email service providers
- Contact and reservation system providers
- Analytics and technical service providers, where applicable
- Other service providers necessary for operating our business
Such service providers may only process personal data to the extent necessary to provide their services and are required to comply with applicable data protection legislation.
7. Transfers Outside the European Union or European Economic Area
Some of the service providers we use may process personal data outside the European Union or European Economic Area.
Where personal data is transferred outside the EU or EEA, we ensure that the transfer is carried out in accordance with the GDPR and that appropriate safeguards are in place where required.
8. How Long We Keep Personal Data
We retain personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by applicable law.
For example, information relating to a reservation or enquiry may be retained for as long as necessary to handle the matter and maintain the relevant customer relationship.
Information required for accounting, taxation, or other statutory purposes is retained for the period required by applicable legislation.
When personal data is no longer required, it will be deleted or anonymised within a reasonable period.
9. Cookies and Website Usage
Our website may use cookies and similar technologies to enable essential website functionality, maintain security, and understand and improve how our website is used.
Essential cookies may be used when necessary for the technical operation of the website. Where non-essential cookies or similar technologies are used, consent will be requested where required by applicable law.
You can manage or disable cookies through your browser settings and, where applicable, through the cookie settings provided on our website.
10. Data Security
We take the security of your personal data seriously and use appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, destruction, or other unlawful processing.
Access to personal data is limited to individuals and service providers who have a legitimate need to access it.
However, no electronic transmission or storage system can be guaranteed to be completely secure, and we cannot guarantee absolute security in all circumstances.
11. Your Rights
Under the GDPR, you may have the following rights regarding your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request that inaccurate or incomplete personal data be corrected.
- Right to erasure: You may request that your personal data be deleted in certain circumstances.
- Right to restriction of processing: You may request that we restrict the processing of your personal data in certain circumstances.
- Right to object: You may object to certain processing of your personal data.
- Right to data portability: Where applicable, you may request to receive your personal data in a structured, commonly used, and machine-readable format or have it transferred to another controller.
- Right to withdraw consent: Where processing is based on consent, you may withdraw your consent at any time.
You can exercise these rights by contacting us using the email address provided in Section 1.
Please note that not all rights apply in every situation. For example, we may be required to retain certain information in order to comply with legal obligations.
12. Right to Lodge a Complaint
If you believe that we have processed your personal data in violation of applicable data protection legislation, you have the right to lodge a complaint with the competent data protection supervisory authority.
In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, for example if our services, website, or applicable legislation changes.
The latest version will always be published on this page, and the date of the latest update will be shown at the beginning of the Privacy Policy.
14. Contact Us
If you have any questions about this Privacy Policy, how we process your personal data, or if you wish to exercise any of your data protection rights, you can contact us:
DM Services / Virtual Realm
Pikkupiiankatu 1 A 9
33580 Tampere
Finland