Privacy notice
Information document in accordance with the EU General Data Protection Regulation regarding the processing of personal data by Patopavelut Oy and its customer register.
Registrar
Patopalvelut Oy, Voimalaitoksentie 50, 29200 Harjavalta, y-tunnus 3462805-8
Contact person for matters related to the register
In matters related to the register and the exercise of the rights of the data subject, the contact person is:
Harri Höglund, 0400 668 079. myynti@hotellipato.fi
Register name
Patopalvelut Oy – customer register
Legal basis for processing personal data
The processing of personal data is based on legitimate interest, meaning that the processing of personal data in the customer register is based on the customer relationship of consumer customers and corporate customers at Patopalvelut Oy. The data controller also processes customer data based on the contract between the data controller and the data subject. On this basis, personal data is processed, which is collected from the customer when making a restaurant or room reservation or for restaurant and room billing purposes.
Purposes of personal data processing
The purposes of using customer data in the customer register are:
• processing of reservations made by the customer
• managing and developing customer relationships
• customer relationship communication
• sales and implementation of services
• marketing of services
• processing of personal data related to payments, invoicing, as well as payment monitoring and collection
• development of the controller's business and customer services
Any special dietary information provided by the customer will only be used for food preparation and serving.
Processed personal data
The data controller processes the following personal data:
• customer's first and last name, date of birth, phone number, address, email address
• nationality
• information regarding reservations
• information on the use and purchases of services
• customer's payment method information, billing information, possible payment delay information
• information regarding the customer's choices and preferences
• possible customer feedback and complaint information
• the person's reported statutory direct marketing opt-out information
In the case of corporate clients, the data controller processes the following personal data:
• the name, address, email address, and phone number of the contact person for the corporate client
• any customer feedback and complaint information
• the direct marketing prohibition information provided by the company's contact person in accordance with the legislation
Where personal data is obtained
The data controller obtains personal data:
• from the data subjects themselves, for example, via email and phone or during promotional events
• information obtained during the use of services and visits
• through order and request for quotation forms on their websites
• from external restaurant reservation websites
• from third-party hotel booking service companies
• from a registered employer at the time of booking services
• from external sources, such as public registers
Henkilötietojen vastaanottajat tai vastaanottajien ryhmät
Asiakasrekisterin tietoja käsittelevät vain henkilöt, joiden työtehtävään tietojen käsittely olennaisesti kuuluu. Rekisteriin pääsyyn on erilliset tunnukset ja salasanat. Tietoja ei luovuteta ulkopuolisille. Tietoja voidaan luovuttaa kuitenkin viranomaisille näiden lakiin perustuvien tietopyyntöjen perusteella.
Tietojen siirto EU:n ulkopuolelle
Käytämme palveluiden tuottamisessa alihankkijoita, jotka voivat olla sijoittautuneena EU:n tai Euroopan talousalueen ulkopuolelle. Kun tietoja siirretään EU:n ja ETA:n ulkopuolelle, huolehdimme henkilötietojen suojan riittävästä tasosta muun muassa sopimalla henkilötietojen luottamuksellisuuteen ja käsittelyyn liittyvistä asioista lainsäädännön edellyttämällä tavalla.
Recipients of personal data or groups of recipients
Only individuals whose job responsibilities essentially involve data processing handle the information in the customer register. Access to the register requires separate credentials and passwords. Information is not disclosed to outsiders. However, information may be disclosed to authorities based on their legally grounded information requests.
Transfer of data outside the EU
We use subcontractors in the provision of services, who may be located outside the EU or the European Economic Area. When data is transferred outside the EU and EEA, we ensure an adequate level of data protection by, among other things, agreeing on the confidentiality and processing of personal data in accordance with legal requirements.
Retention period of personal data
The personal data of the customer in the customer register is processed for the duration of the customer relationship. The data controller considers the customer relationship to have ended if the customer has not used the company's services for 2 years.
However, after the termination of the customer relationship, the data may still be stored and processed if necessary for a justified reason or for handling complaint matters. The retention period for the data in the customer register follows the retention periods required by law, such as the Accounting Act. The information required by the Accounting Act is retained for as long as the Accounting Act requires. The contact information of corporate clients will be deleted in the same manner after the company's customer relationship is considered terminated. However, the information can be retained afterward if there is another basis for doing so. When data is processed based on a contract between the data controller and the data subject, the data will be retained as long as necessary to fulfilll the contract. Once the contract has been fulfilled, the data will be retained as long as the customer relationship exists or there is another basis for processing (e.g., complaint cases or accounting law). During the customer relationship, only data that is necessary for the defined purposes will be processed. The data controller regularly conducts periodic audits to remove unnecessary data.
About the rights of the data subject
The data subject has the right to request access to their own data and the right to demand correction of the data if it is incorrect. At the request of the data subject, the processing of data can be restricted or the data can be completely removed from the register. The data subject has the right to object to the use of their data, for example, in direct marketing.
Right to lodge a complaint with a supervisory authority
The data subject has the right to lodge a complaint with a competent supervisory authority if the data subject considers that the controller has not complied with applicable data protection regulation in its activities.
Requests related to the exercise of the data subject's rights
In matters related to the processing of personal data and situations concerning the exercise of one's rights, the data subject can contact the data controller's contact person mentioned in section 2.
A request regarding the right of access or any other request for the exercise of the data subject's rights to the data controller must be made in writing, either by email or by post. The request can also be made in person at the data controller's office. The data controller may ask the data subject to specify sufficiently what information or processing activities the data subject's request pertains to.
To ensure that personal data related to the exercise of the data subject's rights is not disclosed to anyone other than the data subject themselves, the data controller may, if necessary, request the data subject to submit the inspection request in writing. The data controller may also request the requester to verify their identity with an official identification document or another reliable method.
