Privacy Policy
This Privacy Policy describes how Restaurant Kolme Kruunua processes personal data on its website and in connection with the services offered through it.
Data Controller
Ravintola Kolme Kruunua
Liisankatu 5
00170 Helsinki
Sähköposti: kolmekruunua@sijo.fi
Puhelin: +358 9 135 4172
Purpose of Processing Personal Data
Personal data is processed for the following purposes:
• receiving and handling table reservations
• communicating with customers regarding reservations
• customer service
• developing and improving the website and services
• analyzing website usage and marketing performance
Personal Data Collected
Through the website, the following personal data may be collected:
• first and last name
• email address
• phone number
• reservation-related details (e.g. date, time, number of guests)
In addition, technical data related to website usage may be collected, such as:
• IP address (anonymized where possible)
• browser and device information
• website usage and interaction data
Legal Basis for Processing
Personal data is processed based on:
• the data subject’s consent (e.g. reservation form)
• performance of a contract (handling table reservations)
• legitimate interest of the data controller (website development and analytics)
Cookies and Analytics
The website uses cookies and third-party services, including:
• Google Analytics to analyze website traffic and usage
• Meta (Facebook Pixel) for marketing and performance analysis
The use of cookies is based on the user’s consent, which is managed via a cookie consent banner. Users can change or withdraw their consent at any time.
Data Retention
Personal data is stored only for as long as necessary:
• reservation data is retained for the duration required to manage the reservation and related customer service
• analytics data is stored in accordance with the retention periods defined by the service providers
Disclosure of Personal Data
Personal data is not disclosed to third parties. Data may be disclosed to authorities only where required by law or official regulations.
Transfers Outside the EU/EEA
Some service providers (such as Google and Meta) may process data outside the EU or EEA. In such cases, data transfers are carried out in accordance with applicable data protection legislation, using appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
Data Subject Rights
Data subjects have the right to:
• access their personal data
• request correction or deletion of data
• restrict or object to the processing of data
• withdraw consent at any time
Requests regarding these rights can be submitted using the contact details above.
Data Security
Appropriate technical and organizational measures are used to protect personal data against unauthorized access, loss, alteration, or misuse.
Changes to This Privacy Policy
This Privacy Policy may be updated when necessary. The most current version is always available on the website.