top of page

Privacy Policy

This Privacy Policy describes how Restaurant Kolme Kruunua processes personal data on its website and in connection with the services offered through it.

Data Controller

Ravintola Kolme Kruunua
Liisankatu 5
00170 Helsinki
Sähköposti: kolmekruunua@sijo.fi
Puhelin: +358 9 135 4172

Purpose of Processing Personal Data

Personal data is processed for the following purposes:

    •    receiving and handling table reservations
    •    communicating with customers regarding reservations
    •    customer service
    •    developing and improving the website and services
    •    analyzing website usage and marketing performance

Personal Data Collected

Through the website, the following personal data may be collected:
    •    first and last name
    •    email address
    •    phone number
    •    reservation-related details (e.g. date, time, number of guests)

In addition, technical data related to website usage may be collected, such as:
    •    IP address (anonymized where possible)
    •    browser and device information
    •    website usage and interaction data

Legal Basis for Processing

Personal data is processed based on:
    •    the data subject’s consent (e.g. reservation form)
    •    performance of a contract (handling table reservations)
    •    legitimate interest of the data controller (website development and analytics)

Cookies and Analytics

The website uses cookies and third-party services, including:
    •    Google Analytics to analyze website traffic and usage
    •    Meta (Facebook Pixel) for marketing and performance analysis

The use of cookies is based on the user’s consent, which is managed via a cookie consent banner. Users can change or withdraw their consent at any time.

 Data Retention

Personal data is stored only for as long as necessary:
    •    reservation data is retained for the duration required to manage the reservation and related customer service
    •    analytics data is stored in accordance with the retention periods defined by the service providers

Disclosure of Personal Data

Personal data is not disclosed to third parties. Data may be disclosed to authorities only where required by law or official regulations.

Transfers Outside the EU/EEA

Some service providers (such as Google and Meta) may process data outside the EU or EEA. In such cases, data transfers are carried out in accordance with applicable data protection legislation, using appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.

Data Subject Rights

Data subjects have the right to:
    •    access their personal data
    •    request correction or deletion of data
    •    restrict or object to the processing of data
    •    withdraw consent at any time
 

Requests regarding these rights can be submitted using the contact details above.

Data Security

Appropriate technical and organizational measures are used to protect personal data against unauthorized access, loss, alteration, or misuse.

Changes to This Privacy Policy

This Privacy Policy may be updated when necessary. The most current version is always available on the website.

bottom of page