Personal data
Privacy notice
How the restaurant handles personal data for orders, reservations and enquiries.
Last updated: 2026-08-05
1. Controller and contact details
Meze House Oy · 3321260-8 · Vihdintie 4-6 B 24, 03100 Nummela · mezehouse.fi@gmail.com · +358 41 3138888
2. Personal data we process
- Name, email address, telephone number and communication language.
- Reservation, catering and other enquiry details, including requested date, party size, company information and messages.
- IP address, device and browser information, security logs, consent records and identifiers needed to prevent duplicate or fraudulent submissions.
3. Purposes of processing
- To receive, confirm, prepare, deliver and support orders, reservations and catering requests.
- To meet accounting, tax, food-safety, consumer-protection and other legal obligations.
- To secure the service, prevent fraud, verify transactions and investigate misuse.
- To respond to enquiries, complaints, cancellations and refund requests and to improve operations.
- To send marketing only when the customer has given a separate consent, which can be withdrawn at any time.
4. Legal bases
Processing is based on performance of a contract or steps requested before a contract, compliance with legal obligations, the restaurant’s legitimate interests in security and customer service, and consent where required for marketing, analytics or optional external content.
5. Recipients and processors
Data is disclosed only when needed for the stated purposes or required by law. Processor agreements and access restrictions must be used where applicable.
- Website hosting, maintenance, security and backup providers.
- Transactional email and communications providers.
- Authorised restaurant staff and management.
- Accounting and bookkeeping providers for statutory records.
- Public authorities, courts, insurers or advisers where disclosure is legally required or necessary to establish, exercise or defend legal claims.
6. International transfers
The restaurant should prefer providers processing data in the EU/EEA. If a provider processes data outside the EU/EEA, the transfer must use a lawful safeguard such as an adequacy decision or the European Commission’s standard contractual clauses.
7. Retention periods
- Operational order data is retained for up to 24 months unless a longer period is needed for an active dispute, chargeback or legal obligation.
- Reservation data is retained for up to 12 months after the reservation.
- Catering and other enquiries are retained for up to 12 months after the matter is closed.
- Invoices, receipts and other accounting material are retained for the statutory accounting period; data not needed for accounting is deleted or anonymised earlier.
- Security and technical logs are retained only for the time reasonably needed to detect misuse, investigate incidents and maintain the service.
8. Your rights
- Request access to your personal data.
- Request correction of inaccurate or incomplete data.
- Request deletion when there is no lawful reason to retain the data.
- Request restriction of processing in the situations provided by law.
- Object to processing based on legitimate interests and always object to direct marketing.
- Receive data you provided in a machine-readable format when the legal requirements are met.
- Withdraw consent at any time without affecting earlier lawful processing.
- Lodge a complaint with the Office of the Data Protection Ombudsman in Finland.
Send a privacy request to mezehouse.fi@gmail.com
9. Security
Access is limited by individual accounts and roles. Prices and order totals are calculated on the server. The service uses transport encryption, audit records, rate limits, secure tokens and backups appropriate to the risk. No internet service can guarantee absolute security.
10. Cookies and analytics
Only cookies and local storage necessary for language choice, cart, login, security and consent management are used unless the customer enables optional content.
11. Fraud prevention and automated checks
The service may assign a risk score using order value, order frequency, payment method and technical signals. The score can trigger verification or manual review, but it does not by itself make a decision that produces legal or similarly significant effects.