Privacy Policy
Hotel Oscar customer register
Privacy notice on the processing of personal data in Hotel Oscar’s customer register, in accordance with the EU General Data Protection Regulation.
1. Data Controller
Nemeko Oy (Business ID 0934336-8), Furuborginkatu 3, 00980 Helsinki
2. Contact details for matters concerning the register
For matters concerning the register and the exercise of data subjects’ rights, please contact:
Email: reception@hoteloscar.fi
3. Name of the register
Hotel Oscar – Customer Register
4. Legal basis for processing personal data
The processing of personal data is based on legitimate interest: the personal data in the customer register is processed in connection with customer relationships with consumer and business customers at Nemeko Oy. The data controller also processes customer data on the basis of a contract between the data controller and the data subject. On this basis, personal data provided by customers when making restaurant or room reservations, or for restaurant and room billing, is processed.
5. Purposes of processing personal data
The purposes for which customer data in the customer register is used are:
- handling customer bookings
- customer relationship management and development
- customer relationship communications
- sales and delivery of services
- marketing of services
- processing of personal data related to payments, invoicing, payment monitoring and debt collection
- developing the data controller’s business and customer services
Any dietary information provided by the customer will only be used to prepare and serve food.
6. Personal data processed
The controller processes the following personal data:
- customer’s first and last name, date of birth, phone number, address, email address
- nationality
- reservation details
- information about service usage and purchases
- customer payment details, billing details, any payment delay information
- information about the customer’s choices and preferences
- any customer feedback and complaint information
- information provided by the individual about opting out of direct marketing as required by law
For corporate customers, the data controller processes the following personal data:
- company contact person’s name, address, email address and telephone number
- any customer feedback and complaint information
- direct marketing opt-out details, as required by law, provided by the company’s contact person
7. Sources of Personal Data
The data controller receives personal data:
- from the individuals themselves, for example by email or phone, or at promotional events
- information collected when using our services and during visits
- via order and quote request forms on its website
- third-party restaurant table-booking websites
- external hotel booking service companies
- from the registered employer when booking services
- From a subsidiary belonging to the Nemeko Oy group
- from external sources, such as public registers
8. Recipients of personal data or categories of recipients
Only employees whose duties involve handling customer register data may process it. Access to the register is protected by individual usernames and passwords. Data is not disclosed to third parties. However, data may be disclosed to public authorities in response to requests made under applicable law.
9. Transfers of data outside the EU
We use subcontractors to provide our services, who may be based outside the EU or European Economic Area. When data is transferred outside the EU and EEA, we ensure an adequate level of protection for personal data, including by agreeing on matters relating to the confidentiality and processing of personal data as required by law.
10. Data Retention Period
Customers’ personal data in the customer register is processed for the duration of the customer relationship. The controller considers the customer relationship to have ended if the customer has not used the company’s services for 2 years.
After the customer relationship ends, information may still be retained and processed if required for a legitimate reason or to handle complaints. Data in the customer register is retained in accordance with legally required retention periods, such as those set out in the Accounting Act. Information required under the Accounting Act is retained for as long as the Act requires.
Company customer contact details will be deleted in the same way once the company is no longer considered a customer. The information may nevertheless be retained after this if there is another legal basis for doing so.
When data is processed on the basis of a contract between the controller and the data subject, it is retained for as long as necessary to fulfil the contract. Once the contract has been fulfilled, the data is retained for as long as the customer relationship exists or there is another basis for processing (e.g. complaints or accounting legislation).
During the customer relationship, only data necessary for the specified purposes is processed. The data controller conducts regular reviews to delete unnecessary data.
11. Data subject rights
The data subject has the right to request access to their personal data and to request that any inaccurate data be corrected. At the data subject’s request, processing may be restricted or the data may be deleted from the register entirely. The data subject has the right to object to the use of their data, for example, for direct marketing.
12. Right to lodge a complaint with a supervisory authority
The data subject has the right to lodge a complaint with the competent supervisory authority if they consider that the controller has not complied with applicable data protection regulations in its activities.
13. Requests to exercise data subjects’ rights
For questions about the processing of personal data or to exercise their rights, data subjects may contact the controller’s contact person named in section 2.
Requests to exercise the right of access or any other data subject rights must be submitted to the data controller in writing, either by email or post. A request may also be made in person at the data controller’s premises. The data controller may ask the data subject to clarify sufficiently what information or processing activities their request concerns.
To ensure that personal data is not disclosed to anyone other than the data subject in connection with the exercise of their rights, the controller may, if necessary, ask the data subject to submit a signed inspection request. The controller may also ask the person making the request to prove their identity using an official identity document or another reliable method.
Updated 17 Apr 2026