Legal Information
Privacy Policy
Last updated: 3 September 2026
This Privacy Policy explains how Makukulma Oy (business ID 3565498-7), trading as Suomi Poké (“we”, “us”), collects, uses and protects personal data when you use the website suomipoke.fi, place orders, make reservations or otherwise interact with our services. We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Finnish Data Protection Act and other applicable data protection legislation.
1. Data controller
- Makukulma Oy (business ID 3565498-7)
- Hämeenkatu 12, 20500 Turku, Finland
- Email: hei@suomipoke.fi
- Phone: +358 41 472 7680
All questions concerning this Privacy Policy or the processing of your personal data can be directed to the contact details above. We aim to respond to requests within one month.
2. What personal data we process and why
We process the following categories of personal data. For each category, we state the purpose of the processing and the legal basis under Article 6 of the GDPR.
- Account data — name, email address, phone number, delivery address, password and account type. If you register with Google, we receive the name, email address and profile picture that you have allowed Google to share. Purpose: managing your account, orders, loyalty programme and customer service. Legal basis: performance of a contract (Article 6(1)(b)); consent for the data received through Google sign-in (Article 6(1)(a)).
- Order data — ordered items and customisations, prices, order status, delivery or pickup details, payment method and any notes you give us. Purpose: preparing and delivering your order, handling payments and providing customer service. Legal basis: performance of a contract (Article 6(1)(b)); compliance with accounting and tax obligations (Article 6(1)(c)); our legitimate interest in handling complaints and preventing fraud (Article 6(1)(f)).
- Payment data — online card payments are processed by our payment service provider Stripe. We do not store your full card number. Legal basis: performance of a contract (Article 6(1)(b)) and legal obligations (Article 6(1)(c)).
- Reservation data — name, contact details, number of guests, date and time, and any special requests. Purpose: managing and confirming table reservations. Legal basis: performance of a contract (Article 6(1)(b)).
- Loyalty and promotion data — membership number, purchase history, loyalty stars, discounts, referral information and credits. Purpose: operating the loyalty programme and promotions. Legal basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in rewarding returning customers (Article 6(1)(f)).
- Newsletter data — your email address. Purpose: sending you our newsletter and offers you have requested. Legal basis: your consent (Article 6(1)(a)). You can unsubscribe at any time.
- Messages and inquiries — name, contact details and the content of your message submitted through our contact form, customer service or B2B/catering inquiry form. Purpose: responding to and handling your inquiry. Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b)) and our legitimate interest in serving our customers (Article 6(1)(f)).
- Technical and usage data — device and browser type, IP address, pages visited and interactions with the Service, and settings such as language preference. Purpose: keeping the Service secure and functional and improving it. Legal basis: our legitimate interest (Article 6(1)(f)).
3. Where we get personal data from
- From you directly — when you create an account, place an order, make a reservation, subscribe to the newsletter or contact us.
- From Google — if you sign in with Google, we receive the profile data you have chosen to share with us.
- Automatically — technical data collected when you use the Service (see section 2 above).
- We do not purchase personal data from third parties.
4. Who we share personal data with
We share personal data only with parties that need it to run the Service, and only to the extent necessary. We never sell personal data. Categories of recipients:
- Payment service providers (Stripe) — for processing card payments.
- Identity providers (Google) — for Google sign-in; Google processes the data you have chosen to share in accordance with its own privacy policy.
- IT, hosting and cloud service providers — for example server hosting, database services and image hosting, which keep the Service running and secure.
- Email and messaging service providers — for sending transactional messages such as order confirmations and verification emails, and for WhatsApp Business notifications about new orders to the restaurant.
- Accounting and legal service providers — to the extent required by law, for example for bookkeeping and tax obligations.
Our employees and service providers process personal data only on a need-to-know basis and are bound by confidentiality. All service providers that process personal data on our behalf act as our processors under a written data processing agreement.
5. Transfers outside the EEA
Some of our service providers, such as Stripe, Google and Meta (WhatsApp), are based in the United States or otherwise process data outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we rely on an adequacy decision adopted by the European Commission or, where no adequacy decision exists, on appropriate safeguards such as the European Commission's standard contractual clauses, together with supplementary technical and organisational measures where necessary. You may request a copy of the relevant safeguards from our privacy contact.
6. How long we keep personal data
- Order and payment records — retained for six (6) years as required by the Finnish Accounting Act, after which they are erased or anonymised.
- Customer account data and loyalty history — retained while the account is active and erased after the account is closed or after a reasonable period of inactivity (24 months), unless a statutory retention obligation applies.
- Reservation data — retained for up to twelve (12) months after the reservation.
- Contact form and B2B inquiries — retained while the matter is being handled and for a reasonable period afterwards (up to 24 months after the last contact).
- Newsletter data — retained until you unsubscribe or we discontinue the newsletter.
- Technical and usage data — retained for up to 26 months, unless a longer retention is required for security or legal reasons.
7. Security of personal data
We protect personal data with appropriate technical and organisational measures, including encrypted connections (HTTPS), hashed storage of passwords, restricted access rights, backups and written data processing agreements with our service providers. No method of electronic transmission or storage is completely secure, and you provide your data to us at your own risk.
8. Cookies and local storage
We use strictly necessary, functional technologies to make the Service work: session cookies needed to keep you signed in, and small amounts of data stored in your browser's local storage, such as your language preference and the contents of your shopping cart. We do not use cookies or similar technologies for advertising or cross-site tracking, and we do not sell data to advertisers. You can delete or block these technologies in your browser settings; this may affect how the Service functions.
9. Your rights
Under the GDPR you have the following rights, which you may exercise free of charge by contacting us at hei@suomipoke.fi:
- Right of access — to receive a copy of the personal data we hold about you.
- Right to rectification — to have inaccurate or incomplete personal data corrected.
- Right to erasure (“right to be forgotten”) — to have your personal data deleted where there is no legal basis for continued processing.
- Right to restriction of processing — to restrict how we process your personal data in certain situations.
- Right to data portability — to receive the personal data you have provided in a structured, machine-readable format and to transmit it to another controller.
- Right to object — to object to processing based on our legitimate interest, where your specific situation gives grounds to do so.
- Right to withdraw consent — to withdraw your consent at any time, for example by unsubscribing from the newsletter. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
We will respond to your request without undue delay and within one (1) month, which we may extend by two further months where necessary. We may ask you to verify your identity before processing your request. If you are not satisfied with how we handle your personal data, you may lodge a complaint with the Finnish Data Protection Ombudsman (Office of the Data Protection Ombudsman, Lintulahdenkuja 4, 00530 Helsinki; https://www.tietosuoja.fi).
10. Automated decision-making
We do not use automated decision-making, including profiling, that produces legal effects concerning you or otherwise significantly affects you. Loyalty discounts and similar benefits are calculated using simple, transparent rules.
11. Children
The Service is not directed at children. We do not knowingly collect personal data from children under the age of 16 without the consent of a parent or guardian. If we learn that we have collected such data, we will delete it without undue delay.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example when the Service or legal requirements change. The current version is always available on this page together with the date it was last updated. Where changes are significant, we will draw attention to them on the Service.
13. Contact
Makukulma Oy, Hämeenkatu 12, 20500 Turku, Finland · hei@suomipoke.fi · +358 41 472 7680. If you have any questions about this Privacy Policy or the processing of your personal data, please contact us — we are happy to help.