PRIVACY POLICY (GDPR)

This privacy policy describes how Pizzeria Napoli collects, processes, and protects customers’ personal data in accordance with the EU General Data Protection Regulation (GDPR).

1. Data Controller

Company name: Merluzzo Oy, Pizzeria Napoli
Business ID: 1062572-5
Address: Pizzeria Napoli, Aleksanterinkatu 31, 33100 Tampere, Finland
Email: napoli@pizzerianapoli.fi
Website: www.pizzerianapoli.fi

2. Contact Person for Data Protection Matters

Entrepreneur, Johannes Räsänen
johannes.rasanen@pizzerianapoli.fi
+358 40 508 5320

3. Name of the Register

Pizzeria Napoli customer and online store register.

4. Purpose and Legal Basis for Processing Personal Data

We process personal data for the following purposes:

Online store: Sale of gift cards, delivery, and order management (processing based on contract).

Customer service: Handling table reservations and feedback.

Legal obligations: For example, compliance with accounting legislation.

5. Data Content Processed

We collect only the data necessary for processing, such as:

  • Name
  • Email address (for gift card delivery and receipt)
  • Phone number
  • Payment-related information (we do not store card details ourselves; these are handled by the payment service provider)
  • For business customers: Business ID and billing information

6. Regular Sources of Data

Data is primarily obtained directly from the customer:

  • When placing an order in the online store
  • When making a table reservation or submitting feedback
  • Through website cookies (analytics)

7. Data Disclosure and Transfers

Data may be disclosed to third parties only to implement the service:

  • Payment service providers (e.g., Paytrail, Stripe, or banks) to process payments
  • IT service providers: website and email hosting providers
  • Authorities: within the scope of legal obligations, such as accounting

As a rule, data is not transferred outside the EU or EEA.

8. Data Retention Period

We retain personal data only as long as necessary to fulfill the purposes defined in this policy.

  • Online store order data is retained for the period required by accounting law (6 years after the end of the financial year).
  • Gift card data is retained as long as the gift card is valid.

9. Principles of Register Protection

Your data is important to us. Electronically processed data is protected with user-specific credentials and passwords. Access to data is limited to persons whose duties require it.

10. Rights of the Data Subject

You have the right to:

  1. Access your personal data
  2. Request correction of incorrect data
  3. Request deletion of your data (right to be forgotten), if there is no longer a legal basis for processing
  4. Object to direct marketing
  5. File a complaint with the Data Protection Ombudsman if you believe we violate data protection legislation

If a person wishes to review data stored about them or request correction, the request must be submitted in writing to the data controller. The data controller may request verification of identity if necessary. The data controller will respond within the timeframe specified in the EU General Data Protection Regulation (generally within one month).

Scroll to Top