Dyne

Privacy Notice

Last updated: 2 August 2026 · This notice is maintained by Dyne and explains how we process personal data under the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.

1. Controller and contact details

Dyne (dyne.fi) is a restaurant discovery and table-booking service operating in Helsinki, Finland. Dyne is the data controller for the processing described in this notice.

Controller: Emilia Huikko and Agathon Westin, trading as Dyne (joint controllers).

Business ID: Dyne has not yet been incorporated and therefore has no Finnish Business ID (Y-tunnus). A Business ID and the registered company details will be added to this notice once the company is registered.

Postal address: Kulmakatu 5 B 23, 00170 Helsinki, Finland.

Privacy contact: dynerestaurants@gmail.com. Privacy requests and personal data breach handling are the joint responsibility of Emilia Huikko and Agathon Westin, who can both be reached at that address. Dyne has not appointed a Data Protection Officer; a DPO is not required for processing of this scale.

Restaurants listed on Dyne are separate controllers for the booking data they receive from us and for how they use it in their own operations. Their obligations are set out in our Restaurant Partner Agreement.

2. Categories of personal data we process

CategoryData
Booking dataName, email address, optional phone number, date and time, party size, occasion, and any notes you add (which may include dietary or allergy information).
Booking verification dataA one-time 6-digit code (stored hashed), the email it was sent to, attempt counts, and a device trust cookie identifier.
Diner account dataEmail address, authentication identifiers, sign-in timestamps, and — if you sign in with Google — the basic profile data Google returns (name, email, avatar URL).
Restaurant partner dataWork email address, account identifiers, and the restaurant content the partner publishes (description, photos, menu, opening hours, booking settings).
Venue enquiry dataVenue name, contact name, email, optional phone number and message submitted via the “List your venue” form.
Administrative dataInternal support notes about a customer, and an append-only audit log of administrative actions (who did what, when, and why).
Security and technical dataRate-limiting records tied to a hashed actor key, sign-in attempt records for administrator accounts, session records, email delivery logs, and server error logs.

We do not knowingly process data about children, and we do not ask for special-category data. Allergy information you voluntarily enter into a booking note may relate to health; we pass it to the restaurant solely so they can host you safely, and it is removed when the booking record is anonymised.

3. Purposes and legal bases

PurposeLegal basis
Creating, confirming, amending and cancelling table bookings, and sending the related transactional emails.Article 6(1)(b) — performance of a contract (or steps taken at your request before entering one).
Verifying that a booking email address is genuine, using a one-time code.Article 6(1)(f) — legitimate interest in preventing fake and abusive reservations that harm restaurants.
Operating diner and restaurant-partner accounts, including authentication and password resets.Article 6(1)(b) — performance of a contract.
Responding to venue enquiries and onboarding restaurants.Article 6(1)(b) / 6(1)(f) — pre-contractual steps and our legitimate interest in growing the marketplace.
Preventing abuse: rate limiting, brute-force protection, administrator step-up authentication and audit logging.Article 6(1)(f) — legitimate interest in the security and integrity of the service.
Diagnosing errors and keeping the service reliable.Article 6(1)(f) — legitimate interest in a working, secure service.
Complying with accounting, tax and legal obligations, and handling disputes.Article 6(1)(c) — legal obligation; Article 6(1)(f) — establishing or defending legal claims.

Where we rely on legitimate interests, we have balanced those interests against your rights and limited the processing to what is necessary. You may object at any time (see section 8).

4. Recipients and processors

The restaurant you book. They receive your name, email, optional phone number, party size, time and booking notes so they can hold and host your table. They receive nothing else.

RecipientRoleWhat they process
Lovable Cloud (application hosting, database, authentication, file storage)ProcessorAll application data at rest and in transit.
Transactional email provider used by our platformProcessorRecipient email address and the content of booking, verification and account emails.
Google (Sign in with Google, optional)Independent controller for its own authenticationYour Google account identifier and basic profile, only if you choose Google sign-in.
OpenStreetMap tile serversIndependent controllerYour IP address and browser request data when a map is displayed.
Error and performance loggingHandled by our hosting provider (above)Technical error details and request paths. Dyne does not use a separate third-party error-monitoring service.

We do not sell personal data and we do not use it for advertising or profiling. We may disclose data to authorities where legally required.

5. International transfers

We aim to keep processing within the European Economic Area. Some providers (for example Google, and certain email providers) may process data outside the EEA. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses, an adequacy decision (such as the EU–US Data Privacy Framework), or another Chapter V safeguard, together with the provider's supplementary technical measures. You can request details of the specific safeguards from dynerestaurants@gmail.com.

6. Retention periods

DataRetention
BookingsKept for 24 months from creation, then automatically anonymised (name, email, phone and notes removed) and retained only as non-identifying statistics.
Booking verification codesDeleted automatically after 7 days; the code expires within minutes of being sent.
Device trust cookie for skipping re-verification90 days.
Diner and partner accountsKept while the account exists. Deleted or anonymised on request, or after 36 months of inactivity.
Internal support notes24 months.
Administrative audit log24 months (append-only; cannot be edited).
Administrator sign-in attempt records12 months.
Rate-limiting records30 days.
Email delivery logs90 days.
Venue enquiries24 months.
Server error logsUp to 90 days at our hosting provider.

These periods are enforced by an automated nightly clean-up job. Data needed to meet accounting or legal obligations, or to defend a legal claim, may be retained longer where the law requires it. The full policy is set out in our Data Retention Policy.

7. Cookies and browser storage

Dyne uses only strictly necessary cookies and browser storage:

PurposeTypeLifetime
Authentication — keeping you signed in to a diner, partner or administrator sessionLocal storage / session tokenUntil sign-out or session expiry
Booking verification — remembering that this device already confirmed its email, so you are not asked for a code againHttpOnly, Secure, SameSite cookie90 days
Security — administrator step-up gate and abuse protection stateSession storage / short-lived tokenUntil the browser tab is closed or the session expires

All of these are necessary to deliver a service you have explicitly requested, so under the ePrivacy Directive (as implemented in Finland) they are exempt from consent and no cookie consent banner is required. We use no advertising, tracking or third-party analytics cookies. If we ever introduce non-essential cookies, we will ask for your consent before setting them and update this notice first.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy (Article 15);
  • have inaccurate data corrected (Article 16);
  • have your data erased where the legal conditions are met (Article 17);
  • restrict processing in certain circumstances (Article 18);
  • receive data you provided in a portable, machine-readable format (Article 20) — we provide exports as JSON;
  • object to processing based on legitimate interests, including our anti-abuse measures (Article 21);
  • withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email dynerestaurants@gmail.com from the address associated with your bookings or account. We verify your identity before acting and respond within one month, extendable by two further months for complex requests. Exercising your rights is free unless a request is manifestly unfounded or excessive.

Note that bookings already shared with a restaurant remain with that restaurant as a separate controller — contact them directly for data held in their own systems.

You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) or the supervisory authority in your country of residence.

9. Security

Access to personal data is restricted by role. Diners can only see their own bookings, restaurants only bookings for their venue, and administrator access requires a password, an emailed one-time code, a system access code and a short-lived session — every administrative action is written to an append-only audit log with a stated reason. Data is encrypted in transit (HTTPS) and at rest by our hosting provider. Public endpoints are rate limited and protected against brute force.

10. Data breaches

We maintain an internal incident-response procedure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Finnish Data Protection Ombudsman within 72 hours of becoming aware of it, and inform affected individuals without undue delay where the risk is high.

11. Changes to this notice

We may update this notice as the service evolves. The current version is always available on this page; material changes will be highlighted on the site.

See also our Terms of Service and Data Retention Policy.