Privacy Notice
Last updated: 2 August 2026 · This notice is maintained by Dyne and explains how we process personal data under the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.
1. Controller and contact details
Dyne (dyne.fi) is a restaurant discovery and table-booking service operating in Helsinki, Finland. Dyne is the data controller for the processing described in this notice.
Controller: Emilia Huikko and Agathon Westin, trading as Dyne (joint controllers).
Business ID: Dyne has not yet been incorporated and therefore has no Finnish Business ID (Y-tunnus). A Business ID and the registered company details will be added to this notice once the company is registered.
Postal address: Kulmakatu 5 B 23, 00170 Helsinki, Finland.
Privacy contact: dynerestaurants@gmail.com. Privacy requests and personal data breach handling are the joint responsibility of Emilia Huikko and Agathon Westin, who can both be reached at that address. Dyne has not appointed a Data Protection Officer; a DPO is not required for processing of this scale.
Restaurants listed on Dyne are separate controllers for the booking data they receive from us and for how they use it in their own operations. Their obligations are set out in our Restaurant Partner Agreement.
2. Categories of personal data we process
| Category | Data |
| Booking data | Name, email address, optional phone number, date and time, party size, occasion, and any notes you add (which may include dietary or allergy information). |
| Booking verification data | A one-time 6-digit code (stored hashed), the email it was sent to, attempt counts, and a device trust cookie identifier. |
| Diner account data | Email address, authentication identifiers, sign-in timestamps, and — if you sign in with Google — the basic profile data Google returns (name, email, avatar URL). |
| Restaurant partner data | Work email address, account identifiers, and the restaurant content the partner publishes (description, photos, menu, opening hours, booking settings). |
| Venue enquiry data | Venue name, contact name, email, optional phone number and message submitted via the “List your venue” form. |
| Administrative data | Internal support notes about a customer, and an append-only audit log of administrative actions (who did what, when, and why). |
| Security and technical data | Rate-limiting records tied to a hashed actor key, sign-in attempt records for administrator accounts, session records, email delivery logs, and server error logs. |
We do not knowingly process data about children, and we do not ask for special-category data. Allergy information you voluntarily enter into a booking note may relate to health; we pass it to the restaurant solely so they can host you safely, and it is removed when the booking record is anonymised.
3. Purposes and legal bases
| Purpose | Legal basis |
| Creating, confirming, amending and cancelling table bookings, and sending the related transactional emails. | Article 6(1)(b) — performance of a contract (or steps taken at your request before entering one). |
| Verifying that a booking email address is genuine, using a one-time code. | Article 6(1)(f) — legitimate interest in preventing fake and abusive reservations that harm restaurants. |
| Operating diner and restaurant-partner accounts, including authentication and password resets. | Article 6(1)(b) — performance of a contract. |
| Responding to venue enquiries and onboarding restaurants. | Article 6(1)(b) / 6(1)(f) — pre-contractual steps and our legitimate interest in growing the marketplace. |
| Preventing abuse: rate limiting, brute-force protection, administrator step-up authentication and audit logging. | Article 6(1)(f) — legitimate interest in the security and integrity of the service. |
| Diagnosing errors and keeping the service reliable. | Article 6(1)(f) — legitimate interest in a working, secure service. |
| Complying with accounting, tax and legal obligations, and handling disputes. | Article 6(1)(c) — legal obligation; Article 6(1)(f) — establishing or defending legal claims. |
Where we rely on legitimate interests, we have balanced those interests against your rights and limited the processing to what is necessary. You may object at any time (see section 8).
4. Recipients and processors
The restaurant you book. They receive your name, email, optional phone number, party size, time and booking notes so they can hold and host your table. They receive nothing else.
| Recipient | Role | What they process |
| Lovable Cloud (application hosting, database, authentication, file storage) | Processor | All application data at rest and in transit. |
| Transactional email provider used by our platform | Processor | Recipient email address and the content of booking, verification and account emails. |
| Google (Sign in with Google, optional) | Independent controller for its own authentication | Your Google account identifier and basic profile, only if you choose Google sign-in. |
| OpenStreetMap tile servers | Independent controller | Your IP address and browser request data when a map is displayed. |
| Error and performance logging | Handled by our hosting provider (above) | Technical error details and request paths. Dyne does not use a separate third-party error-monitoring service. |
We do not sell personal data and we do not use it for advertising or profiling. We may disclose data to authorities where legally required.
5. International transfers
We aim to keep processing within the European Economic Area. Some providers (for example Google, and certain email providers) may process data outside the EEA. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses, an adequacy decision (such as the EU–US Data Privacy Framework), or another Chapter V safeguard, together with the provider's supplementary technical measures. You can request details of the specific safeguards from dynerestaurants@gmail.com.
6. Retention periods
| Data | Retention |
| Bookings | Kept for 24 months from creation, then automatically anonymised (name, email, phone and notes removed) and retained only as non-identifying statistics. |
| Booking verification codes | Deleted automatically after 7 days; the code expires within minutes of being sent. |
| Device trust cookie for skipping re-verification | 90 days. |
| Diner and partner accounts | Kept while the account exists. Deleted or anonymised on request, or after 36 months of inactivity. |
| Internal support notes | 24 months. |
| Administrative audit log | 24 months (append-only; cannot be edited). |
| Administrator sign-in attempt records | 12 months. |
| Rate-limiting records | 30 days. |
| Email delivery logs | 90 days. |
| Venue enquiries | 24 months. |
| Server error logs | Up to 90 days at our hosting provider. |
These periods are enforced by an automated nightly clean-up job. Data needed to meet accounting or legal obligations, or to defend a legal claim, may be retained longer where the law requires it. The full policy is set out in our Data Retention Policy.
7. Cookies and browser storage
Dyne uses only strictly necessary cookies and browser storage:
| Purpose | Type | Lifetime |
| Authentication — keeping you signed in to a diner, partner or administrator session | Local storage / session token | Until sign-out or session expiry |
| Booking verification — remembering that this device already confirmed its email, so you are not asked for a code again | HttpOnly, Secure, SameSite cookie | 90 days |
| Security — administrator step-up gate and abuse protection state | Session storage / short-lived token | Until the browser tab is closed or the session expires |
All of these are necessary to deliver a service you have explicitly requested, so under the ePrivacy Directive (as implemented in Finland) they are exempt from consent and no cookie consent banner is required. We use no advertising, tracking or third-party analytics cookies. If we ever introduce non-essential cookies, we will ask for your consent before setting them and update this notice first.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased where the legal conditions are met (Article 17);
- restrict processing in certain circumstances (Article 18);
- receive data you provided in a portable, machine-readable format (Article 20) — we provide exports as JSON;
- object to processing based on legitimate interests, including our anti-abuse measures (Article 21);
- withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email dynerestaurants@gmail.com from the address associated with your bookings or account. We verify your identity before acting and respond within one month, extendable by two further months for complex requests. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Note that bookings already shared with a restaurant remain with that restaurant as a separate controller — contact them directly for data held in their own systems.
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) or the supervisory authority in your country of residence.
9. Security
Access to personal data is restricted by role. Diners can only see their own bookings, restaurants only bookings for their venue, and administrator access requires a password, an emailed one-time code, a system access code and a short-lived session — every administrative action is written to an append-only audit log with a stated reason. Data is encrypted in transit (HTTPS) and at rest by our hosting provider. Public endpoints are rate limited and protected against brute force.
10. Data breaches
We maintain an internal incident-response procedure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Finnish Data Protection Ombudsman within 72 hours of becoming aware of it, and inform affected individuals without undue delay where the risk is high.
11. Changes to this notice
We may update this notice as the service evolves. The current version is always available on this page; material changes will be highlighted on the site.
See also our Terms of Service and Data Retention Policy.