Privacy Policy

Hoitohuone Ogelia – customer register. Updated 3 October 2026.

1. Controller

Hoitohuone Ogelia
Business ID: 1731918-1
Address: Kivalterintie 21 A, 00620 Helsinki, Finland
Email: annastiina@ogelia.fi

Contact person for register matters

Annastiina Honkanen
Email: ogelia.annastiina@gmail.com

Name of the register: Hoitohuone Ogelia customer register.

2. Purposes of processing personal data

We process personal data for the following purposes:

3. Legal bases for processing (GDPR Article 6)

4. Processing of health data (special categories of personal data, GDPR Article 9)

In connection with treatments we may process health-related data (for example ailments, allergies, medication, treatment history). These are special categories of personal data whose processing requires a specific basis under Article 9.

Healthcare services: the processing of health data is based on GDPR Art. 9(2)(h) (provision of health or social care). The data is handled by a person bound by confidentiality. The preparation and retention of patient records is governed by the Finnish Act on the Status and Rights of Patients (785/1992) and the Ministry of Social Affairs and Health decree on patient records (298/2009).

5. Personal data processed

6. Regular sources of data

Data is primarily obtained from the customer themselves at the time of booking (including the Booksalon online booking), by phone, by email, or at the clinic.

7. Recipients, processors and other controllers

We do not disclose personal data to outside parties for marketing purposes.

(a) Personal data processor (processes data on our behalf, under our instructions; a data processing agreement is in place):

(b) Independent controllers to whom data is disclosed in connection with payment (they process the data for their own statutory purposes, such as payment services and anti-money-laundering):

In addition, data may be disclosed to authorities in order to meet statutory obligations.

8. Transfer of data outside the EU or EEA

Hoitohuone Ogelia does not itself transfer personal data outside the EU or EEA. In connection with payment processing, however, the payment processor Adyen may transfer some payment-transaction data to Adyen group companies and service providers located outside the EEA. Adyen states that it protects these transfers with the European Commission’s Standard Contractual Clauses; intra-group transfers use an intra-group agreement containing Standard Contractual Clauses. Further information is available in Adyen’s privacy policy: adyen.com/privacy-policy.

9. Retention period for personal data

We retain personal data only as long as is necessary for the purpose of processing or for statutory obligations:

10. Rights of the data subject

The data subject has the right to:

Requests: requests concerning these rights should be addressed to the contact person named in section 1. Identity may be verified where necessary before a request is carried out.

Supervisory authority: Office of the Data Protection Ombudsman, P.O. Box 800, 00531 Helsinki, tietosuoja.fi, switchboard +358 29 566 6700.

11. Principles of protecting the register

Manual material is kept in a locked space accessible only to authorised persons. Electronic material is appropriately protected: data traffic is encrypted (SSL/TLS), access requires personal credentials, and access rights are limited according to role. The material is backed up. The processing of personal data does not involve automated decision-making or profiling.

12. Cookies

The website uses only necessary cookies. Users can manage cookies through their browser settings.