Privacy Policy
Hoitohuone Ogelia – customer register. Updated 3 October 2026.
1. Controller
Hoitohuone Ogelia
Business ID: 1731918-1
Address: Kivalterintie 21 A, 00620 Helsinki, Finland
Email: annastiina@ogelia.fi
Contact person for register matters
Annastiina Honkanen
Email: ogelia.annastiina@gmail.com
Name of the register: Hoitohuone Ogelia customer register.
2. Purposes of processing personal data
We process personal data for the following purposes:
- managing appointments and providing and delivering treatment services
- managing the customer relationship and customer communication
- invoicing, payment and accounting
- meeting statutory obligations
- direct marketing with the customer’s consent
3. Legal bases for processing (GDPR Article 6)
- Contract (Art. 6(1)(b)): booking and delivering the treatment service.
- Legal obligation (Art. 6(1)(c)): for example accounting and tax obligations.
- Consent (Art. 6(1)(a)): additional information given voluntarily, and any direct marketing. Consent can be withdrawn at any time.
- Legitimate interest (Art. 6(1)(f)): for example service development and prevention of misuse, where it does not override the data subject’s interests.
4. Processing of health data (special categories of personal data, GDPR Article 9)
In connection with treatments we may process health-related data (for example ailments, allergies, medication, treatment history). These are special categories of personal data whose processing requires a specific basis under Article 9.
Healthcare services: the processing of health data is based on GDPR Art. 9(2)(h) (provision of health or social care). The data is handled by a person bound by confidentiality. The preparation and retention of patient records is governed by the Finnish Act on the Status and Rights of Patients (785/1992) and the Ministry of Social Affairs and Health decree on patient records (298/2009).
5. Personal data processed
- name and contact details (address, phone number, email address)
- date of birth (and, where legally required, personal identity code)
- booked services and appointment times
- treatment-related health data provided by the customer themselves (see section 4)
- invoicing and payment data
- customer communication and any feedback
6. Regular sources of data
Data is primarily obtained from the customer themselves at the time of booking (including the Booksalon online booking), by phone, by email, or at the clinic.
7. Recipients, processors and other controllers
We do not disclose personal data to outside parties for marketing purposes.
(a) Personal data processor (processes data on our behalf, under our instructions; a data processing agreement is in place):
- Book Salon Oy – booking and customer-management software. Booksalon privacy policy: booksalon.fi/fi-fi/privacy-policy.
(b) Independent controllers to whom data is disclosed in connection with payment (they process the data for their own statutory purposes, such as payment services and anti-money-laundering):
- Book Salon Oy as a payment institution (payment transmission and settlements)
- the card payment acquirer / payment processor Adyen
- employee-benefit providers used by the customer to pay (e.g. Edenred, ePassi) — each under its own privacy policy
In addition, data may be disclosed to authorities in order to meet statutory obligations.
8. Transfer of data outside the EU or EEA
Hoitohuone Ogelia does not itself transfer personal data outside the EU or EEA. In connection with payment processing, however, the payment processor Adyen may transfer some payment-transaction data to Adyen group companies and service providers located outside the EEA. Adyen states that it protects these transfers with the European Commission’s Standard Contractual Clauses; intra-group transfers use an intra-group agreement containing Standard Contractual Clauses. Further information is available in Adyen’s privacy policy: adyen.com/privacy-policy.
9. Retention period for personal data
We retain personal data only as long as is necessary for the purpose of processing or for statutory obligations:
- accounting material: vouchers for 6 years and accounting books for 10 years from the end of the financial year (Finnish Accounting Act)
- patient records: the retention periods under decree 298/2009
- other customer data: for the duration of the customer relationship and, after that, only for as long as necessary; unnecessary data is deleted regularly
10. Rights of the data subject
The data subject has the right to:
- access their own data (right of access)
- request the correction of inaccurate or incomplete data
- request the erasure of data where there is no lawful basis for processing
- restrict or object to processing
- prohibit direct marketing
- withdraw a given consent at any time
- transfer the data they have provided from one system to another (Art. 20), where processing is based on a contract or consent and is automated
- lodge a complaint with the supervisory authority
Requests: requests concerning these rights should be addressed to the contact person named in section 1. Identity may be verified where necessary before a request is carried out.
Supervisory authority: Office of the Data Protection Ombudsman, P.O. Box 800, 00531 Helsinki, tietosuoja.fi, switchboard +358 29 566 6700.
11. Principles of protecting the register
Manual material is kept in a locked space accessible only to authorised persons. Electronic material is appropriately protected: data traffic is encrypted (SSL/TLS), access requires personal credentials, and access rights are limited according to role. The material is backed up. The processing of personal data does not involve automated decision-making or profiling.
12. Cookies
The website uses only necessary cookies. Users can manage cookies through their browser settings.