Privacy Policy
Key points at a glance
- Meeting Park Group Ltd. operates the Meeting Park online service and forwards the customer’s booking to the venue or service provider identified in the booking.
- The customer can see the Service Provider when viewing the venue or service. The contracting party and invoicing entity are also identified in the booking confirmation.
- Booking data is disclosed only to the Service Provider responsible for that booking and to technical service providers that need to process the data on Meeting Park’s behalf.
- Meeting Park does not sell personal data or disclose it to third parties for their own marketing purposes.
- Payment is made to the Service Provider identified in the booking confirmation. The Meeting Park online service does not request or store payment card numbers, card security codes, online banking credentials or personal identity codes.
- The website does not currently use analytics or marketing cookies. Only cookies that are necessary for the operation of the service are used.
1. Who does this Notice apply to?
This Privacy Notice applies to visitors and users of the Meeting Park online service, including:
- people making bookings and other contact persons connected with a booking;
- contact persons of corporate and organisational customers;
- account holders when user accounts are introduced;
- people who contact customer service; and
- newsletter subscribers.
This Notice describes the processing of personal data carried out by Meeting Park Group Ltd.. The Service Provider identified in the booking confirmation is responsible for its own processing in connection with matters such as delivering the service, invoicing, accounting, access control or video surveillance.
2. Controller and contact details
Meeting Park Group Ltd.Business ID: 2869233-6
Visiting address: Mechelininkatu 3 C, FI-00100 Helsinki, Finland
Postal address: PO Box 275, FI-00101 Helsinki, Finland
Email: support@meetingpark.fi
Telephone: +358 10 5011 501
The contact person for data protection matters is Kare Casals, Managing Director.
Questions and requests concerning data protection or your personal data may be sent to support@meetingpark.fi. You may use “Data protection request” as the subject line.
3. Roles of Meeting Park and the Service Provider
Meeting Park Group Ltd.
Is responsible for personal data processing related to operating the online service, forwarding and managing bookings, customer service, information security, corporate customer relationships and its own marketing.
Service Provider
Is responsible for the data it needs to deliver the service, maintain safety and security, issue invoices, keep accounting records and comply with its other legal obligations.
The Service Provider may be a company within the Meeting Park group or an independent third-party company.
Meeting Park Group Ltd. is not currently the venue or service provider or the invoicing entity identified in the booking confirmation. If this changes, this Privacy Notice will be updated before the new processing begins.
4. What personal data do we process?
The data we process depends on how the service is used.
4.1 Contact and customer information
- name, email address and telephone number;
- the name and Business ID of the company or other organisation and the person’s role within it;
- address and the corporate and invoicing contact details needed for a booking; and
- customer number or another internal identifier.
4.2 Booking information
- the date, time, duration, status, price and number of attendees;
- the venues and services booked;
- the person making the booking and other contact persons connected with it;
- catering, technical, accessibility and other arrangements requested by the customer;
- changes and cancellations; and
- the booking confirmation, related communications and processing history.
Dietary requirement and allergy information: This information is primarily collected as selected options and numbers of people, without the names of attendees. The person making the booking should not enter attendees’ names, diagnoses or other unnecessary health information in free-text fields. If information must exceptionally be linked to a particular person, Meeting Park will first ensure that there is a separate lawful basis for the processing, such as the explicit consent of that person.
4.3 User account information
User account registration is not currently available. When user accounts are introduced in the MeetingBooking system, an account may contain:
- the user’s name, email address and telephone number;
- username, protected password verification data and access rights;
- the selected service language and any newsletter subscription; and
- the dates and times of logins and changes.
Passwords are not stored in plain text.
4.4 Customer service and communications data
- the sender’s contact details;
- the subject, content and time of the message;
- Meeting Park’s replies; and
- information needed to handle a complaint or data protection request.
Only emails are processed in the customer service ticketing system. Other booking system data is not transferred to it unless it is included in the customer’s message or is necessary to resolve the particular matter.
4.5 Technical data from the online service
- IP address;
- basic information about the browser, device and operating system;
- page requests, logins and other technical events;
- the date and time of an event and the function used; and
- security and error logs.
4.6 Newsletter and consent information
- email address;
- the selected newsletter and language;
- the date, time and source of a subscription or unsubscribe request; and
- information needed to demonstrate consent or compliance with an objection to marketing.
Meeting Park does not track newsletter opens or link clicks at an individual recipient level.
5. Why do we process personal data and what are the legal bases?
| Purpose | Legal basis |
|---|---|
| Receiving, forwarding to the identified Service Provider, confirming and managing bookings | The legitimate interests of Meeting Park, the customer and the Service Provider in carrying out the booking requested by the customer. If Meeting Park Group Ltd. is itself a party to the contract, processing may also be based on the contract or on steps taken at the customer’s request before entering into a contract. |
| Providing a user account and online service functions requested by the customer | A contract or steps taken at the customer’s request before entering into a contract, together with the legitimate interest in maintaining the service securely. |
| Customer service, responding to enquiries and handling complaints | A contract where the matter relates to a contract, together with the legitimate interests of Meeting Park and the customer in managing the customer relationship and resolving enquiries. |
| Managing corporate customer relationships and framework agreements | A contract and the legitimate interests of Meeting Park and the corporate customer in managing the customer relationship. |
| Maintaining online service security, preventing misuse and investigating errors | The legitimate interests of Meeting Park, its customers and Service Providers in protecting the service, personal data and contractual relationships. |
| Complying with legal obligations | A legal obligation applicable to Meeting Park. |
| Establishing, exercising or defending legal claims | Meeting Park’s legitimate interest in protecting its legal rights. |
| Sending a newsletter to an individual or a personal email address | The recipient’s consent. |
| Role-related business marketing to an organisation’s address or corporate contact where permitted by law | Meeting Park’s legitimate interest in marketing its business services. The recipient can always object easily and free of charge. |
| Dietary requirement, allergy or other health information that can be linked to a person | The explicit consent of the person concerned or another basis permitted by the GDPR and established before the processing begins. |
In this context, legitimate interest means managing the booking and customer relationship requested by the customer and protecting the online service and the information stored in it. Meeting Park assesses whether the processing is necessary and considers its effects on data subjects. In certain circumstances, a person may object to processing based on legitimate interests.
6. Where do we obtain the data?
We obtain personal data:
- directly from the person through an online form, user account, email or telephone;
- from the company or organisation on whose behalf a booking is made;
- from another contact person connected with the booking;
- from the Service Provider identified in the booking confirmation where the information is needed to manage the booking or provide customer service; and
- automatically from technical use of the online service and necessary cookies.
If the person making the booking provides Meeting Park with another person’s contact details, they must ensure that there is an appropriate basis for providing the information and that the other person is informed of this Privacy Notice.
7. Which information is required?
Information marked as required on the booking form is needed to process the booking and deliver the service. Without it, the booking may not be processed or confirmed.
Providing other information is voluntary unless it is required to safely deliver a special arrangement requested by the customer.
8. Who receives the data?
Meeting Park discloses personal data only to the extent necessary to the following recipients:
- The Service Provider identified in the booking. Booking data is forwarded to the Service Provider that the customer sees when viewing the venue or service and that is identified in the booking confirmation.
- Meeting Park’s technical service providers. Providers of services such as hosting, email, newsletters, booking systems, backups, information security and IT support may process data on Meeting Park’s behalf and under its instructions.
- Professional advisers. An auditor, accountant or lawyer, for example, may receive information necessary for their work and subject to confidentiality obligations.
- Authorities and other recipients required by law. Data may be disclosed where required by law, a court decision or an order issued by a competent authority.
Meeting Park does not disclose booking data to other venue or service providers for their own marketing. Personal data is not sold or rented.
Up-to-date additional information about processors used by Meeting Park may be requested from support@meetingpark.fi.
9. Is personal data transferred outside the EU or EEA?
Meeting Park aims to use service providers that process data within the European Union or European Economic Area. However, some technical service providers or their subcontractors may also process data outside the EU or EEA.
In such cases, Meeting Park uses a transfer mechanism permitted by the GDPR, such as an adequacy decision adopted by the European Commission or the Commission’s Standard Contractual Clauses. Supplementary safeguards are used where necessary. Further information about transfers and safeguards may be requested from support@meetingpark.fi.
10. How long do we retain personal data?
Personal data is retained only for as long as it is needed for the purposes described in this Notice or as required by law.
| Category of data | Standard retention period |
|---|---|
| Information about the person making the booking, a guest or another event contact person, booking history and booking-related communications | 36 months after the event ends. Data may be retained for longer where this is necessary for an unresolved complaint, outstanding payment or legal claim. |
| Dietary requirement and allergy information | 30 days after the event ends. The information is deleted separately from the rest of the booking history. |
| An enquiry that does not result in a booking or customer relationship | 12 months after the matter is closed. |
| Contact details connected with a corporate customer relationship or framework agreement | For the duration of the customer relationship or the person’s role and for 36 months after the last booking or the end of the customer relationship, whichever is later. |
| User account | For as long as the account is used and for 36 months after the last use of the account or the end of the latest booking, whichever is later. The inactive account is then deleted or its identifying data is anonymised unless another lawful basis requires retention. |
| Online service security and event logs | 12 months unless investigating a security incident or handling a legal claim requires longer retention. |
| Active newsletter subscription data | For as long as the subscription remains active. Unsubscribing from one newsletter stops that newsletter but does not stop any other newsletters subscribed to by the person. |
| Minimum information retained after all newsletters have been unsubscribed from | Sending stops immediately. The email address, list information and information needed to demonstrate the consent and its withdrawal are retained for three years. Other profile, tracking and sending history is deleted. After three years, the minimum information is also deleted unless a limited suppression record is needed to comply with an objection to marketing or another lawful basis requires retention. |
| Evidence of consent in other situations | For the duration of the consent and for three years after it is withdrawn or expires. |
| Information included in Meeting Park Group Ltd.’s accounting records | For the period required by the Finnish Accounting Act. Vouchers and other records relating to business transactions are retained for at least six years from the end of the calendar year in which the financial period ended. Financial statements and accounting records are retained for at least ten years after the end of the financial period. |
When a retention period expires, the data is deleted or anonymised. Data in backups is removed through the normal backup rotation. If a backup is restored, data whose retention period had already expired is deleted again and is not used for any other purpose.
13. How do we protect personal data?
Meeting Park protects personal data with measures appropriate to the risks involved in the processing. These include:
- encrypted network connections;
- limiting access to people who need the data;
- user authentication and access-right reviews;
- system updates, logging and backups;
- careful selection of service providers and contractual safeguards; and
- procedures for responding to personal data breaches and other security incidents.
Personal data is accessible only to people whose duties require them to process it.
14. Automated booking confirmation
MeetingBooking may automatically check venue availability and compliance with the booking conditions, record and confirm the booking and send the booking confirmation.
This is a rule-based process that carries out the booking requested by the customer. Meeting Park does not profile individuals or use personal data to make solely automated decisions that produce legal effects or similarly significantly affect a person.
15. Your rights
Depending on the circumstances and the legal basis for processing, you may have the right to:
- obtain confirmation of whether we process your personal data and receive a copy of it;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data;
- ask us to restrict processing;
- object to processing based on legitimate interests on grounds relating to your particular situation;
- object to direct marketing at any time;
- receive the data you have provided in a machine-readable format and transmit it to another controller where the conditions for data portability are met; and
- withdraw your consent at any time.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. The right to deletion or another right may be restricted where a law, a legal claim or another ground provided for in the GDPR requires or permits the processing.
16. How to exercise your rights
Send your request by email to support@meetingpark.fi or by post to:
Meeting Park Group Ltd.Data Protection Matters
PO Box 275
FI-00101 Helsinki
Finland
We may ask for additional information that is necessary to verify your identity. We will not request more information than is needed for verification.
We will respond without undue delay and normally within one month. Where permitted by the GDPR, this period may be extended for a complex request. We will inform you of the extension and the reasons for it.
Exercising your rights is normally free of charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable fee permitted by law or refuse to act on the request.
17. Right to lodge a complaint
If you believe that your personal data has been processed unlawfully, you may lodge a complaint with the competent supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman:
Submit a notification to the Office of the Data Protection Ombudsman
You may also contact Meeting Park first so that we can try to resolve the matter.
18. Changes to this Notice
Meeting Park updates this Privacy Notice when the processing of personal data, its services or applicable legislation changes. The date of the current version is shown at the beginning of the page.
Material changes will be communicated in an appropriate manner, for example through the online service or by email to the people affected by the change.