Where our restaurant listings come from
Information under Article 14 of the GDPR · Skript It Oy · This notice describes processing as at August 5, 2026
If you run a restaurant, café or bar, its name, address, telephone number and website may appear in a listing we hold. Where the business is run by an individual — a sole trader (toiminimi) or another unincorporated operator — that information is personal data about a person, and this page is the information the GDPR requires us to give you.
We did not get it from you. We took it from a published dataset that anyone can download. This page says which dataset, what we kept, what we do with it, and how to have it corrected or removed.
We cannot tell which listings are about a natural person and which are about a company. The dataset carries no field for legal form, and we measured that guessing from the name does not work: of 9,738 Finnish restaurant rows, only 149 — 1.53% — carry an "Oy" or "Oyj" token, in a country where essentially every restaurant business is an Oy or a toiminimi. The reason is structural — the dataset carries trade names, not registered names. So we treat the whole listing as personal data and apply this notice to all of it. We do not know how many people it concerns, and we do not claim the number is small: we cannot show that it is anything. The figure 5,434,801 used below is a count of rows in the dataset, never a count of people.
What is happening today, and what is not
- We hold a copy of the dataset — 5,434,801 rows, taken on 27 July 2026 — on a computer in Finland under our own control, with a replica in object storage. Section 6 says exactly which storage, because the answer is not the flattering one.
- No Cibus software serves any row of it to anybody. The listing is not published, not searchable and not visible in the app. Being precise about the machinery rather than leaving you to assume there is none: an importer does exist, and on 4 August 2026 we ran it once over a single bounding box in Tokyo, producing a sealed 33,989-row generation that sits on that same computer. The code that would answer a request from it is also present in our live service, but it is switched off by configuration and returns "not found" — we checked that against production on the day this notice was published, rather than assuming it.
- The Cibus Maps app has never been publicly released. The version that exists today gets its place data from Google Maps Platform, not from this dataset. What the app processes about the people who use it is described in the Privacy Policy, which is a different subject from this page.
- Anything below written as when serving begins describes what the catalogue is being built to do. It does not happen yet.
1. Who is responsible Art. 14(1)(a), (b)
Skript It Oy (business ID 3483624-4), Kustaantie 9a 2, 01400 Vantaa, Finland, is the controller.
Write to [email protected] about anything on this page. It is a dedicated data-protection address, not the general enquiries address, so a rights request does not have to compete with general mail to be noticed. The GDPR's one-month clock runs from when your request arrives, not from when we read it, and that is the clock we are held to whatever our mail system does with the message.
Representative: none, and the reason is that none is needed. Article 27 requires a representative in the Union from controllers not established in the Union. We are established in Finland.
Data protection officer: none is designated, and we state why rather than leave the absence unexplained. Article 37(1) requires one where the controller is a public authority (we are not), where the core activity is regular and systematic monitoring of data subjects on a large scale, or where the core activity is large-scale processing of special-category or criminal-conviction data (we process none). We reproduce what published sources already contain and add no rating, ranking or evaluation of anyone, which is why we read the monitoring limb as not met. We also decided not to designate an officer voluntarily: a voluntary officer carries the same Articles 37 to 39 duties as a mandatory one, and designating without meeting them would be worse than not designating.
That reading, and the decision not to designate, are self-certified by the controller; no external qualified review obtained.
2. Where the information came from Art. 14(2)(f)
The source is the Overture Maps Foundation Places dataset, release 2026-07-22.0. It is a publicly accessible source: anyone can download the same release we did.
Overture assembles its Places data from contributors, and the contributors recorded for this release are Meta, Microsoft, Foursquare, AllThePlaces, PinMeTo, Krick, RenderSEO, DAC and BrightQuery. Every row records which of them supplied it.
The licence on the release as a whole is CDLA-Permissive-2.0, with exceptions that attach per row — Apache-2.0 with its NOTICE for rows contributed by Foursquare, CC0-1.0 for rows contributed by AllThePlaces. Which licence applies to a given value is resolved from that row's own provenance record, not assumed.
We have never contacted you and we collected nothing from you. If your listing is wrong at the source, correcting it with us corrects our copy and nothing else. We will not raise your request with the upstream source unless you ask us to: doing that through a public channel would republish your request, which would be a fresh disclosure we have no basis for.
3. What we hold about a listed establishment Art. 14(1)(d)
Per listing:
- the primary name — which may incorporate a person's name;
- the complete set of language-tagged common names;
- alternative names admitted from the source, kept as search aliases only;
- the point coordinate — specifically the corner of the source's own bounding box for the establishment, widened to full precision. It is not the source's most precise geometry, which we do not keep;
- the complete address record — which may be a residential address;
- validated telephone numbers — which may be a personal number;
- websites and social handles;
- brand identity as the source asserts it, including a Wikidata identifier. It is kept for matching names across languages; it is never displayed as a raw identifier and nothing is fetched with it;
- the category — its primary type and that type's ancestors — together with the source's two older category fields, and operating status;
- the source's own confidence value for the row. We say this plainly because it would be easy to leave out: it is present on every one of the 5,434,801 rows we hold. It is never shown to anyone and it is never used to rank, order or filter anything — but we hold it, so it belongs in this list and not in the one below;
- the source identifier for the row, the source's own version number for it, and its provenance — which source, which release, which licence.
What we deliberately do not hold. Email addresses are dropped at the moment of acquisition and are never written to any Cibus store — we checked the columns of the copy we hold and there is no email field in it at all. Also excluded, by a permanent product rule rather than by omission: ratings and review counts, opening hours and any open-or-closed indicator derived from them, price level, photographs, and any model-generated claim about an establishment. The app shows none of these and no longer has a field for them.
4. Why we hold it, and on what legal basis Art. 14(1)(c), 14(2)(b)
The basis is Article 6(1)(f) — legitimate interests — throughout. For most of it the interest is ours; for one activity it is a user's, and the last paragraph of this section says which. It is not consent, so there is no consent to withdraw. It is not a contract: you have no contract with us. It is not a legal obligation: no law requires this of us. No Finnish provision qualifies the basis either, because Article 6(2) and 6(3) confine national specification to Articles 6(1)(c) and 6(1)(e).
Naming the interest specifically is itself part of what we owe you, so here it is, in the exact words our assessment uses:
Skript It Oy's commercial interest in building and keeping current a complete, unranked worldwide listing of restaurants — containing only what its published sources already contain, with no rating, ranking, or judgement of any kind added — and in serving that listing so that a person who frames a circle on a map is shown every restaurant inside it.
The purpose is that a restaurant is findable by customers who are searching an area, at the moment when they do not know its name.
The same interest restated for reading. This is not the wording above and never replaces it:
A traveller or a new resident standing in a district they do not know, who does not know what is there and cannot search for your name because they have never heard it, draws a circle on a map and is shown every restaurant inside it — including yours — with what it is called, where it is, and how to reach you. Nothing in the list says which is better.
One activity relies on a different interest and we say so rather than let the wording above cover it: when a user of the app publishes a snapshot of what they scanned (section 5), that publication rests on the user's interest in sharing what they found, not on ours.
Our assessment of this basis, and the balancing of our interest against yours, is written down. It is self-certified by the controller; no external qualified review obtained. It has not been reviewed or approved by a lawyer or any other qualified adviser, and we do not describe it as reviewed anywhere.
5. Who else can see it Art. 14(1)(e)
Today the copy we hold is disclosed to nobody. It is not served to anyone and no product reads from it. The one party outside the controller that holds it at all is Cloudflare, Inc., as our processor — the object storage the release sits in, and the servers the service runs on. It processes on our instructions and not for its own purposes.
When serving begins, two more recipients appear:
- people using the app, who receive the places inside the area they scan;
- anyone holding the link to a snapshot a user has published.
There is no data broker, no advertising network, no analytics recipient, and no sale or sharing of the listing. Whether someone who simply reads a public page is a "recipient" in the GDPR's sense is a question we have not settled; we list them because that is the more transparent choice.
Publishing a snapshot is a disclosure, and here is what it actually is. A user of the app can publish the set of places they scanned as a web page with a link.
- The page, and the data behind it, are open to anyone who has the link. The link carries a short random identifier and nothing else: there is no password and no sign-in, and we do not claim the identifier is unguessable.
- The page a visitor sees lists the names of the nearest ten places to the centre of the scanned area, and a count of how many more there are. Nothing else per place — no address, no telephone number, no coordinate on the page itself.
- The data behind the page carries more, and anyone holding the link can fetch it directly. For every place in the scan — not only the ten shown — that data carries the name, the coordinate, the telephone number, the website and the category type. It also carries the area that was scanned. We describe this because the link is the only thing protecting it, and a reader who judged the disclosure by the visible page alone would underestimate it.
- The page asks search engines not to index it. The preview text that unfurls in a chat app is a count of places and the title the user gave the area — never an establishment name.
- It expires at most 30 days after publication, and often sooner. The 30 days are counted from when the underlying scan data was fetched rather than from when the link was made, so publishing a snapshot of an older saved scan produces a shorter-lived link — a 25-day-old scan becomes a 5-day link. Whichever date that lands on is fixed when the snapshot is published: it never renews and never moves. It is a limit on storage, not a substitute for removing something when you ask.
- And the part we will not dress up: we cannot currently find every published snapshot that contains a given place, because no index from a place to the snapshots holding it exists. So we cannot promise to pull a place out of snapshots that have already been published. Each of them expires within 30 days.
- Today this feature carries places from our current provider, not from this catalogue.
6. Where it is stored, and whether it leaves the EU Art. 14(1)(f)
Where the copy actually is today, measured on the day this notice was published rather than described from the plan. An earlier draft of this page said the catalogue sat in EU-jurisdiction storage. That was wrong in the direction that flattered us, so here is what we found when we asked our storage provider directly:
- The primary copy is on a computer in Finland, in our own hands. That is also where the 33,989-row generation from the single trial import sits.
- The replica — 116 objects, about 823 MB — is in an object-storage bucket that is in our provider's default jurisdiction, not its EU one. A second bucket in the same default jurisdiction holds three test fixtures, and those fixtures contain real establishment names and address lines.
- We do hold two buckets created in the EU jurisdiction on 23 July 2026, which answer only the EU endpoint and whose jurisdiction cannot be changed after creation. Both are empty. They are reserved for the catalogue when serving begins, and we will not describe the catalogue as EU-stored until something is actually in them.
Whether that is a transfer out of the EU, and what protects it.
- The import runs on a machine in Finland under our own control, so that step involves no third-country transfer.
- Downloading the release brings data to us rather than sending it away. We read that as an inbound receipt and not a transfer, and we mark it as our own reading.
- The servers that answer a request run at whichever location is nearest to it, and the replica is in a bucket we have just told you is not jurisdiction-pinned to the EU. So the honest description is: computation distributed, storage intended to be pinned to the EU and not yet pinned in fact, with standard contractual clauses relied on with our processor and a transfer impact assessment cross-referenced.
- There is no European Commission adequacy decision that we rely on for this. We are naming the absence rather than leaving the question open: the protection here rests on the contractual clauses below, not on a finding of adequacy for the destination.
- How to get a copy of those safeguards. The clauses are part of our processor's published data-processing addendum, which anyone can read at cloudflare.com/cloudflare-customer-dpa. If you would rather we sent you the terms we are actually on, write to [email protected] and ask, and we will send them.
- The transfer impact assessment does not exist yet. We record it as owed rather than imply it is done. Nobody is assigned to it and no date is set, and saying so is more use to you than a promise we have not scheduled.
7. How long we keep it Art. 14(2)(a)
| What | How long |
|---|---|
| A listing | No fixed expiry. When serving begins the catalogue is intended to be rebuilt monthly, each rebuild replacing the one before it, and a listing would stay for as long as it is still in the source release we build from. There is no rebuild schedule today — there is one generation, built by hand, and nothing that runs on a timer. |
| A published snapshot | At most 30 days, counted from when the scan data was fetched rather than from when the link was made — so a snapshot of an older saved scan expires sooner. Fixed at publication, never renewed. |
| A suppression record | None exists; the mechanism is not built. If it is built, the design is to keep it indefinitely. The cost of that is stated below. |
| Our copy of the source release | Kept for as long as we need it to reproduce and account for a release. We have not set a schedule for it, and rather than invent one we say so. |
The cost of honouring a removal, stated rather than hidden. Source identifiers are not stable between monthly releases, so to stop a removed listing coming back we would have to keep something that matches it — a tolerance-based fingerprint of the name, address and coordinate — and keep it indefinitely. And because we cannot tell which listings relate to natural persons, we cannot narrow that store to them. Honouring a removal therefore means holding more identifying information about the person who asked than the listing we removed contained. That is a real cost of the remedy and you should know it before you ask for it.
8. Your rights Art. 14(2)(c), (d), (e)
- Access (Art. 15) — a copy of what we hold about your establishment.
- Rectification (Art. 16) — have it corrected.
- Erasure (Art. 17) — have it removed.
- Restriction (Art. 18) — have us stop using it while something is disputed.
Objection (Article 21), set out separately because it is the one that matters most here. Because we rely on legitimate interests, you can object at any time. Write to [email protected] and say so. The GDPR allows a controller to keep processing after an objection only where it can demonstrate compelling legitimate grounds, or for legal claims. We have not recorded a standing decision never to rely on that, so we are not making you a promise here that we have not made internally. What we can tell you is that we will give you a decision and the reason for it.
Portability (Article 20) does not apply, and rather than list it and let you find out, here is why. It applies only where processing rests on consent or on a contract, and ours rests on legitimate interests. It also applies only to data you provided to the controller, and you provided us nothing. Withdrawal of consent is likewise unavailable because we do not rely on consent for any of this.
Complaining to a supervisory authority (Article 77). You do not have to come to us first. Ours is the Office of the Data Protection Ombudsman — Tietosuojavaltuutetun toimisto — in Finland:
- Post: PL 800, 00531 Helsinki, Finland
- Visiting address: Lintulahdenkuja 4, 00530 Helsinki, Finland
- Telephone: +358 29 566 6700
- How to make a notification to the Data Protection Ombudsman
You may also complain to the supervisory authority of the EU or EEA country where you live or work, or where you believe the problem arose, under Article 56(2). That authority handles it or passes it to ours.
9. What actually happens when you write to us
Write to [email protected]. There is no account, no form and no identity document: we reply to the address you write from. We read the message and act on it by hand. The law gives us one month to reply.
Two things we are not going to dress up.
- The company is one person. There is no rota and no ticketing system behind that address.
- The mechanism that would make a removal survive the monthly rebuild is not built yet. Today a removal is applied by hand to the copy we hold. Nothing is served from that copy, so there is nothing published to take down — but if we rebuilt from the source release without that mechanism, the listing would reappear. Until it exists we will not tell you a removal is permanent.
10. No profiling and no automated decisions Art. 14(2)(g)
There are none. We do not rank, rate, score, order by merit, recommend, or evaluate you or your establishment in any way. There is no automated decision within Article 22 and no profiling within Article 4(4). Results are ordered by distance from the centre of the area the user drew, and there is no sort control at all — the sort options that once ranked by rating and review count were removed along with the fields they used.
11. Why we did not write to you individually Art. 14(5)(b)
We did not, and we are not going to pretend otherwise. The GDPR allows the information on this page to be made publicly available instead of delivered individually where individual delivery would take disproportionate effort, and where it does, publication is the measure a controller is expected to take. This page is that publication, and we are publishing it either way — if the exception is available to us, this is what it requires; if it is not, this is the information we owe you in full, and you should have it now rather than after the question is settled.
Being exact about what we are and are not saying:
- We are not saying it was impossible to reach you. We hold complete address records and validated telephone numbers for many listed establishments, and we are not going to claim otherwise.
- We are not saying that telling you would frustrate the purpose of the listing.
- What we are saying is that any individual round would have to address every row, because we cannot pick out the rows that are about natural persons. At one euro an item, that is over five million euros against an operating budget of six hundred to twelve hundred US dollars a year. We hold no email addresses at all — we dropped them at acquisition.
- And the weakness in our own argument, recorded rather than papered over: cost by itself is not enough. What has to carry the argument is that we have no relationship with you, no channel you chose to give us, and nothing that came from you rather than from a published dataset. We do not assert that this is a strong case.
The determination on this point has not been made or signed. The reasoning is written down and is self-certified by the controller; no external qualified review obtained.
12. Changes to this notice
We may update it. Material changes are reflected by the date at the top, which is the date this notice describes — not a promise about what comes after it.
13. Contact
Skript It Oy (business ID 3483624-4)
Kustaantie 9a 2, 01400 Vantaa, Finland
Data-protection requests: [email protected]
Everything else: [email protected]
Cibus Maps · Skript It Oy · Privacy Policy