← Cibus Maps

Where our restaurant listings come from

Information under Article 14 of the GDPR · Skript It Oy · This notice describes processing as at August 5, 2026

If you run a restaurant, café or bar, its name, address, telephone number and website may appear in a listing we hold. Where the business is run by an individual — a sole trader (toiminimi) or another unincorporated operator — that information is personal data about a person, and this page is the information the GDPR requires us to give you.

We did not get it from you. We took it from a published dataset that anyone can download. This page says which dataset, what we kept, what we do with it, and how to have it corrected or removed.

We cannot tell which listings are about a natural person and which are about a company. The dataset carries no field for legal form, and we measured that guessing from the name does not work: of 9,738 Finnish restaurant rows, only 149 — 1.53% — carry an "Oy" or "Oyj" token, in a country where essentially every restaurant business is an Oy or a toiminimi. The reason is structural — the dataset carries trade names, not registered names. So we treat the whole listing as personal data and apply this notice to all of it. We do not know how many people it concerns, and we do not claim the number is small: we cannot show that it is anything. The figure 5,434,801 used below is a count of rows in the dataset, never a count of people.

What is happening today, and what is not

1. Who is responsible Art. 14(1)(a), (b)

Skript It Oy (business ID 3483624-4), Kustaantie 9a 2, 01400 Vantaa, Finland, is the controller.

Write to [email protected] about anything on this page. It is a dedicated data-protection address, not the general enquiries address, so a rights request does not have to compete with general mail to be noticed. The GDPR's one-month clock runs from when your request arrives, not from when we read it, and that is the clock we are held to whatever our mail system does with the message.

Representative: none, and the reason is that none is needed. Article 27 requires a representative in the Union from controllers not established in the Union. We are established in Finland.

Data protection officer: none is designated, and we state why rather than leave the absence unexplained. Article 37(1) requires one where the controller is a public authority (we are not), where the core activity is regular and systematic monitoring of data subjects on a large scale, or where the core activity is large-scale processing of special-category or criminal-conviction data (we process none). We reproduce what published sources already contain and add no rating, ranking or evaluation of anyone, which is why we read the monitoring limb as not met. We also decided not to designate an officer voluntarily: a voluntary officer carries the same Articles 37 to 39 duties as a mandatory one, and designating without meeting them would be worse than not designating.

That reading, and the decision not to designate, are self-certified by the controller; no external qualified review obtained.

2. Where the information came from Art. 14(2)(f)

The source is the Overture Maps Foundation Places dataset, release 2026-07-22.0. It is a publicly accessible source: anyone can download the same release we did.

Overture assembles its Places data from contributors, and the contributors recorded for this release are Meta, Microsoft, Foursquare, AllThePlaces, PinMeTo, Krick, RenderSEO, DAC and BrightQuery. Every row records which of them supplied it.

The licence on the release as a whole is CDLA-Permissive-2.0, with exceptions that attach per row — Apache-2.0 with its NOTICE for rows contributed by Foursquare, CC0-1.0 for rows contributed by AllThePlaces. Which licence applies to a given value is resolved from that row's own provenance record, not assumed.

We have never contacted you and we collected nothing from you. If your listing is wrong at the source, correcting it with us corrects our copy and nothing else. We will not raise your request with the upstream source unless you ask us to: doing that through a public channel would republish your request, which would be a fresh disclosure we have no basis for.

3. What we hold about a listed establishment Art. 14(1)(d)

Per listing:

What we deliberately do not hold. Email addresses are dropped at the moment of acquisition and are never written to any Cibus store — we checked the columns of the copy we hold and there is no email field in it at all. Also excluded, by a permanent product rule rather than by omission: ratings and review counts, opening hours and any open-or-closed indicator derived from them, price level, photographs, and any model-generated claim about an establishment. The app shows none of these and no longer has a field for them.

4. Why we hold it, and on what legal basis Art. 14(1)(c), 14(2)(b)

The basis is Article 6(1)(f) — legitimate interests — throughout. For most of it the interest is ours; for one activity it is a user's, and the last paragraph of this section says which. It is not consent, so there is no consent to withdraw. It is not a contract: you have no contract with us. It is not a legal obligation: no law requires this of us. No Finnish provision qualifies the basis either, because Article 6(2) and 6(3) confine national specification to Articles 6(1)(c) and 6(1)(e).

Naming the interest specifically is itself part of what we owe you, so here it is, in the exact words our assessment uses:

Skript It Oy's commercial interest in building and keeping current a complete, unranked worldwide listing of restaurants — containing only what its published sources already contain, with no rating, ranking, or judgement of any kind added — and in serving that listing so that a person who frames a circle on a map is shown every restaurant inside it.

The purpose is that a restaurant is findable by customers who are searching an area, at the moment when they do not know its name.

The same interest restated for reading. This is not the wording above and never replaces it:

A traveller or a new resident standing in a district they do not know, who does not know what is there and cannot search for your name because they have never heard it, draws a circle on a map and is shown every restaurant inside it — including yours — with what it is called, where it is, and how to reach you. Nothing in the list says which is better.

One activity relies on a different interest and we say so rather than let the wording above cover it: when a user of the app publishes a snapshot of what they scanned (section 5), that publication rests on the user's interest in sharing what they found, not on ours.

Our assessment of this basis, and the balancing of our interest against yours, is written down. It is self-certified by the controller; no external qualified review obtained. It has not been reviewed or approved by a lawyer or any other qualified adviser, and we do not describe it as reviewed anywhere.

5. Who else can see it Art. 14(1)(e)

Today the copy we hold is disclosed to nobody. It is not served to anyone and no product reads from it. The one party outside the controller that holds it at all is Cloudflare, Inc., as our processor — the object storage the release sits in, and the servers the service runs on. It processes on our instructions and not for its own purposes.

When serving begins, two more recipients appear:

There is no data broker, no advertising network, no analytics recipient, and no sale or sharing of the listing. Whether someone who simply reads a public page is a "recipient" in the GDPR's sense is a question we have not settled; we list them because that is the more transparent choice.

Publishing a snapshot is a disclosure, and here is what it actually is. A user of the app can publish the set of places they scanned as a web page with a link.

6. Where it is stored, and whether it leaves the EU Art. 14(1)(f)

Where the copy actually is today, measured on the day this notice was published rather than described from the plan. An earlier draft of this page said the catalogue sat in EU-jurisdiction storage. That was wrong in the direction that flattered us, so here is what we found when we asked our storage provider directly:

Whether that is a transfer out of the EU, and what protects it.

7. How long we keep it Art. 14(2)(a)

WhatHow long
A listingNo fixed expiry. When serving begins the catalogue is intended to be rebuilt monthly, each rebuild replacing the one before it, and a listing would stay for as long as it is still in the source release we build from. There is no rebuild schedule today — there is one generation, built by hand, and nothing that runs on a timer.
A published snapshotAt most 30 days, counted from when the scan data was fetched rather than from when the link was made — so a snapshot of an older saved scan expires sooner. Fixed at publication, never renewed.
A suppression recordNone exists; the mechanism is not built. If it is built, the design is to keep it indefinitely. The cost of that is stated below.
Our copy of the source releaseKept for as long as we need it to reproduce and account for a release. We have not set a schedule for it, and rather than invent one we say so.

The cost of honouring a removal, stated rather than hidden. Source identifiers are not stable between monthly releases, so to stop a removed listing coming back we would have to keep something that matches it — a tolerance-based fingerprint of the name, address and coordinate — and keep it indefinitely. And because we cannot tell which listings relate to natural persons, we cannot narrow that store to them. Honouring a removal therefore means holding more identifying information about the person who asked than the listing we removed contained. That is a real cost of the remedy and you should know it before you ask for it.

8. Your rights Art. 14(2)(c), (d), (e)

Objection (Article 21), set out separately because it is the one that matters most here. Because we rely on legitimate interests, you can object at any time. Write to [email protected] and say so. The GDPR allows a controller to keep processing after an objection only where it can demonstrate compelling legitimate grounds, or for legal claims. We have not recorded a standing decision never to rely on that, so we are not making you a promise here that we have not made internally. What we can tell you is that we will give you a decision and the reason for it.

Portability (Article 20) does not apply, and rather than list it and let you find out, here is why. It applies only where processing rests on consent or on a contract, and ours rests on legitimate interests. It also applies only to data you provided to the controller, and you provided us nothing. Withdrawal of consent is likewise unavailable because we do not rely on consent for any of this.

Complaining to a supervisory authority (Article 77). You do not have to come to us first. Ours is the Office of the Data Protection Ombudsman — Tietosuojavaltuutetun toimisto — in Finland:

You may also complain to the supervisory authority of the EU or EEA country where you live or work, or where you believe the problem arose, under Article 56(2). That authority handles it or passes it to ours.

9. What actually happens when you write to us

Write to [email protected]. There is no account, no form and no identity document: we reply to the address you write from. We read the message and act on it by hand. The law gives us one month to reply.

Two things we are not going to dress up.

10. No profiling and no automated decisions Art. 14(2)(g)

There are none. We do not rank, rate, score, order by merit, recommend, or evaluate you or your establishment in any way. There is no automated decision within Article 22 and no profiling within Article 4(4). Results are ordered by distance from the centre of the area the user drew, and there is no sort control at all — the sort options that once ranked by rating and review count were removed along with the fields they used.

11. Why we did not write to you individually Art. 14(5)(b)

We did not, and we are not going to pretend otherwise. The GDPR allows the information on this page to be made publicly available instead of delivered individually where individual delivery would take disproportionate effort, and where it does, publication is the measure a controller is expected to take. This page is that publication, and we are publishing it either way — if the exception is available to us, this is what it requires; if it is not, this is the information we owe you in full, and you should have it now rather than after the question is settled.

Being exact about what we are and are not saying:

The determination on this point has not been made or signed. The reasoning is written down and is self-certified by the controller; no external qualified review obtained.

12. Changes to this notice

We may update it. Material changes are reflected by the date at the top, which is the date this notice describes — not a promise about what comes after it.

13. Contact

Skript It Oy (business ID 3483624-4)
Kustaantie 9a 2, 01400 Vantaa, Finland
Data-protection requests: [email protected]
Everything else: [email protected]


Cibus Maps · Skript It Oy · Privacy Policy