Who is responsible for your information
Fjallaþjónustan ehf., trading as Norse Adventures, is the controller of the personal information described in this policy. Our address is Brúarfljót 7e, 270 Mosfellsbær, Iceland. Send privacy questions or requests to adventures@norse.is.
Information we collect
When you contact us, request a tailored itinerary, submit an inquiry, join our mailing list, or book a trip, we collect the information you provide. This may include your name, contact details, travel interests, group details, dates, passenger and emergency-contact details, messages, booking references, payment status, and secure customer-portal access data.
Payment card details are handled by the payment processor and card networks. We normally receive transaction references, status, amount, and related booking information rather than your full card details.
Why we use it and our legal bases
We use inquiry and trip-planning information to take steps at your request before a contract, and booking information to perform our contract with you. We may also process information to meet accounting and other legal obligations, and for legitimate interests such as customer service, fraud prevention, website security, improving our services, and establishing or defending legal claims, provided those interests are not overridden by your rights.
We rely on consent for optional newsletters and other marketing, and for non-essential analytics or advertising cookies. You can withdraw consent at any time without affecting processing that took place before withdrawal.
Service messages and marketing
Replies to your inquiry and messages about bookings, payments, safety, or trip operations are service communications. We send them when needed to answer your request or deliver your trip; they are separate from marketing.
We send newsletters, guide content, and offers only when you have chosen to receive them. You can unsubscribe at any time through the email link or by contacting us. Opting out of marketing does not stop necessary service communications.
Health and medical information
Health conditions, medication, allergies, and some dietary information are special-category personal data. We request only information relevant to trip safety and emergency preparation, and ask for your explicit consent before using it. In a genuine emergency, we may also use it where necessary to protect someone's vital interests.
Medical answers are stored in an encrypted record separate from ordinary booking details. The lead booker can complete and update requested forms for passengers in their booking after confirming that the passenger authorized them to do so; invited passengers can also review and manage their own form. Lead-booker submissions and staff access are logged. Within Norse, access is limited to authorized operations staff and guides, and information is shared with relevant trip providers or medical responders only on a need-to-know basis. Medical-form reminder emails never contain health answers. We do not use health or medical-form information for marketing. Withdrawing consent before the trip may affect our ability to operate your trip safely; contact us so we can discuss what can be done.
Who receives information and international transfers
We do not sell personal information. We share only what is reasonably necessary with guides, accommodation and transport providers, other trip suppliers, and services that support our website, forms, customer communications, booking portal, payments, newsletter, analytics, and advertising. These may include Netlify, Heimdall, myPOS or another payment provider, Mailchimp, Google, and Meta, depending on the service you use and your cookie choices.
A provider may process information outside the European Economic Area. Where that happens, we use an applicable adequacy decision or appropriate safeguards required by data-protection law, such as the European Commission's Standard Contractual Clauses. Contact us for more information about safeguards relevant to your information.
Analytics and cookies
Essential technologies support functions such as security and booking access. With your consent, analytics and advertising tools may collect information such as device and browser type, approximate location, pages viewed, referral source, and online identifiers so we can measure performance and campaign results.
You can use our cookie controls to accept or decline non-essential cookies, and can also control cookies through your browser. Some website features may not work as intended if essential storage is disabled.
Data retention and security
We keep unbooked inquiry records while a request is active and for a limited follow-up period. Newsletter details are kept until you unsubscribe or withdraw consent, after which we may keep a minimal suppression record so we honor your choice. Booking, payment-reference, accounting, and customer-service records are kept for the applicable statutory period and as needed for legal claims.
Encrypted medical-form answers are automatically deleted 30 days after the scheduled trip ends. If a documented safety incident, legal obligation, or claim requires specific information to be retained longer, access remains restricted and it is deleted when that need ends. We may keep non-medical audit information, such as when a form was requested or completed, without retaining the health answers. We delete or anonymize other information when it is no longer needed for the purpose for which it was collected.
We use reasonable technical and organizational measures to protect personal information, including short-lived email verification codes for Booking Portal access and separate encrypted storage for medical answers, but no website, email system, or online service can be guaranteed completely secure. If you believe someone has accessed your booking without permission, contact us.
Your rights and complaints
Under EEA data-protection law, you may request access, correction, erasure, restriction, or portability where applicable. You may object to processing based on legitimate interests and may object to direct marketing at any time. Where processing relies on consent, you may withdraw it at any time. These rights can be subject to legal conditions and exceptions.
Send a request to adventures@norse.is. We may need to verify your identity and will normally respond within one month. You also have the right to lodge a complaint with the Icelandic Data Protection Authority, Persónuvernd.
Submit a complaint to Persónuvernd