Risøyhamn Kafe

Privacy Policy – Risoyhamn.no

Privacy Policy – Risoyhamn.no

Last updated: 09.11.2025

1. Introduction

This Privacy Policy describes how Risøyhamn Kafe AS (“we”, “our”, “us”) collects, uses, and protects your personal data when you visit our website www.risoyhamn.no, contact us, or use our services.

We are committed to protecting your privacy and handling your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (Personopplysningsloven).

2. Data Controller

Risøyhamn Kafe AS
Org. nr.: 933537374
Address: Withs Vei 162, 8484 Risøyhamn, Norway
Email: Use contact form
Phone: +47 76145500

3. Personal Data We Collect

We may collect and process the following categories of personal data:

Contact information: name, email address, phone number.

Booking information: arrival/departure dates, guest names, preferences, and payment status (no full payment details are stored).

Communication data: messages sent via our contact form, email, or chat.

Technical data: IP address, browser type, device information, operating system, referring URLs, and cookies (see section 8).

Marketing preferences: consent to newsletters or promotional materials.

We do not collect or store sensitive personal information unless strictly necessary for legal compliance (e.g., guest registration requirements).

4. How We Use Your Data

We use your personal data for the following purposes:

To manage and confirm your bookings and reservations.

To communicate with you regarding inquiries, feedback, or support.

To comply with legal obligations (e.g., accounting, tax, and hospitality regulations).

To improve our website, services, and customer experience.

To send optional marketing information (only if you have consented).

We will not use your data for purposes incompatible with those above.

5. Legal Basis for Processing

We process your personal data based on the following legal grounds under the GDPR:

Article 6(1)(b): Processing is necessary for the performance of a contract (e.g., bookings).

Article 6(1)(c): Processing is necessary to comply with legal obligations.

Article 6(1)(a): Based on your consent (e.g., marketing emails).

Article 6(1)(f): Legitimate interests (e.g., website analytics, security).

6. Data Retention

We retain your personal data only as long as necessary to fulfil the purposes outlined above, or as required by law.

Booking and transaction data: up to 5 years (per accounting requirements).

Marketing consents: until you withdraw your consent.

Website logs and analytics: typically 12 months or less.

7. Sharing of Data

We may share personal data only when necessary with:

Booking partners (e.g., Booking.com, Airbnb, Sirvoy).

Payment providers (e.g., Stripe, Vipps, or banks).

Service providers who help us operate the website or IT systems under strict confidentiality agreements.

Public authorities, when required by law.

We do not sell or rent personal data to third parties.

8. Cookies and Analytics

Our website uses cookies to improve functionality and user experience.
Cookies are small text files stored on your device. You can manage or disable cookies in your browser settings.

We may use:

Essential cookies: required for basic site operation.

Analytics cookies (e.g., Google Analytics): to understand visitor behavior.

Marketing cookies: only if consented.

For more information, see our [Cookie Policy].

9. Your Rights

Under the GDPR, you have the following rights:

Access: to know what personal data we hold about you.

Correction: to request rectification of inaccurate data.

Erasure (“right to be forgotten”): to have data deleted when no longer needed.

Restriction: to limit how your data is processed.

Portability: to receive a copy of your data in a structured format.

Objection: to processing based on legitimate interest or direct marketing.

Withdraw consent: at any time (without affecting prior lawful processing).

To exercise your rights, contact us at [insert email].

10. Data Security

We use appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, loss, or misuse.
Only authorized personnel have access to your personal information.

11. Transfers Outside the EEA

If we transfer data outside the European Economic Area (EEA), we ensure adequate protection through:

EU Commission adequacy decisions, or

Standard Contractual Clauses (SCCs) approved by the EU Commission.

12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The latest version will always be available at www.risoyhamn.no/privacy-policy
.

13. Contact and Complaints

If you have questions about this policy or how we process your personal data, please contact us:
📧 use contact form
📞 +47 76145500

If you believe your rights have been violated, you can lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet):
📍 www.datatilsynet.no