Skip to main content
Víkingaheimar logoVÍKINGAHEIMAR

Privacy Policy

Last updated: TODO

This policy explains how Víkingaheimar processes personal data of visitors to our museum and users of vikingworld.is.

Data Controller

Víkingaheimar
Víkingabraut 1, 260 Reykjanesbær, Iceland
info@vikingworld.is

What we collect

TODO — List categories of personal data collected (e.g. name, email, booking details, IP for security logging, form submissions).

Third-party processors

The following processors handle personal data on our behalf:

  • Bókun — booking engine and ticketing
  • Teya — card payment processing
  • Vercel — website hosting and edge delivery
  • Analytics — none currently in use on vikingworld.is

TODO — Confirm whether any additional processors (e.g. Supabase for data storage, Resend for transactional email, Google Calendar for booking sync) should be disclosed here, and add each with the data category shared, purpose, and jurisdiction.

Lawful basis for processing

TODO — Specify the GDPR Article 6 basis per processing activity (contract performance for bookings, legitimate interest for site security, consent for optional communications, legal obligation for financial records, etc.).

Retention periods

TODO — State how long each category of data is retained, and the criteria used to determine that period. Reference Icelandic bookkeeping law where applicable (financial records).

Your rights

TODO — Enumerate GDPR data-subject rights: access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent. Include the right to lodge a complaint with the Icelandic Data Protection Authority (Persónuvernd).

How to make a request

TODO — Describe the process for exercising rights above — email address, information the requester should provide, identity verification, and response timeframe (typically one month under GDPR).

Requests can be sent to info@vikingworld.is.