Privacy Policy
Last updated: TODO
This policy explains how Víkingaheimar processes personal data of visitors to our museum and users of vikingworld.is.
Data Controller
Víkingaheimar
Víkingabraut 1, 260 Reykjanesbær, Iceland
info@vikingworld.is
What we collect
TODO — List categories of personal data collected (e.g. name, email, booking details, IP for security logging, form submissions).
Third-party processors
The following processors handle personal data on our behalf:
- Bókun — booking engine and ticketing
- Teya — card payment processing
- Vercel — website hosting and edge delivery
- Analytics — none currently in use on vikingworld.is
TODO — Confirm whether any additional processors (e.g. Supabase for data storage, Resend for transactional email, Google Calendar for booking sync) should be disclosed here, and add each with the data category shared, purpose, and jurisdiction.
Lawful basis for processing
TODO — Specify the GDPR Article 6 basis per processing activity (contract performance for bookings, legitimate interest for site security, consent for optional communications, legal obligation for financial records, etc.).
Retention periods
TODO — State how long each category of data is retained, and the criteria used to determine that period. Reference Icelandic bookkeeping law where applicable (financial records).
Your rights
TODO — Enumerate GDPR data-subject rights: access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent. Include the right to lodge a complaint with the Icelandic Data Protection Authority (Persónuvernd).
How to make a request
TODO — Describe the process for exercising rights above — email address, information the requester should provide, identity verification, and response timeframe (typically one month under GDPR).
Requests can be sent to info@vikingworld.is.