Who we are
Sommarbukt is a luxury vacation home company located north of the Arctic Circle in Northern Norway, directly on the Ulsfjord. We operate two properties, Tind and Nordlys, and we take the privacy of our guests seriously.
If you have any questions about how we handle your data, you are always welcome to reach out to us directly.
Sommarbukt Utvikling AS
Stordalstrandvegen 285, Sjursnes, Norway
[email protected]
What data we collect and why
We only collect personal data when there is a good reason for it. Depending on how you interact with us, this can happen when you:
- visit our website,
- send us a message or enquiry,
- make a booking, or
- complete our online check-in before your stay.
Personal data means any information that can be used to identify you, such as your name, email address, date of birth or passport number.
When you contact us
If you send us a message through our contact form or by email, we use the information you provide to answer your question and follow up if needed. This typically includes your name, email address and the content of your message.
We keep this data only for as long as it takes to handle your request, or as long as required by law.
Legal basis
When you make a booking
Our bookings are handled through an online booking system. When you check availability or complete a reservation, the information you enter, such as your travel dates, number of guests and contact details, is processed to confirm and manage your booking.
The booking system is provided by Lodgify (Lodgify SL, Barcelona, Spain), a company based within the European Union. They process your data on our behalf and are contractually bound to keep it secure. You can read more in Lodgify's own privacy policy.
Legal basis
Online check-in
Before your arrival, we ask you to complete a short online check-in. This helps us prepare for your stay and also allows us to meet our obligations under Norwegian law.
- Full name
- Date of birth
- Nationality
- Home address
- Passport or identity document number and type (including a document upload)
- Estimated arrival time
- Phone number
Norwegian law requires accommodation providers to keep a register of all overnight guests. This register must be available to the Norwegian Police on request. For guests who are not citizens of a Nordic country, this includes passport or identity document details.
We know that sharing this kind of information requires trust. We want to be clear: your passport data is stored securely, only accessible to authorised staff, and never used for anything other than what is described here.
Legal basis
Guest registration data is kept for at least two years, in line with Norwegian administrative practice.
Cookies
When you visit our website for the first time, you will see a banner asking for your preferences. You can choose which types of cookies you are comfortable with, and you can change your mind at any time by revisiting the banner settings.
Some cookies are essential for the website to work at all, for example to keep your booking session active. These cannot be switched off.
With your permission, we use Google Analytics to understand how visitors use our website. This helps us improve the experience over time. The data is anonymised and no personal profile is built. Google may process some of this data in the United States, with appropriate safeguards in place.
Legal basis
With your permission, we also use tools from Google and Meta (Facebook/Instagram) to measure how well our advertising works and to show relevant ads to people who have previously visited our site. These tools use anonymous identifiers and do not reveal who you are.
Legal basis
Who we share your data with
We do not sell your personal data. We only share it with the service providers we need to run our website and manage bookings. All of them are contractually required to handle your data responsibly.
| Provider | What they do for us | Where they are based | Data protection |
|---|---|---|---|
| Lodgify | Booking and property management | Spain (within the EU) | Protected by EU law |
| Website analytics and advertising | Ireland / United States | Standard Contractual Clauses | |
| Meta (Facebook/Instagram) | Advertising | Ireland / United States | Standard Contractual Clauses |
Where data is transferred to the United States, we rely on Standard Contractual Clauses, a legal mechanism approved by the European Commission to ensure your data remains protected.
How long we keep your data
We do not keep your data longer than necessary. Here is a rough overview:
| Type of data | How long we keep it |
|---|---|
| Messages and enquiries | Until your request is resolved, and up to 3 years afterwards |
| Booking information | Up to 5 years after your stay (required for accounting purposes) |
| Check-in and guest registration data | At least 2 years (required by Norwegian law) |
| Analytics and advertising data | As set by Google and Meta in their own policies |
Your rights
You have a number of rights when it comes to your personal data. To exercise any of them, just send us an email at [email protected] and we will get back to you.
You can ask us what data we hold about you and receive a copy of it.
If something is wrong or out of date, you can ask us to correct it.
You can ask us to delete your data, where we are not required by law to keep it.
You can ask us to pause how we use your data in certain situations.
You can ask for your data in a format that makes it easy to transfer elsewhere.
You can object to certain types of processing, including direct marketing.
If you have given consent for something, you can take it back at any time.
If you feel we have not handled your data correctly, you also have the right to file a complaint with the Norwegian data protection authority:
Updates to this policy
We may update this policy from time to time, for example if we start using a new service or if the law changes. The date at the top of this page always shows when it was last revised. We recommend checking back occasionally if you want to stay up to date.
