Persónuverndar-stefna

Privacy policy

1. Introduction

At Hrauneyjarehf., we are committed to protecting your privacy and ensuring that yourpersonal data is processed in a transparent, secure, and lawful manner.

Hrauneyjar ehf.,company registration no. 600421-1310, Urriðaholtsstræti 2-4, 210 Garðabær,Iceland (“we”, “us”, or “our”), operates The Highland Center Hrauneyjar,including its accommodation and dining facilities.

This PrivacyPolicy explains how we collect, use, disclose and otherwise process yourpersonal data, the purposes for which your personal data is processed, thelegal bases on which we rely, and your rights in relation to the processing ofyour personal data.

For thepurposes of Regulation (EU) 2016/679 (the “General Data Protection Regulation”or “GDPR”), Hrauneyjar ehf. is the data controller responsible for theprocessing of your personal data as described in this Privacy Policy.

 

2. PersonalData We Collect

We processpersonal data primarily to provide and improve our services, communicateeffectively with our customers, protect the safety and security of ourpremises, guests, employees, and property, and to market our products andservices where permitted by law.

We will onlyprocess your personal data where we have a lawful basis for doing so underArticle 6 of the GDPR and, in the case of special categories of personal data,where the additional requirements under Article 9 of the GDPR are met.

2.1 Accommodation, Restaurant, and Related Services

When you book aroom at The Highland Center Hrauneyjar or a table at our restaurant, we collectthe personal data necessary to provide the services you have requested.

The personaldata we may collect includes:

     • Name- Required to process your booking and welcome you at the scheduledtime.

     • Emailaddress - Used to send booking confirmations, payment receiptsand updates regarding your booking, or to contact you for other reasonsrelating to your reservation where necessary.

     • Telephonenumber - In exceptional circumstances, we may contact you bytelephone where we consider it necessary to provide important informationregarding your booking and believe that email communication would not besufficient.

     • Addressand copy of identification documents - We onlyrequest this information when you book hotel accommodation, as we are requiredto do so under applicable law.

     • Paymentinformation - Payment information is processed securely throughour payment service provider, Planet.

     • Otherinformation you voluntarily provide to us - This mayinclude, for example, health information or requests for additional assistance.

2.2 Inquiries

When yousubmit a request, inquiry, complaint or feedback to us, we process your contactdetails and any other information you provide in order to respond to yourinquiry and, where necessary, process and resolve your request.

2.3 Analyticsand Market Research

We may useinformation derived from personal data that has been anonymized for analytics,market research, and statistical purposes to help us improve our products andservices.

2.4 OurWebsite

When you visitour website, we may collect information about the use of the website throughcookies and similar technologies. This information is used to provide websitefunctionality, analyze website usage, and, where you have provided yourconsent, support marketing activities.

Detailedinformation about the cookies and similar technologies we use, including theirpurposes, providers, and retention periods, is available in our CookieDeclaration, which can be accessed through our cookie banner.

2.5 CCTV

We use CCTVcameras at our premises for security purposes and to protect the safety of ourguests, employees, and property. Access to CCTV recordings and otherinformation collected through CCTV is strictly controlled, and onlyspecifically authorized employees have access to such information.

CCTVrecordings are not retained for longer than 30 days unless they are required tobe retained in connection with potential legal matters, such as accidents,theft, or other incidents requiring further review.

 

3. LegalBases for Processing Personal Data

We processpersonal data based on one or more lawful bases under the GDPR, depending onthe nature of the processing activity.

We processpersonal data based on the following lawful bases:

     • Performanceof a contract (Article 6(1)(b) GDPR) Processingof your name, email address, phone number, and payment information is necessaryfor us to manage and fulfill your booking and provide the services you haverequested.

Processingof your name, email address, phone number, and payment information is necessaryfor us to manage and fulfill your booking and provide the services you haverequested.

     • Legitimateinterests (Article 6(1)(f) GDPR)

Incertain circumstances, we process personal data based on our legitimateinterests where this processing is necessary for our business operations anddoes not override your rights and freedoms. This applies to processingactivities such as communicating with our customers, for example whenresponding to inquiries about our services or requests regarding customerrights under applicable data protection laws. We have a legitimate interest inresponding to such inquiries and providing appropriate assistance. Processingof personal data through CCTV is based on our legitimate interests inmaintaining security and protecting our premises, guests, employees, andproperty. We may also create and use anonymized information for analytics andmarket research purposes based on our legitimate interests in improving ourproducts and services.

     • Consent(Articles 6(1)(a) and 9(2)(a) GDPR)

Whereapplicable, we process personal data based on your consent. This may includesituations where you voluntarily provide us with special categories of personaldata, such as health information. We may also process information collectedthrough non-essential cookies and similar technologies, such as analytics andmarketing cookies, where you have provided your consent. Where you have chosento receive newsletters, marketing communications, or other information from us,such processing is based on your consent. Where we process personal data basedon your consent, you have the right to withdraw your consent at any time.Withdrawal of consent will not affect the lawfulness of processing carried outbefore the withdrawal.

     • Legalobligation (Article 6(1)(c) GDPR)

Weprocess personal data where necessary to comply with legal obligations thatapply to us. This legal basis applies, for example, to obligations relating tomaintaining records of hotel guests’ addresses and copies of identificationdocuments, and to retaining accounting records in accordance with applicableaccounting and record-keeping requirements.

     • Vitalinterests (Article 6(1)(d) GDPR)

We may processpersonal data where necessary to protect your vital interests or the vitalinterests of another individual. This legal basis may apply, for example, inthe event of an accident or medical emergency at our premises.

 

4. SharingPersonal Data with Processors and Third Parties

We do not sellpersonal data.

We may sharepersonal data with processors who provide services to us or provide services toour customers on our behalf where this involves processing personal data on ourinstructions. This may include, for example, providers of IT services, cloudsolutions, payment services, and other services necessary to support ouroperations.

An example ofa processor is our parent company, Blue Lagoon Ltd., which provides us withvarious support services, including IT, human resources, management, andfinance services.

Where thirdparties act as data processors on our behalf, we ensure that appropriate dataprocessing agreements are in place, requiring personal data to be handledsecurely, confidentially, and only for the purposes we specify. Processors onlyhave access to the personal data necessary to perform their specific tasks andare prohibited from using it for any other purpose.

Some of thesethird parties may be located outside Iceland. We will not transfer personaldata outside the European Economic Area (EEA) unless permitted under applicabledata protection laws, for example where the European Commission has adopted anadequacy decision for the destination country or where appropriate safeguardsare in place, such as Standard Contractual Clauses.

We may alsodisclose personal data:

     • Whenrequired by law, for example under a court order or at the request of lawenforcement or other public authorities.

     • Toour legal advisors to protect the company’s legal rights or the rights of ourstaff.

In addition,we may use third-party providers to assist us with website analytics,marketing, and improving our services. Depending on the service provided, theseproviders may act as our processors or as independent controllers. We only usenon-essential cookies and similar technologies where you have provided consent.Further information about the cookies and technologies used on our website,including their purposes and providers, is available in our Cookie Declaration,which can be accessed through our cookie banner.

 

5. Retentionof Personal Data

We retainpersonal data only for as long as necessary for the purposes for which it wascollected, or as required to comply with applicable legal obligations.

The length ofthe time we retain personal data may be determined by legal obligations thatapply to us. For example, accounting records may be required to be retained forseven years from the end of the relevant financial year under applicableaccounting legislation, and certain information relating to hotel guests may berequired to be retained for a period of one year under applicable accommodationlegislation.

When theretention period ends, we securely delete personal data or anonymize it so thatit can no longer be used to identify you.

 

6. PersonalData Received from Third Parties

Where you haveauthorized a third party, such as a travel agency or booking service, to shareyour personal data with us (for example, to make a booking on your behalf),this Privacy Policy applies to our processing of that personal data once wereceive it.

Where otherservice providers provide part of your service, stay, or travel arrangements,those providers are responsible for their own processing of personal datacarried out by them. Their privacy policy and information about theirprocessing activities should be available from those providers.

 

7. Paymentsand Security

Payments areprocessed through our payment service provider, Planet. Payment transactionsare protected using appropriate security measures and are processed inaccordance with the PCI DSS (Payment Card Industry Data Security Standard) tohelp ensure the secure handling of payment card information.

Our websitesare secured using SSL certificates and encryption technologies designed toprotect communications between our websites and your browser.

 

8. YourRights

Under theGDPR, you have the following rights in relation to your personal data:

     • Access -request access to the personal data we hold about you and information about howwe process it.

     • Correction- request that inaccurate or incomplete personal data be corrected.

     • Restrictionof Processing - request that we restrict the processing of yourpersonal data in certain circumstances, such as where you challenge theaccuracy of the data or where you believe the processing is unlawful.

     • Erasure- request deletion of your personal data where applicable, for examplewhere the data is no longer necessary for the purpose for which it wascollected or where you withdraw your consent where processing is based onconsent. This right does not apply where we are required to retain personaldata by law.

     • DataPortability - receive personal data you have provided to us in astructured, commonly used, and machine-readable format, and request that it betransferred to another controller where the processing is based on your consentand carried out by automated means. This right must not adversely affect therights and freedoms of others.

     • Withdrawalof Consent - withdraw your consent at any time where processingis based on your consent. Withdrawal of consent does not affect the lawfulnessof processing carried out before consent was withdrawn.

     • Objectto Processing - object to processing based on our legitimateinterests. You also have the right to object at any time to processing carriedout for direct marketing purposes, including marketing communications such asnewsletters.

     • Lodgea Complaint - lodge a complaint directly with the Icelandic DataProtection Authority (Persónuvernd) if you believe your rights have beenviolated.

To exerciseany of the rights listed above, please contact us at info@hrauneyjar.is.

Please notethat these rights are not absolute and may be subject to limitations under theGDPR, including where we are required to retain information to comply withlegal obligations or where exercising a right would adversely affect the rightsand freedoms of others.

 

9. Childrenunder 13 years of age

We may provideservices to families and may process personal data relating to children inconnection with bookings or visits to our premises. We do not knowingly collectpersonal data from children under the age of 13 without appropriate involvementor authorization from a parent or legal guardian.

If a parent orlegal guardian becomes aware that personal data has been provided by a childunder the age of 13 without appropriate authorization, they should contact usimmediately. If we become aware of such collection or use, we will takeappropriate steps to address the situation, including deleting such data whererequired.

 

10. Job Applicants

If you applyfor a position with us, we will process the personal data you provide as partof your application, such as your name, contact details, CV, cover letter,qualifications, interview notes, references, and any other information relevantto the recruitment process.

We processthis information for the purpose of managing the recruitment process, assessingyour suitability for employment, and taking steps at your request prior toentering into an employment contract.

We retainapplicant data only for as long as necessary for the recruitment process and,where you have provided your consent, for a limited period thereafter toconsider you for future employment opportunities.

Applicantsalso receive separate information describing how we process personal dataduring the recruitment process.

 

11. PersonalData Breaches

In the eventof a personal data breach, we will notify the Icelandic Data ProtectionAuthority (Persónuvernd) without undue delay and, where feasible, no later than72 hours after becoming aware of the breach, unless the breach is unlikely toresult in a risk to the rights and freedoms of individuals.

If the breachis likely to result in a high risk to your rights and freedoms, we will alsoinform you directly without undue delay, unless otherwise required byapplicable law.

 

12. Questionsand Complaints

If you haveany questions about this Privacy Policy or how we process your personal data,please contact us at:

Email: info@hrauneyjar.is

Mail:Urriðaholtsstræti 2-4, 210 Garðabær, Iceland

If you believethat our processing of your personal data does not comply with applicable dataprotection laws, you have the right to lodge a complaint with the IcelandicData Protection Authority (Persónuvernd). Further information is available onits website: www.island.is/en/o/the-data-protection-authority

 

13. Changesto this Privacy Policy

We may updatethis Privacy Policy from time to time to reflect changes in our processingactivities, legal requirements, or our services.

Any changeswill become effective when the updated Privacy Policy is published on ourwebsite.

Last updated: July3, 2026

 

Persónuverndarstefna