This Privacy Policy is effective from the date of publication on this website and may be updated from time to time. The most recent version will always be available here.
Your privacy, our responsibility
At Arctic Adventures, everything we do is built on trust – whether we’re guiding you across a glacier, taking you into Iceland’s wild landscapes, or helping you plan your trip.
That trust also applies to how we handle your personal data.
We believe privacy information should be clear and straightforward – something you can actually read and understand. In this Policy, we guide you through how we handle your personal data: what we collect, why we use it, how long we keep it, who we may share it with, and what choices and rights you have along the way.
We’ve structured this Policy so you can easily find what matters to you – whether you’re booking a tour, contacting us, or simply browsing our website.
1. WHO THIS POLICY APPLIES TO
This Privacy Policy explains how Arctic Adventures (“we”, “us”, “the Company”) collects and uses personal data in connection with our services. It applies to:
In other words, if you interact with us as a customer or website user, this Policy applies to you.
1.1. Who this Policy does not cover
This Policy does not apply to:
We process personal data in those contexts as well, but under separate, dedicated privacy notices, which provide more specific information relevant to those relationships. If you are applying for a role with Arctic Adventures, please refer to the Recruitment Privacy Notice available on our website.
1.2. Who is responsible for your data
Arctic Adventures acts as the data controller, meaning we are responsible for deciding how and why your personal data is used.
Our contact details:
Straumhvarf ehf, registration number: 550405-0240
Registered address: Klettagarður 11, 104 Reykjavik, Iceland
E-mail: dpo@adventures.com
1.3. Legal framework
Arctic Adventures is based in Iceland, and we process personal data in accordance with the General Data Protection Regulation (“GDPR”) and other applicable data protection laws within the European Economic Area (EEA).
At the same time, we welcome travellers from all over the world. Depending on your location, additional local data protection laws may also apply.
Regardless of where you are based, we apply a consistent and high standard of data protection, guided by the principles of transparency, fairness, and security.
1.4. Changes to this Policy
We may update this Policy from time to time – for example, to reflect changes in our services or legal requirements. Whenever we do, the updated version will be published on our website.
2. WHAT PERSONAL DATA WE COLLECT AND WHY?
The personal data we collect – and how we use it – depends on how you interact with us. Below is an overview of the main situations in which we process personal data, what information is involved, the legal basis we rely on, and how long we keep that data.
|
For what purpose do we use your personal data? |
What personal data do we collect? |
What legal basis do we rely on? |
How long do we retain this data? |
||||||||
|
To process and manage your booking, including confirming and administering your reservation. This data is required to enter into and perform a contract with you. If you do not provide this information, we may not be able to confirm your booking or secure your place on a tour. |
|
Performance of a contract (Article 6(1)(b) GDPR) |
|
||||||||
|
To provide and manage your customer account, including giving you access to your booking history, saved preferences, wishlists, and other account features available through our customer portal. You are not required to create a customer account. However, without an account, certain self-service features and access to historical booking information may not be available. |
|
Article 6(1)(f) GDPR – Legitimate interest: to provide customers with access to account-based features, booking history, saved preferences, and other self-service functionality. |
We retain account information for as long as your account remains active. If your account remains inactive for 5 consecutive years, we may notify you using the email address associated with your account and invite you to log in to keep your account active. If you do not reactivate your account within 30 days after our reminder, your account and the personal data associated with it will be permanently deleted, unless we are required to retain certain information for a longer period to comply with legal obligations or to establish, exercise, or defend legal claims. |
||||||||
|
To organise and operate your tour, including planning logistics and coordinating with guides, transport providers, and other partners to deliver your experience. This data is required to provide the booked service. Without it, we may not be able to properly organise or carry out your tour. |
|
Performance of a contract (Article 6(1)(b) GDPR) |
|
||||||||
|
To assess your ability to safely participate in certain activities and to ensure your safety during the tour. Providing this information may be necessary for participation in specific activities. If not provided, we may not be able to allow participation for safety reasons. |
|
Performance of a contract (Article 6(1)(b) GDPR) – to ensure that the booked activity can be delivered safely Explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR) – where health-related data is voluntarily provided |
|
||||||||
|
To document and investigate accidents, injuries, or safety incidents during tours, including managing follow-up actions and handling potential legal claims. Providing this data may be necessary in the context of an incident and related legal or safety obligations. |
|
Legal obligation (Article 6(1)(c) GDPR) – where reporting or documentation is required Legitimate interest (Article 6(1)(f) GDPR) – to investigate incidents and protect individuals and the Company Article 9(2)(f) GDPR – for the establishment, exercise, or defence of legal claims (for health-related data) |
Incident and injury records (including reports and documentation) are retained for 10 years after the incident |
||||||||
|
To communicate with you and provide customer support, including answering inquiries and handling feedback or complaints. You are not required to provide this data, but without it we may not be able to respond to your request or assist you effectively. |
|
Performance of a contract (Article 6(1)(b) GDPR) – where communication relates to an existing booking or support request connected to our services. Legitimate interest (Article 6(1)(f) GDPR) – to respond to general inquiries, manage customer communication, and improve our services. |
|
||||||||
|
To record and review customer service calls for quality assurance and handling complaints or disputes. You are not required to participate in recorded calls; alternative contact methods are available where feasible. |
|
Legitimate interest (Article 6(1)(f) GDPR) – to maintain service quality, train staff, and resolve complaints or disputes |
Call recordings, transcripts, and related metadata are retained for 6 months after the call. Where a call is relevant to a complaint, dispute, or legal claim, it may be retained for longer, for the duration necessary to resolve the matter and/or comply with legal requirements. |
||||||||
|
To process payments and manage financial transactions related to your booking. This data is required to perform a contract with you. If you do not provide this information, we will not be able to process your payment or confirm your booking. |
|
Performance of a contract (Article 6(1)(b) GDPR) We may also rely on legal obligation (Article 6(1)(c) GDPR) to comply with accounting and tax requirements, and legitimate interest (Article 6(1)(f) GDPR) for fraud prevention and transaction security |
Payment transaction and financial records are retained for 10 years in accordance with accounting and tax legislation. |
||||||||
|
To take and share photos or videos from tours, including making them available to participants and, where agreed, using them for marketing purposes. You are not required to appear in photos or videos, and your consent will be requested where images or recordings are used for promotional purposes. |
Photographs, video recordings or other visual content of tour participants |
Legitimate interest (Article 6(1)(f) GDPR) – to provide images or recordings to participants Consent (Article 6(1)(a) GDPR) – for use of images or recordings in marketing or promotional materials |
|
||||||||
|
General newsletters (customers and subscribers) To send you newsletters and travel-related updates (you can unsubscribe at any time) |
|
Consent (Article 6(1)(a) GDPR) – where you subscribe to receive marketing communications. You can withdraw your consent at any time by unsubscribing. We may also send marketing communications to existing customers in relation to similar services where permitted under applicable laws implementing the ePrivacy Directive. In such cases, you will always have a clear opportunity to opt out both when your contact details are collected and in each communication we send. |
|
||||||||
|
Agent newsletter (B2B) To send newsletters and business-related updates to travel agents (you will only receive these communications if you have subscribed, and you can unsubscribe at any time) |
|
Consent (Article 6(1)(a) GDPR) – you can withdraw your consent at any time by unsubscribing |
|
||||||||
|
To send you important service updates related to your booking, such as notifications about Northern Lights tour conditions. This data is required to provide the service. Without it, we may not be able to inform you about changes or conditions affecting your tour. |
|
Performance of a contract (Article 6(1)(b) GDPR) – to provide updates necessary for the delivery of the booked service |
Phone number is retained as part of booking data (see booking retention period above) |
||||||||
|
To send you relevant reminders if you start but do not complete a booking. You are not required to provide this data, but without it we cannot send reminders. |
|
Legitimate interest (Article 6(1)(f) GDPR) – to assist you in completing your booking and improve user experience |
Abandoned booking data and reminder communication is retained for 14 days from last interaction |
||||||||
|
To personalise marketing communications and recommend tours that may be of interest to you (you can object to this processing at any time) |
|
Consent (Article 6(1)(a) GDPR) – applied where you have agreed to receive personalised marketing communications based on your booking history, preferences, or interactions |
|
||||||||
|
To analyse how our website is used and improve performance, functionality, and marketing (you can manage your preferences through our cookie settings) |
|
Consent (Article 6(1)(a) GDPR) – for non-essential cookies and tracking technologies |
Cookies and similar technologies used on our website have different lifespans depending on their purpose. Some cookies are deleted automatically when you close your browser, while others remain on your device for a defined period to recognise your preferences or improve your experience on future visits. For more detailed information about the specific cookies we use and how long each is retained, please see the Cookies section below. |
||||||||
|
To maintain records of individuals who have opted out of marketing communications (this ensures we respect your preferences and do not contact you again) |
|
Legal obligation (Article 6(1)(c) GDPR) – to ensure that individuals who have opted out of marketing communications are not contacted again, in accordance with applicable data protection and electronic communications laws |
Suppression list data is retained for as long as necessary to ensure we continue to respect your opt-out request. |
||||||||
|
To ensure the safety and security of our premises, people, and property through video surveillance (CCTV) |
Video recordings of individuals in monitored areas |
Legitimate interest (Article 6(1)(f) GDPR) – to ensure safety, prevent incidents, and investigate security events |
|
||||||||
|
To manage relationships with our suppliers, service providers, and contractors, including coordinating services, managing contracts, and processing payments. This data is required to enter into and perform a business relationship. Without it, we may not be able to work with the supplier or deliver certain services. |
|
Performance of a contract (Article 6(1)(b) GDPR) – where we work directly with individual contractors Legitimate interest (Article 6(1)(f) GDPR) – to manage relationships with supplier organisations and their representatives Legal obligation (Article 6(1)(c) GDPR) – to comply with accounting, tax, and recordkeeping requirements |
|
3. WHO WE SHARE YOUR DATA WITH?
To provide our services and operate our business, we work with a range of trusted partners and service providers. We only share personal data where it is necessary for a specific purpose, and we always ensure that appropriate safeguards are in place to protect your information.
Depending on the role of the provider and the nature of the service, third parties may process personal data either on our behalf and under our instructions (acting as “processors”), or as independent controllers responsible for their own processing activities. For example, payment providers, banks, social media platforms, and certain analytics or advertising partners may process personal data as independent controllers in accordance with their own privacy policies.
Below we describe the main categories of recipients with whom we may share personal data, depending on how you interact with us. Where relevant, we may also provide additional information about specific recipients upon request.
3.1. Service delivery partners
If you book or participate in a tour, we may share relevant information with partners involved in delivering your experience. This may include:
These partners use your data only to the extent necessary to provide the services you have booked.
3.2. Payment and financial service providers
If you make a payment or book a service with us, your data may be shared with the service providers and financial institutions involved in processing transactions and managing our financial obligations. This may include:
Payment providers, banks, and financial institutions generally process payment-related data as independent controllers in accordance with their own legal and regulatory obligations.
3.3. Communication and customer support providers
If you contact us or communicate with us, we may use external providers to help manage customer support, booking-related communication, and day-to-day operational coordination. This may include:
These providers generally process personal data on our behalf and under our instructions.
3.4. Marketing, social media, and community platforms
If you subscribe to newsletters, participate in campaigns, collaborate with us, or interact with us on social media, we may share your data with providers that help us manage marketing communications, online engagement, and community activities. This may include:
Many of these providers process personal data on our behalf and under our instructions. However, when you interact with us through social media platforms or engage with our content there, your personal data may also be processed by the relevant platform provider in accordance with their own privacy policies and terms. This may include platforms such as Facebook (Meta), Instagram, TikTok, LinkedIn, Pinterest, X (Twitter), Rednote, or similar social networks. These platform providers generally act as independent controllers for processing carried out through their own platforms and services.
3.5. Website, analytics, and advertising providers
To help us operate and improve our website, understand how visitors use it, manage advertising campaigns, and improve online visibility, we may share certain personal data with providers supporting website functionality, analytics, advertising, consent management, and search engine optimisation activities. This may include:
Some of these providers – particularly advertising platforms and social media providers – may process certain personal data as independent controllers for their own analytics, advertising, measurement, and platform improvement purposes.
3.6. IT, cloud, and infrastructure providers
We rely on trusted technology providers to operate our systems, support our day-to-day operations, and store data securely. This may include providers of:
These providers generally process personal data on our behalf and under our instructions.
3.7. Legal, safety, and regulatory disclosures
In certain situations, we may share personal data where necessary to comply with legal obligations, respond to lawful requests, protect individuals and property, investigate incidents or disputes, or establish, exercise, or defend legal claims. This may include sharing data with:
These recipients act as independent controllers when processing personal data for their own legal, regulatory, or insurance-related purposes.
3.8. Business transfers
If we are involved in a merger, acquisition, restructuring, sale of assets, or similar business transaction, personal data may be transferred as part of that process. Where this happens, we will ensure that any such transfer is carried out in accordance with applicable data protection laws and that your personal data remains appropriately protected.
4. INTERNATIONAL DATA TRANSFERS
Because we work with travellers, partners, and service providers located in different countries, your personal data may in certain situations be transferred to or accessed from countries outside your country of residence, including outside the European Economic Area (“EEA”).
Where personal data is transferred internationally, we take steps to ensure that it remains protected in accordance with applicable data protection laws. Depending on the circumstances, we may rely on:
Where appropriate, we may also implement supplementary technical and organisational measures designed to protect personal data during international transfers.
Many of our providers operate globally, including providers of cloud infrastructure, communication tools, customer support systems, analytics services, marketing platforms, and social media services.
You may request additional information about international transfers relevant to your personal data, including information about applicable safeguards, by contacting us using the details provided in this Privacy Policy.
5. YOUR DATA PROTECTION RIGHTS
Under the GDPR, you have certain rights in relation to your personal data. You may have the right to:
You can exercise your rights over your personal data by contacting us at: dpo@adventures.com
To protect your privacy and security, we may need to verify your identity before responding to certain requests, particularly where the request involves access to or deletion of personal data.
We will respond to your request in accordance with applicable data protection laws. In most cases, this means responding within 1 (one) month of receiving your request. If your request is particularly complex or involves multiple requests, this period may be extended by up to an additional 2 (two) months. Where this applies, we will inform you accordingly.
If you believe that your personal data has been processed unlawfully or that your rights have been violated, you also have the right to lodge a complaint with your local data protection authority. If you are located within the European Economic Area (EEA), information about national data protection authorities is available here: https://edpb.europa.eu/about-edpb/about-edpb/members_en
6. ADDITIONAL INFORMATION FOR US RESIDENTS
If you are a resident of a US state with applicable privacy laws, you may have additional privacy rights in relation to your personal information. Depending on your state of residence, these rights may include the right to:
We do not sell personal information in exchange for monetary compensation. However, certain online advertising and analytics activities may be considered “sharing”, “targeted advertising”, or similar processing under applicable US privacy laws.
You may exercise applicable privacy rights by contacting us using the contact details provided in this Privacy Policy.
7. COOKIES AND SIMILAR TECHNOLOGIES
Like most websites, we use cookies and similar technologies to ensure our website functions properly, improve user experience, understand how visitors use our website, and support our marketing activities.
Cookies are small text files stored on your device when you visit a website. Some cookies are necessary for the website to function, while others help us analyse website traffic, remember your preferences, or personalise content and advertising.
Depending on your preferences, we may use:
As required by applicable law, non-essential cookies are only used with your consent. You can manage your cookie preferences at any time through our cookie settings tool available on the website.
Because the cookies and technologies used on our website may change from time to time as our website and services evolve, the most up-to-date information about the specific cookies in use, including their providers, purposes, and retention periods, is available through our cookie settings tool and cookie declaration accessible on the website.
Some cookies may be placed by third-party providers such as analytics, advertising, or social media partners. Where this happens, those third parties may also process certain information collected through cookies in accordance with their own privacy policies.
Third-party websites
Our website may contain links to third-party websites or services. Please note that we are not responsible for the content, security, or privacy practices of third-party websites. If you visit a third-party website, we encourage you to review their privacy information separately.
8. CONTACT US
If you have any questions about this Privacy Policy, how we process your personal data, or if you would like to exercise your data protection rights, you can contact us using the details below:
Straumhvarf ehf.
Registered address: Klettagarður 11, 104 Reykjavik, Iceland
E-mail: dpo@adventures.com
We will do our best to respond to your inquiry as soon as reasonably possible.