Rare Summer Savings: Up to 30% Off July Tours! Special Offers

Last updated: July 02, 2026

Privacy Policy

This Privacy Policy is effective from the date of publication on this website and may be updated from time to time. The most recent version will always be available here. 

Your privacy, our responsibility 

At Arctic Adventures, everything we do is built on trust – whether we’re guiding you across a glacier, taking you into Iceland’s wild landscapes, or helping you plan your trip.  

That trust also applies to how we handle your personal data. 

We believe privacy information should be clear and straightforward – something you can actually read and understand. In this Policy, we guide you through how we handle your personal data: what we collect, why we use it, how long we keep it, who we may share it with, and what choices and rights you have along the way. 

We’ve structured this Policy so you can easily find what matters to you – whether you’re booking a tour, contacting us, or simply browsing our website. 

1. WHO THIS POLICY APPLIES TO 

This Privacy Policy explains how Arctic Adventures (“we”, “us”, “the Company”) collects and uses personal data in connection with our services. It applies to:

  • visitors of our website 
  • customers booking or participating in our tours 
  • individuals contacting our customer support 
  • and other individuals whose personal data we process in connection with our services

In other words, if you interact with us as a customer or website user, this Policy applies to you.

1.1. Who this Policy does not cover

This Policy does not apply to:

  • job applicants (candidates) 
  • employees

We process personal data in those contexts as well, but under separate, dedicated privacy notices, which provide more specific information relevant to those relationships. If you are applying for a role with Arctic Adventures, please refer to the Recruitment Privacy Notice available on our website. 

1.2. Who is responsible for your data 

Arctic Adventures acts as the data controller, meaning we are responsible for deciding how and why your personal data is used. 

Our contact details: 

Straumhvarf ehf, registration number: 550405-0240 

Registered address: Klettagarður 11, 104 Reykjavik, Iceland 

E-mail: dpo@adventures.com  

1.3. Legal framework 

Arctic Adventures is based in Iceland, and we process personal data in accordance with the General Data Protection Regulation (“GDPR”) and other applicable data protection laws within the European Economic Area (EEA). 

At the same time, we welcome travellers from all over the world. Depending on your location, additional local data protection laws may also apply. 

Regardless of where you are based, we apply a consistent and high standard of data protection, guided by the principles of transparency, fairness, and security. 

1.4. Changes to this Policy 

We may update this Policy from time to time – for example, to reflect changes in our services or legal requirements. Whenever we do, the updated version will be published on our website.

2. WHAT PERSONAL DATA WE COLLECT AND WHY?  

The personal data we collect – and how we use it – depends on how you interact with us. Below is an overview of the main situations in which we process personal data, what information is involved, the legal basis we rely on, and how long we keep that data.

For what purpose do we use your personal data?

What personal data do we collect?

What legal basis do we rely on?

How long do we retain this data? 

To process and manage your booking, including confirming and administering your reservation.  

This data is required to enter into and perform a contract with you. If you do not provide this information, we may not be able to confirm your booking or secure your place on a tour.

  • Identification and contact details:  
    • Full name 
    • Email address and phone number 
  • Booking information: 
    • Selected tour, travel dates, number of participants, preferences 
    • Nationality and responses to booking-related questions 
  • Additional tour-specific information (where required): 
    • For certain activities (e.g., diving): age, height, weight, gender (for safety and equipment purposes) 
    • For self-drive tours: date of birth, nationality, confirmation of valid driving license.

Performance of a contract (Article 6(1)(b) GDPR)

  • Customer identification and booking data: 5 years after completion of the booking 
  • Cancelled bookings (no payment): 6 months after cancellation

To provide and manage your customer account, including giving you access to your booking history, saved preferences, wishlists, and other account features available through our customer portal. 

You are not required to create a customer account. However, without an account, certain self-service features and access to historical booking information may not be available.

  • Identification and contact details:  
    • Full name 
    • Email address 
  • Account data: 
    • Login credentials and authentication information  
    • Account creation date and account status 
  • Customer account content: 
    • Booking history 
    • Saved preferences 
    • Wishlists and other information stored within the account

Article 6(1)(f) GDPR – Legitimate interest: to provide customers with access to account-based features, booking history, saved preferences, and other self-service functionality.

We retain account information for as long as your account remains active. 

If your account remains inactive for 5 consecutive years, we may notify you using the email address associated with your account and invite you to log in to keep your account active. If you do not reactivate your account within 30 days after our reminder, your account and the personal data associated with it will be permanently deleted, unless we are required to retain certain information for a longer period to comply with legal obligations or to establish, exercise, or defend legal claims.

To organise and operate your tour, including planning logistics and coordinating with guides, transport providers, and other partners to deliver your experience.  

This data is required to provide the booked service. Without it, we may not be able to properly organise or carry out your tour.

  • Identification and contact data: 
    • Full name 
    • Email address and phone number 
  • Booking and logistics data: 
    • Tour details, travel dates, number of participants 
    • Accommodation address (for pick-up and drop-off) 
    • Logistical requirements and preferences (e.g. timing, coordination needs)

Performance of a contract (Article 6(1)(b) GDPR) 

  • Printed transport coordination data: deleted no later than 7 days after the tour 
  • Information that forms part of booking records: retained in line with booking data (5 years)

To assess your ability to safely participate in certain activities and to ensure your safety during the tour.  

Providing this information may be necessary for participation in specific activities. If not provided, we may not be able to allow participation for safety reasons.

  • Identification and contact data: 
    • Full name 
    • Emergency contact details (where provided) 
  • Health-related information (only where relevant): 
    • Medical conditions, allergies, dietary requirements 
    • Fitness declarations or confirmations related to the activity 
  • Safety-related data: 
    • Participation eligibility assessments 

Performance of a contract (Article 6(1)(b) GDPR) – to ensure that the booked activity can be delivered safely 

Explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR) – where health-related data is voluntarily provided

  • Health data and safety-related information: retained for 4 years after completion of the tour 
  • Medical forms (including declarations): retained for 4 years, unless required for an incident or legal claim

To document and investigate accidents, injuries, or safety incidents during tours, including managing follow-up actions and handling potential legal claims.  

Providing this data may be necessary in the context of an incident and related legal or safety obligations.

  • Identification and contact data: 
    • Full name 
    • Contact details (email, phone number) 
    • ID number (where required under local law) 
  • Incident-related data: 
    • Description of the incident, including date, time, and location 
    • Witness statements and staff reports 
  • Health-related data: 
    • Injury details and relevant medical information 
    • Treatment provided or required

Legal obligation (Article 6(1)(c) GDPR) – where reporting or documentation is required

Legitimate interest (Article 6(1)(f) GDPR) – to investigate incidents and protect individuals and the Company

Article 9(2)(f) GDPR – for the establishment, exercise, or defence of legal claims (for health-related data)

Incident and injury records (including reports and documentation) are retained for 10 years after the incident 

To communicate with you and provide customer support, including answering inquiries and handling feedback or complaints. 

You are not required to provide this data, but without it we may not be able to respond to your request or assist you effectively.

  • Identification and contact data: 
    • Full name 
    • Email address and phone number 
  • Booking-related data (where applicable): 
    • Booking references and tour details linked to your request 
  • Communication data: 
    • Messages, inquiries, complaints, and feedback 
    • Communication history (email, chat, social media, or phone) 
  • Customer-provided information: 
    • Travel preferences or other information you choose to share

Performance of a contract (Article 6(1)(b) GDPR) – where communication relates to an existing booking or support request connected to our services.

Legitimate interest (Article 6(1)(f) GDPR) – to respond to general inquiries, manage customer communication, and improve our services.

  • General enquiries (no booking): 12 months after case closure 
  • Support related to bookings: 3 years after completion of the service 
  • Complaints or dispute-related communication: 5 years after resolution 
  • Health-related information shared in communication: deleted within 30 days after the tour unless required for an incident

To record and review customer service calls for quality assurance and handling complaints or disputes.  

You are not required to participate in recorded calls; alternative contact methods are available where feasible.

  • Identification and contact data: 
    • Name (if provided during the call) 
    • Phone number 
  • Call-related data: 
    • Audio recordings of calls 
    • Call transcripts (where applicable) 
    • Date and time of the call, call duration and call logs 
  • Content of communication: 
    • Inquiries, complaints, feedback, and booking-related discussions

Legitimate interest (Article 6(1)(f) GDPR) – to maintain service quality, train staff, and resolve complaints or disputes

Call recordings, transcripts, and related metadata are retained for 6 months after the call.  

Where a call is relevant to a complaint, dispute, or legal claim, it may be retained for longer, for the duration necessary to resolve the matter and/or comply with legal requirements.

To process payments and manage financial transactions related to your booking.  

This data is required to perform a contract with you. If you do not provide this information, we will not be able to process your payment or confirm your booking.

  • Identification and contact data: 
    • Full name 
    • Email address and phone number 
  • Payment and transaction data: 
    • Payment amount, transaction identifiers, payment reference numbers 
    • Payment status and billing information (e.g., invoices, confirmations) 
  • Limited card-related data: 
    • Cardholder name and masked card details (e.g., last four digits)

Performance of a contract (Article 6(1)(b) GDPR)

We may also rely on legal obligation (Article 6(1)(c) GDPR) to comply with accounting and tax requirements, and legitimate interest (Article 6(1)(f) GDPR) for fraud prevention and transaction security

Payment transaction and financial records are retained for 10 years in accordance with accounting and tax legislation.

To take and share photos or videos from tours, including making them available to participants and, where agreed, using them for marketing purposes.  

You are not required to appear in photos or videos, and your consent will be requested where images or recordings are used for promotional purposes.

Photographs, video recordings or other visual content of tour participants

Legitimate interest (Article 6(1)(f) GDPR) – to provide images or recordings to participants

Consent (Article 6(1)(a) GDPR) – for use of images or recordings in marketing or promotional materials

  • Photos and videos shared with participants: retained for 2 months after the tour 
  • Photos and videos used for marketing (with consent): 5 years from publication or until consent is withdrawn

General newsletters (customers and subscribers) 

To send you newsletters and travel-related updates (you can unsubscribe at any time)

  • Identification and contact data: 
    • Name and surname 
    • Email address 
  • Marketing data: 
    • Subscription status and preferences 
    • Engagement data (e.g., email opens, clicks) 
  • Technical data: 
    • IP address (where collected during subscription)

Consent (Article 6(1)(a) GDPR) – where you subscribe to receive marketing communications. You can withdraw your consent at any time by unsubscribing. 

We may also send marketing communications to existing customers in relation to similar services where permitted under applicable laws implementing the ePrivacy Directive. In such cases, you will always have a clear opportunity to opt out both when your contact details are collected and in each communication we send.

  • We keep your subscription data for as long as you remain subscribed to receive our newsletters. 
  • If you stop interacting with our emails, we will normally retain your data for 36 months from your last engagement. Before this period ends, we may contact you to check whether you would like to continue receiving updates. 
  • If you unsubscribe, we will remove your contact details from our mailing list without undue delay. 
  • We keep a limited record of your consent and unsubscribe request for 4 years, to demonstrate compliance with our legal obligations.

Agent newsletter (B2B) 

To send newsletters and business-related updates to travel agents (you will only receive these communications if you have subscribed, and you can unsubscribe at any time)

  • Identification and contact data: 
    • Name and surname 
    • Email address and phone number 
    • Company name 
  • Marketing data: 
    • Subscription status and preferences 
    • Engagement data (e.g., email opens, clicks) 
  • Technical data: 
    • IP address (where collected during subscription)

Consent (Article 6(1)(a) GDPR) – you can withdraw your consent at any time by unsubscribing

  • We keep your subscription data for as long as you remain subscribed to receive our newsletters. 
  • If you stop interacting with our emails, we will normally retain your data for 36 months from your last engagement. Before this period ends, we may contact you to check whether you would like to continue receiving updates. 
  • If you unsubscribe, we will remove your contact details from our mailing list without undue delay. 
  • We keep a limited record of your consent and unsubscribe request for 4 years, to demonstrate compliance with our legal obligations.

To send you important service updates related to your booking, such as notifications about Northern Lights tour conditions.  

This data is required to provide the service. Without it, we may not be able to inform you about changes or conditions affecting your tour.

  • Identification and contact data: 
    • Name and surname 
    • Phone number 
  • Booking data: 
    • Tour booking details relevant to the notification

Performance of a contract (Article 6(1)(b) GDPR) – to provide updates necessary for the delivery of the booked service 

Phone number is retained as part of booking data (see booking retention period above) 

To send you relevant reminders if you start but do not complete a booking.  

You are not required to provide this data, but without it we cannot send reminders.

  • Identification and contact data: 
    • Name and surname 
    • Email address 
  • Booking-related data: 
    • Selected services, booking details, travel preferences

Legitimate interest (Article 6(1)(f) GDPR) – to assist you in completing your booking and improve user experience 

Abandoned booking data and reminder communication is retained for 14 days from last interaction 

To personalise marketing communications and recommend tours that may be of interest to you (you can object to this processing at any time)

  • Identification and contact data: 
    • Name and surname 
    • Email address 
  • Customer and interaction data: 
    • Booking history, preferences 
    • Engagement data (email opens, clicks) 

Consent (Article 6(1)(a) GDPR) – applied where you have agreed to receive personalised marketing communications based on your booking history, preferences, or interactions

  • We keep your profiling and subscription data while you remain an active subscriber. 
  • If you stop interacting with our emails, we will normally retain your data for 36 months from your last engagement. Before this period ends, we may contact you to check whether you would like to continue receiving updates. 
  • If you unsubscribe, we will remove your contact details from our mailing list without undue delay. 
  • We keep a limited record of your consent and unsubscribe request for 4 years, to demonstrate compliance with our legal obligations.

To analyse how our website is used and improve performance, functionality, and marketing (you can manage your preferences through our cookie settings)

  • Online identifiers: 
    • Cookie IDs and device identifiers 
    • IP address, browser type, device information 
  • Usage and behavioural data: 
    • Pages visited, session duration, interactions 
    • Preferences and navigation patterns

Consent (Article 6(1)(a) GDPR) – for non-essential cookies and tracking technologies

Cookies and similar technologies used on our website have different lifespans depending on their purpose. 

Some cookies are deleted automatically when you close your browser, while others remain on your device for a defined period to recognise your preferences or improve your experience on future visits. 

For more detailed information about the specific cookies we use and how long each is retained, please see the Cookies section below.

To maintain records of individuals who have opted out of marketing communications (this ensures we respect your preferences and do not contact you again) 

  • Contact data: 
    • Email address 
  • Preference data: 
    • Opt-out status and reason, date of opt-out

Legal obligation (Article 6(1)(c) GDPR) – to ensure that individuals who have opted out of marketing communications are not contacted again, in accordance with applicable data protection and electronic communications laws 

Suppression list data is retained for as long as necessary to ensure we continue to respect your opt-out request. 

To ensure the safety and security of our premises, people, and property through video surveillance (CCTV)

Video recordings of individuals in monitored areas

Legitimate interest (Article 6(1)(f) GDPR) – to ensure safety, prevent incidents, and investigate security events 

  • Standard CCTV recordings: retained for 30 days 
  • Footage related to incidents: retained for the duration of the investigation and any related proceedings

To manage relationships with our suppliers, service providers, and contractors, including coordinating services, managing contracts, and processing payments.

This data is required to enter into and perform a business relationship. Without it, we may not be able to work with the supplier or deliver certain services.

  • Identification and contact data: 
    • Full name, identification number (where applicable) 
    • Email address and phone number 
  • Professional and business data: 
    • Job title, company name, business contact details 
  • Contractual and financial data: 
    • Contract details, service descriptions, engagement terms 
    • Invoice data, payment details, bank account information, tax identification details

Performance of a contract (Article 6(1)(b) GDPR) – where we work directly with individual contractors

Legitimate interest (Article 6(1)(f) GDPR) – to manage relationships with supplier organisations and their representatives

Legal obligation (Article 6(1)(c) GDPR) – to comply with accounting, tax, and recordkeeping requirements

  • Supplier and contractual data: retained for 10 years after the end of the contractual relationship 
  • Financial and invoice data: retained for 10 years in line with accounting and tax requirements

3. WHO WE SHARE YOUR DATA WITH? 

To provide our services and operate our business, we work with a range of trusted partners and service providers. We only share personal data where it is necessary for a specific purpose, and we always ensure that appropriate safeguards are in place to protect your information. 

Depending on the role of the provider and the nature of the service, third parties may process personal data either on our behalf and under our instructions (acting as “processors”), or as independent controllers responsible for their own processing activities. For example, payment providers, banks, social media platforms, and certain analytics or advertising partners may process personal data as independent controllers in accordance with their own privacy policies. 

Below we describe the main categories of recipients with whom we may share personal data, depending on how you interact with us. Where relevant, we may also provide additional information about specific recipients upon request. 

3.1. Service delivery partners 

If you book or participate in a tour, we may share relevant information with partners involved in delivering your experience. This may include:  

  • tour operators and activity providers 
  • accommodation providers (e.g., hotels) 
  • transport providers (e.g., ferry operators, car rental companies) 

These partners use your data only to the extent necessary to provide the services you have booked. 

3.2. Payment and financial service providers 

If you make a payment or book a service with us, your data may be shared with the service providers and financial institutions involved in processing transactions and managing our financial obligations. This may include: 

  • payment service providers (e.g., Stripe, Adyen, Teya and similar providers) 
  • banks and financial institutions 
  • accounting and audit service providers (e.g., KPMG or similar providers) 

Payment providers, banks, and financial institutions generally process payment-related data as independent controllers in accordance with their own legal and regulatory obligations.  

3.3. Communication and customer support providers 

If you contact us or communicate with us, we may use external providers to help manage customer support, booking-related communication, and day-to-day operational coordination. This may include: 

  • email, messaging, and communication platform providers (e.g., Microsoft, Meta messaging services, or similar providers) 
  • customer support and ticketing systems providers (e.g., Freshworks or similar providers) 
  • telephony and call handling system providers (e.g., 3CX or similar providers) 
  • cloud storage and collaboration tool providers  

These providers generally process personal data on our behalf and under our instructions. 

3.4. Marketing, social media, and community platforms 

If you subscribe to newsletters, participate in campaigns, collaborate with us, or interact with us on social media, we may share your data with providers that help us manage marketing communications, online engagement, and community activities. This may include: 

  • email marketing platforms (e.g., Klaviyo or similar providers) 
  • messaging infrastructure and email delivery providers (e.g., Mandrill or similar providers) 
  • cloud and collaboration providers supporting marketing communications 
  • social media and content-sharing platforms (e.g., Facebook (Meta), Instagram, TikTok, LinkedIn, Pinterest, X (Twitter), Rednote, or similar providers) 

Many of these providers process personal data on our behalf and under our instructions. However, when you interact with us through social media platforms or engage with our content there, your personal data may also be processed by the relevant platform provider in accordance with their own privacy policies and terms. This may include platforms such as Facebook (Meta), Instagram, TikTok, LinkedIn, Pinterest, X (Twitter), Rednote, or similar social networks. These platform providers generally act as independent controllers for processing carried out through their own platforms and services. 

3.5. Website, analytics, and advertising providers 

To help us operate and improve our website, understand how visitors use it, manage advertising campaigns, and improve online visibility, we may share certain personal data with providers supporting website functionality, analytics, advertising, consent management, and search engine optimisation activities. This may include: 

  • analytics providers (e.g., Google Analytics, Hotjar)  
  • advertising and social media platforms (e.g., Google, Meta, LinkedIn, TikTok, Microsoft Ads) 
  • consent management platform providers 
  • website hosting providers 
  • website optimisation and testing providers (e.g., VWO, Unbounce) 
  • SEO, paid media, and digital marketing support providers 

Some of these providers – particularly advertising platforms and social media providers – may process certain personal data as independent controllers for their own analytics, advertising, measurement, and platform improvement purposes. 

3.6. IT, cloud, and infrastructure providers 

We rely on trusted technology providers to operate our systems, support our day-to-day operations, and store data securely. This may include providers of: 

  • cloud hosting and storage services  
  • internal communication and collaboration tools  
  • booking and reservation systems  
  • IT infrastructure services  
  • accounting and business management systems  

These providers generally process personal data on our behalf and under our instructions. 

3.7. Legal, safety, and regulatory disclosures 

In certain situations, we may share personal data where necessary to comply with legal obligations, respond to lawful requests, protect individuals and property, investigate incidents or disputes, or establish, exercise, or defend legal claims. This may include sharing data with:  

  • regulators and public authorities  
  • law enforcement authorities  
  • insurance providers  
  • legal advisors  
  • emergency services 

These recipients act as independent controllers when processing personal data for their own legal, regulatory, or insurance-related purposes. 

3.8. Business transfers  

If we are involved in a merger, acquisition, restructuring, sale of assets, or similar business transaction, personal data may be transferred as part of that process. Where this happens, we will ensure that any such transfer is carried out in accordance with applicable data protection laws and that your personal data remains appropriately protected. 

4. INTERNATIONAL DATA TRANSFERS 

Because we work with travellers, partners, and service providers located in different countries, your personal data may in certain situations be transferred to or accessed from countries outside your country of residence, including outside the European Economic Area (“EEA”).  

Where personal data is transferred internationally, we take steps to ensure that it remains protected in accordance with applicable data protection laws. Depending on the circumstances, we may rely on:  

  • adequacy decisions issued by the European Commission;  
  • the European Commission’s Standard Contractual Clauses (“SCCs”); or  
  • other lawful transfer mechanisms and safeguards recognised under applicable data protection laws.  

Where appropriate, we may also implement supplementary technical and organisational measures designed to protect personal data during international transfers.  

Many of our providers operate globally, including providers of cloud infrastructure, communication tools, customer support systems, analytics services, marketing platforms, and social media services.  

You may request additional information about international transfers relevant to your personal data, including information about applicable safeguards, by contacting us using the details provided in this Privacy Policy. 

5. YOUR DATA PROTECTION RIGHTS  

Under the GDPR, you have certain rights in relation to your personal data. You may have the right to:  

  • access the personal data we hold about you, including information about how and why we use it, who we share it with, and how long we keep it. This may include requesting a copy of your booking information, customer support communication, or other personal data associated with your interaction with us;  
  • request correction of inaccurate or incomplete personal data. For example, this may include asking us to update incorrect contact information, travel details, or booking information;  
  • request deletion of your personal data in certain situations, including where the data is no longer necessary for the purpose for which it was collected or where processing was based on consent that you later withdraw. Please note that we may still need to retain certain information where required by law or where necessary for legitimate business purposes, such as handling disputes, enforcing agreements, preventing fraud, or complying with accounting and tax obligations;  
  • request restriction of processing of your personal data in certain situations. This may include temporarily limiting how we use your personal data while we assess a correction request, review an objection, or verify whether processing remains lawful;  
  • object to certain types of processing based on legitimate interests. For example, this may include objecting to reminder communications where you started but did not complete a booking; 
  • withdraw your consent at any time where processing is based on consent. For example, you can unsubscribe from marketing communications or change your cookie preferences through our website settings. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal;  
  • request transfer of personal data you have provided to us in a structured, commonly used, and machine-readable format, where technically feasible and legally applicable;  
  • not be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you. Please note that we do not currently use personal data for fully automated decision-making of this nature.  

You can exercise your rights over your personal data by contacting us at: dpo@adventures.com 

To protect your privacy and security, we may need to verify your identity before responding to certain requests, particularly where the request involves access to or deletion of personal data.  

We will respond to your request in accordance with applicable data protection laws. In most cases, this means responding within 1 (one) month of receiving your request. If your request is particularly complex or involves multiple requests, this period may be extended by up to an additional 2 (two) months. Where this applies, we will inform you accordingly.  

If you believe that your personal data has been processed unlawfully or that your rights have been violated, you also have the right to lodge a complaint with your local data protection authority. If you are located within the European Economic Area (EEA), information about national data protection authorities is available here: https://edpb.europa.eu/about-edpb/about-edpb/members_en  

6. ADDITIONAL INFORMATION FOR US RESIDENTS 

If you are a resident of a US state with applicable privacy laws, you may have additional privacy rights in relation to your personal information. Depending on your state of residence, these rights may include the right to:  

  • request access to personal information;  
  • request deletion or correction of personal information;  
  • opt out of certain targeted advertising or profiling activities; and  
  • receive additional information about how personal information is processed.  

We do not sell personal information in exchange for monetary compensation. However, certain online advertising and analytics activities may be considered “sharing”, “targeted advertising”, or similar processing under applicable US privacy laws.  

You may exercise applicable privacy rights by contacting us using the contact details provided in this Privacy Policy. 

7. COOKIES AND SIMILAR TECHNOLOGIES 

Like most websites, we use cookies and similar technologies to ensure our website functions properly, improve user experience, understand how visitors use our website, and support our marketing activities.  

Cookies are small text files stored on your device when you visit a website. Some cookies are necessary for the website to function, while others help us analyse website traffic, remember your preferences, or personalise content and advertising.  

Depending on your preferences, we may use:  

  • strictly necessary cookies – required for the website to function properly and securely. These cookies cannot be switched off through our cookie settings tool; 
  • functional cookies – used to remember your preferences and improve website functionality and user experience; 
  • analytics cookies – used to understand how visitors use our website, measure website performance, and improve our services and content;  
  • marketing cookies – used to personalise advertising, measure the effectiveness of campaigns, and display more relevant content across websites and platforms. 

As required by applicable law, non-essential cookies are only used with your consent. You can manage your cookie preferences at any time through our cookie settings tool available on the website.  

Because the cookies and technologies used on our website may change from time to time as our website and services evolve, the most up-to-date information about the specific cookies in use, including their providers, purposes, and retention periods, is available through our cookie settings tool and cookie declaration accessible on the website. 

Some cookies may be placed by third-party providers such as analytics, advertising, or social media partners. Where this happens, those third parties may also process certain information collected through cookies in accordance with their own privacy policies.  

Third-party websites  

Our website may contain links to third-party websites or services. Please note that we are not responsible for the content, security, or privacy practices of third-party websites. If you visit a third-party website, we encourage you to review their privacy information separately.

8. CONTACT US 

If you have any questions about this Privacy Policy, how we process your personal data, or if you would like to exercise your data protection rights, you can contact us using the details below:  

Straumhvarf ehf. 

Registered address: Klettagarður 11, 104 Reykjavik, Iceland 

E-mail: dpo@adventures.com   

 

We will do our best to respond to your inquiry as soon as reasonably possible.