Skip to content

Your Information

Privacy Policy

In this section, Sju Sjöar Konferens AB explains what personal data we process, why it is needed, how long it is retained, and what rights you have.

Responsibility for Personal Data

Who is responsible for your information?

Sju Sjöar Konferens AB is the data controller for the processing described in this policy. This means that the company determines why and how personal data is processed in connection with contact, reservations, payments, and stays.

Questions, requests for registry extracts, or other privacy-related matters should be sent to the contact information provided on this page.

Data We Process

Everything you need for your visit and stay.

Contact Information

Name, email address, phone number, company, or organization.

Inquiries and Reservations

Check-in and check-out dates, number of guests, selected rooms or services, reservation number, price, messages, and other practical information.

Participant Information

Names of participants, as well as any requests regarding rooms, accessibility, or special dietary needs, as applicable for the stay.

Payment and Finance

Payment status, order, receipt, and invoice information. Card and payment information is processed by Stripe during the payment step, and Sju Sjöar Konferens AB does not store full card numbers.

Communication

The content of emails, forms, booking messages, and other communications with us.

Technical Information

IP address, time stamp, browser information, and necessary cookies or logs required for functionality and security.

The information comes primarily from you. It may also be provided by the person making a reservation for a group, an event organizer, or an external booking channel. The person providing information about other participants is responsible for ensuring that the individuals concerned receive this information.

Purpose and Legal Basis

Every treatment must have a specific purpose.

Inquiry

To respond, provide a quote, and take action before entering into a contract. Legal basis: contract or actions taken at your request prior to entering into a contract, Article 6.1(b) of the GDPR.

Reservations and Stay

To manage the reservation, facilitate the stay, communicate practical information, and process payment. Legal basis: performance of a contract, Article 6.1(b) of the GDPR.

Accounting and Legal Requirements

To comply with accounting, tax, and other legal requirements. Legal basis: legal obligation, Article 6(1)(c) of the GDPR.

Service and Safety

To follow up on cases, prevent misuse, protect the website, and handle legal claims. Legal basis: our legitimate interest in secure operations and in safeguarding our rights, Article 6(1)(f) of the GDPR.

Optional Mailings

Newsletters or similar marketing materials are sent once you have opted in to receive them. Legal basis: consent, Article 6.1(a) of the GDPR.

Special Diets and Needs

When the data reveals health or other sensitive information, it is processed with explicit consent in accordance with Article 9(2)(a) of the GDPR.

When Information Is Needed

What happens if you don't provide the information?

Information marked as required on a booking or contact form is necessary for us to respond, enter into an agreement, or process the booking. If this information is not provided, we may be unable to handle your request or offer the requested stay.

Information regarding special dietary needs, allergies, or accessibility requirements is voluntary, but may be necessary for us to tailor your stay in a safe manner. Such information must be limited to what is actually needed and made available only to relevant employees and vendors. Anyone providing sensitive information about another participant must have that participant’s express consent.

Reservation System and Data Processor

Reservations are managed in Sirvoy.

Sju Sjöar Konferens AB uses the Sirvoy booking system, which is provided by Sirvoy Limited in Ireland. Sju Sjöar Konferens AB remains the data controller for guest and booking information. Sirvoy processes the data as a data processor in accordance with documented instructions and the requirements of Article 28 of the GDPR.

Sirvoy may engage subprocessors for, among other things, IT operations, email, payments, support, and security. According to Sirvoy’s information, most data is stored in Ireland or within the EEA, but certain subprocessors may process data in, for example, the United States and Japan. Sirvoy states that such transfers are protected by an adequacy decision, the EU–US Data Privacy Framework, or the European Commission’s standard contractual clauses, depending on the recipient.

Payment Service

Payments are processed by Stripe.

When you pay online, the information needed for the transaction is transferred to Stripe. This may include your name, email address, payment details, amount, currency, date and time, IP address, and information about the payment status. Stripe processes payment data as a data processor when the service is provided at the direction of Sju Sjöar Konferens AB.

At the same time, Stripe is the independent data controller for certain processing activities that Stripe determines itself, including fraud prevention, security, and obligations under financial and payment services legislation. For customers within the EEA, Irish Stripe companies are typically involved. Stripe may also process data outside the EEA and states that transfers are protected by, among other things, the EU–US Data Privacy Framework and the European Commission’s Standard Contractual Clauses.

Other recipients

Only those who need the information may access it.

In addition to Sirvoy and Stripe, authorized employees and vendors in areas such as food, lodging, IT operations, and accounting may be granted access to the information necessary for their respective assignments. Data processors must be subject to agreements, confidentiality obligations, and appropriate security requirements.

Information may also be disclosed to a government agency or other recipient when required by law, or when necessary to establish, assert, or defend legal claims. Sju Sjöar Konferens AB does not sell personal data.

Retention period

No longer than is necessary for the purpose.

Inquiries

They are normally retained for a maximum of 12 months after the last contact, unless they result in a booking or need to be retained for an ongoing matter.

Reservations and Stay

Data is normally retained for 24 months after check-out or cancellation for service, follow-up, and the handling of any claims.

Special Diets and Needs

The data is normally deleted or anonymized no later than 30 days after the end of the stay, unless the information is needed for a documented incident or claims case.

Financial Data

Financial information is retained through the seventh year following the end of the calendar year in which the relevant fiscal year ended.

Optional Mailings

Stored until consent is withdrawn or, at the latest, after 24 months of inactivity.

Technical Logs

Data is retained for as short a period as possible, and normally for no more than 12 months, unless it needs to be retained longer to investigate a security incident.

If the Sirvoy subscription is terminated, Sirvoy states that customer data will be deleted no later than one year after termination or earlier at the customer’s request. In certain cases, data may be retained for a longer period when required by law or for as long as it is needed to support a legal claim.

Website and Cookies

Mandatory at first—optional after the election.

Essential cookies and technical logs may be used to ensure that the website and the booking process function properly and remain secure. If analytics, marketing, or other optional cookies are used, they will not be enabled until you have given your consent. It must be possible to withdraw consent just as easily as it was given.

Your Rights

You should be able to understand and influence your treatment.

Access and Correction

You may request information about what data we process and have any inaccurate or incomplete data corrected.

Deletion and Restriction

In certain situations, you may request that your data be deleted or that its processing be restricted.

Objection

You may object to processing based on legitimate interests and may always object to direct marketing.

Data Portability

For data processed automatically based on consent or a contract, you may, in certain cases, receive it in a structured, machine-readable format.

Withdraw Consent

Consent may be withdrawn at any time with future effect without rendering previous processing unlawful.

A request is normally free of charge and is answered without undue delay, usually within one month. We may need to verify your identity. Some rights are subject to exceptions, such as when data must be retained by law.

Please contact Sju Sjöar Konferens AB if you wish to exercise any of your rights. You also have the right to file a complaint with the Data Protection Authority (IMY).

Automated Decisions

No profiling that determines your reservation.

Sju Sjöar Konferens AB does not use automated decision-making or profiling that has legal consequences or similarly significantly affects you. Availability and price can be displayed automatically in the reservation system based on the selected dates, number of guests, and reservation rules; however, this is not an automated decision as referred to in Article 22 of the GDPR.

Changes

The policy is updated as services change.

If there are changes to booking processes, payment services, cookies, or other providers, the information will be updated to ensure that it continues to accurately describe the actual processing. The latest version is always available on this page.