Your Information
Privacy Policy
In this section, Sju Sjöar Konferens AB explains what personal data we process, why it is needed, how long it is retained, and what rights you have.
Responsibility for Personal Data
Who is responsible for your information?
Sju Sjöar Konferens AB is the data controller for the processing described in this policy. This means that the company determines why and how personal data is processed in connection with contact, reservations, payments, and stays.
Questions, requests for registry extracts, or other privacy-related matters should be sent to the contact information provided on this page.
Data We Process
Everything you need for your visit and stay.
Contact Information
Name, email address, phone number, company, or organization.
Inquiries and Reservations
Check-in and check-out dates, number of guests, selected rooms or services, reservation number, price, messages, and other practical information.
Participant Information
Names of participants, as well as any requests regarding rooms, accessibility, or special dietary needs, as applicable for the stay.
Payment and Finance
Payment status, order, receipt, and invoice information. Card and payment information is processed by Stripe during the payment step, and Sju Sjöar Konferens AB does not store full card numbers.
Communication
The content of emails, forms, booking messages, and other communications with us.
Technical Information
IP address, time stamp, browser information, and necessary cookies or logs required for functionality and security.
The information comes primarily from you. It may also be provided by the person making a reservation for a group, an event organizer, or an external booking channel. The person providing information about other participants is responsible for ensuring that the individuals concerned receive this information.
Purpose and Legal Basis
Every treatment must have a specific purpose.
Inquiry
To respond, provide a quote, and take action before entering into a contract. Legal basis: contract or actions taken at your request prior to entering into a contract, Article 6.1(b) of the GDPR.
Reservations and Stay
To manage the reservation, facilitate the stay, communicate practical information, and process payment. Legal basis: performance of a contract, Article 6.1(b) of the GDPR.
Accounting and Legal Requirements
To comply with accounting, tax, and other legal requirements. Legal basis: legal obligation, Article 6(1)(c) of the GDPR.
Service and Safety
To follow up on cases, prevent misuse, protect the website, and handle legal claims. Legal basis: our legitimate interest in secure operations and in safeguarding our rights, Article 6(1)(f) of the GDPR.
Optional Mailings
Newsletters or similar marketing materials are sent once you have opted in to receive them. Legal basis: consent, Article 6.1(a) of the GDPR.
Special Diets and Needs
When the data reveals health or other sensitive information, it is processed with explicit consent in accordance with Article 9(2)(a) of the GDPR.
When Information Is Needed
What happens if you don't provide the information?
Information marked as required on a booking or contact form is necessary for us to respond, enter into an agreement, or process the booking. If this information is not provided, we may be unable to handle your request or offer the requested stay.
Information regarding special dietary needs, allergies, or accessibility requirements is voluntary, but may be necessary for us to tailor your stay in a safe manner. Such information must be limited to what is actually needed and made available only to relevant employees and vendors. Anyone providing sensitive information about another participant must have that participant’s express consent.
Reservation System and Data Processor
Reservations are managed in Sirvoy.
Sju Sjöar Konferens AB uses the Sirvoy booking system, which is provided by Sirvoy Limited in Ireland. Sju Sjöar Konferens AB remains the data controller for guest and booking information. Sirvoy processes the data as a data processor in accordance with documented instructions and the requirements of Article 28 of the GDPR.
Sirvoy may engage subprocessors for, among other things, IT operations, email, payments, support, and security. According to Sirvoy’s information, most data is stored in Ireland or within the EEA, but certain subprocessors may process data in, for example, the United States and Japan. Sirvoy states that such transfers are protected by an adequacy decision, the EU–US Data Privacy Framework, or the European Commission’s standard contractual clauses, depending on the recipient.
Payment Service
Payments are processed by Stripe.
When you pay online, the information needed for the transaction is transferred to Stripe. This may include your name, email address, payment details, amount, currency, date and time, IP address, and information about the payment status. Stripe processes payment data as a data processor when the service is provided at the direction of Sju Sjöar Konferens AB.
At the same time, Stripe is the independent data controller for certain processing activities that Stripe determines itself, including fraud prevention, security, and obligations under financial and payment services legislation. For customers within the EEA, Irish Stripe companies are typically involved. Stripe may also process data outside the EEA and states that transfers are protected by, among other things, the EU–US Data Privacy Framework and the European Commission’s Standard Contractual Clauses.
Other recipients
Only those who need the information may access it.
In addition to Sirvoy and Stripe, authorized employees and vendors in areas such as food, lodging, IT operations, and accounting may be granted access to the information necessary for their respective assignments. Data processors must be subject to agreements, confidentiality obligations, and appropriate security requirements.
Information may also be disclosed to a government agency or other recipient when required by law, or when necessary to establish, assert, or defend legal claims. Sju Sjöar Konferens AB does not sell personal data.
Retention period
No longer than is necessary for the purpose.
Inquiries
They are normally retained for a maximum of 12 months after the last contact, unless they result in a booking or need to be retained for an ongoing matter.
Reservations and Stay
Data is normally retained for 24 months after check-out or cancellation for service, follow-up, and the handling of any claims.
Special Diets and Needs
The data is normally deleted or anonymized no later than 30 days after the end of the stay, unless the information is needed for a documented incident or claims case.
Financial Data
Financial information is retained through the seventh year following the end of the calendar year in which the relevant fiscal year ended.
Optional Mailings
Stored until consent is withdrawn or, at the latest, after 24 months of inactivity.
Technical Logs
Data is retained for as short a period as possible, and normally for no more than 12 months, unless it needs to be retained longer to investigate a security incident.
If the Sirvoy subscription is terminated, Sirvoy states that customer data will be deleted no later than one year after termination or earlier at the customer’s request. In certain cases, data may be retained for a longer period when required by law or for as long as it is needed to support a legal claim.
Website and Cookies
Mandatory at first—optional after the election.
Essential cookies and technical logs may be used to ensure that the website and the booking process function properly and remain secure. If analytics, marketing, or other optional cookies are used, they will not be enabled until you have given your consent. It must be possible to withdraw consent just as easily as it was given.
Your Rights
You should be able to understand and influence your treatment.
Access and Correction
You may request information about what data we process and have any inaccurate or incomplete data corrected.
Deletion and Restriction
In certain situations, you may request that your data be deleted or that its processing be restricted.
Objection
You may object to processing based on legitimate interests and may always object to direct marketing.
Data Portability
For data processed automatically based on consent or a contract, you may, in certain cases, receive it in a structured, machine-readable format.
Withdraw Consent
Consent may be withdrawn at any time with future effect without rendering previous processing unlawful.
A request is normally free of charge and is answered without undue delay, usually within one month. We may need to verify your identity. Some rights are subject to exceptions, such as when data must be retained by law.
Please contact Sju Sjöar Konferens AB if you wish to exercise any of your rights. You also have the right to file a complaint with the Data Protection Authority (IMY).
Automated Decisions
No profiling that determines your reservation.
Sju Sjöar Konferens AB does not use automated decision-making or profiling that has legal consequences or similarly significantly affects you. Availability and price can be displayed automatically in the reservation system based on the selected dates, number of guests, and reservation rules; however, this is not an automated decision as referred to in Article 22 of the GDPR.
Changes
The policy is updated as services change.
If there are changes to booking processes, payment services, cookies, or other providers, the information will be updated to ensure that it continues to accurately describe the actual processing. The latest version is always available on this page.