Privacy Policy
Last Updated: November 12, 2025
At Aurora Hotel, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the General Data Protection Regulation (GDPR) and Icelandic data protection laws.
Information We Collect
Personal Information
- Name and contact details (email, phone number, address)
- Email address for booking confirmations and communications
- Phone number for reservation management
- Billing and shipping address
- Payment card information and billing details
- Passport or identification information as required by Icelandic law
Automatically Collected Information
- IP address and device information
- Browser type and operating system
- Cookies and similar tracking technologies
- Website usage data and preferences
How We Use Your Information
- Process and manage your reservations and bookings
- Send booking confirmations, updates, and important notifications
- Provide customer service and respond to your inquiries
- Comply with legal obligations and law enforcement requests
- Send promotional offers and newsletters (with your consent)
- Improve our services, website, and guest experience
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing is necessary to fulfill our contract with you (your reservation)
- Consent: You have given explicit consent for specific processing activities (e.g., marketing communications)
- Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., fraud prevention, service improvement)
- Legal Obligation: Processing is required to comply with legal requirements (e.g., tax reporting, guest registration)
Data Sharing and Disclosure
We may share your personal data with:
- Service Providers: Third-party vendors who assist with payment processing, booking systems, and hotel operations
- Business Partners: Travel agencies and booking platforms through which you made your reservation
- Legal Authorities: Law enforcement or government agencies when required by law or to protect our rights
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience. Types of cookies we use:
- Essential Cookies: Necessary for website functionality and security
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how visitors use our website
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect website functionality.
Data Retention
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and resolve disputes. Booking and financial records are typically retained for 7 years in accordance with Icelandic tax laws.
Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Request restriction of processing under certain circumstances
- Right to Data Portability: Receive your data in a structured, commonly used format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us using the information provided below. We will respond to your request within 30 days.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, secure servers, access controls, and regular security assessments. However, no method of transmission over the internet is 100% secure.
International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Children's Privacy
Our services are not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated policy will be posted on our website with a new "Last Updated" date. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection Officer:
Aurora Hotel
Borgartún 35, 105 Reykjavík, Iceland
Email: privacy@aurorahotel.is
Phone: +354 420 1234