Privacy Policy (retreatsiceland.com)
Last updated: [07 April 2026]
This Privacy Policy explains how Armonia ehf – retreatsiceland.com (“we”, “us”, or “our”) collects, uses, and protects your personal information when you visit our website, contact us, or book retreats and related services.
We are committed to protecting your privacy and handling your personal data in a transparent and secure way, in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
1) Who We Are (Data Controller)
The data controller responsible for processing your personal data is:
Business/Company name: [Your legal entity name]
Address: [Your business address]
Email: [[email protected] or your email]
Phone: [your phone]
Country of establishment: Iceland
If you have any questions about this Privacy Policy or how we handle your data, please contact us using the details above.
2) What Personal Data We Collect
We may collect the following categories of personal data:
A) Data you provide to us
- Contact details: name, email, phone number
- Booking details: retreat dates, preferences, number of guests, special requests
- Messages: information you submit via contact forms, email, chat, or enquiries
- Payment-related data: (note: we typically do not store full card details—payments are processed by third-party payment providers)
B) Data collected automatically
When you browse the site, we may collect:
- Device and technical data: IP address, browser type, device identifiers, operating system
- Usage data: pages visited, time on site, clicks, referrals, approximate location (based on IP)
- Cookie data: as described in the Cookies section below
C) Sensitive data (special category data)
We do not request sensitive personal data (such as health information) as standard.
If you voluntarily provide sensitive details (e.g., dietary needs, medical considerations), we will treat it with additional care and only use it for the purpose you provided it.
3) Why We Use Your Data (Purposes)
We use your personal data to:
- Provide and manage bookings (retreat reservations, confirmations, schedules)
- Respond to enquiries and provide customer support
- Send service communications (booking confirmations, important updates, changes)
- Improve the website (analytics, performance, user experience)
- Process payments through secure third-party providers
- Prevent fraud and ensure security
- Comply with legal obligations (accounting, tax, regulatory requirements)
- Marketing communications (only when permitted—see section 6)
4) Legal Bases for Processing (GDPR)
We process personal data under one or more of the following legal bases:
- Contract: to perform a contract with you (e.g., booking a retreat)
- Legitimate interests: to run and improve our business and website, prevent fraud, and provide customer service (balanced against your rights)
- Consent: for certain cookies and optional marketing communications
- Legal obligation: for tax, accounting, and other regulatory compliance
5) Who We Share Your Data With
We may share your data with trusted third parties only when necessary, such as:
- Booking and reservation systems (if used)
- Payment providers (e.g., Stripe, PayPal) to process transactions
- Email/SMS providers used for confirmations and communication
- Analytics providers (e.g., Google Analytics) to understand website usage
- Advertising platforms (e.g., Meta/Facebook, Google) if you consent to marketing cookies
- Service providers (hosting, security, IT support) who help operate the site
- Authorities where required by law (e.g., tax, legal requests)
We do not sell your personal data.
6) Marketing Emails & Communications
If you sign up for updates or request information, we may send you marketing messages about retreats, offers, or content.
- You can unsubscribe at any time using the link in our emails or by contacting us.
- Where required by law, we will only send marketing communications with your consent.
7) Cookies & Tracking Technologies
We use cookies and similar technologies to:
- Make the website function properly (necessary cookies)
- Improve site performance and understand usage (analytics cookies)
- Support marketing/advertising (marketing cookies), if enabled
You can control cookies through:
- Your browser settings
- Our cookie banner/consent tool (if implemented)
Note: Disabling cookies may impact site functionality.
8) International Transfers
Some of our service providers may process data outside the European Economic Area (EEA).
When this happens, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs), or
- Processing in countries recognized as providing adequate protection
9) How Long We Keep Your Data (Retention)
We keep personal data only as long as necessary for the purposes outlined in this policy:
- Booking and customer records: typically retained for legal/accounting purposes (e.g., [5–7 years] depending on applicable rules)
- Enquiries: retained for as long as necessary to respond and follow up
- Marketing data: retained until you unsubscribe or withdraw consent
- Analytics data: retained according to the configuration of the analytics platform
10) Your Rights (GDPR)
You have the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Delete your data (in certain cases)
- Restrict processing (in certain cases)
- Object to processing based on legitimate interests
- Withdraw consent at any time (where processing is based on consent)
- Data portability (where applicable)
To exercise these rights, contact us at: [your privacy email].
You also have the right to lodge a complaint with your local data protection authority.
In Iceland, this is typically the Icelandic Data Protection Authority (Persónuvernd).
11) Security
We take appropriate technical and organisational measures to protect your data against unauthorised access, loss, misuse, or alteration.
However, no method of transmission over the internet is 100% secure.
12) Children’s Privacy
Our services are not intended for children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can remove it.
13) Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites. Please review their privacy policies.
14) Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date.
Hafðu samband
If you have questions about this Privacy Policy or how we handle your data:
Email: [email protected]
Address: Tjarnarmói 8, 800 Selfoss, Iceland
Website: retreatsiceland.com
Quick Questions (so I can tailor it perfectly)
If you answer these, I can customize the text to match your exact setup (and remove placeholders):
- What is the legal business name behind retreatsiceland.com?
- Do you use a booking platform (e.g., Bókun, FareHarbor, TrekkSoft, etc.) or just forms/email?
- Do you use Google Analytics, Meta Pixel, or Google Ads tracking?
- Which payment provider do you use (Stripe/PayPal/other)?
- Do you want a separate Cookie Policy page too? (Recommended)
If you give me those details, I’ll return a final “ready-to-publish” version in one go.
