top of page

​Privacy and cookies

 

Last updated: 3 October 2026

 

Who is responsible?

 

Eidegrend AS, organisation number 927 534 045, is the controller of the information we use to answer enquiries, manage reservations and provide stays at Eidegrend. Our registered business address is Holdhusvegen 517, 5640 Eikelandsosen, Norway.

 

This notice covers our website, contact with us and direct reservations. For privacy questions or to exercise your rights, contact post@eidegrend.no or +47 930 32 282.

 

Information we receive

 

When you contact us, we receive your name, contact details and message. Reservations involve information about the person booking, stay dates, room, guest numbers, extras, price, payment and communications about the stay. The booking form also includes an address, a gender field and the names of additional guests.

 

We receive information from you or someone booking on your behalf. If you book for others, please tell them about this notice. Required fields should be marked on the form. If information needed for a reservation or payment is missing, we cannot complete it.

 

Please avoid sending national identity numbers, identity documents, payment card details or detailed health information through the contact form or ordinary email. Contact us to discuss how we can accommodate your needs.

 

Why we use the information

 

We use necessary contact and reservation information to provide quotations you request, complete reservations, manage payments and cancellations, and communicate about your stay. The legal basis is taking steps towards, or performing, our contract with you under Article 6(1)(b) of the GDPR.

 

Invoices, payment records and other accounting information are processed to meet bookkeeping obligations under Article 6(1)(c).

 

For other enquiries, we use the information to respond to the matter you contact us about, based on our legitimate interest in following up your enquiry under Article 6(1)(f). Necessary handling of specific legal claims also relies on legitimate interests. You can object to this processing. Optional analytics and any advertising tracking require consent under Article 6(1)(a).

 

Reservations, payments and providers

 

Wix provides the website and Wix Hotels by HotelRunner manages reservations. Wix describes its role as a processor of website customer information: Wix. HotelRunner’s Wix terms identify SAAS Hospitality Limited as the contracting party and HotelRunner as a processor of guest data: HotelRunner.

 

Stripe processes online payments. Stripe acts as a processor for some tasks and as an independent controller for purposes including its own legal duties and fraud prevention. See Stripe.

 

Email and communications providers process messages we exchange. Accounting records may be made available to accounting service providers and authorities entitled to request them. Google processes analytics information through Google Analytics; see Google and Google Analytics.

 

Processing outside the EEA

 

Providers may process information outside the EEA. Wix describes transfers to Israel under an adequacy decision and onward transfers using applicable safeguards in its data processing agreement: Wix.

 

Stripe and Google describe international transfers, including to the United States, and the adequacy decisions and standard contractual clauses they rely on: Stripe and Google.

 

HotelRunner’s Wix terms describe processing by affiliates and providers outside the hotel’s country: HotelRunner. Contact us for more information about recipients and transfer mechanisms, or to request a copy of relevant safeguards.

 

How long information is kept

 

For enquiries, retention depends on whether the matter has been answered and closed. For reservations, the criteria are whether the stay is complete, payments and refunds are settled, and a specific complaint or legal claim remains outstanding. Continued retention must relate to such an outstanding purpose or a legal duty; having been a guest does not itself justify indefinite retention.

 

Invoices, payment vouchers and other accounting records covered by the ordinary Norwegian bookkeeping obligation must be retained for five years after the financial year ends. This does not automatically apply to all guest information. You can contact us for information about retention and deletion of your information.

 

Analytics information and cookies have separate retention periods. Google explains its settings and the information they cover at Google Analytics.

 

Cookies and analytics

 

Cookies and similar technologies store or access information on your device. Strictly necessary functions, such as security and delivering a service you request, may be used without consent. Optional analytics and advertising technologies require your active consent in advance.

 

Google Analytics 4 is connected to the website to measure use and improve its content and booking journey. Analytics may include pages and actions, traffic source, device, browser and identifiers. This information is not necessarily anonymous.

 

You have the right to reject optional cookies and later withdraw consent as easily as you gave it. Withdrawal does not affect lawful processing before withdrawal. Consent to a reservation or necessary functions is not consent to advertising tracking. Contact us if you need help with your privacy choices.

 

Your rights

 

You can request access, correction, deletion or restriction of processing. Where the conditions apply, you can receive information in a portable format and object to processing based on legitimate interests. Some information must be retained to meet legal obligations even if you request deletion.

 

We normally respond within one month. We may request information needed to confirm your identity. You can complain to the Norwegian Data Protection Authority, www.datatilsynet.no, or the relevant supervisory authority in the EEA country where you live or work.

bottom of page