Privacy Policy

Last updated: 01.11.24

1.    OVERVIEW

This privacy notice is prepared by Geilo Booking AS ("Geilo Booking" or "we") to ensure that you receive the information we are required to provide to you, and which is necessary for you to exercise your rights under the General Data Protection Regulation (the "GDPR") and the Norwegian data protection legislation (together "Data Protection Legislation"). This privacy notice describes how we process personal data about you, the purpose of our processing activities, and the legal basis for our processing activities. 
The data controller for the processing of your personal data is Geilo Booking (unless otherwise is specified below). As the data controller, we are responsible for safeguarding your rights under the Data Protection Legislation, including your right to receive information about how your data is processed.

2.    CONTACT US

If you have any questions about this privacy notice, including how we process personal data, or would like to submit a request to exercise your rights, please contact us at:
Geilo Booking AS
Vesleslåttvegen 11, 3580 Geilo
[email protected]
+47 32 09 00 00

3.    WHAT IS PERSONAL DATA

Personal any information relating to an identified or identifiable natural person (a "data subject"). Your name, social security number, address, telephone number and e-mail address are examples of information that generally is regarded as personal data. Personal data may also include special categories of personal data (previously called sensitive personal data), such as information about health, religious beliefs, ethnic origin, or sexual orientation.  
By processing of personal data, we mean the collection, storage, compilation, deletion and any other use of personal data. 

4.    WHO DO WE PROCESS PERSONAL DATA ABOUT?

This privacy notice covers our processing of personal data about the following categories of individuals:
•    Private individuals, including individuals who are customers of our business partners (such as travel agencies and tour operators) ("Guests")
•    Contact persons at suppliers/service providers and partners
•    Private individuals who rent out their holiday cottage/home via Geilo Booking
•    People who are signed up for our newsletter or attend our events
•    People who are looking for a job, or are otherwise relevant for employment in Team SkiGeilo 

5.    WHAT PERSONAL DATA DO WE PROCESS?

5.1    Customer care – Guests
In connection with providing our services to you as a Guest, we process personal data such as:
•    Information about you and your contact information: such as your name, date of birth, address, telephone number and email address.
•    Your customer history, including which products and services you have purchased, when you have purchased them and associated receipts.
•    Payment information, such as your bank and/or credit card information used in connection with your payments to us.
•    Other information that you provide to us, e.g., If you contact our customer service department. 
•    When renting skis and bikes, we also process the following personal data: height, weight and shoe size.  
•    If you wish to cancel your booking, we will ask for a doctor's certificate in order to offer you a refund. 

When you use our booking platform, we will forward your booking to one or more service providers. This also means that we share your personal data with the service provider, who in turn is responsible for the delivery of the ordered product and/or service. Each of the service providers is the data controller for their processing of your personal data. If you want to know more or have questions related to the service providers' processing of personal data, please contact the service provider (e.g. via the service providers' websites).   
In certain cases, you will be redirected to the SkiPerformance platform to order season passes and ski passes. The personal data that you provide in connection with your booking at such platform, SkiGeilo AS is the data controller for the personal data that you provide in connection with your booking at such platform. You can find more information about how SkiGeilo AS processes your personal data in SkiGeilo AS' privacy policy
If you are our contact person of our service providers or partners, or another employee we have direct contact with, we may process personal data such as:
•    Information about you and your contact information: such as your name, telephone number, email address, job title as well as other information about you and your employment that you have provided to us in connection with our cooperation.

5.2    Letting of holiday homes/cottages
If you list your holiday home/cottage via Geilo Booking, we process the following personal data: 
•    Information about you and your contact information: such as your name, date of birth, address, telephone number and email address, as well as the account number for disbursement. 

5.3    Email marketing, event invitations, and promotions
If you receive newsletters, other marketing emails, invitations to our events, or participate in one of our campaigns, we may process personal data such as:
•    Information about you and your contact information: Name, date of birth, gender, email address, telephone number, job title and employer (if you represent a business partner or service provider).
•    Your customer history: including information about which products and services you have purchased and when you purchased them (including indirect information about family relationships, e.g. if you've purchased a season ticket family package).

We may also process the above information to improve the service offering in Geilo. As a general rule, we will anonymize or pseudonymize your personal data before it is used in connection with analyses or for statistical purposes.

5.4    Visits on our website
When you visit our website, we and certain third parties may collect information about how you use our website, using cookies that are stored on your device. You can read more about our use of cookies in our cookie notice here.

5.5    Job seekers and recruitment
If you wish to become part of Team SkiGeilo, we (and other companies in our group that may be involved) will process the personal data you provide to us in connection with the recruitment process, including your name, your contact information, study and work experience, current job title, etc. We may also process the names and contact details of any references you provide. Please note that the data controller for the processing of personal data in this case, is the company in our group with which you are applying for a job.  
We use the Nuu recruitment system in connection with our recruitment processes. You can read more about the processing of personal data in this system here

6.    WHAT IS THE PURPOSE OF OUR PROCESSING OF PERSONAL DATA?

We process the personal data specified in sections 5.1, 5.2 and 5.3 above, because it is necessary to establish and administrate our customer or service provider relationship, for invoicing purposes and to enable Geilo Booking and our service providers to deliver our products and services to you. Payment and other purchase documentation is further processed for purposes related to e.g. internal reporting and compliance with bookkeeping obligations.
We process the personal data specified in section 5.4 for marketing purposes and to adapt and improve our own and our service providers' products, services and events.
We process the personal data specified in section 5.6 to assess you as a potential employee in Team SkiGeilo, and to form a sound basis for decision making in our recruitment processes.

7.    WHAT IS THE LEGAL BASIS FOR OUR PROCESSING OF PERSONAL DATA?

If you are a Guest or if you list your holiday home/cottage via Geilo Booking, we process your contact details, payment details and any other information about you (as further described above) because it is necessary for us, our service providers and partners to deliver products and services to you. The legal basis for our processing of information about your height and weight, and  a medical certificate in the event of a refund, is that you have provided us consent. 
If you are a contact person or a representative of one of our service providers or partners, we will process your data because it is necessary for purposes related to Geilo Booking's legitimate interests. This legitimate interest is the establishment and administration of our relationship with the company for which you are the contact person.
Any personal data about you included in documents related to purchases or bookkeeping, will be processed according to our legal obligations.
We process the personal data described in section 5.4 for purposes related to Geilo Booking's legitimate interests. These legitimate interests are the marketing and improvement of Geilo Booking's services and products, our service providers' services and products, as well as the service offering at Geilo in general. We also process this information for marketing purposes to know what relationship you have with Geilo Booking. The legal basis for our processing of your personal data in connection with sending electronic marketing inquiries to you, is your consent. 
We process the personal data described in section 5.5 for purposes related to Geilo Booking's (and Team SkiGeilo's) legitimate interests, which is to recruit and hire relevant candidates in our business.
If we have asked for your consent to the processing of personal data, you can withdraw this at any time.

8.    DISCLOSURE OF PERSONAL DATA AND USE OF DATA PROCESSORS

In specific intances, we will share and receive personal data with other companies within our group for the purposes of recruitment, as well as for marketing and statistical analyses. This includes information (such as name, e-mail or order information) from SkiGeilo AS, if you have booked a ski pass with them at the Skiperformance platform. In the latter case, we share the data for marketing purposes and to improve our services. We consider that these interests outweigh the consideration of your privacy.   
Furthermore, we use various suppliers who provide IT services and other administrative services to us. We have entered into data processing agreements with these service providers that require the companies in question to ensure that personal data is stored in a secure manner, to prevent unauthorized access to personal data, and that personal data is not used for purposes other than those designated by Geilo Booking.
We will not disclose your personal data to parties other than those mentioned above, unless we are required by law to disclose information.
If it is relevant to disclose your personal data to countries outside the EU/EEA, we will ensure that your personal data is adequately secured, for example by entering into Standard Contractual Clauses (SCCs) prepared by the European Commission.

9.    HOW LONG WILL WE KEEP YOUR PERSONAL DATA?

We will delete or anonymize personal information when it is no longer necessary for the purpose for which it was collected, as well as in accordance with the following deletion practices:
•    The personal data related to the customer relationship, including your name and contact information, will be processed for as long as we have an active customer relationship with you. After the customer relationship ends, the information will be deleted after 3 years.
•    Depending on the nature of the documentation, the documentation of your purchase will be stored for either 3 1/2 or 5 years in accordance with the Bookkeeping Act.
•    All medical certificates will be deleted upon the completion of the processing of your refund application.
•    Once you have consented to receive newsletters and other marketing from us, your information will be deleted if you choose to withdraw your consent.
•    Information about job applicants who are not hired will be deleted after the recruitment process has ended, unless you have provided your consent for us to retain your personal data for a period thereafter, enabling us to reach out to you should new positions become available.

10.    WHAT RIGHTS DO YOU HAVE?

If we process your personal data, you have a number of rights under the Data Protection Act that you can assert against us. 
•    Access. You may contact us if you want to obtain confirmation with respect to whether or not we are processing your personal data, as well as access to and further information regarding our processing of your personal data. You may also request a copy of the personal data we are processing about you. 
•    Correcting personal data (rectification). You may ask us to rectify any errors in your personal data. 
•    Erasure (the right to be forgotten). You may ask us to erase your personal data, which request we will respect and comply with. 
•    Restriction. You may ask us to restrict the processing of your personal data. 
•    Object. You are entitled to object to certain processing activities. You are furthermore, on grounds relating to your particular situation (for example, a specific need for protection of your identity), entitled to object to processing of personal data based on legitimate interests, which we will comply with, unless there exists compelling legitimate grounds for our processing which override your interest, or if our processing is necessary for the establishment, exercise or defence of legal claims. 
•    Data portability. You may ask us to provide you or others with your personal data in a structured, commonly used and machine-readable format. 
Please note that there are exceptions and further conditions to the rights described above and that not all of the rights will be relevant to all of our connections and customers. 
You may contact us as stated in section 2 above, if you wish to exercise any of the above rights. Please note that we may request additional information from you if such information is necessary to confirm your identity. 

11.    THE NORWEGIAN DATA PROTECTION AUTHORITY, COMPLAINTS AND APPLICABLE DATA PROTECTION LEGISLATION

If you have additional questions on how we process personal data, or are dissatisfied with our processing, you are welcome to contact us. Please find our contact information in section 2 above. 
You may also lodge a complaint with the relevant supervisory authority. Please click here to access the contact information to the Norwegian Data Protection Authority. The contact details for all EU Supervisory Authorities can be found here
Further details on your rights are available in the Data Protection Act and the General Data Protection Regulation (GDPR), which can be accessed by clicking here

12.    CHANGES

We may update the privacy notice from time to time. The privacy notice will, for example, be updated to comply with any legislative amendments or if we make changes to our processing of personal data.  The most recent version of the privacy notice will always be available at our website. This privacy notice is effective as of the date indicated initially.