Privacy Policy

Haugastøl 1000 masl

Privacy Policy

Last updated: 22.02.2026

The mountain feeling

Calm, authentic and well-rounded.

Rallarvegen Signature

Cycling experiences with quality.

Nature as neighbour

Views, trails and high mountains right nearby.

This privacy policy explains how Haugastøl Turistsenter AS ("we", "us") process personal data when you visit our website www.haugastol.no, use our forms, or consent to cookies/tracking.

1) Data controller

Data controller: Haugastøl Turistsenter AS

Org. no.: 931 039 849

Address: Haugastølvegen 200, 3595 Haugastøl

Email: mail@haugastol.no

Phone: 32 08 75 64

If you have questions about privacy or wish to exercise your rights, contact us at the email above.

2) What personal data we collect

We may collect the following types of data:

A) Data you give us directly

• Name, email, phone and message content when you submit forms or enquiries.

B) Technical data (when using the website)

• IP address (often shortened/technically processed), browser type, device, language, timestamps, page views, referring page (referrer), and events on the site (clicks/scroll/outbound links, etc.).

C) Marketing/measurement data (only with consent)

• Events used for measurement and advertising (e.g. "page view", "click", booking-related events, campaign parameters). This is set up via tags/pixels and may be used for targeting/remarketing when you have consented.

3) Why we process data (purposes)

We process personal data to:

1. Deliver and secure the website (operation, troubleshooting, security).

2. Respond to enquiries and follow up requests.

3. Understand use of the website (statistics and improvements).

4. Measure and improve marketing (conversion measurement, remarketing) – only with consent.

6) Who we share data with (processors)

We may share personal data with suppliers who help us deliver the website and measurement, typically:

• Hosting/operations supplier (website/infrastructure)

• Analytics and tag suppliers (e.g. Google)

• Marketing suppliers (e.g. Meta)

They receive data only to the extent necessary for the purpose and under agreements.

7) Transfers to countries outside the EU/EEA

Some suppliers (e.g. Google and Meta) may process data outside the EU/EEA. We use EU standard contractual clauses (SCC) or other approved transfer mechanisms where required.

8) Retention

We retain personal data for as long as necessary for the purposes:

• Enquiries: normally 12 months after the dialogue has ended, unless otherwise required (e.g. documentation).

• Analytics/marketing data: according to the settings in the tools and as short as practically possible for the purpose. (GA4 has its own retention settings.)

9) Your rights

You may have the right to:

• access, rectification and erasure

• restriction and objection

• data portability (where relevant)

• withdraw consent (without affecting the lawfulness of processing before withdrawal)

You may also complain to the Norwegian Data Protection Authority (Datatilsynet) if you believe the processing is in breach of the regulations.

10) Security

We work to protect personal data through technical and organisational measures (access control, logging, minimisation, etc.). No systems are 100% secure, but we take reasonable and relevant measures based on risk.

11) Children

The website is not directed at children, and we do not knowingly collect personal data about children without parental involvement.

12) Changes to this policy

We may update the policy when the website, technology or regulations change. The "Last updated" date at the top shows the latest revision.