Skip to content
    Boreal Yachting

    Privacy policy

    Last updated: 23.09.2026

    Who we are

    Boreal Yachting AS ("Boreal Yachting", "we", "us") is the data controller for the personal data described in this policy.

    Boreal Yachting AS, Eidevegen 666, 9105 Kvaløysletta, Norway

    Organisation number: 997 672 488

    Email: post@boreal-yachting.com Telephone: +47 77 72 92 00

    We are established in Norway. Norway is part of the European Economic Area, and we process personal data in accordance with the General Data Protection Regulation (GDPR) as implemented in Norwegian law.

    We have not appointed a Data Protection Officer. For any question about this policy or about how we handle your data, write to post@boreal-yachting.com.

    What this policy covers

    This policy explains what personal data we collect when you visit boreal-yachting.com, enquire about a voyage, book with us, travel with us, or work with us as a travel partner — and what we do with it.

    The personal data we collect

    When you send an enquiry

    Through our enquiry forms we collect your name, email address, country, and — if you provide it — your telephone number. We also collect what you tell us about your plans: the experience you are interested in, preferred dates, group size, group type, your sailing or ski touring experience, and anything you write in the free-text field.

    When you enquire or book as a travel partner

    If you contact us as a travel agency, tour operator, guiding company or travel designer, we collect your company name, website, country, your name, your role, your email address and telephone number, and the details of the enquiry — including, where relevant, information about the clients you are booking for.

    When you book a voyage

    Bookings are handled through MMK Booking System. Depending on the voyage, we collect your name, contact details, billing information, the names of everyone in your party, and information needed to operate the voyage safely.

    For some voyages we also collect:

    • date of birth
    • passport or identity document details, where required for travel to Svalbard
    • next-of-kin or emergency contact details
    • travel insurance details
    • relevant sailing, skiing or medical information needed to plan the voyage safely

    We invoice for voyages. We do not take payments online.

    To issue an invoice we collect the billing name and address, and for companies and travel partners the company name and organisation number.

    We do not collect, process or store payment card details at any point. Payment is made by bank transfer to our account. When a payment reaches us, our bank provides us with the payer's name and account details, as banks are required to do.

    Dietary requirements and health information

    Before departure we ask about dietary requirements, including allergies and intolerances, so that meals can be prepared safely on board.

    Information about allergies and intolerances is health data. Under the GDPR this is a special category of personal data, which receives additional protection. Information about a vegetarian or other diet may also reveal religious or philosophical beliefs, which is likewise a special category.

    We process this information only with your explicit consent, given when you provide it, and only for the purpose of preparing food safely and planning the voyage. We share it only with the crew who need it to do that. You may withdraw your consent at any time by contacting us — although if you do, we may not be able to cater safely for you.

    If you tell us about a medical condition that affects your participation, we treat it the same way.

    When you visit the website

    We collect technical and usage information through cookies and similar technologies: your IP address, browser and device type, pages visited, how you reached the site, and how you interact with it.

    Analytics and marketing cookies are only set after you consent. Until then, no non-essential cookies are placed and no analytics or advertising data is collected. Strictly necessary cookies, which make the site work, are set without consent because the site cannot function without them.

    When you contact us directly

    If you email, call or message us, we keep a record of that correspondence.

    Purposes of processing and their legal basis
    What we do Why Legal basis
    Answer your enquiry and prepare a proposal To respond to a request you made and to take steps before entering a contract Contract / pre-contractual steps — GDPR Art. 6(1)(b)
    Manage a booking and operate your voyage To perform our contract with you Contract — Art. 6(1)(b)
    Cater for allergies, intolerances and dietary needs To prepare food safely Explicit consent — Art. 9(2)(a), together with Art. 6(1)(a)
    Operate voyages safely, including emergency contacts To protect health and safety, and to perform our contract Contract — Art. 6(1)(b); vital interests — Art. 6(1)(d) in an emergency
    Keep accounting records To comply with Norwegian bookkeeping law Legal obligation — Art. 6(1)(c)
    Manage relationships with travel partners and agencies To run and develop our business relationships Legitimate interests — Art. 6(1)(f)
    Analytics and measuring how the website is used To understand what works and improve the site Consent — Art. 6(1)(a)
    Advertising and measuring advertising performance To reach people who may be interested in our voyages Consent — Art. 6(1)(a)
    Send you marketing emails To tell you about voyages and availability Consent — Art. 6(1)(a)
    Handle complaints and legal claims To establish, exercise or defend legal claims Legitimate interests — Art. 6(1)(f)

    Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can object to this processing at any time — see Your rights below.

    Providing your name and contact details is necessary for us to answer an enquiry or take a booking. Everything else is optional, although some of it affects what we are able to offer you.

    Who we share your data with

    We do not sell your personal data. We share it with the following categories of recipient:

    Service providers who process data on our behalf

    Service providers who process data on our behalf
    Provider What they do Where
    MMK Booking System Booking and reservation management Croatia
    Google (Analytics, Tag Manager) Website analytics and tag management EU / United States
    Meta Platforms Advertising measurement and audiences EU / United States
    HubSpot Customer relationship management and email [BEKREFT: ta ut hvis ikke i bruk ved publisering] EU / United States
    Microsoft Business email
    Wordpress Website hosting
    Poweroffice Invoicing and accounting Norway

    Each of these acts as a data processor under a data processing agreement, and may only use your data on our instructions.

    Others

    • Crew and guides operating your voyage, who receive only what they need to run it safely
    • Partner agencies, where you booked through one
    • Our accountant and auditor
    • Public authorities, including Sysselmesteren (the Governor of Svalbard), where regulations require passenger information for expeditions to Svalbard
    • Insurers, and legal advisers if a claim arises
    • Our bank. Payments are made by bank transfer. Our bank processes payment information as an independent data controller under its own legal obligations, including anti-money-laundering and accounting law, rather than on our instructions. Its own privacy policy governs that processing.

    Transfers outside the EEA

    Some of our providers are based in, or transfer data to, the United States.

    Google, Meta and HubSpot are certified under the EU–US Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection. Where a provider is not covered by that framework, we rely on the European Commission's Standard Contractual Clauses together with additional safeguards.

    You may ask us for details of the safeguards that apply to a specific transfer.

    How long we keep your data

    How long we keep personal data
    Data Retention
    Enquiries that do not lead to a booking 24 months after last contact
    Booking and guest records 5 years after the end of the financial year, as required by Norwegian bookkeeping law
    Accounting records 5 years after the end of the financial year, as required by Norwegian bookkeeping law
    Dietary and health information Deleted after the voyage ends and latest within 30 days]
    Partner and agency records For the duration of the relationship, and afterwards
    Marketing consent and email subscriptions Until you withdraw consent, and a record of the withdrawal afterwards
    Website analytics 14 Months

    When a retention period ends, we delete the data or anonymise it so that it can no longer identify you.

    Cookies

    We use cookies and similar technologies for three purposes: to make the website work, to understand how it is used, and to measure advertising.

    Only strictly necessary cookies are set when you arrive. Analytics and advertising cookies are set only after you give consent through our cookie banner. You can change or withdraw your consent at any time through .

    [BEKREFT: legg inn en tabell over faktiske informasjonskapsler — navn, formål, varighet, leverandør. Samtykkeverktøyet deres genererer som regel denne automatisk.]

    Your rights

    Under the GDPR you have the right to:

    • Access the personal data we hold about you, and receive a copy
    • Correct data that is inaccurate or incomplete
    • Erase your data, where we no longer have grounds to keep it
    • Restrict how we use your data while a question about it is resolved
    • Object to processing based on our legitimate interests, and to direct marketing at any time
    • Portability — receive data you gave us in a machine-readable format, and have it sent to another controller where technically feasible
    • Withdraw consent at any time, where we rely on consent. This does not affect anything we did before you withdrew it.

    To exercise any of these rights, write to post@boreal-yachting.com. We will respond within one month. We may ask you to confirm your identity first.

    Complaints

    If you think we have handled your personal data incorrectly, please contact us first — we would rather hear about it and fix it.

    You also have the right to complain to the Norwegian Data Protection Authority:

    Datatilsynet www.datatilsynet.no

    If you live in another EEA country, you may complain to your local supervisory authority instead.

    Security

    We take reasonable technical and organisational measures to protect personal data against loss, misuse and unauthorised access. Access to guest and partner data is limited to people who need it to do their work. Our website is served over an encrypted connection.

    No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify Datatilsynet and, where required, you.

    Children

    Our voyages are sold to adults, and the website is not directed at children. Where children travel as part of a family or group booking, we process their data on the basis of the booking contract with the adult who made it, and we collect no more than is needed to carry them safely.

    Automated decision-making

    We do not make decisions about you by automated means alone, and we do not carry out profiling that produces legal or similarly significant effects.

    Changes to this policy

    We update this policy when our practices change. The date at the top shows when it was last revised. If a change materially affects how we use your data, we will tell you directly where we can.

    Contact

    Questions about this policy, or about your data:

    post@boreal-yachting.com +47 77 72 92 00 Boreal Yachting AS, Tromsø, Norway

    Cookies on this site

    We use essential cookies to run the site. Analytics cookies stay off unless you accept them. You can change your choice at any time.