

Privacy Policy
Last updated: September 2026*
Andenes Suite Hotel AS (“Andenes Suite Hotel”, “we”, “us” or “our”) is committed to processing personal data in a safe and responsible manner.
This Privacy Policy explains how we process personal data when you:
-
make a reservation or stay at our hotel
-
contact us
-
use our website
-
receive information or marketing from us
-
otherwise interact with Andenes Suite Hotel.
We process personal data in accordance with the Norwegian Personal Data Act and the EU General Data Protection Regulation (GDPR).
1. Who is the data controller?
Andenes Suite Hotel AS is the data controller for the personal data processed in connection with our services.
Contact information:
Andenes Suite Hotel AS
[Address]
Org. no.: [organisation number]
Email: [email address]
Telephone: [telephone number]
If you have questions about how we process personal data, or wish to exercise your rights, you can contact us by email or telephone.
2. What personal data do we process?
The information we process depends on how you interact with us.
When you make a reservation or stay at the hotel, we may process, among other things:
-
name
-
contact details, such as email address and telephone number
-
information relating to your reservation and stay
-
arrival and departure dates
-
number of guests
-
room and reservation information
-
payment and invoicing information
-
communication between you and the hotel
-
other information you provide to us in connection with your reservation or stay.
We may also process information that is necessary to handle payments, accounting, security, complaints, customer service or other matters relating to your hotel stay.
We ask that you do not send us sensitive personal data or other information that is not necessary for handling your enquiry or stay.
3. Why do we process personal data?
We process personal data for the following purposes:
Reservations and hotel stays
We use personal data to:
-
register and manage reservations
-
communicate with you before, during and after your stay
-
provide the services you have booked
-
manage check-in and check-out
-
manage payments and invoicing
-
handle changes or cancellations
-
respond to questions, requests and other enquiries.
The legal basis is normally that the processing is necessary to perform the agreement with you.
Customer service and communication
We process personal data when you contact us, for example by email, telephone or other communication channels.
We do this in order to respond to your enquiry, follow up on your stay or handle other matters relating to the customer relationship.
The legal basis will normally be performance of a contract, compliance with a legal obligation or our legitimate interest in being able to administer and respond to customer enquiries.
Accounting and other legal requirements
We process personal data when this is necessary to comply with our legal obligations, including requirements relating to accounting, bookkeeping, payments and reporting to public authorities.
Security and prevention of misuse
We may process personal data when this is necessary to maintain security at the hotel, protect our guests, employees and business, and prevent or handle fraud, misuse or other security incidents.
In such cases, the processing may be based on our legitimate interest or a legal obligation.
Marketing
We may send information and marketing about our services where we have a valid legal basis for doing so.
Where consent is required, we will obtain consent before sending such marketing.
In certain circumstances, we may send marketing communications to existing customers in accordance with the rules applicable to electronic marketing. You will always have the opportunity to opt out of such marketing.
You can contact us at any time if you do not wish to receive marketing communications from us.
4. What is our legal basis for processing personal data?
We process personal data on one or more of the following legal bases:
-
Performance of a contract – when the processing is necessary to provide services you have booked, such as a hotel stay.
-
Legal obligation – when we are required to process personal data under applicable laws or regulations, for example for accounting and bookkeeping purposes.
-
Legitimate interest – when we have a legitimate interest in processing personal data and this interest outweighs considerations relating to your privacy.
-
Consent – when the processing requires your consent. You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
We always assess which legal basis applies to the relevant processing activity.
5. Who may we share personal data with?
We do not share personal data with others except where this is necessary to provide our services, comply with legal obligations or protect our legitimate interests.
Personal data may be processed by service providers that assist us with:
-
hotel and reservation systems
-
payment services
-
accounting and financial services
-
operation and maintenance of IT systems
-
website and technical services
-
communication and customer service.
Such service providers may process personal data on our behalf and will be subject to appropriate agreements and requirements relating to privacy and information security.
We may also disclose information where required by law, regulations or an order from a public authority.
6. Reservations through third-party booking platforms
If you make a reservation through an external booking platform or other partner, your personal data may also be processed by that company.
The relevant company will be responsible for its own processing of personal data. We recommend that you also read the privacy policy of the booking platform you use.
7. How long do we keep personal data?
We retain personal data for as long as necessary for the purpose for which it was collected, unless we are required by law or regulations to retain the information for a longer period.
The retention period therefore depends, among other things, on:
-
the type of information
-
the purpose for which it is processed
-
whether you have an active customer relationship with us
-
legal requirements concerning retention
-
the need to document or handle potential claims or disputes.
When personal data is no longer necessary, it will be securely deleted or anonymised unless we have another lawful basis for retaining it.
8. Information security
We have technical and organisational measures in place to protect personal data against, among other things, unauthorised access, alteration, loss or other unlawful processing.
Access to personal data is limited to persons and service providers who have a legitimate need for access.
9. Cookies
Our website may use cookies and similar technologies.
Some cookies may be necessary for the website to function. Other cookies may be used for purposes such as statistics, analytics or other purposes.
Where consent is required for the use of cookies or similar technologies, we will obtain such consent in accordance with applicable regulations.
You can read more about the cookies we use, their purposes and how you can manage your consent in our Cookie Policy.
[Link to Cookie Policy]
10. Your rights
Depending on the circumstances and the conditions set out in the data protection regulations, you have several rights in relation to your personal data.
You may have the right to:
Access
You can request information about which personal data we process about you.
Rectification
You can ask us to correct personal data that is inaccurate or incomplete.
Erasure
In certain circumstances, you can request that personal data relating to you be deleted.
However, we may be legally required to retain certain information, for example due to statutory retention requirements.
Restriction of processing
In certain circumstances, you can request that the processing of your personal data be restricted.
Right to object
In certain circumstances, you can object to the processing of your personal data where the processing is based on our legitimate interest.
You also have an unconditional right to object to the processing of personal data for direct marketing purposes.
Data portability
Where the relevant conditions are met, you may have the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format.
Withdraw consent
Where processing is based on consent, you may withdraw your consent at any time.
11. How can you exercise your rights?
If you wish to exercise any of your rights, you can contact us:
Email: resepsjon@andenessuitehotel.no
Telephone: +47 4141 5550
We will normally respond to your request without undue delay and no later than one month after receiving it. In certain circumstances, this period may be extended in accordance with applicable data protection regulations.
To protect your personal data, we may ask for information necessary to verify your identity before processing your request.
12. Complaints to the Norwegian Data Protection Authority
If you believe that our processing of personal data does not comply with applicable data protection regulations, you can contact us so that we have an opportunity to investigate the matter.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe that your personal data is being processed in breach of applicable data protection regulations.
13. Changes to this Privacy Policy
We may update this Privacy Policy if there are changes to how we process personal data, our services or applicable laws and regulations.
The latest version will always be available on our website.
Last updated: September 2026*