Legal
Privacy Policy
Stillhavn Resort & Casino is a hotel project in development. This website collects no analytics and runs no advertising trackers. The only personal data we hold is what you choose to send us.
1. Who is responsible for your data
The controller of the personal data described here — the person who decides why and how it is processed — is the owner and publisher of this website:
- Controller
- Ruslan Manko
- Address
- prosp. Nauky 42, Kyiv 02000, Ukraine
- Data protection contact
- [email protected]
2. What this policy covers
This policy covers the website at stillhavnresort.com and the email correspondence that follows from it. Stillhavn Resort & Casino is a planned resort on the fjord coast north of Bergen. It has not been built and accepts neither guests nor reservations, so there is no booking system, guest account, payment processing or loyalty programme for this policy to describe.
If reservations open in the future, the processing involved will be different, and this policy will be rewritten and republished before that happens rather than quietly stretched to cover it.
3. What data we collect
We collect two kinds of data: what you send us yourself, and what any web server records automatically.
Data you send us
The interest list form has no backend: submitting it opens your own email application with a message prepared for you, and nothing leaves your device until you send it. When you do, we receive:
- your name, as you give it;
- your email address, and whatever else your provider puts in the message headers;
- what you told us you are interested in, such as a room type or events;
- whether you ticked the box consenting to project news, with the date and time of the message, which is how we record that consent was given;
- anything else you decide to write in the body of your message.
Data recorded by the server
Our hosting provider's servers keep the usual technical logs: IP address, date and time, page requested, referring page and user-agent string. We do not use them to profile or identify you; they exist to keep the site running and secure.
Storage in your own browser
The site stores a little interface state in your browser. It stays on your device, is never sent to us and is not used to recognise you; the Cookie Policy lists exactly what is stored.
4. No analytics and no advertising trackers
There is no analytics on this website. No Google Analytics, no pixels, no advertising or social media trackers, no heatmaps, no session recording, no fingerprinting, and no third-party scripts of any kind.
This is a design decision. Every asset the site needs — fonts, styles, scripts, images — is served from our own domain, so opening a page here does not cause your browser to contact anybody else. We take no automated decisions producing legal or similarly significant effects, so Article 22 of the GDPR does not apply.
If analytics is ever added, a consent banner will appear and nothing non-essential will be set before you agree to it.
5. Why we use your data, and our legal bases
Under Article 6 of the GDPR every purpose needs its own legal basis. Ours are these:
Answering your message
If you write to us about the project, we use your name, address and message to reply. The basis is our legitimate interest in responding to people who contact us, under Article 6(1)(f).
Sending you project news
If you tick the consent box, we use your name and email address to send occasional news: design updates, progress towards construction, the opening date once there is one, and word of when reservations open. This is a separate purpose on a separate basis — your consent, under Article 6(1)(a). For email marketing to recipients in Norway, consent is also required by section 15 of the Norwegian Marketing Control Act (Markedsføringsloven), and we apply that standard to everyone on the list.
You are never added as a side effect of asking us something: the box is separate and never pre-ticked.
Keeping the site running and secure
Server logs are used to operate the site and defend against abuse — our legitimate interest in the security of our own website, under Article 6(1)(f).
Meeting our legal obligations
Where the law requires us to keep or disclose something, such as proof that consent was validly obtained, the basis is Article 6(1)(c).
6. Consent to project news, and how to withdraw it
You can withdraw your consent at any time, for any reason or none, and it costs you nothing:
- write to [email protected] and ask to be removed; or
- reply to any email we have sent you and say so.
Either way is enough, and you need not explain yourself.
The list is currently run by hand from an ordinary mailbox, so withdrawal is handled by a person rather than a link. When we move to a mailing service, every message will also carry a one-click unsubscribe link and this policy will say so. We would rather describe the mechanism we have than promise one we do not.
Withdrawing consent does not affect the lawfulness of anything we did while the consent stood.
7. How long we keep your data
We keep personal data only as long as the purpose it was collected for exists.
- Interest list entries — until you withdraw consent or the project is abandoned, whichever comes first.
- The record of consent — the message and its date, for as long as we could reasonably be asked to prove consent existed.
- General correspondence — up to two years after the exchange ends, then deleted.
- Server logs — the short period our host retains them, normally weeks.
When a period ends, the data is deleted from our mailbox and from any backup still within its rotation.
8. Who receives your data
We do not sell or rent personal data, and we do not share it for anyone else's marketing. The only parties who handle it are those we need to run a website and a mailbox, each a processor acting on our instructions:
- Our hosting provider, which stores the site files and keeps the server logs described above.
- Our email provider, which carries and stores the messages you send us.
- A mailing service, if one is engaged for project news. It will be named here before it is used.
Beyond those there are no recipients: the fonts are self-hosted, the site makes no third-party requests, and no advertising network, analytics vendor or data broker is involved. We would disclose data to a public authority only where legally obliged.
9. International transfers
The controller is established in Ukraine, outside the European Economic Area, so if you write to us from Norway or elsewhere in the EEA your message is read and stored outside the EEA.
Ukraine is not currently the subject of an adequacy decision under Article 45 of the GDPR. Transfers are therefore made on the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c), with the safeguards in section 13. Where a provider is itself established in the EEA or an adequate country, that route applies instead.
10. Your rights under the GDPR
Articles 15 to 22 of the GDPR give you the following rights over your own data:
- Access (Art. 15) — to be told whether we hold data about you and receive a copy.
- Rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17) — to have your data deleted where we no longer have good reason to hold it.
- Restriction (Art. 18) — to have processing paused while a dispute about accuracy or legitimate interest is resolved.
- Portability (Art. 20) — to receive the data you gave us in a structured, machine-readable format, and to have it sent to another controller where feasible.
- Objection (Art. 21) — to object to processing based on our legitimate interests; against direct marketing the right is absolute.
- Withdrawal of consent (Art. 7(3)) — as described in section 6.
Write to [email protected] to exercise any of these. We answer within one month, as Article 12(3) requires; a genuinely complex request may take up to two months more, and we will say so within the first. Exercising your rights is free, and we will not use a request as an excuse to collect more data about you than we already hold.
11. How to complain
If you think we have handled your data badly, please tell us first — most problems are quicker to fix directly. You are not obliged to, and may go straight to a supervisory authority.
In Norway that authority is Datatilsynet, Postboks 458 Sentrum, 0105 Oslo (datatilsynet.no). Elsewhere in the EEA you may complain to the authority where you live or work, or where you believe the infringement took place.
In Ukraine, where the controller is established, it is the Ukrainian Parliament Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини), vul. Instytutska 21/8, Kyiv 01008, Ukraine.
12. Children
This website is intended for adults. It is not directed at children and we do not knowingly collect personal data from anyone under 18. The planned gaming lounge, subject to licensing, would in any case be open only to guests aged 18 and over.
If you believe a child has sent us personal data, write to [email protected] and we will delete it.
13. How we protect your data
Our measures are proportionate to what we actually hold — a small amount of contact information in a mailbox:
- the site is served over HTTPS;
- the mailbox receiving interest list messages has a strong, unique password and two-factor authentication, and access is limited to those working on the project;
- the site loads no third-party code, which removes an entire class of risk;
- data is deleted when its retention period ends, because the safest data is what you no longer hold.
No method of storage is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay under Article 34, and the supervisory authority within 72 hours under Article 33.
14. Changes to this policy
This policy will change as the project moves forward, most obviously when reservations open. We will update the effective date above and publish the new version here.
If a change materially affects how we use data you have already given us, we will email everyone on the interest list to explain what changed. Where a change requires your consent, we will ask for it.
15. How to contact us
For anything in this policy — a question, a request under section 10, or a withdrawal of consent under section 6 — write to [email protected]. For general questions about the project write to [email protected], and for other legal matters to [email protected]. Post can be sent to the address in section 1.