Personvern
Privacy Policy for Hafjell-Kvitfjell Alpin AS
1 INTRODUCTION
This Privacy Policy describes how Hafjell-Kvitfjell Alpin AS, organisation no. 875907832 (“we”, “us” or “our”), processes personal data when you:
- visit our websites;
- purchase tickets for World Cup events;
- register for or participate in the Summit Kvitfjell business week;
- are a speaker, sponsor, supplier or other contributor to our events; or
- are a contact person at a company with which we cooperate.
Hafjell-Kvitfjell Alpin AS is the data controller for the processing activities described in this Privacy Policy. We process your personal data in accordance with the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
If you have any questions about this Privacy Policy or how we process personal data, please contact us at marie@worldcupkvitfjell.no.
2 PROCESSING OF PERSONAL DATA
The personal data we process about you, the purposes for which we process it and the legal basis for the processing depend on your relationship with us. Our various processing activities and their legal bases are described below.
Visitors to Our Websites
When you visit our websites, https://worldcupkvitfjell.no/ or https://summitkvitfjell.no/, a pop-up window will ask whether you consent to our use of cookies. If you consent, we may collect:
- Technical information about your device: IP address, browser type, operating system, time of visit, language settings, etc.
- Usage data: pages you visit, links or features you click on, any error messages, etc.
The legal basis for collecting this information is your explicit consent, cf. Article 6(1)(a) of the GDPR and Section 3-15 of the Norwegian Electronic Communications Act.
We may also use technical logs and analytics tools to ensure the stable and secure operation of our websites, including to identify and address technical errors and security incidents, improve the user experience and compile anonymised statistics. For purposes covered by Section 3-15, second paragraph, of the Norwegian Electronic Communications Act, our legal basis is our legitimate interest in pursuing these purposes, cf. Article 6(1)(f) of the GDPR.
Purchasers of Tickets for World Cup Events
When you purchase tickets for World Cup events through our Ticket Provider, we process information including:
- Contact information: name, email address, telephone number, postcode, country and year of birth.
- Ticket and event information: ticket type, event, date, seat/area information where relevant, price and time of purchase.
- Information linking you to other tickets/participants if you also purchase tickets on behalf of others.
- Communication data: emails/SMS messages we send regarding the event, such as practical information and changes.
Payment is handled by the Ticket Provider and its subcontractors. We do not receive full payment details in connection with a purchase, but we may receive limited payment information, such as transaction ID, amount paid and payment status, for reconciliation and accounting purposes.
We process this information because it is necessary in order to enter into a ticket purchase agreement at your request, cf. Article 6(1)(b) of the GDPR.
On the same legal basis, we will also send you practical information by email and/or SMS once you have registered or purchased a ticket, for example regarding the programme, schedules, changes, safety and logistics.
We will also process some of this information in order to comply with our legal obligations, including accounting and bookkeeping requirements, cf. Article 6(1)(c) of the GDPR, and where necessary for our legitimate interests in ensuring efficient operations, providing customer service, handling incidents and errors, and managing claims and complaints, cf. Article 6(1)(f) of the GDPR.
Participants at Summit Kvitfjell
When you register for and participate in Summit Kvitfjell, we typically process:
- Contact information: name, email address and mobile telephone number.
- Employer and job title/role.
- Information about the ticket/participant category you have selected and the days/events you will attend.
- Accommodation booked through us (where offered): choice of hotel, room type, number of nights and special requests.
- Billing information: billing address, reference and, where applicable, purchase order number.
- Any preferences and additional services you provide, such as seminar choices, transport, social events, dietary preferences or food allergies.
- Information about your attendance at the event, such as check-in registration.
We process this information because it is necessary to perform the agreement entered into regarding your participation in the event, cf. Article 6(1)(b) of the GDPR.
For certain events, we may prepare participant lists to facilitate networking. These may include:
- name;
- company/organisation; and
- title/role.
The legal basis for this processing is a balancing of interests pursuant to Article 6(1)(f) of the GDPR. You will have the opportunity to opt out of being included on such participant lists, either when registering or by contacting us (see Section 8).
During our events, we may take photographs and video recordings in which participants and members of the audience may appear. This may include:
- general and overview photographs from events;
- video recordings of stages, presentations and audience areas; and
- in certain cases, close-up images in which individuals are identifiable. Such close-up images are normally only used with specific consent.
The legal basis for taking photographs and video recordings is a balancing of interests pursuant to Article 6(1)(f) of the GDPR. We will clearly inform participants about photography and filming at the event and will, to the extent practically and administratively feasible, provide an opportunity to opt out.
Contributors, Speakers, Sponsors and Suppliers
For contributors to our events, including speakers, sponsors, suppliers, subcontractors and volunteers, we typically process:
- name;
- contact information (email address, telephone number and address);
- date of birth (only for accredited personnel);
- employer, role and area of expertise;
- agreement and contract information (contracts, fees and billing information);
- programme information (topic, presentation title and short introduction);
- correspondence relating to the cooperation; and
- allergies and dietary requirements.
We process this information in order to plan and conduct the event, including administering agreements, fees/billing and practical arrangements, documenting deliveries and handling claims and complaints.
Our legal basis for processing is the performance of an agreement with the person concerned, cf. Article 6(1)(b) of the GDPR; compliance with our legal obligations, including bookkeeping and tax obligations, cf. Article 6(1)(c) of the GDPR; or our legitimate interests in administering and managing relationships with suppliers and business partners, cf. Article 6(1)(f) of the GDPR.
3 OUR MARKETING
If you have previously attended our events, we may wish to send you information and marketing about upcoming events, newsletters or similar communications by email or SMS. We only send such information if you have consented to receiving it, cf. Article 6(1)(a) of the GDPR. You may withdraw your consent or opt out of marketing at any time (see Section 8).
We use photographs and videos from our events to market future events, including on websites, social media and in printed materials. We have determined that we have a legitimate interest in documenting and marketing our events in this manner, cf. Article 6(1)(f) of the GDPR. We will not use close-up images or situational photographs in which individuals are the main subject and are readily identifiable without first obtaining explicit consent, cf. Article 6(1)(a) of the GDPR.
You may at any time ask us not to use, or to remove, photographs or videos in which you are identifiable, to the extent this is practically possible and does not conflict with other overriding considerations.
4 WHO WE SHARE PERSONAL DATA WITH
We do not share personal data with others unless this is necessary for the purposes described above or we are legally required to do so. The categories of recipients that may typically have access to information you share with us are described below.
Data Processors
We use several service providers (“data processors”) that process personal data on our behalf, including:
- Ticket Provider – provides ticketing and registration solutions for World Cup tickets and Summit Kvitfjell. The provider processes your personal data and payment information on our behalf in order to complete ticket sales/registrations.
- IT, system and operational service providers – for example, website platform providers and office system providers, including cloud storage and backup services.
- Marketing and communications providers – for example, newsletter and SMS distribution services.
We have entered into data processing agreements with all our data processors governing how personal data is processed, the security measures that must be implemented, and the requirement that the data may not be used for the provider’s own purposes unless this has been explicitly communicated (see the section on our Ticket Provider below).
Other Recipients
Personal data may also be shared with:
- Hotel and accommodation providers where accommodation is booked through us in connection with an event.
- Transport providers where we organise transport, such as buses or trains, to or from an event.
- Partners/contributors, to a limited extent, for example where necessary to carry out a programme activity or networking activity.
- Public authorities where we are legally required to disclose information, for example pursuant to an order from tax authorities or other supervisory authorities.
We ensure that information is only shared with recipients that have a legitimate need for it and that there is a valid legal basis for such sharing.
The Ticket Provider as Data Controller for Certain Processing Activities
If you purchase a ticket through our Ticket Provider, the provider may, in addition to acting as a data processor on our behalf, have its own purposes for processing your personal data, such as managing its own customer relationships, user accounts and statistics.
In such cases, the Ticket Provider acts as an independent data controller. We recommend that you read the Ticket Provider’s own privacy policy and terms and conditions of purchase for further information.
5 TRANSFERS TO COUNTRIES OUTSIDE THE EEA (THIRD COUNTRIES)
As a general rule, we aim to ensure that all processing of personal data takes place within the European Economic Area (EEA).
If personal data is transferred to countries outside the EEA, we will ensure that the transfer takes place in accordance with applicable legislation, for example by ensuring that:
- the country has been recognised by the European Commission as providing an adequate level of protection (an adequacy decision); or
- we enter into the EU Standard Contractual Clauses (SCCs) with the relevant provider, supplemented by additional safeguards where necessary.
6 RETENTION AND DELETION
We retain personal data for as long as necessary for the purposes for which it was collected and in accordance with the principle of storage limitation.
Information concerning participation in our events is retained for as long as necessary to administer the event and is deleted no later than 12 months after the event has ended, unless statutory retention requirements, such as bookkeeping regulations, require longer retention.
Information relating to ticket purchases and the organisation of events is retained for as long as necessary to manage the ticket relationship, claims and complaints. Accounting-related information, including invoices and payment information, is retained in accordance with applicable bookkeeping requirements (normally five years after the end of the relevant financial year).
Agreement and contract documentation is retained for the duration of the agreement and for such period thereafter as is necessary to manage claims and comply with legal obligations.
Contact information used to send marketing communications on the basis of consent is retained until consent is withdrawn or you opt out, after which it may be retained for a limited period solely to document that we have complied with the opt-out/deletion request.
Technical logs are normally retained for a limited period, for example three to twelve months, for troubleshooting and security purposes.
Photographs and videos used for documentation and marketing are retained for as long as they are considered relevant for these purposes. You may request the removal of material in which you are identifiable; see Section 8.
7 SECURITY OF PROCESSING
We have implemented technical and organisational security measures to protect personal data against unauthorised access, loss, alteration or destruction. These measures include:
- access controls and role-based access to our systems;
- the use of secure networks and encryption where appropriate;
- backup procedures;
- internal policies and employee training; and
- data processing agreements requiring our service providers to maintain appropriate information security standards.
8 YOUR RIGHTS
As a data subject, you have a number of rights under Chapter III of the GDPR, including the right to information, access, rectification, erasure and restriction of processing. You may exercise your rights by contacting us using the contact details provided in Section 1.
Where our processing of your personal data is based on your consent, for example for sending newsletters, you may withdraw your consent at any time by contacting us. Please note that withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
We also encourage you to contact us if you wish to opt out of, for example, the use of photographs from our events or inclusion on participant lists shared with other participants. We will normally comply with such requests and will provide you with an explanation if we are unable to do so.
We will respond to requests concerning your rights without undue delay and normally within one month. For complex or extensive requests, this period may be extended by up to two additional months. If so, we will inform you of the reason for the delay.
9 COMPLAINTS TO THE NORWEGIAN DATA PROTECTION AUTHORITY
If you believe that our processing of personal data is in breach of applicable data protection legislation, you have the right to lodge a complaint directly with the Norwegian Data Protection Authority (Datatilsynet).
Please visit www.datatilsynet.no for information on how to submit a complaint.
However, we encourage you to contact us first so that we have an opportunity to clarify or rectify the matter giving rise to your complaint.
10 CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy when changes occur in our business or in applicable legislation. In the event of material changes, we will provide notice on our websites and, where relevant and possible, directly to you, for example by email.
September 2026
Jeg har blant annet brukt de etablerte GDPR-begrepene data controller, data processor, data subject, legitimate interests, legal basis, Standard Contractual Clauses (SCCs) og right to erasure, slik at teksten fungerer som en faktisk engelskspråklig personvernerklæring og ikke bare som en ord-for-ord-oversettelse.


