Privacy policy
You can read all of Pharos Hotel Journal (gorunexavi.com) without an account, a sign-up or a name. This policy sets out the limited personal data that is still involved in running the site, what we do with it and what you can ask of us.
1. Data controller
The controller responsible for your personal data is Torstein Rafgård, Frøyas gate 15, Postboks 1165 Sentrum, 0107 Oslo, Norway. For anything about this policy or your data, email [email protected].
If the GDPR requires us to designate a representative in the European Union, we will name them here.
Pharos is offered to readers in Spain and elsewhere in the European Union. The EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") therefore applies to the processing of personal data of readers in the EU and the European Economic Area (EEA), wherever our company is established (Article 3). For readers in Spain we also follow Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD") where it applies. The data protection law of the country where Torstein Rafgård is established may also apply. Cookies and similar technologies are also covered by the EU ePrivacy rules; see our cookie policy.
2. The data involved
- Server logs. Whenever a browser loads a page, it sends technical information such as your IP address, the date and time, the page requested, the referring page, and your browser and operating system. Our hosting provider records this automatically so the site can be delivered and protected against abuse.
- Data kept in your own browser. Your shortlist, passport stamps, trip checklist, departure city and cookie choices are saved in your browser's local storage. They never leave your device and we can't read them. Clearing your browser data removes them.
- Analytics and advertising data, only if you agree. If you accept these categories, Google may set cookies and receive information such as the pages you view, the device you use and whether you came from one of our ads. Until you accept, they stay off.
- Emails. If you write to us, we receive your address, your name if you give it, and whatever you choose to tell us.
We don't ask for, and don't want, sensitive data such as health information. Please leave it out of your emails.
3. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Serving the website and keeping it secure | Server logs, technical data | Legitimate interests (Art. 6(1)(f)) |
| Making your shortlist, passport and other tools work | Local storage on your device | Strictly necessary for a service you request; legitimate interests (Art. 6(1)(f)) |
| Remembering your cookie choice | Consent record in local storage | Legal obligation to record consent (Art. 6(1)(c)) |
| Audience measurement | Analytics cookies (Google Analytics) | Consent (Art. 6(1)(a)) |
| Measuring our own Google ads and showing ads | Advertising cookies (Google) | Consent (Art. 6(1)(a)) |
| Replying to you | Your email and what it contains | Legitimate interests (Art. 6(1)(f)); for privacy requests, legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, our interest is running a reliable, secure journal and answering readers. You can object to this processing at any time (see section 7).
4. Cookies, Google and other services
When you arrive, analytics and advertising are switched off. We use Google Consent Mode, which tells Google's tags to wait for your decision and respect it. You can change your choice whenever you like under Cookie settings. The full list of cookies and storage keys is in our cookie policy.
- Google Analytics and Google Ads (Google Ireland Limited, with Google LLC as a sub-processor): used only with your consent, to count visits, see which pages are useful and measure how our ads perform. How Google uses this data: policies.google.com/technologies/partner-sites. You can manage ad personalization at adssettings.google.com.
- Google Fonts: our typefaces are loaded from Google's servers, which receive your IP address in order to send them.
- Currency converter: to show exchange rates, the tool requests reference rates from open.er-api.com, which receives your IP address to answer.
- Newsletter: we don't run one today. If we launch a newsletter, it will be opt-in, we will use your email address only to send it, via an email provider acting on our instructions, and every issue will include an unsubscribe link.
5. Who receives data and international transfers
We never sell personal data. It is shared only with providers who help us run the site and act on our behalf or under their own terms as described above: our hosting provider and, if you consent, Google. Some of our providers and their sub-processors may process personal data outside the EEA, for example Google in the United States. Where that happens we rely on appropriate safeguards: transfers to US companies certified under the EU–US Data Privacy Framework, such as Google LLC, rely on the European Commission's adequacy decision of 10 July 2023; other transfers by our providers are covered by the Commission's Standard Contractual Clauses.
6. How long we keep data
- Server logs: kept by the host for a short period for security and troubleshooting, then deleted.
- Emails: kept as long as needed to deal with your message, and deleted within 24 months unless we need them to handle a legal claim.
- Your consent choice: stays in your browser until you clear it or change it; if our use of cookies changes, we will ask you again.
- Analytics and advertising cookies: see the durations in our cookie policy.
- Local storage: stays on your device until you clear it.
7. Your rights
You have the right to access your data, have it corrected or erased, restrict its use, receive it in a portable format and object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time, without affecting what happened before. Email [email protected] (subject "Privacy"); we may ask for information to confirm your identity, and we reply within one month.
If you think we have handled your data wrongly and you live in the EU or the EEA, you can complain to the data protection supervisory authority of the country where you live or work, or where you believe the infringement took place. In Spain, that is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, aepd.es. You can also complain to the data protection authority of the country where Torstein Rafgård is established. We would appreciate the chance to sort it out with you first.
8. Children
Pharos is written for adults planning travel and is not aimed at children. We don't knowingly collect data from anyone under the age of digital consent in their country (14 in Spain, up to 16 elsewhere in the EU); if you believe a child has sent us information, tell us and we will delete it. Information about casino resorts is meant only for adults of legal gambling age.
9. Changes to this policy
If the way we use data changes, we will update this page and the date at the top. Where a change requires your consent, we will ask for it again through the cookie banner.