PHAROS
Home/Privacy policy

Privacy policy

Last updated 8 October 2026

You can read all of Pharos Hotel Journal (gorunexavi.com) without an account, a sign-up or a name. This policy sets out the limited personal data that is still involved in running the site, what we do with it and what you can ask of us.

1. Data controller

The controller responsible for your personal data is Torstein Rafgård, Frøyas gate 15, Postboks 1165 Sentrum, 0107 Oslo, Norway. For anything about this policy or your data, email [email protected].

If the GDPR requires us to designate a representative in the European Union, we will name them here.

Pharos is offered to readers in Spain and elsewhere in the European Union. The EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") therefore applies to the processing of personal data of readers in the EU and the European Economic Area (EEA), wherever our company is established (Article 3). For readers in Spain we also follow Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD") where it applies. The data protection law of the country where Torstein Rafgård is established may also apply. Cookies and similar technologies are also covered by the EU ePrivacy rules; see our cookie policy.

2. The data involved

We don't ask for, and don't want, sensitive data such as health information. Please leave it out of your emails.

3. Purposes and legal bases

PurposeDataLegal basis (GDPR)
Serving the website and keeping it secureServer logs, technical dataLegitimate interests (Art. 6(1)(f))
Making your shortlist, passport and other tools workLocal storage on your deviceStrictly necessary for a service you request; legitimate interests (Art. 6(1)(f))
Remembering your cookie choiceConsent record in local storageLegal obligation to record consent (Art. 6(1)(c))
Audience measurementAnalytics cookies (Google Analytics)Consent (Art. 6(1)(a))
Measuring our own Google ads and showing adsAdvertising cookies (Google)Consent (Art. 6(1)(a))
Replying to youYour email and what it containsLegitimate interests (Art. 6(1)(f)); for privacy requests, legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, our interest is running a reliable, secure journal and answering readers. You can object to this processing at any time (see section 7).

4. Cookies, Google and other services

When you arrive, analytics and advertising are switched off. We use Google Consent Mode, which tells Google's tags to wait for your decision and respect it. You can change your choice whenever you like under Cookie settings. The full list of cookies and storage keys is in our cookie policy.

5. Who receives data and international transfers

We never sell personal data. It is shared only with providers who help us run the site and act on our behalf or under their own terms as described above: our hosting provider and, if you consent, Google. Some of our providers and their sub-processors may process personal data outside the EEA, for example Google in the United States. Where that happens we rely on appropriate safeguards: transfers to US companies certified under the EU–US Data Privacy Framework, such as Google LLC, rely on the European Commission's adequacy decision of 10 July 2023; other transfers by our providers are covered by the Commission's Standard Contractual Clauses.

6. How long we keep data

7. Your rights

You have the right to access your data, have it corrected or erased, restrict its use, receive it in a portable format and object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time, without affecting what happened before. Email [email protected] (subject "Privacy"); we may ask for information to confirm your identity, and we reply within one month.

If you think we have handled your data wrongly and you live in the EU or the EEA, you can complain to the data protection supervisory authority of the country where you live or work, or where you believe the infringement took place. In Spain, that is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, aepd.es. You can also complain to the data protection authority of the country where Torstein Rafgård is established. We would appreciate the chance to sort it out with you first.

8. Children

Pharos is written for adults planning travel and is not aimed at children. We don't knowingly collect data from anyone under the age of digital consent in their country (14 in Spain, up to 16 elsewhere in the EU); if you believe a child has sent us information, tell us and we will delete it. Information about casino resorts is meant only for adults of legal gambling age.

9. Changes to this policy

If the way we use data changes, we will update this page and the date at the top. Where a change requires your consent, we will ask for it again through the cookie banner.