Privacy Policy – NorseHeart
Who we are and Data Controller
Our website address is: https://norseheart.com.
NorseHeart is operated by Prikken Over Livet ApS, located at Palleskærvej 39, DK-9800 Hjørring, Denmark. If you have any questions regarding your personal data, please contact us at hello@norseheart.com.
Personal data collected
We collect information such as your name, email address, phone number, payment details, IP address, cookies and similar identifiers, and other data when you use our website, subscribe to our newsletter, leave comments, or book retreats and services.
If you register a user account, we store the personal information you provide in your user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username), and website administrators can also see and edit that information.
Purpose of data processing
We process your personal data to:
-
Fulfil your orders and bookings and perform our contract with you.
-
Provide customer support and respond to your enquiries.
-
Send newsletters and other email communications where you have subscribed.
-
Deliver marketing communications, including targeted advertisements, and measure campaign performance.
-
Operate, maintain, and improve our website and services, including analytics and security.
Legal basis for processing
Depending on the situation, the processing of your personal data is based on:
-
Your consent (for example, newsletters, certain cookies, and marketing).
-
The performance of a contract (for example, retreat bookings and payment handling).
-
Compliance with legal obligations (for example, accounting or tax rules).
-
Our legitimate interests (for example, website security and basic analytics), where such interests are not overridden by your rights and freedoms.
Retention and security
Your data will be stored securely and only for as long as necessary for the purposes described in this policy or as required by law.
We implement appropriate technical and organisational measures to protect your information, including SSL encryption, access controls, and regular software updates to prevent unauthorised access, disclosure, or loss.
Data transfer outside the EU
Your personal data may be transferred to data processors in third countries outside the EU/EEA, such as the USA (for example, MailChimp or other email/marketing tools).
Where data is transferred outside the EU/EEA, we ensure adequate safeguards, such as using the EU Commission’s Standard Contractual Clauses or equivalent legal mechanisms.
Sharing with third parties and data processors
We share data only with necessary partners such as:
-
Payment providers and payment processors.
-
Marketing and advertising platforms.
-
Email and newsletter providers.
-
IT and hosting vendors and other service providers.
These third parties act as data processors and only process your data on our behalf in accordance with applicable data protection laws and our instructions.
Cookies and tracking technologies
We use cookies and tracking pixels (such as Facebook Pixel and Google Analytics) for:
-
Statistics and aggregated analytics about site use.
-
Personalised advertising and retargeting on third‑party platforms.
You have the right to give or withhold your consent to non‑essential cookies and can manage or withdraw your consent at any time through cookie settings (where available) or your browser controls.
In addition, WordPress may set cookies to remember your login, screen display choices, and comment preferences: -
If you leave a comment, you may opt in to saving your name, email address and website in cookies so you do not have to fill these in again. These cookies last for one year.
-
A temporary cookie is set on the login page to check if your browser accepts cookies; it contains no personal data and is discarded when you close your browser.
-
When you log in, several cookies are set to save your login information and screen options. Login cookies last for two days, screen options cookies for one year. If you select “Remember me”, your login persists for two weeks. When you log out, login cookies are removed.
-
If you edit or publish an article, an additional cookie will be saved in your browser, containing only the post ID of the article you just edited, and it expires after one day.
Consent on forms
All contact and booking forms include clear, unchecked consent checkboxes linked to this Privacy Policy, ensuring you actively agree to the processing of your personal data when submitting the form where such consent is required.
User rights and requests (Your rights)
You have the right to:
-
Access the personal data we hold about you.
-
Rectify or update inaccurate or incomplete data.
-
Delete your data (“right to be forgotten”) where legally possible.
-
Restrict the processing of your data in certain circumstances.
-
Obtain a portable copy of your personal data in a commonly used format.
-
Object to certain processing, including direct marketing.
-
Withdraw your consent at any time, where processing is based on consent.
If you wish to exercise any of these rights, please contact us at hello@norseheart.com. We will comply with your requests in accordance with applicable laws and within the required time frames.
Data security
We implement appropriate technical and organisational measures to protect your data, including SSL encryption, access controls, and regular software updates to prevent unauthorised access, disclosure, alteration, or loss.
Automated decision‑making and profiling
If we use automated decision‑making or profiling (for example, to create audience segments for advertising), this will be limited to marketing and analytics purposes. You have the right to object to such processing and to request human review where applicable under data protection laws.
Data breach procedures
In the unlikely event of a data breach, we have procedures in place to promptly assess the incident, contain the breach, and notify affected individuals and relevant authorities where required by law.
Comments
When visitors leave comments on the site, we collect the data shown in the comments form, as well as the visitor’s IP address and browser user agent string to help with spam detection.
An anonymised string created from your email address (a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar privacy policy is available at https://automattic.com/privacy/. After approval of your comment, your profile picture (if any) is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS). Visitors to the website can download and extract any location data from images on the website.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website directly.
These external websites may collect data about you, use cookies, embed additional third‑party tracking, and monitor your interaction with that embedded content, including tracking if you have an account and are logged in to that website.
Who we share your data with (specific cases)
If you request a password reset, your IP address will be included in the reset email as part of standard security measures.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely so we can recognise and approve any follow‑up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we store the personal information they provide in their user profile for as long as the account is active or as long as necessary for the purposes described in this policy, unless a longer retention period is required by law.
What rights you have over your data (summary)
If you have an account on this site or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided. You can also request that we erase any personal data we hold about you, except for data we are obliged to keep for administrative, legal, or security purposes.
Where your data is sent
Visitor comments may be checked through an automated spam detection service and may be processed by external service providers as described above.
Children under 16
Our site and services are not targeted at children under 16, and we do not knowingly collect personal data from minors. If we become aware that we have collected data from a child under 16, we will take steps to delete such information.
GDPR and US consumer protection
We comply with the EU General Data Protection Regulation (GDPR) and, where applicable, relevant consumer protection principles for international (including US) customers. Our aim is transparency, fairness, and giving you easy access to manage your personal data.
Changes to this Privacy Policy / Privacy Policy updates
We may update this Privacy Policy from time to time, for example to reflect changes in our services or in applicable law. Any significant changes will be posted on this page together with the date of the latest revision. We recommend reviewing this policy periodically.
Contact
For questions, concerns, or complaints about this Privacy Policy or our handling of your data, please contact:
Email: hello@norseheart.com
Address: Prikken Over Livet ApS, Palleskærvej 39, DK-9800 Hjørring, Denmark.


