Last updated: 1 October 2026
This policy explains what personal data the Lysskjul website and its interest list involve, why, and what you can do about it. The short version: there is no analytics, no tracking and no advertising on this website, and we only hold the details you choose to send us.
1. Who is responsible
The controller of personal data processed through this website is Vasyl Dudko, 28 Skvyrska Street, Kyiv 02000, Ukraine ("we", "us"). We run this website for Lysskjul Varanger Resort & Casino, a planned resort on the Varanger coast in Finnmark, Norway, which has not been built and does not yet take bookings.
For anything to do with your personal data, write to [email protected]. We have not appointed a data protection officer, as we are not required to; the privacy address reaches the people who handle these questions.
2. What data we handle
We handle only a small amount of personal data, in three situations:
- When you join the interest list. Your name, your email address, the part of the project you are interested in (for example a room type, the hides or general news) and a record that you gave consent, including the wording you agreed to and the date of your email.
- When you write to us. Your email address, your name if you include it, the content of your message and any attachments, and the usual technical details that come with an email, such as the date and the sending server.
- When you visit the website. Technical log data recorded by the hosting provider: your IP address, the date and time, the page or file requested, the browser's user agent string and, where your browser sends it, the referring page.
We do not ask for, and ask you not to send, special categories of data such as health information, or identity documents. If you send them anyway, we will delete them.
3. Why, and on what legal basis
We rely on the EU General Data Protection Regulation (GDPR), which applies in Norway through the EEA Agreement and the Norwegian Personal Data Act.
- Interest list: your consent, under Article 6(1)(a) GDPR. Because the interest list means sending you news by email, we also rely on your prior consent as required by section 15 of the Norwegian Marketing Control Act (markedsføringsloven) for electronic marketing.
- Answering your messages: our legitimate interest in replying to people who contact us, under Article 6(1)(f).
- Technical logs: our legitimate interest in keeping the website available and secure and in investigating misuse, under Article 6(1)(f).
- Keeping a record of consent and withdrawal: our legal obligation to be able to show that consent was given, under Articles 6(1)(c) and 7(1).
Where we rely on legitimate interests, we have weighed them against your rights and kept the processing to the minimum needed. You can object at any time; see section 10.
4. The interest list form
The form on the contact page does not send anything to a server. When you press the button, your browser checks the fields and then opens your own email app with a message already written to [email protected]. Nothing reaches us until you press send in your email app, and you can read or change the message before you do.
You can withdraw your consent at any time by writing to [email protected]. We will remove you from the interest list and confirm by email. Withdrawing consent does not affect anything we did with your consent before you withdrew it. At present there is no automatic unsubscribe link; a short email is enough.
Interest list messages are currently sent from our ordinary email account. If we start using a separate mailing service, we will name it in this policy before any of your data is passed to it.
5. Technical logs
Like almost every website, this one is served by a hosting provider whose servers keep short technical logs of requests. These logs are used to deliver pages, to detect faults and attacks, and to keep the website secure. They are not used to build profiles, are not combined with the interest list and are not used for marketing. Logs are normally kept for no longer than 30 days, unless a specific security incident requires us to keep a particular entry for longer while it is investigated.
6. What we do not do
- We do not use analytics, statistics or measurement tools of any kind.
- We do not use advertising, tracking pixels, social media plugins or embedded third-party content.
- We do not set cookies. The only thing this website stores in your browser is one setting for the footer menu on small screens, explained in the Cookie Policy.
- We do not load fonts, scripts or images from other websites. Everything is served from this domain.
- We do not sell, rent or trade personal data, and we do not make decisions about you by automated means or profiling.
7. Who else sees your data
We share personal data only with service providers who process it on our behalf and under written data processing terms:
- the provider that hosts this website and keeps its technical logs;
- the provider of our email accounts, which stores the messages you send to us and the replies we send.
The names of these providers will be listed here and in the Legal Information once they are confirmed. We may also disclose data where the law requires it, for example to a court or a public authority, or where it is needed to establish or defend legal claims.
8. Transfers outside the EEA
The controller is based in Ukraine, which is outside the European Economic Area and does not currently have an adequacy decision from the European Commission. Where personal data of people in the EEA is transferred to us or to a service provider outside the EEA, we use the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) together with any additional safeguards that are needed. You can ask for a copy of the relevant safeguards by writing to [email protected].
9. How long we keep it
- Interest list: until you withdraw your consent, or at the latest twelve months after the resort opens or after the project is ended, whichever comes first.
- Record of consent and withdrawal: for as long as we keep your interest list entry, and for up to three years afterwards so that we can show that we acted on your request.
- Messages you send us: for as long as the conversation needs, and normally no longer than 24 months after the last message, unless a longer period is needed for a legal claim.
- Technical logs: normally no longer than 30 days.
10. Your rights
Under Articles 15 to 22 GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- have the processing restricted (Article 18), and be told about corrections, erasure or restriction we pass on to others (Article 19);
- receive the data you gave us in a structured, commonly used format, and have it sent to someone else where that is technically possible (Article 20);
- object to processing based on our legitimate interests (Article 21);
- not be subject to decisions based solely on automated processing (Article 22); we make no such decisions.
To use any of these rights, write to [email protected]. We will reply within one month, and may ask for information to confirm that the request comes from you.
You also have the right to complain to a data protection authority. In Norway this is Datatilsynet (datatilsynet.no). As the controller is based in Ukraine, you may also contact the Ukrainian Parliament Commissioner for Human Rights, who supervises personal data protection there. If you live in another EEA country, you can complain to the authority in that country. We would appreciate the chance to answer your concern first, but you do not have to contact us before complaining.
11. Guests' photographs
Lysskjul is planned with a darkroom and a viewing room where guests will be able to print their own film. Those photographs belong to the guests who made them. The resort will not keep, copy, scan, publish or use guests' negatives or prints for any purpose, including marketing, and the darkroom staff will not look at them beyond what is needed to help with the printing itself. Nothing guests make in the darkroom will be processed by us as personal data. If the resort ever wishes to show a guest's photograph, it will ask for separate, specific permission, under a separate policy, and refusing will have no consequences.
12. Age
This website and the interest list are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has sent us their details, write to [email protected] and we will delete them.
13. Security
We keep personal data to a minimum, store it only in accounts protected by strong passwords and two-factor authentication where available, and limit access to the people who need it. The website is served over an encrypted connection and loads nothing from third parties. No method of storage or transmission is completely secure, but if a breach affecting your data were to occur, we would act on it and notify you and the authorities where the law requires.
14. Changes and contact
We will update this policy when the project changes, for example when a mailing service, a booking system or the resort itself comes into use. The date at the top shows the latest version. If a change affects how we use data you have already given us, we will tell people on the interest list by email before the change takes effect.
Questions about this policy: [email protected]. Postal address: 28 Skvyrska Street, Kyiv 02000, Ukraine.