Michael Rosenberg

Founder

At Astra, we’re committed to clear, fair terms that protect both our clients and our team. If you have any questions, ask us, we’re always here to help.

Michael Rosenberg

Founder

At Astra, we’re committed to clear, fair terms that protect both our clients and our team. If you have any questions, ask us, we’re always here to help.

Michael Rosenberg

Founder

At Astra, we’re committed to clear, fair terms that protect both our clients and our team. If you have any questions, ask us, we’re always here to help.

Astra

Privacy Policy

Stars background

Aurora & Locals ("we," "us," "our"), operated by Premier Tours ehf. (Kennitala: 4612231680), is committed to protecting your privacy and personal data.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website, book a travel experience, or interact with our services.

We process personal data in compliance with:

  • The Icelandic Data Protection Act (No. 90/2018)

  • The EU General Data Protection Regulation (GDPR) (Regulation 2016/679)

  • The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)

  • Applicable Icelandic, European, and international privacy laws

By using our services, you acknowledge that you have read and understood this Privacy Policy.

Privacy Policy

Aurora & Locals
Operated by Premier Tours ehf.

Effective Date: August 16, 2026
Last Updated: August 16, 2026

1. Introduction

Aurora & Locals ("we," "us," "our"), operated by Premier Tours ehf. (Kennitala: 4612231680), is committed to protecting your privacy and personal data.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website, book a travel experience, or interact with our services.

We process personal data in compliance with:

  • The Icelandic Data Protection Act (No. 90/2018)

  • The EU General Data Protection Regulation (GDPR) (Regulation 2016/679)

  • The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)

  • Applicable Icelandic, European, and international privacy laws

By using our services, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

The data controller responsible for your personal data is:

Detail

Information

Company

Premier Tours ehf.

Trading Name

Aurora & Locals

Kennitala

4612231680

VAT Number

151515

Icelandic Tourist Board License

461223-1680

Email

[privacy@auroraandlocals.is]

Country

Iceland

3. What Personal Data We Collect

We collect and process the following categories of personal data:

3.1. Information You Provide Directly

  • Identity Data: Full name, date of birth, nationality

  • Contact Data: Email address, phone number, postal address

  • Booking Data: Travel dates, experience preferences, number of guests, special requirements (dietary, accessibility, medical)

  • Payment Data: Credit/debit card details, billing address (processed securely via third-party payment processors)

  • Communication Data: Messages, enquiries, reviews, and feedback you send to us

  • Account Data: Username, password (if you create an account)

3.2. Information Collected Automatically

  • Technical Data: IP address, browser type and version, device type, operating system

  • Usage Data: Pages visited, time spent on pages, click patterns, referral source

  • Cookie Data: Session identifiers, preferences, analytics cookies (see Section 9)

  • Location Data: Approximate geographic location based on IP address

3.3. Information from Third Parties

  • Partner Providers: Booking confirmations, experience updates, or customer feedback from our third-party experience providers

  • Payment Processors: Transaction confirmations and fraud prevention data

  • Analytics Providers: Aggregated website usage statistics

4. How We Use Your Personal Data

We process your personal data for the following purposes:

Purpose

Legal Basis (GDPR)

Processing and fulfilling your booking

Performance of a contract (Art. 6(1)(b))

Sending booking confirmations and travel information

Performance of a contract (Art. 6(1)(b))

Processing payments and refunds

Performance of a contract (Art. 6(1)(b))

Communicating with you about your experience

Legitimate interest (Art. 6(1)(f))

Responding to enquiries and customer support

Legitimate interest (Art. 6(1)(f))

Sending marketing emails and newsletters

Consent (Art. 6(1)(a))

Improving our website and services

Legitimate interest (Art. 6(1)(f))

Fraud prevention and security

Legitimate interest (Art. 6(1)(f))

Compliance with legal obligations

Legal obligation (Art. 6(1)(c))

Sharing data with experience providers to fulfil your booking

Performance of a contract (Art. 6(1)(b))

5. Who We Share Your Data With

We only share your personal data where necessary and with appropriate safeguards:

5.1. Third-Party Experience Providers (Partners)

When you book an experience operated by a third-party Partner, we share relevant booking details (name, contact, group size, special requirements) so they can deliver your experience.

5.2. Payment Processors

We use secure, PCI-compliant payment processors to handle transactions. We do not store your full card details on our servers.

5.3. Technology & Service Providers

We work with trusted providers for:

  • Website hosting and infrastructure

  • Email communications

  • Customer support tools

  • Analytics and performance monitoring

All service providers are bound by data processing agreements and GDPR-compliant safeguards.

5.4. Legal & Regulatory

We may disclose personal data if required by law, court order, or government request, or to protect our legal rights.

5.5. We Never

  • Sell your personal data to third parties

  • Share your data for unrelated advertising purposes

  • Transfer data without appropriate legal safeguards

6. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (EEA).

Where data is transferred outside the EEA (e.g., to service providers in the US or elsewhere), we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs)

  • Adequacy decisions by the European Commission

  • Binding Corporate Rules where applicable

7. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

Data Category

Retention Period

Booking and transaction data

7 years (Icelandic accounting law)

Customer communications

3 years after last interaction

Marketing consent records

Until consent is withdrawn

Website analytics data

26 months

Account data

Until account deletion is requested

After the retention period expires, data is securely deleted or anonymised.

8. Your Rights (GDPR)

Under the GDPR and Icelandic Data Protection Act, you have the following rights:

  • Right of Access — Request a copy of the personal data we hold about you

  • Right to Rectification — Request correction of inaccurate or incomplete data

  • Right to Erasure — Request deletion of your personal data ("right to be forgotten")

  • Right to Restrict Processing — Request limitation of how we use your data

  • Right to Data Portability — Receive your data in a structured, machine-readable format

  • Right to Object — Object to processing based on legitimate interest or for marketing purposes

  • Right to Withdraw Consent — Withdraw consent at any time (without affecting prior processing)

  • Right to Lodge a Complaint — File a complaint with the Icelandic Data Protection Authority (Persónuvernd)

To exercise any of these rights, contact us at: [privacy@auroraandlocals.is]

We will respond to all requests within 30 days.

9. Cookies

Our website uses cookies to improve functionality and understand how visitors interact with our site.

Types of Cookies We Use

Cookie Type

Purpose

Duration

Essential

Website functionality, security, session management

Session

Analytics

Understanding traffic, page views, user behaviour

Up to 26 months

Marketing

Personalised ads and retargeting (with consent)

Up to 12 months

Preference

Remembering your language and display settings

Up to 12 months

Managing Cookies

You can manage or disable cookies through your browser settings. Note that disabling essential cookies may affect website functionality.

We obtain consent for non-essential cookies via our cookie banner upon your first visit.

10. Marketing Communications

10.1. We only send marketing emails with your explicit consent (opt-in).

10.2. Every marketing email includes a clear unsubscribe link. You can opt out at any time.

10.3. Opting out of marketing will not affect transactional communications related to your bookings.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • SSL/TLS encryption for all data in transit

  • Encrypted storage for sensitive data

  • Access controls limiting data to authorised personnel only

  • Regular security audits and vulnerability assessments

  • Secure payment processing via PCI-compliant providers

  • Staff training on data protection and privacy

While we take all reasonable precautions, no system is 100% secure. In the event of a data breach, we will notify affected individuals and the Icelandic Data Protection Authority (Persónuvernd) within 72 hours as required by GDPR.

12. Children's Privacy

Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children.

If we become aware that we have collected data from a minor without parental consent, we will delete it immediately.

13. Third-Party Links

Our website may contain links to third-party websites (e.g., Partner provider sites, social media platforms). We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before sharing your data.

14. Your California Privacy Rights (CCPA/CPRA)

If you are a resident of California, United States, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

14.1. Your Rights Under CCPA

  • Right to Know — You have the right to request what personal information we have collected, used, disclosed, or sold about you in the past 12 months

  • Right to Delete — You have the right to request deletion of your personal information, subject to certain legal exceptions

  • Right to Opt-Out of Sale — You have the right to opt out of the "sale" of your personal information. Aurora & Locals does not sell your personal information.

  • Right to Non-Discrimination — We will not discriminate against you for exercising any of your CCPA rights (no denial of service, price differences, or reduced quality)

  • Right to Correct — You have the right to request correction of inaccurate personal information we hold about you

  • Right to Limit Use of Sensitive Personal Information — You can request that we limit how we use and disclose sensitive personal information

14.2. Categories of Personal Information Collected

In the preceding 12 months, we may have collected the following categories of personal information as defined by the CCPA:

Category

Examples

Collected

Sold

Shared for Advertising

Identifiers

Name, email, phone number, IP address

Yes

No

No

Customer Records

Billing address, payment information

Yes

No

No

Commercial Information

Booking history, experiences purchased, preferences

Yes

No

No

Internet/Network Activity

Browsing history, site interactions, search history

Yes

No

No

Geolocation Data

Approximate location via IP address

Yes

No

No

Sensitive Personal Information

Account login credentials

Yes

No

No

Professional/Employment Info

N/A

No

No

No

Biometric Information

N/A

No

No

No

Audio/Visual Information

N/A

No

No

No

14.3. Business Purposes for Collection

We collect the above categories of personal information for the business purposes described in Section 4, including:

  • Providing and fulfilling travel experience bookings

  • Processing payments and transactions

  • Maintaining and improving our website and services

  • Communicating with you about your bookings

  • Detecting and preventing fraud or security incidents

  • Complying with legal obligations

14.4. Sale & Sharing of Personal Information

We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising purposes. We have not sold or shared personal information in the preceding 12 months.

14.5. Exercising Your CCPA Rights

To submit a verifiable consumer request, you may:

Verification: We will verify your identity before processing any request by matching the information you provide with the information we already have on file. You may also designate an authorised agent to submit a request on your behalf (written authorisation required).

Response Timeline: We will acknowledge your request within 10 business days and provide a substantive response within 45 days. If additional time is needed, we will notify you of an extension (up to 90 days total).

You may submit a Right to Know request up to twice within a 12-month period.

14.6. Do Not Track Signals

Our website currently does not respond to "Do Not Track" (DNT) browser signals. However, you can manage your cookie and tracking preferences through our cookie banner or your browser settings.

14.7. Financial Incentives

We do not offer financial incentives or price differences in exchange for the retention or sale of personal information.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance.

Updates will be posted on this page with a revised effective date. For significant changes, we will notify you via email or a prominent notice on our website prior to the changes taking effect.

Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.

16. Contact Us & Complaints

For any privacy-related questions, data requests, or concerns:

Aurora & Locals (Premier Tours ehf.)

Icelandic Data Protection Authority (Persónuvernd)

European Online Dispute Resolution (ODR)

California Attorney General (CCPA Complaints)

This Privacy Policy is governed by Icelandic law, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) where applicable.