1. Who is responsible for your data
The controller of your personal data is Roman Karas, 3 Ochakivskyi Lane, Kyiv 02000, Ukraine (“we”, “us”), the owner of this website and of the Tauvik project.
For anything to do with your personal data, write to [email protected]. There is no telephone line while the project is in development.
We are established outside the European Economic Area (EEA). Because this website is aimed at people in Norway and elsewhere in the EEA, the General Data Protection Regulation (GDPR), as it applies in Norway through the Personal Data Act (personopplysningsloven), governs how we handle your data. We also comply with the Law of Ukraine “On Personal Data Protection”. Where Article 27 GDPR requires us to appoint a representative in the EEA, we will name that representative in this section before the interest list is promoted.
2. What we collect
The interest list
The form on our contact page does not send anything by itself. When you press the button, it opens a ready-made email in your own mail program, addressed to [email protected]. Only if you then send that email do we receive:
- your name and email address;
- the part of the project you are interested in, such as a room type, the knot room or gatherings;
- the consent statement included in the message;
- anything else you choose to write, together with the usual technical details of an email, such as the date, the sending address and the mail server headers.
Emails you send us
If you write to any of our addresses (info@, events@, privacy@ or [email protected]), we receive your message, your email address and any details you include, such as your name or the dates you are planning for.
Technical logs
Like any website, this one is delivered by a web server. The server automatically records basic information about each request: the IP address it came from, the date and time, the page or file requested, the referring page, the type of browser and the response status. We do not combine these logs with any other data.
What we do not collect
We do not use analytics, tracking pixels, advertising networks, social media plugins or device fingerprinting. Fonts and images are served from our own server, so your browser does not contact third parties when you visit. We collect no payment details and no identity documents. We do not ask for special categories of data, such as health information, and we ask you not to send them.
3. Why we use it, and on what legal basis
- Interest list. We keep your name, email address and choice of interest to write to you with news about the project. The legal basis is your consent (Article 6(1)(a) GDPR). Sending news by email also requires your prior consent under section 15 of the Norwegian Marketing Control Act (markedsføringsloven). We rely on the consent you give when you tick the box and send the email.
- Replying to your messages. We use what you send us to answer you and, for events, to discuss possible plans. The legal basis is our legitimate interest in handling correspondence (Article 6(1)(f) GDPR) or, where you ask about a future event, steps taken at your request before any agreement (Article 6(1)(b)).
- Running and protecting the website. Server logs help us keep the site available and investigate misuse or attacks. The legal basis is our legitimate interest in the security and operation of the site (Article 6(1)(f)).
- Legal obligations. We may keep or disclose data where the law requires it (Article 6(1)(c)).
We do not use your data for profiling or automated decision-making, and we never sell or rent it to anyone.
4. Leaving the interest list
You can withdraw your consent at any time. Write to [email protected] from the address you signed up with, or tell us which address to remove. We will delete your entry from the list and confirm by email, normally within a few days and in any case within one month.
At present there is no automatic unsubscribe link: each request is handled by a person. Withdrawing consent does not affect anything we did lawfully before you withdrew it.
We will only write about the project itself: progress, the opening date once it is announced and the moment reservations open. We will not write often, and we will not pass on messages from anyone else.
5. Who else sees your data
We use a small number of service providers who process data for us and on our instructions, under written agreements as required by Article 28 GDPR:
- Our hosting provider, which runs the server that delivers the website and keeps its technical logs.
- Our email provider, which runs the mailboxes at ilmiomacrame.com where your messages and the interest list are kept.
We keep the interest list ourselves. If we begin to use a dedicated mailing service to send news, we will name it in this section before the first mailing goes out. We do not share your data with anyone else, except where we are legally required to, for example in response to a lawful request from a public authority.
6. International transfers
We are based in Ukraine, which the European Commission has not recognised as providing an adequate level of data protection. Where your data is transferred from the EEA to us, or to a service provider outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (SCC) or another safeguard recognised in Chapter V GDPR, together with additional technical and organisational measures where they are needed.
You can ask for a copy of the relevant safeguards by writing to [email protected]. Parts of a copy may be redacted to protect commercial terms.
7. How long we keep it
- Interest list: until you withdraw your consent, and at the latest twelve months after the resort opens or after the project is abandoned, whichever comes first.
- Correspondence: for as long as we need it to deal with your message, normally no longer than 24 months after our last exchange, unless we need it longer to establish or defend a legal claim.
- Server logs: for a short period, normally no longer than 30 days, unless a log is needed to investigate a specific security incident.
When the period ends, the data is deleted or irreversibly anonymised.
8. Your rights
Under Articles 15 to 22 GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- restrict our processing in certain cases (Article 18), and be told about corrections, erasure or restriction we pass on (Article 19);
- receive the data you gave us in a portable format (data portability, Article 20);
- object to processing based on our legitimate interests (Article 21);
- not be subject to decisions based solely on automated processing (Article 22). We make no such decisions.
To use any of these rights, write to [email protected]. We may ask you to confirm your identity, usually by replying from the email address concerned. Requests are free of charge, and we answer within one month. For complex requests that period can be extended by up to two further months, in which case we will tell you why.
9. Complaints
If you think we have handled your data wrongly, please tell us first so that we can try to put it right. You also have the right to complain to a supervisory authority:
- in Norway, Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no);
- the data protection authority of the EEA country where you live or work, or where you believe the problem occurred;
- in Ukraine, the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua), which supervises personal data protection.
10. Age
This website and the interest list are intended for adults. Please do not join the interest list if you are under 18. If we learn that someone under 18 has signed up, we will delete their details.
11. Security
Access to the interest list and our mailboxes is limited to the people who need it, protected by strong passwords and two-step verification. No personal data is stored in the code of the website. The site is designed to be served only over an encrypted connection. No method of storage or transmission is completely secure, but if a personal data breach does occur, we will notify the supervisory authority and, where required, the people affected, as set out in Articles 33 and 34 GDPR.
12. Cookies and local storage
This website sets no cookies. It stores one small item in your browser’s local storage, and only if you open a section of the footer on a phone. It remembers which footer sections you opened and never leaves your device. The Cookie Policy explains this in full.
13. Changes to this policy
We will update this policy when our practices change, for example when we appoint a mailing service or an EEA representative. The date at the top always shows the latest version. If a change materially affects people on the interest list, we will tell them by email before it takes effect.