Astra
Privacy Policy

Aurora & Locals ("we," "us," "our"), operated by Premier Tours ehf. (Kennitala: 4612231680), is committed to protecting your privacy and personal data.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website, book a travel experience, or interact with our services.
We process personal data in compliance with:
The Icelandic Data Protection Act (No. 90/2018)
The EU General Data Protection Regulation (GDPR) (Regulation 2016/679)
The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
Applicable Icelandic, European, and international privacy laws
By using our services, you acknowledge that you have read and understood this Privacy Policy.
Privacy Policy
Aurora & Locals
Operated by Premier Tours ehf.
Effective Date: August 16, 2026
Last Updated: August 16, 2026
1. Introduction
Aurora & Locals ("we," "us," "our"), operated by Premier Tours ehf. (Kennitala: 4612231680), is committed to protecting your privacy and personal data.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website, book a travel experience, or interact with our services.
We process personal data in compliance with:
The Icelandic Data Protection Act (No. 90/2018)
The EU General Data Protection Regulation (GDPR) (Regulation 2016/679)
The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
Applicable Icelandic, European, and international privacy laws
By using our services, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
Detail | Information |
|---|---|
Company | Premier Tours ehf. |
Trading Name | Aurora & Locals |
Kennitala | 4612231680 |
VAT Number | 151515 |
Icelandic Tourist Board License | 461223-1680 |
Country | Iceland |
3. What Personal Data We Collect
We collect and process the following categories of personal data:
3.1. Information You Provide Directly
Identity Data: Full name, date of birth, nationality
Contact Data: Email address, phone number, postal address
Booking Data: Travel dates, experience preferences, number of guests, special requirements (dietary, accessibility, medical)
Payment Data: Credit/debit card details, billing address (processed securely via third-party payment processors)
Communication Data: Messages, enquiries, reviews, and feedback you send to us
Account Data: Username, password (if you create an account)
3.2. Information Collected Automatically
Technical Data: IP address, browser type and version, device type, operating system
Usage Data: Pages visited, time spent on pages, click patterns, referral source
Cookie Data: Session identifiers, preferences, analytics cookies (see Section 9)
Location Data: Approximate geographic location based on IP address
3.3. Information from Third Parties
Partner Providers: Booking confirmations, experience updates, or customer feedback from our third-party experience providers
Payment Processors: Transaction confirmations and fraud prevention data
Analytics Providers: Aggregated website usage statistics
4. How We Use Your Personal Data
We process your personal data for the following purposes:
Purpose | Legal Basis (GDPR) |
|---|---|
Processing and fulfilling your booking | Performance of a contract (Art. 6(1)(b)) |
Sending booking confirmations and travel information | Performance of a contract (Art. 6(1)(b)) |
Processing payments and refunds | Performance of a contract (Art. 6(1)(b)) |
Communicating with you about your experience | Legitimate interest (Art. 6(1)(f)) |
Responding to enquiries and customer support | Legitimate interest (Art. 6(1)(f)) |
Sending marketing emails and newsletters | Consent (Art. 6(1)(a)) |
Improving our website and services | Legitimate interest (Art. 6(1)(f)) |
Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
Sharing data with experience providers to fulfil your booking | Performance of a contract (Art. 6(1)(b)) |
5. Who We Share Your Data With
We only share your personal data where necessary and with appropriate safeguards:
5.1. Third-Party Experience Providers (Partners)
When you book an experience operated by a third-party Partner, we share relevant booking details (name, contact, group size, special requirements) so they can deliver your experience.
5.2. Payment Processors
We use secure, PCI-compliant payment processors to handle transactions. We do not store your full card details on our servers.
5.3. Technology & Service Providers
We work with trusted providers for:
Website hosting and infrastructure
Email communications
Customer support tools
Analytics and performance monitoring
All service providers are bound by data processing agreements and GDPR-compliant safeguards.
5.4. Legal & Regulatory
We may disclose personal data if required by law, court order, or government request, or to protect our legal rights.
5.5. We Never
Sell your personal data to third parties
Share your data for unrelated advertising purposes
Transfer data without appropriate legal safeguards
6. International Data Transfers
Your data is primarily stored and processed within the European Economic Area (EEA).
Where data is transferred outside the EEA (e.g., to service providers in the US or elsewhere), we ensure appropriate safeguards are in place, including:
EU Standard Contractual Clauses (SCCs)
Adequacy decisions by the European Commission
Binding Corporate Rules where applicable
7. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
Data Category | Retention Period |
|---|---|
Booking and transaction data | 7 years (Icelandic accounting law) |
Customer communications | 3 years after last interaction |
Marketing consent records | Until consent is withdrawn |
Website analytics data | 26 months |
Account data | Until account deletion is requested |
After the retention period expires, data is securely deleted or anonymised.
8. Your Rights (GDPR)
Under the GDPR and Icelandic Data Protection Act, you have the following rights:
Right of Access — Request a copy of the personal data we hold about you
Right to Rectification — Request correction of inaccurate or incomplete data
Right to Erasure — Request deletion of your personal data ("right to be forgotten")
Right to Restrict Processing — Request limitation of how we use your data
Right to Data Portability — Receive your data in a structured, machine-readable format
Right to Object — Object to processing based on legitimate interest or for marketing purposes
Right to Withdraw Consent — Withdraw consent at any time (without affecting prior processing)
Right to Lodge a Complaint — File a complaint with the Icelandic Data Protection Authority (Persónuvernd)
To exercise any of these rights, contact us at: [privacy@auroraandlocals.is]
We will respond to all requests within 30 days.
9. Cookies
Our website uses cookies to improve functionality and understand how visitors interact with our site.
Types of Cookies We Use
Cookie Type | Purpose | Duration |
|---|---|---|
Essential | Website functionality, security, session management | Session |
Analytics | Understanding traffic, page views, user behaviour | Up to 26 months |
Marketing | Personalised ads and retargeting (with consent) | Up to 12 months |
Preference | Remembering your language and display settings | Up to 12 months |
Managing Cookies
You can manage or disable cookies through your browser settings. Note that disabling essential cookies may affect website functionality.
We obtain consent for non-essential cookies via our cookie banner upon your first visit.
10. Marketing Communications
10.1. We only send marketing emails with your explicit consent (opt-in).
10.2. Every marketing email includes a clear unsubscribe link. You can opt out at any time.
10.3. Opting out of marketing will not affect transactional communications related to your bookings.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
SSL/TLS encryption for all data in transit
Encrypted storage for sensitive data
Access controls limiting data to authorised personnel only
Regular security audits and vulnerability assessments
Secure payment processing via PCI-compliant providers
Staff training on data protection and privacy
While we take all reasonable precautions, no system is 100% secure. In the event of a data breach, we will notify affected individuals and the Icelandic Data Protection Authority (Persónuvernd) within 72 hours as required by GDPR.
12. Children's Privacy
Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children.
If we become aware that we have collected data from a minor without parental consent, we will delete it immediately.
13. Third-Party Links
Our website may contain links to third-party websites (e.g., Partner provider sites, social media platforms). We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before sharing your data.
14. Your California Privacy Rights (CCPA/CPRA)
If you are a resident of California, United States, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
14.1. Your Rights Under CCPA
Right to Know — You have the right to request what personal information we have collected, used, disclosed, or sold about you in the past 12 months
Right to Delete — You have the right to request deletion of your personal information, subject to certain legal exceptions
Right to Opt-Out of Sale — You have the right to opt out of the "sale" of your personal information. Aurora & Locals does not sell your personal information.
Right to Non-Discrimination — We will not discriminate against you for exercising any of your CCPA rights (no denial of service, price differences, or reduced quality)
Right to Correct — You have the right to request correction of inaccurate personal information we hold about you
Right to Limit Use of Sensitive Personal Information — You can request that we limit how we use and disclose sensitive personal information
14.2. Categories of Personal Information Collected
In the preceding 12 months, we may have collected the following categories of personal information as defined by the CCPA:
Category | Examples | Collected | Sold | Shared for Advertising |
|---|---|---|---|---|
Identifiers | Name, email, phone number, IP address | Yes | No | No |
Customer Records | Billing address, payment information | Yes | No | No |
Commercial Information | Booking history, experiences purchased, preferences | Yes | No | No |
Internet/Network Activity | Browsing history, site interactions, search history | Yes | No | No |
Geolocation Data | Approximate location via IP address | Yes | No | No |
Sensitive Personal Information | Account login credentials | Yes | No | No |
Professional/Employment Info | N/A | No | No | No |
Biometric Information | N/A | No | No | No |
Audio/Visual Information | N/A | No | No | No |
14.3. Business Purposes for Collection
We collect the above categories of personal information for the business purposes described in Section 4, including:
Providing and fulfilling travel experience bookings
Processing payments and transactions
Maintaining and improving our website and services
Communicating with you about your bookings
Detecting and preventing fraud or security incidents
Complying with legal obligations
14.4. Sale & Sharing of Personal Information
We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising purposes. We have not sold or shared personal information in the preceding 12 months.
14.5. Exercising Your CCPA Rights
To submit a verifiable consumer request, you may:
Email us at: [privacy@auroraandlocals.is]
Submit a request through our website contact form
Verification: We will verify your identity before processing any request by matching the information you provide with the information we already have on file. You may also designate an authorised agent to submit a request on your behalf (written authorisation required).
Response Timeline: We will acknowledge your request within 10 business days and provide a substantive response within 45 days. If additional time is needed, we will notify you of an extension (up to 90 days total).
You may submit a Right to Know request up to twice within a 12-month period.
14.6. Do Not Track Signals
Our website currently does not respond to "Do Not Track" (DNT) browser signals. However, you can manage your cookie and tracking preferences through our cookie banner or your browser settings.
14.7. Financial Incentives
We do not offer financial incentives or price differences in exchange for the retention or sale of personal information.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance.
Updates will be posted on this page with a revised effective date. For significant changes, we will notify you via email or a prominent notice on our website prior to the changes taking effect.
Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.
16. Contact Us & Complaints
For any privacy-related questions, data requests, or concerns:
Aurora & Locals (Premier Tours ehf.)
Email: [privacy@auroraandlocals.is]
Website: [www.auroraandlocals.is]
Icelandic Data Protection Authority (Persónuvernd)
Website: www.personuvernd.is
Email: postur@personuvernd.is
Address: Rauðarárstígur 10, 105 Reykjavík, Iceland
European Online Dispute Resolution (ODR)
Website: https://ec.europa.eu/consumers/odr
California Attorney General (CCPA Complaints)
Website: https://oag.ca.gov/privacy
This Privacy Policy is governed by Icelandic law, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) where applicable.

