Fjordvia
← Back to Fjordvia
DRAFT — pending legal review.
This privacy policy has not yet been reviewed by a lawyer. Items shown in
red placeholders (company name, address, contact details) must be
completed before publication. Retention periods mentioned below are target values from a
pending internal decision (wishlist item #152) and may change.
Privacy Policy
Last updated: 28 August 2026
1. Who is responsible for your data (controller)
The controller within the meaning of the EU General Data Protection Regulation (GDPR) for the
personal data processed via this website is:
- Company name: [LEGAL_NAME]
- Address: [ADDRESS]
- Chamber of Commerce (KvK) number: [KVK]
- VAT identification number: [VAT_ID]
Contact for privacy questions and requests: [EMAIL]
(telephone: [PHONE]). We aim to respond to any privacy request within
30 days.
2. Which data we collect
-
Itineraries and travel preferences — the trip parameters you enter (start
and end point, country, travel dates, must-visit and avoid lists) and the generated
itinerary, saved so you can share and edit it.
-
Anonymous owner UUID and edit tokens — a random identifier and the share /
edit tokens belonging to an itinerary. By themselves these do not identify a person.
-
Lead e-mail address and consent flag — if you leave your e-mail address
(for example to be notified about new features), we store that address together with a flag
recording that you consented.
-
Click events — anonymous clicks on outbound affiliate links (car rental,
hotels, activities), recorded via our
/api/track endpoint.
-
IP address and diagnostic logs — your IP address is used for rate limiting,
and technical logs are collected in Azure Application Insights for security and
troubleshooting.
3. Why we use your data and on what legal basis
| Data category |
Purpose |
Legal basis (GDPR) |
| Itineraries and travel preferences |
Generating, saving, sharing and editing your trip plan |
Performance of a contract / steps prior to entering into it (Art. 6(1)(b)); legitimate interest for improving the service (Art. 6(1)(f)) |
| Anonymous owner UUID and edit tokens |
Linking you to your saved itinerary and protecting edits |
Performance of a contract (Art. 6(1)(b)) |
| Lead e-mail address and consent flag |
Sending updates you asked for; proving consent |
Consent (Art. 6(1)(a)), withdrawable at any time |
Click events (/api/track) |
Anonymous statistics on outbound partner links |
Legitimate interest (Art. 6(1)(f)); no personally identifying profiles are built |
| IP address and diagnostic logs |
Security, abuse and rate limiting, fault diagnosis |
Legitimate interest (Art. 6(1)(f)); legal obligation where logs are required (Art. 6(1)(c)) |
4. How long we keep your data (retention)
-
Itineraries: deleted 365 days after the last update.
-
Lead e-mail addresses: deleted 730 days after the last
interaction, or earlier if consent is withdrawn.
-
Click events: kept in aggregated form; raw events are removed once
statistics have been processed.
-
Diagnostic logs: kept for the retention period configured in Azure
Application Insights (currently up to 90 days).
Note: the itinerary and lead retention periods above are target values from a pending
internal decision (wishlist item #152). Until that decision is implemented and legally
reviewed, these figures are indicative.
5. Sub-processors
We use the following processors to operate this website. Each processes data only on our
instructions and under a data-processing agreement:
- Microsoft Azure — hosting of the website, API and database (EU region).
- Azure Maps — map display and route calculation.
- Azure OpenAI / Azure AI Foundry — AI generation of itinerary content.
- Azure Application Insights — technical logs and error monitoring.
- Travelpayouts — affiliate programme for flights and travel partners (outbound links).
- DiscoverCars — affiliate programme for car rental (outbound links).
- GetYourGuide — affiliate programme for activities and tours (outbound links).
Clicking an outbound partner link takes you to that partner's own website, where their privacy
policy applies to any data you provide there.
6. Your rights
You have the following rights under the GDPR:
- Access — a copy of the personal data we process about you;
- Rectification — correction of incorrect data;
- Erasure — deletion of your data ("right to be forgotten");
- Restriction — temporary restriction of processing;
- Data portability — receipt of your data in a structured, commonly used format;
- Objection — objection to processing based on legitimate interest.
Send your request to [EMAIL]. We handle requests according to our
documented internal privacy-request procedure and respond within 30 days. You also have the
right to lodge a complaint with the Dutch supervisory authority, the
Autoriteit Persoonsgegevens.
7. International data transfers
Our Azure resources process data in EU data regions. The Azure AI Foundry resource used for
itinerary generation is intended to run in an EU region as well; its exact region still needs
to be verified ([FOUNDRY_REGION]). If a transfer to a country outside
the EEA ever becomes necessary, we will ensure an adequate level of protection, for example
via the European Commission's standard contractual clauses, and update this policy.
8. Changes to this policy
We may update this privacy policy from time to time. The date under the title always shows
when it was last changed.