Skip to content

Privacy

Your data. Our approach.

How we process personal data when you visit the website or send a booking request.

Last updated: July 2026

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Björkfors Outdoor AB, Gamla landsvägen 13, 59046 Rimforsa (Björkfors), Sweden

Organisation number: 559472-3958 · Phone: +46 (0) 73-239 09 93 · Email: info@bjorkfors-outdoor.se

If you have questions about data protection or wish to exercise your rights, you can contact us at any time using the details above.

A data protection officer is not legally required for a business of this size and has not been appointed.

2. General information

We take the protection of your personal data seriously. Personal data is any data that can be used to identify you personally. This policy explains which data we collect when you visit our website or make an enquiry or booking, what we use it for, and what rights you have.

Processing is based on the GDPR and Swedish data protection law. The following legal bases apply in particular:

  • Art. 6(1)(a) GDPR — your consent (e.g. for optional cookies)
  • Art. 6(1)(b) GDPR — performance of a contract and pre-contractual measures (e.g. your booking request)
  • Art. 6(1)(c) GDPR — compliance with legal obligations (e.g. retention periods)
  • Art. 6(1)(f) GDPR — our legitimate interests (e.g. secure operation of the website)

3. Hosting and server log files

Our website is provided as a static website via the GitHub Pages service, offered by GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. For security reasons, GitHub collects technical access data when the website is accessed, in particular the IP address of the accessing device, the date and time of access, and browser and operating system information.

This processing is based on our legitimate interest in a secure and reliable provision of the website (Art. 6(1)(f) GDPR). GitHub is certified under the EU-US Data Privacy Framework (see clause 11). We have no influence over the scope and duration of storage of this log data; further information can be found in GitHub's privacy statement at docs.github.com/privacy.

Our email inboxes and the domain are operated at one.com A/S, Kalvebod Brygge 24, 1560 Copenhagen, Denmark. Processing of emails therefore takes place within the European Union.

4. SSL/TLS encryption

For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar begins with "https://". When encryption is active, the data you transmit to us cannot be read by third parties.

5. Cookies

Our website uses only technically necessary cookies required for the operation and security of the website. The legal basis is our legitimate interest in a functioning offering (Art. 6(1)(f) GDPR).

We do not use cookies for analytics, tracking or advertising purposes, and we do not create usage profiles. You can set your browser to block cookies generally; this may limit the functionality of the website.

6. Enquiry form

On our website you can send a booking request via a form. When you submit it, your entries are not sent to our own server but transmitted directly and securely to our form service provider Formspree, Inc., based in the USA. Formspree then forwards the request to us by email.

We process the following data in particular:

  • Name and contact details (email address, phone number if provided)
  • Billing address
  • Desired travel period and number of people
  • Type of interest (e.g. accommodation, fishing package, guided activity)
  • Your free-text message and confirmation that you have accepted our House Rules and Terms & Conditions

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). See clause 11 regarding the transfer to Formspree in the USA. If your enquiry does not lead to a booking, we delete the message no later than 12 months after the last contact, unless statutory retention obligations require otherwise. For information on how long Formspree itself retains data, please refer to their privacy policy at formspree.io/legal/privacy-policy.

7. Contact by email and phone

If you contact us by email or phone, we process your details to handle your request. The legal basis is Art. 6(1)(b) GDPR if the enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR (interest in responding to enquiries). Please note that unencrypted email communication may have security vulnerabilities.

8. Booking processing and your stay

Once a booking is made, we process the data required to carry it out, in particular name, address, contact details, stay period, booked services, and payment and billing data. The legal basis is Art. 6(1)(b) GDPR.

Where we are legally obliged to retain booking and billing records, we also process the data on the basis of Art. 6(1)(c) GDPR. Under Swedish accounting law (bokföringslagen), the retention period for accounting records is seven years.

If you voluntarily tell us about dietary preferences or intolerances, we process this information exclusively to prepare your meals and on the basis of your explicit consent (Art. 9(2)(a) GDPR). You can withdraw this consent at any time.

9. Bookings via booking platforms

If your booking is made via a booking platform (e.g. Airbnb), we receive the data required to carry out your stay from the respective platform. The platform's operator is independently responsible for data processing on the platform itself; its own privacy terms apply. We process the data transmitted to us exclusively to carry out your stay.

10. Disclosure of data

We disclose your data to third parties only where necessary for contract performance, where we are legally obliged to do so, or where you have consented. Recipients may include in particular:

  • our hosting and email provider (as processor)
  • our form service provider Formspree, Inc. (USA), for the technical forwarding of your booking request
  • payment service providers and banks in connection with payment processing
  • tax advisors and accountants for statutory compliance purposes
  • partner organisations, where necessary to carry out a service you have booked (e.g. an arranged transfer)

We do not sell your data and do not use it for third-party advertising.

11. Transfers to third countries

A transfer of personal data to countries outside the EU or EEA only takes place if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision of the European Commission or standard contractual clauses.

Such a transfer currently takes place in connection with the hosting of our website by GitHub, Inc. (see clause 3). It is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework; GitHub is certified under this framework.

A further transfer to the USA takes place when your booking request is sent via our form service provider Formspree, Inc. (see clause 6). Formspree does not state a specific adequacy decision or standard contractual clauses for this transfer in its own privacy policy. The transfer is therefore based on Art. 49(1)(b) GDPR, as it is necessary for the performance of pre-contractual measures that you yourself initiated by submitting your request.

12. Fonts and external content

12.1 Fonts

The fonts used on our website are hosted locally on our own web space and served from there. No connection to font providers' servers (e.g. Google Fonts) is made when you visit our website, and no data is transmitted to third parties in this respect.

12.2 Social media and embedded content

Where we link to social networks, these are simple links. Data is only transmitted to the operators once you actively click the link. We only load embedded third-party content (e.g. videos) after your consent.

12.3 Web analytics

We do not use any web analytics, tracking or advertising services. No evaluation of individual visitors' usage behaviour takes place.

13. Retention period

We store personal data only for as long as necessary for the respective purposes or as required by statutory retention periods:

Data Retention period Basis
Server log files (at hosting provider) per GitHub's policies Legitimate interest
Enquiries not leading to a booking 12 months after last contact Pre-contractual measures
Booking and billing data 7 years Bokföringslagen (accounting law)
Consents given until withdrawn Consent

14. Your rights

As a data subject, you have the following rights:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data, unless retention obligations apply (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)

To exercise your rights, an informal message to the contact details given in clause 1 is sufficient.

15. Right to complain

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for us is the Swedish data protection authority: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden — imy.se.

Alternatively, you may contact the supervisory authority of your usual place of residence.

16. Changes to this privacy policy

We adapt this privacy policy whenever the legal situation or our processing activities change. The version published on our website at any given time applies.