Privacy Policy

Last updated: 22 September 2026

This Privacy Policy explains what personal data we handle when you visit this website or join the interest list for Mountain Streams Resort & Casino, a planned resort on the Hardangerfjord in western Norway. The resort does not exist yet: it is a project in development, and no bookings are taken. We collect very little, and we have tried to explain it plainly.

1. Who is responsible for your data

The controller of your personal data is Rostyslav Dmytruk, 22 Luhova Street, Kyiv 02000, Ukraine (“we”, “us”). For anything to do with privacy, write to [email protected]. We have not appointed a data protection officer, as the law does not require one for processing of this scale, but every message to that address is read by a person.

2. The short version

  • There is no analytics, no advertising tracker, no social media pixel and no cookie on this website.
  • The interest list form does not send anything to a server. It prepares an email in your own email program, and nothing reaches us unless you press send there.
  • We use your name and email address only to send news about the project, and only with your consent.
  • You can withdraw your consent at any time by writing to [email protected].
  • We do not sell, rent or share your data for anyone else’s marketing.

3. What data we handle and why

3.1. The interest list

The form on the contact page asks for your name, your email address and, optionally, what you are most interested in (for example a type of room or the evenings in Kvasir’s Hall). When you press the button, your browser opens a pre-filled email addressed to [email protected]. We receive the data only if you send that email. We then hold:

  • your name and email address;
  • the topic you chose, and anything else you decide to write in the email;
  • the date of your message and the fact that you gave consent.

Purpose: to keep a list of people who would like to hear about the project, and to send them occasional news — for example when an opening date is announced, when room plans are confirmed or when reservations open.

Legal basis: your consent, under Article 6(1)(a) of the General Data Protection Regulation (GDPR). Because this is electronic marketing to private individuals, we also follow section 15 of the Norwegian Marketing Control Act (markedsføringsloven), which requires your prior consent before we send you marketing by email. Joining the list is entirely voluntary; if you do not join, you simply will not receive the news.

3.2. Emails you send us

If you write to any of our addresses — info@, events@, privacy@ or legal@ — we receive your email address, your name if you give it, the content of your message and the usual technical details that come with an email, such as the date and time it was sent.

Purpose: to read and answer your question and to keep a record of our correspondence.

Legal basis: our legitimate interest in answering the people who contact us, under Article 6(1)(f) GDPR. Where your message concerns your rights under data protection law, we also process it to meet our legal obligations, under Article 6(1)(c) GDPR.

3.3. Technical logs

Like almost every website, this one is delivered by a web server that keeps short technical logs. When your browser requests a page, the server may record your IP address, the date and time, the page or file requested, the response code, the address of the page that linked to it and the browser’s user-agent string.

Purpose: to deliver the website, keep it secure, detect abuse and fix faults. We do not use these logs to build profiles, to follow you across websites or to identify you, and we do not combine them with the interest list.

Legal basis: our legitimate interest in running a secure and working website, under Article 6(1)(f) GDPR.

3.4. What we do not collect

This website has no analytics, statistics or heat-mapping tools, no advertising or remarketing tags, no embedded videos, maps or social media widgets and no fonts or scripts loaded from other companies. Everything you see is served from this website alone. The only thing the site stores in your browser is a small preference for the footer menu, described in our Cookie Policy. It contains no personal data and never leaves your device.

4. How long we keep it

  • Interest list: until you withdraw your consent, or until the project is completed or abandoned, whichever comes first. We review the list at least every 24 months and delete entries that are no longer needed.
  • Correspondence: up to 24 months after our last exchange, unless a longer period is required to meet a legal obligation or to establish, exercise or defend a legal claim.
  • Technical logs: for a short period set by the hosting provider’s standard configuration, after which they are deleted or overwritten automatically.
  • Records of withdrawn consent: we keep a minimal note that you asked not to be contacted, so that we do not write to you again by mistake.

5. Who else sees your data

We do not sell your personal data and we do not share it with anyone for their own marketing. We use a small number of service providers who handle data on our behalf, under written agreements that require them to protect it and to use it only on our instructions:

  • the provider that hosts this website and keeps its technical logs;
  • the provider of our email mailboxes, which stores the messages you send us.

At present we send news to the interest list directly from our own mailbox, without a separate newsletter service. If that changes, we will update this policy and name the service before it is used.

We may also disclose data where the law requires it, for example to a court or public authority, or where it is needed to establish, exercise or defend a legal claim.

6. International transfers

This website is aimed at visitors in Norway and the wider European Economic Area (EEA), but the controller is based in Ukraine, which does not currently benefit from an adequacy decision of the European Commission. Some of our service providers may also be located outside the EEA. Where your personal data is transferred outside the EEA, we protect it with appropriate safeguards under Article 46 GDPR, in particular the Standard Contractual Clauses adopted by the European Commission, together with any additional measures that are needed. You can ask for a copy of the relevant safeguards by writing to [email protected].

7. Your rights

Under Articles 15 to 22 GDPR you have the right to:

  • access the personal data we hold about you and receive a copy of it (Article 15);
  • have inaccurate data corrected (Article 16);
  • have your data erased (Article 17);
  • restrict how we use your data in certain cases (Article 18), and be told when we pass a correction, erasure or restriction on to others (Article 19);
  • receive the data you gave us in a portable format, or have it sent to someone else (data portability, Article 20);
  • object to processing based on our legitimate interests, and object at any time to direct marketing (Article 21);
  • not be subject to a decision based solely on automated processing that significantly affects you (Article 22). We do not make any such decisions.

To use any of these rights, write to [email protected]. We will answer within one month. If a request is complex, we may extend this by up to two further months and will tell you why. We may ask you to confirm your identity before we act, so that we do not give your data to someone else.

Withdrawing consent

You can withdraw your consent to the interest list at any time, without giving a reason, by writing to [email protected] from the address you signed up with. We will remove you from the list and confirm by email. Withdrawal does not affect anything we did lawfully before it. We will also remind you of this address in every news email we send.

8. Complaints

If you are unhappy with how we handle your data, please tell us first; we would like the chance to put it right. You also have the right to complain to a supervisory authority, in particular in the country where you live, work or where the issue arose:

  • Norway: Datatilsynet (the Norwegian Data Protection Authority), datatilsynet.no;
  • Ukraine: the Ukrainian Parliament Commissioner for Human Rights, ombudsman.gov.ua;
  • in another EEA country, the data protection authority of that country.

9. Security

We keep personal data in password-protected accounts with two-factor authentication where available, limit access to the people who need it and delete what we no longer need. The website is served over an encrypted connection (HTTPS) and uses a strict content security policy that prevents it from loading code or content from other websites. No system is perfectly secure, but if a breach ever puts your data at risk, we will notify the supervisory authority and, where required, you.

10. Children

This website is not intended for anyone under 18, and the planned gaming lounge will be open only to adults. We do not knowingly collect personal data from children. If you believe that a child has joined the interest list, write to [email protected] and we will delete the entry.

11. Links to other websites

Some pages link to other websites, such as Hjelpelinjen or the supervisory authorities listed above. We do not control those websites, and their own privacy policies apply when you visit them.

12. Changes to this policy

We will update this policy when the project, the website or the law changes — for example if a booking system or a newsletter service is introduced. The date at the top shows the latest version. If a change affects how we use data you have already given us, we will tell the people on the interest list by email before it takes effect.