Storypulsecrossrods
Overview The Cabins Aurora Suite Wilderness & Spa Reservations
Reserve
Storypulsecrossrods
  • Retreat Overview
  • Cabin Architecture Portfolio
  • The Aurora Suite Feature
  • Nordic Rituals & Experiences
  • Concierge & Inquiries
Compliance & Data Governance

Privacy Policy

Effective Date: January 1, 2026 · Storypulsecrossrods Nordic Hospitality AB

1. Introduction & Scope

Storypulsecrossrods Nordic Hospitality AB ("Storypulsecrossrods", "we", "us", or "our") is dedicated to protecting the fundamental privacy rights and personal data of our guests, website visitors, and prospective clients. This Privacy Policy sets forth our practices regarding the collection, processing, transfer, storage, and erasure of personal information collected through our official digital platform storypulsecrossrods.baby and during on-premise stays at our Swedish estate.

Our operations comply with the European Union General Data Protection Regulation (EU GDPR Regulation 2016/679), the Swedish Data Protection Act (Dataskyddslagen 2018:218), and applicable international standards including the California Consumer Privacy Act (CCPA/CPRA) where relevant.

2. Data Controller Information

The legal data controller responsible for your personal data is:

  • Legal Entity: Storypulsecrossrods Nordic Hospitality AB
  • Company Registration Number: SE559382-9104
  • Registered Physical Address: Furuörundet 42, 934 94 Kåge, Skellefteå Archipelago, Sweden
  • Designated Data Protection Contact: [email protected]

3. Categories of Personal Data We Collect

We only collect data strictly necessary to facilitate high-touch luxury hospitality, safety compliance, and bespoke concierge arrangements:

  • Identification and Contact Details: Full name, nationality, passport/identification number (for Swedish guest registry compliance), email address, contact telephone number, and residential address.
  • Reservation & Concierge Preferences: Dates of stay, choice of glass cabin suite, dietary restrictions, emergency contact details, sauna preferences, and airport transport coordinates.
  • Financial & Payment Transaction Data: Encrypted payment token identifiers processed through PCI-DSS Level 1 payment gateways (we never store raw credit card numbers on our local servers).
  • Technical & Usage Data: Anonymized IP addresses, browser version, device category, time zone settings, and telemetry on interaction with our website.

4. Legal Grounds for Processing (GDPR Article 6)

We process your personal information strictly under the following lawful bases:

  1. Contractual Performance (Art. 6(1)(b)): Processing necessary to fulfill your accommodation booking, concierge transfers, and guest services.
  2. Legal Obligation (Art. 6(1)(c)): Processing required by Swedish law, including mandatory hospitality guest registers and local tax reporting (Skatteverket).
  3. Legitimate Interests (Art. 6(1)(f)): Maintaining property security, cyber integrity of our booking platform, and anonymous performance analytics.
  4. Explicit Consent (Art. 6(1)(a)): For non-essential analytics cookies and voluntary subscription to seasonal retreat newsletters.

5. Third-Party Data Processors

We never sell, rent, or commercialize your personal information. Data is disclosed only to verified Data Processors bound by strict Data Processing Agreements (DPAs):

  • Cloud infrastructure and encrypted hosting within the European Economic Area (Stockholm/Frankfurt regions).
  • Secure payment processing gateways adhering strictly to PCI-DSS Level 1 requirements.
  • Local Swedish licensed transport partners for verified airport shuttle arrangements.

6. International Data Transfers

Your data is primarily processed within the European Economic Area (EEA). In any instance where a technical support subcontractor is located outside the EEA, we enforce Standard Contractual Clauses (SCCs) adopted by the European Commission along with supplementary technical safeguards.

7. Data Retention Schedule

Personal data linked to completed bookings is retained for 7 years to satisfy Swedish statutory accounting regulations (Bokföringslagen 1999:1078). Inquiries that do not culminate in a confirmed booking are automatically purged from our operational database after 18 months.

8. Your Rights Under GDPR & International Law

You maintain full statutory rights regarding your personal records:

  • Right of Access: Obtain confirmation and a machine-readable copy of the personal data we hold.
  • Right to Rectification: Request correction of inaccurate or incomplete records.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of data no longer necessary for legal retention.
  • Right to Restrict or Object: Restrict processing under contested circumstances or object to processing based on legitimate interests.
  • Right to Data Portability: Transfer your personal records directly to another service provider in structured JSON or CSV format.

To exercise any statutory right, contact our Data Protection Officer at [email protected]. If you believe your privacy rights have been infringed, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY).

Storypulsecrossrods

Scandinavian luxury glass cabin retreats engineered for stillness, privacy, and sub-arctic natural phenomena.

Accommodations
  • All Glass Suites
  • The Aurora Observatory
  • Lakeside Mirrored Haven
  • Old Pine Hermitage
Experiences
  • Smoke Sauna & Cold Plunge
  • Private Stargazing Expeditions
  • Nordic Foraged Gastronomy
Legal & Info
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Contact & Concierge

Business Address: Furuörundet 42, 934 94 Kåge, Skellefteå Archipelago, Sweden · Email: [email protected]

© 2026 Storypulsecrossrods Nordic Hospitality AB. Company No. SE559382-9104. Registered in Furuörundet 42, 934 94 Kåge, Sweden. All rights reserved.

We use essential cookies and anonymous analytics to refine your reservation experience and honor Scandinavian data privacy standards. Manage your settings below.

Preferences