Privacy Notice
Last updated: 8 August 2026
We collect as little as we can, we ask before we measure anything, and we never sell personal data.
This notice explains what happens to personal data when you read The Nordic Compendium. It is written to be understood rather than to be survived, and it applies to every page on this website.
1. Who is responsible for your data
The controller of the personal data described here is [PUBLISHER LEGAL NAME], registered at [REGISTERED ADDRESS], company registration number [REGISTRATION NUMBER], publisher of The Nordic Compendium.
For anything to do with privacy, write to [PRIVACY EMAIL]. We do not currently operate at a scale that requires a designated Data Protection Officer; if that changes, the contact details will appear here.
Placeholder fields. The bracketed details above must be replaced with a genuine legal entity and a monitored address before this site goes live. A privacy notice naming no real controller has no legal effect.
2. What this notice covers
This notice covers this website only. It does not cover Restaurant Frantzén, Frantzén Group or any other organisation. We are an independent publication with no relationship to them, and we cannot answer for how they handle data. If you have contacted the restaurant, that is between you and the restaurant.
It also does not cover other websites we link to. Once you follow an external link, that site's own notice applies.
3. What we collect
Data you give us deliberately
If you write to us — for a correction, an editorial question, a press enquiry or a privacy request — we receive your email address, your name if you give it, and whatever is in your message. We ask you not to send us sensitive personal data, health information or anything confidential; there is no reason to and we would rather not hold it.
Data collected automatically by the web server
Like every website, ours is served by infrastructure that keeps short-lived technical logs. These may include your IP address, the page requested, the time of the request, the referring page, and your browser and device type. These logs exist to deliver pages, diagnose faults and defend against abuse. We do not use them to build profiles.
Data collected only if you allow it
Statistics and marketing technologies are switched off by default. Nothing in those categories runs until you actively allow it through the privacy banner or the preferences panel. If you allow them, the categories and the specific technologies involved are described in the cookie notice.
What we never collect
- Payment details. We take no payments and hold no accounts.
- Special category data as defined by Article 9 of the GDPR.
- Data about children, knowingly and in any circumstance.
- Data bought from data brokers or scraped from elsewhere.
4. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Delivering the pages you request and keeping the site online | Technical log data, strictly necessary storage | Legitimate interests, Art. 6(1)(f) — running a website that works |
| Remembering your privacy choice so we do not ask again on every page | A single item of local storage | Legitimate interests, Art. 6(1)(f), and compliance with our duty under the ePrivacy rules to respect your choice |
| Protecting the site against abuse, scraping and attack | Technical log data | Legitimate interests, Art. 6(1)(f) — security |
| Replying to your message | Your email address, name and message content | Legitimate interests, Art. 6(1)(f) — answering someone who wrote to us |
| Understanding which chapters are read, in aggregate | Statistics technologies | Consent, Art. 6(1)(a) — withdrawable at any time |
| Measuring whether an advertising campaign led to a visit | Marketing technologies | Consent, Art. 6(1)(a) — withdrawable at any time |
| Meeting legal obligations and defending legal claims | Whatever is strictly relevant | Legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f) |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded that it is not, because the processing is minimal, expected, and does not involve profiling. You can object at any time — see section 10.
5. Cookies and similar technologies
We use a small amount of strictly necessary storage that cannot be switched off, and three optional categories that are off until you allow them. Full detail, including what each item is called and how long it lasts, is in the cookie notice.
You can change or withdraw your choice at any time using the control at the bottom left of any page, or by opening privacy preferences. Withdrawing consent is as easy as giving it, and it takes effect immediately.
6. Advertising and measurement partners
If, and only if, you allow the statistics or marketing categories, data may be processed by the following kinds of partner:
- Analytics providers, to count page views and referral sources in aggregate.
- Advertising platforms, to measure whether an advertisement led to a visit and to limit how often the same advertisement is shown to the same person.
Where a Google service is used, we implement Google Consent Mode so that Google receives a signal reflecting your actual choice. With consent denied, tags are restricted and identifying storage is not set. Google acts as an independent controller for some of this processing; its own terms and privacy information govern that part, and we link to them in the cookie notice.
We do not sell personal data, and we do not share it for cross-context behavioural advertising in the sense used by US state privacy laws. If you are in a jurisdiction that grants an opt-out right of that kind, declining the marketing category in our banner is the mechanism.
7. Who else sees your data
- Our hosting and infrastructure providers, who process technical data on our instructions to deliver the site.
- Our email provider, if you write to us.
- The optional partners in section 6, only where you have consented.
- Professional advisers, courts or authorities, where we are legally required to disclose or need to establish or defend a legal claim.
Where a provider processes data on our behalf, there is a written processing agreement in place under Article 28 of the GDPR. We do not pass your data to anyone for their own marketing.
8. Transfers outside the EEA
Some providers operate infrastructure outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on one of the safeguards permitted by Chapter V of the GDPR — an adequacy decision of the European Commission where one applies, or Standard Contractual Clauses together with supplementary technical and organisational measures where it does not.
You may request a copy of the relevant safeguard by writing to [PRIVACY EMAIL].
9. How long we keep it
| Data | Kept for |
|---|---|
| Your recorded privacy choice | Up to 180 days on your own device, after which we ask again |
| Server log data | Normally no more than 30 days, unless needed to investigate an incident |
| Correspondence with us | Up to 24 months after the matter is closed, then deleted |
| Correction requests we have acted on | Retained as an editorial record, with personal identifiers removed |
| Statistics data | As set out in the cookie notice; typically 14 months at most |
10. Your rights
If the GDPR applies to you, you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data where there is no overriding reason for us to keep it.
- Restriction of processing in certain circumstances.
- Portability — to receive data you gave us in a structured, machine-readable format.
- Object to processing based on legitimate interests, including profiling. If you object, we stop unless we can show compelling legitimate grounds that override your interests.
- Withdraw consent at any time, without affecting processing already carried out lawfully before the withdrawal.
To exercise any of these, write to [PRIVACY EMAIL]. We respond within one month. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive requests, and we will explain our reasoning if we ever do.
We may need to verify your identity before acting, because handing personal data to the wrong person is itself a breach.
11. Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile readers.
12. Children
This site is written for an adult general readership. It is not directed at children, we do not knowingly collect data from anyone under 16, and we do not market to children. If you believe a child has sent us personal data, write to [PRIVACY EMAIL] and we will delete it.
13. Security
The site is served over HTTPS. Access to any personal data we hold is limited to people who need it, and correspondence is held in accounts protected by strong authentication. No system is perfectly secure, and we do not claim otherwise. Where a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours and, where the risk is high, we notify you directly.
14. Links to other websites
We link to external sources, including the restaurant's own website and the Michelin Guide, so that readers can verify what we say. We do not control those sites and are not responsible for their content or their privacy practices. Their notices apply once you arrive.
15. Changes to this notice
We update this notice when our practices change or the law does. The date at the top always reflects the current version. Where a change materially affects your rights, we will surface it through the privacy banner rather than relying on you to re-read the page.
16. Complaints
If you are unhappy with how we have handled your data, please tell us first at [PRIVACY EMAIL] — most things are resolved quickly at that stage.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live, where you work, or where you believe the problem occurred. The list of national authorities is published by the European Data Protection Board. Complaining to us first is not a precondition of complaining to them.