The Nordic Compendium
Legal & policy

Privacy Notice

Last updated: 8 August 2026

We collect as little as we can, we ask before we measure anything, and we never sell personal data.

This notice explains what happens to personal data when you read The Nordic Compendium. It is written to be understood rather than to be survived, and it applies to every page on this website.

1. Who is responsible for your data

The controller of the personal data described here is [PUBLISHER LEGAL NAME], registered at [REGISTERED ADDRESS], company registration number [REGISTRATION NUMBER], publisher of The Nordic Compendium.

For anything to do with privacy, write to [PRIVACY EMAIL]. We do not currently operate at a scale that requires a designated Data Protection Officer; if that changes, the contact details will appear here.

Placeholder fields. The bracketed details above must be replaced with a genuine legal entity and a monitored address before this site goes live. A privacy notice naming no real controller has no legal effect.

2. What this notice covers

This notice covers this website only. It does not cover Restaurant Frantzén, Frantzén Group or any other organisation. We are an independent publication with no relationship to them, and we cannot answer for how they handle data. If you have contacted the restaurant, that is between you and the restaurant.

It also does not cover other websites we link to. Once you follow an external link, that site's own notice applies.

3. What we collect

Data you give us deliberately

If you write to us — for a correction, an editorial question, a press enquiry or a privacy request — we receive your email address, your name if you give it, and whatever is in your message. We ask you not to send us sensitive personal data, health information or anything confidential; there is no reason to and we would rather not hold it.

Data collected automatically by the web server

Like every website, ours is served by infrastructure that keeps short-lived technical logs. These may include your IP address, the page requested, the time of the request, the referring page, and your browser and device type. These logs exist to deliver pages, diagnose faults and defend against abuse. We do not use them to build profiles.

Data collected only if you allow it

Statistics and marketing technologies are switched off by default. Nothing in those categories runs until you actively allow it through the privacy banner or the preferences panel. If you allow them, the categories and the specific technologies involved are described in the cookie notice.

What we never collect

  • Payment details. We take no payments and hold no accounts.
  • Special category data as defined by Article 9 of the GDPR.
  • Data about children, knowingly and in any circumstance.
  • Data bought from data brokers or scraped from elsewhere.

4. Why we use it, and on what legal basis

PurposeData usedLegal basis (GDPR)
Delivering the pages you request and keeping the site onlineTechnical log data, strictly necessary storageLegitimate interests, Art. 6(1)(f) — running a website that works
Remembering your privacy choice so we do not ask again on every pageA single item of local storageLegitimate interests, Art. 6(1)(f), and compliance with our duty under the ePrivacy rules to respect your choice
Protecting the site against abuse, scraping and attackTechnical log dataLegitimate interests, Art. 6(1)(f) — security
Replying to your messageYour email address, name and message contentLegitimate interests, Art. 6(1)(f) — answering someone who wrote to us
Understanding which chapters are read, in aggregateStatistics technologiesConsent, Art. 6(1)(a) — withdrawable at any time
Measuring whether an advertising campaign led to a visitMarketing technologiesConsent, Art. 6(1)(a) — withdrawable at any time
Meeting legal obligations and defending legal claimsWhatever is strictly relevantLegal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f)

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded that it is not, because the processing is minimal, expected, and does not involve profiling. You can object at any time — see section 10.

5. Cookies and similar technologies

We use a small amount of strictly necessary storage that cannot be switched off, and three optional categories that are off until you allow them. Full detail, including what each item is called and how long it lasts, is in the cookie notice.

You can change or withdraw your choice at any time using the control at the bottom left of any page, or by opening privacy preferences. Withdrawing consent is as easy as giving it, and it takes effect immediately.

6. Advertising and measurement partners

If, and only if, you allow the statistics or marketing categories, data may be processed by the following kinds of partner:

  • Analytics providers, to count page views and referral sources in aggregate.
  • Advertising platforms, to measure whether an advertisement led to a visit and to limit how often the same advertisement is shown to the same person.

Where a Google service is used, we implement Google Consent Mode so that Google receives a signal reflecting your actual choice. With consent denied, tags are restricted and identifying storage is not set. Google acts as an independent controller for some of this processing; its own terms and privacy information govern that part, and we link to them in the cookie notice.

We do not sell personal data, and we do not share it for cross-context behavioural advertising in the sense used by US state privacy laws. If you are in a jurisdiction that grants an opt-out right of that kind, declining the marketing category in our banner is the mechanism.

7. Who else sees your data

  • Our hosting and infrastructure providers, who process technical data on our instructions to deliver the site.
  • Our email provider, if you write to us.
  • The optional partners in section 6, only where you have consented.
  • Professional advisers, courts or authorities, where we are legally required to disclose or need to establish or defend a legal claim.

Where a provider processes data on our behalf, there is a written processing agreement in place under Article 28 of the GDPR. We do not pass your data to anyone for their own marketing.

8. Transfers outside the EEA

Some providers operate infrastructure outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on one of the safeguards permitted by Chapter V of the GDPR — an adequacy decision of the European Commission where one applies, or Standard Contractual Clauses together with supplementary technical and organisational measures where it does not.

You may request a copy of the relevant safeguard by writing to [PRIVACY EMAIL].

9. How long we keep it

DataKept for
Your recorded privacy choiceUp to 180 days on your own device, after which we ask again
Server log dataNormally no more than 30 days, unless needed to investigate an incident
Correspondence with usUp to 24 months after the matter is closed, then deleted
Correction requests we have acted onRetained as an editorial record, with personal identifiers removed
Statistics dataAs set out in the cookie notice; typically 14 months at most

10. Your rights

If the GDPR applies to you, you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Rectification of data that is inaccurate or incomplete.
  • Erasure of your data where there is no overriding reason for us to keep it.
  • Restriction of processing in certain circumstances.
  • Portability — to receive data you gave us in a structured, machine-readable format.
  • Object to processing based on legitimate interests, including profiling. If you object, we stop unless we can show compelling legitimate grounds that override your interests.
  • Withdraw consent at any time, without affecting processing already carried out lawfully before the withdrawal.

To exercise any of these, write to [PRIVACY EMAIL]. We respond within one month. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive requests, and we will explain our reasoning if we ever do.

We may need to verify your identity before acting, because handing personal data to the wrong person is itself a breach.

11. Automated decision-making

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile readers.

12. Children

This site is written for an adult general readership. It is not directed at children, we do not knowingly collect data from anyone under 16, and we do not market to children. If you believe a child has sent us personal data, write to [PRIVACY EMAIL] and we will delete it.

13. Security

The site is served over HTTPS. Access to any personal data we hold is limited to people who need it, and correspondence is held in accounts protected by strong authentication. No system is perfectly secure, and we do not claim otherwise. Where a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours and, where the risk is high, we notify you directly.

We link to external sources, including the restaurant's own website and the Michelin Guide, so that readers can verify what we say. We do not control those sites and are not responsible for their content or their privacy practices. Their notices apply once you arrive.

15. Changes to this notice

We update this notice when our practices change or the law does. The date at the top always reflects the current version. Where a change materially affects your rights, we will surface it through the privacy banner rather than relying on you to re-read the page.

16. Complaints

If you are unhappy with how we have handled your data, please tell us first at [PRIVACY EMAIL] — most things are resolved quickly at that stage.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live, where you work, or where you believe the problem occurred. The list of national authorities is published by the European Data Protection Board. Complaining to us first is not a precondition of complaining to them.