The company processes personal data in accordance with the law, cf. Act No. 90/2018 on Data Protection and the Processing of Personal Data.
The following sections outline how the company handles personal information..
This privacy policy covers the company's processing of personal data concerning current, former, and prospective customers. The policy also applies to all those who process personal data on behalf of the company in the role of a data controller.
The objective of this policy is to:
- Ensure compliance with applicable laws, regulations, and the company's internal procedures regarding the handling of personal data.
- Define the company's responsibilities and primary obligations regarding the secure processing and protection of information.
- Ensure that the data protection framework is always in accordance with the current legal framework, guidelines, and official requirements.
The Board of Directors bears ultimate responsibility for designing and maintaining a secure framework for the processing of personal data. This includes the implementation of effective control systems and operational procedures.
The main responsibilities of the Board are:
- Monitoring: To ensure that the privacy policy is followed across all departments and business units.
- Compliance: To ensure that all personnel, including both staff and outsourced service providers, operate in accordance with legal requirements.
- Protection of Rights: To maintain active security measures that minimize risk and protect the rights of individuals.
Tvístirni emphasizes transparency in the collection and processing of its customers' personal data. The processing of information is based on the nature of the service and may include, among others, the following categories:
- Contact and Identity Information: Information such as name, national ID number (kennitala), email address, phone number, physical address, and banking information.
- Communication History:Data from correspondence, emails, and other interactions. This enables us to provide personalized service, respond to feedback, and improve the customer service experience.
- Submitted Data and Documents: Copies of documents provided by customers to the company, for example, in connection with the drafting of service agreements.
- Contractual Information: Data regarding active contracts, purchased products, and services rendered that are necessary to fulfill our contractual obligations.
- Public Records: Information retrieved from public registries (e.g., Registers Iceland or the Register of Enterprises) or data that has been made public online.
- Sensitive Personal Data: For their handling, please refer to the section on Legal Basis for Processing Personal Data.
- Consent and Permissions: Information regarding any consent or authorizations that the customer has granted to the company.
Tvístirni, in its role as a data controller, emphasizes ensuring the rights of individuals in accordance with data protection laws. Subject to legal limitations, data subjects have the right to the following:
- Information and Access: The right to be informed about the processing of information and to access one's own personal data.
- Rectification and Erasure: The right to have inaccurate information corrected or to request the deletion of data where applicable (the right to be forgotten).
- Restriction and Objection: The right to request that processing be restricted or to object to it altogether.
- Data Portability: The right to receive one's own data in a machine-readable format for transfer to another party.
Inquiries or requests regarding these rights can be sent to the email address:
The Icelandic Data Protection Authority (Persónuvernd) monitors compliance with data protection and personal data processing laws in Iceland. If you believe that the processing of your information is not in accordance with applicable laws, you have the right to lodge a complaint with the authority.
Contact Information for the Icelandic Data Protection Authority:
Address: Rauðarárstígur 10, 105 Reykjavík [Islanda]
Phone: [+354] 510 9600
E-mail:
Retention Period
Tvístirni retains customers' personal data for as long as necessary to provide the requested services and to fulfill legal obligations, such as those under the Accounting Act.
The retention period for data may vary depending on its nature, the type of service, and current legal requirements. Strict security and access control rules apply to all processing and storage of data to ensure its protection.
Sharing with Third Parties
We share personal data with external partners when necessary to deliver products or provide specific services in accordance with our contractual obligations.
In accordance with data protection laws, all processing of personal data at Tvístirni is based on a lawful basis. Processing is only permitted if it meets at least one of the following conditions:
- Contractual Obligation: The processing is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract (e.g., for translation services).
- Legal Obligation: The processing is necessary for compliance with a legal obligation to which the company is subject, such as those under the Accounting Act.
- Legitimate Interests: The processing is necessary for the purposes of the legitimate business interests pursued by the company or a third party, except where such interests are overridden by your interests.
- Consent: You have given unambiguous consent to the processing of your personal data for one or more specific purposes.
Processing of Special Categories of Personal Data
In general, the processing of sensitive personal data (e.g., concerning health, political opinions, or origin) is prohibited. Such processing only takes place if specific legal conditions are met, such as if:
- The data subject has given their unambiguous consent.
- The processing is necessary for the establishment, exercise, or defense of legal claims.
- The processing relates to personal data which are manifestly made public by the data subject.
Tvístirni places great emphasis on not sharing personal data with unrelated parties. The disclosure of data occurs only in exceptional cases and is based on the following grounds:
- Consent: When the customer has given explicit consent for the disclosure.
- Legal Obligations: When it is mandatory to provide data based on a legal authority or pursuant to a binding court order.
- Partners and Service Providers: When it is necessary to provide the requested services or for the hosting and operation of our information systems.
When selecting partners and data processors, we set strict requirements for them to have implemented appropriate security measures and to fully comply with data protection laws and regulations.
Main Data Processors and Technology
To ensure the proper functionality of the website and to analyze its usage, we utilize the services of the following parties:
- Hosting and System Operations: Cloud Access LLC – See their privacy policy.
- Web Analytics and Analysis:: Google Analytics – Used for statistical summaries and to improve user experience.
In certain cases, personal data may be stored or transferred abroad, for instance through the use of international cloud services.
If personal data is transferred to countries outside the European Economic Area (EEA), Tvístirni places great emphasis on ensuring that data protection is comparable to that which applies within the area. Such transfers take place only when appropriate safeguards are met, such as:
- Standard Contractual Clauses: The use of approved European Union Standard Contractual Clauses (SCCs) for data protection.
- Binding Corporate Rules: Ensuring that the service provider operates according to approved internal regulations (Binding Corporate Rules, or BCRs).
- Adequacy Decisions: That transfers only take place to countries that provide an adequate level of protection as determined by the European Commission.
In this way, we ensure that the security of your data is always guaranteed, regardless of where it is hosted.
Tvístirni may use information for the purpose of its legitimate interests in the direct marketing of the company's products and services. We place great emphasis on respecting the right of individuals to opt-out of such communications.
Individuals always have the right to object to the processing of personal data for marketing purposes, whether it concerns direct mail or phone calls.
If you do not wish to receive information from us, you can also contact us directly at:
One of the fundamental duties of Tvístirni is to ensure the maximum security of the personal data entrusted to us. We have implemented appropriate technical and organizational measures to protect data against unauthorized access, destruction, or misuse.
In the event of a personal data breach, all such matters are handled in strict accordance with data protection laws. This includes:
- Notification Requirements: A notification will be sent to the Icelandic Data Protection Authority (Persónuvernd) within the time limits prescribed by law..
- Communication of a Breach: Data subjects will be informed without undue delay if the personal data breach is likely to result in a high risk to their rights and freedoms.
This privacy policy is approved by the Board of Directors of Tvístirni, which is responsible for its implementation and the monitoring of its execution within the organization.
Tvístirni is committed to continuously improving its services, which may lead to changes in the processing of personal data. All updates to this policy take effect as soon as they are published on the company's website. We encourage customers to review the contents of this policy regularly.
Effective Date: March 8, 2021 (Last updated: March 23, 2026).