Vestra privacy policy
1. Introduction
Vestra AI ehf. ("Vestra", "we") is committed to protecting personal data and complying with Act No. 90/2018 on Data Protection and the Processing of Personal Data and the EU General Data Protection Regulation (GDPR). This policy explains what personal data is collected on the website vestra.is, how it is used and what rights you have.
The data controller is:
Vestra AI ehf., reg. no. 570125-0360, Bolholt 8, 105 Reykjavík, Iceland, hallo@vestra.is
2. What information do we collect?
The website does not require a login and has no user accounts. We only collect the following information:
Information you provide to us
- Your name and email address when you fill in the contact form on the website.
- Information you include when you contact us by email or phone.
Technical information
- The website's hosting provider keeps standard server logs for operational and security purposes, such as IP addresses, timestamps and browser type.
3. How do we use the information?
- To answer enquiries and book the assessments or meetings requested.
- To operate the website, keep it secure and prevent abuse.
We do not use the information for any other purpose, we do not send marketing emails without consent, and we never sell personal data.
4. Legal basis for processing
- Processing related to enquiries and communication is based on taking steps at your request prior to entering into a contract, or on our legitimate interest in responding to enquiries.
- Processing of technical information is based on our legitimate interest in operating the website securely.
- Where processing is based on consent, you can withdraw it at any time.
5. Processors and sharing of information
We do not share personal data with third parties except the following service providers, which are involved in operating the website and act as processors on our behalf:
- Vercel — website hosting.
- Resend — sends emails from the contact form (a confirmation to you and a notification to us).
- Prismic — the content management system that stores the website's content.
Some of these providers are located outside the European Economic Area, mainly in the United States. Transfers of personal data to them are based on appropriate safeguards, such as the European Commission's adequacy decision (EU-US Data Privacy Framework) or the EU standard contractual clauses.
6. Cookies
The website uses no cookies for analytics or marketing, and it contains no third-party tracking cookies.
7. Data retention
Correspondence about enquiries is kept in our email inbox for as long as needed to answer and follow up on the enquiry. Information from the contact form is not stored in any database operated by the website. The hosting provider's server logs are retained for a limited time in accordance with its terms.
8. Security
We apply recognised technical and organisational measures to protect personal data, including encrypted data transfer (HTTPS) and restricted access to our email and systems.
9. Your rights
Under data protection law you have the right to:
- be informed about and access the personal data we process about you,
- have inaccurate or incomplete data corrected,
- have data erased when it is no longer needed,
- restrict or object to processing,
- have your data transferred to another party (data portability),
- withdraw consent at any time, where processing is based on it.
Requests can be sent to hallo@vestra.is and we will respond as soon as possible, and no later than within one month. If you believe our processing does not comply with the law, you can lodge a complaint with the Icelandic Data Protection Authority, Persónuvernd (personuvernd.is).
10. Changes
This policy may be updated. The latest version is always available at vestra.is/personuverndarstefna and the date of the last update is shown at the bottom of the document.
Version 2.0 approved 22 JUL 2026