Privacy Policy

This policy explains how Datera ehf. handles personal data about the people we deal with as a company: visitors to this website, people who contact us, clients and prospective clients, and people who apply to work with us. It does not cover what happens inside our products. If you use Kvasir Dashboards, Mímir or Birta, read the Privacy and data handling in our services page. Cookies and analytics on this website are covered separately in our Cookie Policy.

Who we are

Datera ehf. Company registration number (kennitala) 541118-2330 Laugavegur 7, 101 Reykjavík, Iceland
Datera ehf. is the data controller for the processing described on this page.
Data protection contact: Tryggvi Freyr Elínarson, tryggvi@datera.is

What this policy covers

This policy applies to personal data we process in the course of running Datera as a business. Three other documents deal with adjacent topics:

Data we collect about website visitors

When you browse datera.is, the analytics and tags described in our Cookie Policy may collect technical data about your visit. Which tools are in use, what they collect and how to opt out are all set out there, and we keep that page current rather than repeating it here.

If you contact us through the website or by email, we receive whatever you choose to send us: typically your name, email address, company and the content of your message. We use it to answer you and, where it leads to a working relationship, to set that up.

Data we collect about clients and prospective clients

When you are a client or are considering becoming one, we process the personal data needed to run the relationship:

  • contact details of the people we work with (name, role, work email, phone)

  • correspondence, meeting notes and proposals

  • contract and billing information, including invoices and payment records

  • access records for the products we provide to you (covered in more detail on the services page)

We do not build marketing profiles of individuals, and we do not sell or rent personal data to anyone.

Recruitment

We run open positions through the recruitment platform Alfred, whose own privacy terms apply when you apply through it. We also welcome general applications by email to hallo@datera.is. Because we recruit infrequently, we keep unsolicited applications for up to twelve months so we can come back to you if a suitable role opens; you can ask us to delete yours at any time.

Legal bases

We rely on the following legal bases under the GDPR and the Icelandic Data Protection Act (lög nr. 90/2018):

Purpose

Legal basis

Answering enquiries and discussing potential work

Legitimate interest in responding to people who contact us (Art. 6(1)(f))

Delivering services under a client agreement

Performance of a contract (Art. 6(1)(b))

Invoicing, accounting and tax records

Legal obligation (Art. 6(1)(c))

Keeping unsolicited job applications on file

Consent, given when you send the application (Art. 6(1)(a))

Occasional professional updates to existing contacts

Legitimate interest; you can object at any time (Art. 6(1)(f))

Website analytics

As set out in the Cookie Policy

How long we keep it

Data

Retention

Enquiries that do not lead to a relationship

Up to 24 months after our last contact

Client contact details and correspondence

For the duration of the relationship and up to 24 months after it ends

Contracts, invoices and payment records

Seven years after the end of the financial year, as required by the Icelandic Accounting Act (lög um bókhald nr. 145/1994)

Job applications

Up to 12 months from receipt

Product access and usage records

As described on the services page

When a retention period ends we delete the data or anonymise it so that it no longer identifies anyone.

Who we share it with

We use a small number of service providers for accounting, email, document handling and similar business functions. Each acts on our instructions under a contract that meets the requirements of Article 28 GDPR. We do not publish the list, but we will provide it on request to anyone with a legitimate reason to ask: write to tryggvi@datera.is

The processors used by our products are a different list and are set out on the services page.

We may also disclose personal data where the law requires it, for example to tax authorities or in response to a lawful request from a public body.

International transfers

We keep company data within the European Economic Area wherever we can. Where a provider processes personal data outside the EEA, we rely on a European Commission adequacy decision or on the Commission's Standard Contractual Clauses, together with any additional safeguards the transfer requires.

Your rights

You have the right to:

  • access the personal data we hold about you and receive a copy

  • rectify data that is inaccurate or incomplete

  • erase your data where we no longer have a lawful reason to keep it

  • restrict processing while a dispute about the data is resolved

  • receive the data you gave us in a portable, machine-readable format

  • object to processing based on legitimate interest, including any marketing

  • withdraw consent at any time where consent is the legal basis

To exercise any of these rights, email tryggvi@datera.is. We will confirm receipt and respond within one month. If a request is complex we may take up to two further months, and we will tell you if that is the case. We may ask you to verify your identity before acting on a request.

If you are not satisfied with how we have handled your data, you have the right to complain to the Icelandic Data Protection Authority, Persónuvernd (Laugavegur 166, 105 Reykjavík, personuvernd.is), or to the supervisory authority in the EEA country where you live or work.

Changes to this policy

We will update this page when our practices change, and the date at the top will always show when it was last revised. Substantial changes affecting clients will also be communicated directly.

Last updated: 8 September 2026