Hugdrif
EN / IS

Privacy Policy

Hugdrif is an independent enterprise architecture practice in Reykjavík owned by Pétur Snæland, who runs the company and handles data protection personally.

  • We collect only what you send us when you get in touch, what a project needs while we do the work, and what the law requires for invoicing.
  • We do not sell or share your data. No marketing lists, no advertising networks, no tracking you across other websites, no advertising cookies of any kind.
  • The website is quiet by default. It sets only what it needs in order to work and stay secure. 
  • We do not keep things forever. Enquiries go after a year. Project material goes within two years of a project closing. Accounting records stay for seven years because the law requires it.
  • You are in control. Ask for a copy of your data, a correction, or its deletion, at any time, at privacy@hugdrif.is. We respond within a month.
  • If we get something wrong, please tell us and we will put it right. You can also contact Persónuvernd, the Icelandic Data Protection Authority.

This policy follows Regulation (EU) 2016/679 (GDPR) as implemented in Iceland by Act No. 90/2018 on Data Protection and the Processing of Personal Data.

Last updated September 9, 2026.

Who is responsible for my data?

Hugdrif is registered in Iceland under the registration number below, and its registered office is recorded in the Icelandic company register (Fyrirtækjaskrá).

  • Legal entity: Hugdrif ehf.
  • Registration number (kennitala): 600826-2120
  • Email: privacy@hugdrif.is
  • Telephone: +354 899 6996
  • Website: hugdrif.is and hugdrif.com

Hugdrif is the data controller for the personal data described here. We have not appointed a Data Protection Officer and are not required to under Article 37 GDPR, because our core activities involve neither large-scale monitoring nor large-scale processing of special categories of data. The principal handles these matters personally.

What exactly do you collect, and on what legal basis?

Enquiries

What: your name, email, telephone, organisation, and whatever you write to us.
Why: to answer you.
Legal basis: Article 6(1)(b), steps taken at your request before a contract, or Article 6(1)(f), our legitimate interest in responding to enquiries about our services.
Kept for: 12 months from our last exchange, unless it becomes a client engagement.

Client engagements

What: contact details of the people we work with, and the material we are given or produce in order to do the work.
Why: to deliver the advisory work we agreed.
Legal basis: Article 6(1)(b), performance of a contract.
Kept for: the duration of the engagement, then deleted or stripped of identifying detail within 24 months of close, except where the accounting rules below apply.

Invoicing and accounting

What: name, kennitala, address, payment details.
Why: because the law requires it.
Legal basis: Article 6(1)(c), compliance with a legal obligation.
Kept for: 7 years after the end of the financial year, under Article 20 of the Bookkeeping Act No. 145/1994. Annual financial statements are kept for 25 years.

Website technical data

What: IP address, browser and device type, pages viewed, approximate location derived from IP address.
Why: to run the site and keep it secure.
Legal basis: Article 6(1)(f), our legitimate interest in a functioning, secure website.
Kept for: a short, rolling period set by our hosting provider's standard access logs.

Website analytics

What: aggregated, cookieless visit statistics (page views, referrers, country-level location) via Vercel Analytics.
Why: to see which pages are read, and improve them.
Legal basis: Article 6(1)(f), our legitimate interest in a functioning website; no cookie or device identifier is used, so no consent is required under the ePrivacy rules.
Kept for: held in aggregate, with no directly identifying data.

Do I have to give you my data?

No. Neither law nor contract requires it. But if you do not give us a name and a way to reply, we cannot answer your enquiry, and if you do not give us what a project needs, we cannot do the work.

Please do not send us special categories of data as defined in Article 9 GDPR, such as health, biometric or political data, or confidential material, through the website contact form.

We do not carry out automated decision-making or profiling under Article 22 GDPR.

Which cookies does the website use?

The website does not set cookies. It stores two small preferences in your browser's local storage instead: your language choice, and your cookie decision below. Both stay on your device only and are never sent to us.

Language and consent, strictly necessary

Storage: two local storage entries, hugdrif.lang and hugdrif.cookieConsent.
Purpose: remember which language you're reading in, and your cookie choice, as evidence that we asked under Article 7(1) GDPR.
Duration: until you clear your browser's storage or change your choice.

Analytics, no cookie involved

Storage: none. Vercel Analytics measures aggregated page views and referrers without setting a cookie or storing a device identifier.
Purpose: see which pages are read, and improve them.
Duration: not applicable, no identifier is kept.

We use no advertising cookies, no social media pixels, no marketing tools and no third-party analytics such as Google Analytics, the Meta Pixel or the LinkedIn Insight Tag. If that ever changes we will update this policy and add the category to the banner first.

Your browser can clear local storage at any time; doing so resets your language choice but breaks nothing on the site.

Which other companies see my data?

We never sell personal data or pass it on for marketing. The contact page opens your own email client; nothing you write there passes through us until you send it, and it then arrives directly in our Microsoft 365 mailbox. We use a small number of service providers, each acting as our processor under a written agreement:

  • Vercel Inc. Website hosting and cookieless analytics.
  • Microsoft Ireland Operations Limited. Email, calendar and document storage on Microsoft 365.
  • PayDay. Invoicing, payroll and day-to-day bookkeeping.
  • Enor. Accounting, annual accounts and audit.

PayDay and Enor are Icelandic companies, and the data they handle for us stays within the EEA. Beyond these, we disclose data only where the law requires it, or to our own professional advisers under a duty of confidentiality. Client project material stays inside our Microsoft 365 environment and is not shared with anyone outside the engagement without instruction.

Is my data sent outside Europe?

Our providers operate servers in the EEA and elsewhere, including the United States. Where personal data leaves the EEA it is transferred under the safeguards in Chapter V GDPR, in practice the European Commission's Standard Contractual Clauses together with the technical and organisational measures in each provider's data processing agreement. Microsoft additionally applies its EU Data Boundary commitments.

How is my data protected?

The website is served over HTTPS. Our accounts use multi-factor authentication, devices are encrypted, and access to client material is limited to those who need it. Our providers apply their own technical and organisational measures, including encryption in transit and at rest. No system is perfectly secure, but we take this seriously and will tell you and Persónuvernd promptly if a breach affects you and the law requires it.

What are my rights, exactly?

You have the right to:

  • Access. Obtain confirmation that we process your data, and receive a copy.
  • Rectification. Have inaccurate or incomplete data corrected.
  • Erasure. Have your data deleted where Article 17 applies.
  • Restriction. Require us to limit processing in the circumstances of Article 18.
  • Portability. Receive data you gave us in a structured, machine-readable format.
  • Objection. Object to processing based on our legitimate interests, on grounds relating to your situation.
  • Withdrawal of consent. Withdraw consent at any time where we rely on it, without affecting what was lawful beforehand.

Some of these have limits. We cannot delete accounting records the law requires us to keep, and we may need to retain material relating to a completed engagement in order to defend a legal claim.

Write to privacy@hugdrif.is to exercise any of these rights. We reply within one month, extendable by two months for complex requests, in which case we will inform you of the extension within the first month. It costs nothing unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity first.

What if I have a complaint?

Tell us first if you think we have got something wrong, and we will try to put it right. You can also complain to the Icelandic Data Protection Authority:

Persónuvernd
Laugavegur 166, 4th floor, 105 Reykjavík
Telephone 510 9600
postur@personuvernd.is
personuvernd.is

What happens when this policy changes?

We update it when our services, our providers or the law change. The current version is always on this page with the date at the top, and material changes will be flagged on the site.