PanionPanion
For guidesFor tour operatorsContactHelp?Log in
Sign up

Privacy Policy

v1.1 · Last updated: 3 August 2026

Contents

  1. 1. Controller
  2. 2. What personal data we process and why
  3. 3. Sources of data
  4. 4. Recipients and processors
  5. 5. Transfers outside the EEA
  6. 6. Storage periods
  7. 7. Your rights (GDPR Art. 15–22)
  8. 8. Automated decision-making
  9. 9. Security
  10. 10. Changes to this Privacy Policy

1. Controller

Panion Norge AS, org. no. 937 759 614, with its registered business address at Tønsnesvegen 14, 9020 Tromsdalen, Norway, is the data controller for the personal data processed via panion.travel. Contact: hello@panion.travel.

In this Privacy Policy, “Panion”(or “we”, “us”, “our”) refers to Panion Norge AS. “Panions” refers to the individual travel guides and local experts who promote and sell activities through the panion.travel platform.

Our use of cookies and similar technologies is described in our Cookie Policy.

We take your privacy seriously and have taken several steps to ensure that we give you clear information about how we process your data and what rights you have. If you feel that something is unclear or missing, please do not hesitate to contact us at hello@panion.travel.

2. What personal data we process and why

We process personal data for the following purposes, on the following legal bases:

Category of dataPurposeLegal basis (GDPR)
Name, email, phoneProcess and confirm bookings; send booking-related communicationArt. 6(1)(b) - performance of contract
Payment information (handled by SagaPay, our payment service provider; we receive limited transaction data)Process paymentArt. 6(1)(b)
Account/login data for Panions and Activity ProvidersProvide platform accountsArt. 6(1)(b)
Bank account details (Panions/Providers)Pay out commission/settlementArt. 6(1)(b) and (c) - contract and legal obligations (bookkeeping)
IP address, device, usage dataSecurity, analytics, fraud preventionArt. 6(1)(f) - legitimate interest
Referral identifier (which Panion's link/QR you arrived through), processed via BókunAttribute commission to the correct Panion; report sales to PanionsArt. 6(1)(a) - consent (cookie); Art. 6(1)(b)/(f) - performance of contract with the Panion / our legitimate interest in correct commission settlement
Approximate locationShow relevant activitiesArt. 6(1)(a) - consent
Marketing communications (if any)Send offers and newslettersArt. 6(1)(a) - consent (cf. markedsføringsloven § 15)
Account, transaction and payout data for Providers and PanionsVerify identity, prevent fraud, assess compliance with our Terms, decide on suspension or termination of accounts, and manage withholding or release of fundsArt. 6(1)(b) - performance of contract; Art. 6(1)(c) - legal obligations (anti-money laundering, tax, accounting); Art. 6(1)(f) - legitimate interest in protecting the Platform, Customers and Panion Norge AS from fraud and misuse
Accounting recordsComply with bookkeeping legislationArt. 6(1)(c) - bokføringsloven

Providing certain personal data (such as name, contact details and payment information) is necessary to enter into and perform the booking contract with you; if you do not provide it, we may be unable to process your booking or provide an account. Where we rely on legitimate interests (Art. 6(1)(f)), we have carried out a balancing assessment, and you may object to such processing (see Section 7).

3. Sources of data

We collect personal data directly from you when you use the Platform, make a booking, or create an account. We may also receive data from SagaPay (payment processing), Bókun (booking and referral tracking), and referring Panions (referral identifiers linked to their unique links or QR codes).

4. Recipients and processors

To operate the platform efficiently and securely, we share personal data with the following categories of recipients where necessary:

  • SagaPay (payment processing)
  • Bókun ehf.(a TripAdvisor company) – booking management and referral/affiliate tracking. Established in Iceland (EEA); may use sub-processors within the TripAdvisor group, including in the United States.
  • Google Analytics(statistics) – subject to consent
  • Meta Pixel(marketing measurement) – subject to consent
  • Cloud hosting providers (e.g. AWS / Vercel / Google Cloud)
  • Email service providers (e.g. Mailchimp / SendGrid)
  • Customer support / chatbot tools
  • Activity Providers– we share only the data necessary to perform the booking (typically name, email, phone, booking details)
  • Panions– aggregated/non-identifying booking information and commission reports (generated by Bókun)
  • Public authorities where required by law

Where required under GDPR Article 28, we enter into data processing agreements with recipients acting as our processors.

Not all recipients act as our processors. For data collected via the Meta Pixel, Panionand Meta Platforms Ireland Ltd. act as joint controllers under GDPR Article 26. Bókun ehf. (a TripAdvisor company) may act as an independent controller for processing carried out for its own and the TripAdvisor group’s purposes. Activity Providers act as independent controllers for the customer data they receive to deliver the activity.

5. Transfers outside the EEA

Some of our processors are located outside the EEA (typically in the United States). Such transfers are based on the EU Commission’s Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework. You may request a copy of relevant safeguards by contacting hello@panion.travel.

6. Storage periods

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, or as required by applicable law. Our standard retention periods are as follows:

  • Booking and customer service data: kept for as long as necessary to process bookings and handle complaints, typically up to 3 years after the activity.
  • Accounting records: 5 years after the end of the financial year (cf. bokføringsloven § 13).
  • Marketing data: until you withdraw consent or object.
  • Account data for Panions/Providers: until the account is closed, plus a reasonable retention period.
  • Documentation related to suspension, termination or withholding decisions: typically 3–5 years, in line with applicable limitation periods.
  • Analytics data: anonymised or deleted within 14 months.

7. Your rights (GDPR Art. 15–22)

Under GDPR Articles 15–22, you have the following rights in relation to your personal data:

  • Access– you may request a copy of the personal data we hold about you.
  • Rectification– you may ask us to correct inaccurate or incomplete data.
  • Erasure– in certain circumstances you may ask us to delete your personal data.
  • Restriction– you may ask us to restrict the processing of your data in certain circumstances.
  • Objection– where we rely on legitimate interests (Art. 6(1)(f)), you have the right to object to that processing; we will then assess your objection and respond promptly.
  • Portability– where processing is based on consent or contract, you may ask us to transfer your data to you or to another controller in a structured, commonly used and machine-readable format.
  • Withdraw consent– where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at hello@panion.travel. We will respond within 30 days.

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with Datatilsynet (www.datatilsynet.no) or the supervisory authority in your country of residence within the EEA. We hope, however, that you will contact us first so that we can try to resolve the matter for you.

8. Automated decision-making

We may use automated tools to help detect fraud, misuse and breaches of our Terms (for example, in connection with account suspension or the withholding of funds). Decisions that produce legal effects concerning you or similarly significantly affect you are not based solely on automated processing; they are subject to human review before they take effect. You have the right to obtain human intervention, to express your point of view, and to contest such a decision by contacting hello@panion.travel.

9. Security

We apply industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These measures include encryption of data in transit, strict access controls, and regular security reviews. We require all processors and other recipients who handle personal data on our behalf to maintain equivalent standards of data security.

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. The latest version is always available on panion.travel. We encourage you to review this page periodically.

Panion
Built by

© Panion Norge AS. All rights reserved.


Panion
For guidesFor tour operatorsHelpContactTermsPrivacyCookie policy
For guidesFor tour operatorsHelpContact
Panion
TermsPrivacyCookie policy
For guidesFor tour operatorsContactHelp?
Log in
Sign up