Privacy policy

ECIT Privacy Statement

Last updated in January 2025

In Iceland, there are 2 companies operating under the name ECIT. On the one hand, ECIT Virtus ehf. (ID 550922-0960) and on the other hand, ECIT Bókað ehf. (ID 580823-0840). Hereinafter referred to collectively as ECIT.

ECIT is concerned about the confidentiality and privacy of the information entrusted to the company. ECIT is therefore committed to ensuring the appropriate protection and use of personally identifiable information (also known as “personal data” or “personal information”) collected from the website.

In general, our goal is to collect only personal information that is voluntarily provided by users of the Company's website in order to provide users with information and/or services, or to provide information about the jobs available at the Company. Please review this Privacy Statement for more information about the collection, use, sharing, and protection of the personal information collected.

1. Collection and use of personal information

1.1 What data we collect

We collect personal information about you if you choose to provide it, for example, if you send us an email via the website or register for a specific event or service. You may also have previously provided personal information to ECIT, for example, if you are a former employee. If you log in to an ECIT website using a third-party login option that identifies you and links to your ECIT login via a social media platform, such as Facebook, LinkedIn, Google or X, ECIT will collect the information or content required for registration or login that you as a user have authorized your social media platform to share with the third party, such as your name and email address. Other information that ECIT collects depends on your personal settings on the social media platforms you use. It is recommended that you familiarize yourself with the privacy policy/statement of the relevant platform.

When you register or provide ECIT with personal information, we will use it in the manner described in this Privacy Statement. Your personal information will not be used for any other purpose except with your consent or as permitted by law or professional standards. For example, if you register on an ECIT website and provide information about your preferences, that information will be used to tailor your user experience to those preferences. When you register or use a third-party login, you may be recognized as the same user across the devices you use, thereby adapting your personal use and interface on other ECIT sites you may visit. If you send us your CV or other information in connection with a job application on the ECIT website, the information you provide will be matched to available positions at ECIT in Iceland.

When you have registered for certain services, ECIT will in some cases temporarily store your email address until confirmation of the information you provided via email has been received, i.e. when ECIT sends an email to the email address provided in the registration process to confirm the registration request.

1.2 Legal authorization for the use of personal information

In general, ECIT only collects the personal information that is necessary to fulfill your request. If more detailed information is collected, you will be informed of that data collection when it occurs.

According to Icelandic law, ECIT is authorized to process personal data provided that such processing is based on the provisions of the law. ECIT is also required to inform you of the basis for the processing. When we process your personal data, we will rely on one of the following processing grounds:

    • Based on a contract: When processing personal data is necessary to fulfill our obligations under a contract.
    • Legal obligation: When processing your personal data is necessary to comply with a legal obligation, such as keeping records for tax purposes or reporting to public authorities or regulatory authorities.
    • Legitimate interests: We will process information about you when it is in the legitimate operational interests of the company, unless your opposing interests outweigh them.
    • Consent. In some cases, we will specifically request your informed consent in relation to the processing of your personal data and will only carry out such processing provided that your consent is given in this regard. You may withdraw your consent at any time by contacting ECIT via the email address  ecit@ecit.is

Examples of the "legitimate interests" cited above include:

 

    • to offer information and/or services to individuals who visit our website or to offer information about career opportunities at the company.
    • to prevent fraud or criminal activity and to safeguard the security of our IT systems.
    • to customize the user experience on the website and to improve the usability and efficiency of the ECIT website.
    • to conduct marketing and analysis thereof.
    • to fulfill ECIT's commercial and social obligations.
    • to exercise the company's constitutionally protected rights, including property rights and the right to engage in commercial activities.

In some cases, the personal information we collect will also include special categories of personal information, such as information about social diversity, including information about ethnicity or trade union membership, health information, or information about alleged or proven criminal offences. Such information is collected only to the extent permitted by law.

1.3 Automatic collection of personal information

In certain cases, ECIT and its service providers use cookies, web beacons, and other technological solutions to automatically, electronically collect information when you visit our websites and through our email communications. The collection of this information allows us to customize and improve your experience using the website, enhance the usability and effectiveness of ECIT websites, and measure the effectiveness of our marketing efforts.

1.3.1 IP addresses

An IP address is a unique number assigned to your computer each time you access the World Wide Web. An IP address allows computers and servers to communicate and exchange data. The IP addresses of users of the ECIT website are recorded in connection with the company's information security and for system analysis purposes. Such information may also be used in aggregate form to perform an overall analysis of the use and performance of the ECIT website.

1.3.2 Cookies

When you browse our websites, cookies are often stored on your computer or device. Cookies allow our websites to recognize your computer or device and serve various purposes.

Some of our websites will display a notification bar that allows you to accept or decline cookies. Below is a summary of the types of cookies our websites use and how your acceptance may affect your experience of certain features of the websites:

    • Necessary cookies: These cookies are essential to enable users to navigate the site and use certain features, such as logging in. These cookies cannot be disabled, as the site would not function without them.
    • Performance measurement cookies: These cookies collect data to measure and improve website performance and functionality.
    • Functionality cookies: Functionality cookies serve the purpose of remembering the settings a user has selected to affect the appearance or functionality of the website. You can opt out of such cookies, but this may affect your user experience of the website and you may have to repeat certain choices each time you visit the site.
    • Marketing cookies: Marketing cookies are used to deliver content tailored to your interests, reduce repetition in the display of advertising content, and to measure the effectiveness of promotional and advertising content. If you do not accept marketing cookies, your computer or device will not be measured for marketing purposes.

You can control whether cookies (other than strictly necessary cookies) are accepted using the cookie banner or by setting your browser to not allow cookies. Such settings can often be found under “Tools” or “Preferences”.

Although most browsers accept cookies, you can choose whether or not to accept them by configuring your browser settings. You can also delete cookies from your device at any time. However, please note that if you do not accept cookies, some features of the website may not be available.

More information about managing cookies can be found in your browser under "Help" or on a page such as www.allaboutcookies.org.

Below is a list of the cookies we use on our website:

Purpose Description Type/Expires
Browser performance Our websites are built on a common foundation and have embedded cookies to simplify interoperability (e.g., identify what type of browser is being used) and to improve performance (e.g., by faster content downloads). SessionDeleted when browser is closed
Security (e.g. Asp.NET cookies) If you log in to a restricted website, cookies will ensure that your device is logged in for the duration of your visit to that restricted website. You will need to log in with your ID and password. SessionDeleted when browser is closed
Web settings Our cookies will also recognize your website preferences (e.g. language) and/or seek to improve your experience (e.g. with personalized greetings or content). This applies to those websites where you have registered for special access or created an account. SessionDeleted when browser is closed
Diagnostic tool We use third-party analytics tools to analyze how visitors use the company's website. In this way, we strive to improve the quality and content of the website. Analytics information includes information about the number of visitors and referrals to the website. See further explanations of ECIT's use of Google Analytics below. Persistent, but will be automatically deleted after two years if you no longer use the ECIT.is site.
User feedback ECIT uses a third-party survey tool to invite a certain portion of its users to provide feedback. Cookies are used to prevent users from being repeatedly invited to participate in such surveys. The first cookie (1) is set if a visitor to an ECIT website is not invited to participate in a survey of the user experience of the website and is used to ensure that visitors are not invited to participate after visiting the website for the first time. The second cookie (2) is set if a user of the website is invited to participate in a survey of the user experience of the website and is used to ensure that the user is not invited to participate again within a 90-day period. 1 Usage cycle.
Deleted when browser is closed.2 Persistent.
Automatically deleted after 90 days or after a site user is invited to participate in an experience review.
Sharing content on social media We use action buttons and other third-party social media links to enable you to share content from the Company's website on social media or via email. The use of such links may include the placement of cookies on your device to facilitate your use of the service, ensure that sharing appears on our pages (e.g., updating the number of shares on social media), and to record information about your actions online and on the Company's website. We encourage you to carefully review the privacy policy of each social media platform before using it. See more information about our use of social media below. Persistent, but will be automatically deleted after two years if you no longer use the ECIT.is site.
Marketing Some ECIT websites use third-party services to analyze website traffic, measure ad performance, and serve personalized ads to visitors, such as Google Analytics and Facebook Pixel, which collect information anonymously to analyze website usage. ECIT may also use the remarketing systems of these third parties to serve ads to users. Persistent, but automatically deleted after 180 days.

Other third-party software may be used on certain pages of our website from time to time to ensure functionality. Typically, these tools will place a cookie on your device to facilitate your use of them and to ensure that communications are displayed correctly on the company's websites.

The cookies themselves do not reveal your email address or otherwise identify you. Other identifying factors, such as IP addresses, will be used in analytics reports. These are only intended to identify the number of unique visitors to our website and the geographic origin of web traffic, and not to identify individual users.

1.3.3 Google Analytics

ECIT uses the analytics tool Google Analytics. More information about how Google Analytics is used by ECIT can be found here: http://www.google.com/analytics/learn/privacy.html

To better enable website users to control the collection of data about them through Google Analytics, Google has developed certain extensions called Google Analytics Opt-out Browser Add-onThese add-ons send a message to the Google Analytics JavaScript (ga.js) that information about a website visit should not be sent to Google Analytics. The add-on in question does not prevent information from being sent to the website itself or to other service providers that analyze website traffic.

1.3.4 Web sensors ("Web beacons")

A web beacon is a small image file on a website that allows certain information to be collected from your computer, such as your IP address, when the website content was viewed, which web browser was used, and the presence of cookies previously set by the same server. ECIT only uses web beacons in accordance with applicable laws.

ECIT or its service providers use web beacons to measure the effectiveness of third-party websites that provide human resources or marketing services to the company, compile information about web traffic, or manage cookies.

You can disable certain web beacons by rejecting the use of the cookies they include. The web beacon may still record your visit to the website, without authentication, based on your IP address, but information from the cookie will not be recorded.

In some ECIT newsletters and other company communications, the recipient's responses will be monitored, for example, opening emails through links in the email. ECIT collects this information to measure user interest and to improve future experiences.

1.3.5 Tool for recording geographical position

ECIT will collect and use the geographic location of your computer or smart device. This location information is collected for the purpose of providing you with more targeted and better information about services that may appeal to you based on your geographic location, and also to improve local products and services.

1.4 Social media

ECIT websites generally allow users to share content through social media platforms operated by third parties, for example, with the “Like” button on Facebook and on X. These social media platforms collect and use information about your use of ECIT websites, cf. the discussion of cookies above. Personal information that you provide through such social media platforms may be collected and used by other parties on that social media platform. Such actions are subject to the privacy policies of the companies operating the relevant platform. We have no control over, nor are we responsible for, these companies or their use of your personal information.

In addition, ECIT websites may host blogs or other forums for discussion or services, for the purpose of facilitating the sharing of knowledge and content. If you provide personal information on any such social media platform operated by ECIT, it will generally, unless specifically stated otherwise, be shared with other users of the platform, over whom we often have no or very limited control.

1.5 Children

ECIT recognizes the importance of protecting children's privacy, especially when using the World Wide Web. Our websites are not designed for or directed to children under the age of 13. It is our policy not to knowingly collect or maintain any information about children under the age of 13, except to the extent necessary to provide a specific service.

2. Sharing and transferring personal data

2.1 Transfer of data between ECIT members

We share your information with other ECIT member companies in the event of multinational projects. The company also shares information with ECIT AS and other member companies to the extent necessary or desirable in order to comply with the requirements of laws and government regulations in each country. Other ECIT entities also provide various services, such as hosting and maintenance of IT systems, certain types of insurance for member companies and their customers, conflict of interest assessments, money laundering checks, assistance in providing services to customers and other things that may be necessary for the operation of ECIT.

2.2 Transfer of data to third parties

We do not share personal information with any third party unless this is necessary for our legitimate business or professional interests, in order to carry out your instructions, and/or where permitted or required by law or professional rules. See the appendix below.

In addition, ECIT may transfer certain personal information outside the EEA to affiliated companies or parties that perform services on behalf of the company, in accordance with the purposes described in this privacy statement. ECIT may also store personal information outside the EEA. To the extent such transfer or storage of data may occur, your information will continue to be fully protected as provided for in applicable Icelandic data protection legislation. ECIT will not provide your personal information to third parties for their marketing purposes.

3. Freedom of choice

In general, you are not required to provide ECIT with any personal information. However, the Company requests that you provide certain personal information if you wish to receive further information about the Company's services or events. ECIT may also request your consent for certain uses of your personal information, which you may either accept or decline. If you register for a particular service or communication, such as a newsletter, you may unsubscribe at any time by following the instructions provided in any such communication. If you decide to unsubscribe from a particular service or communication, we will endeavour to remove all information about you as soon as possible. However, further information from you may be required before your request can be processed.

As described in the discussion of cookies above, you can prevent cookies from being used to track your use of the website. You can do this by changing the settings in your web browser, either to reject all cookies or to inform you when a cookie is being used. However, we would like to point out that the functionality of some parts of our websites may be impaired if you choose to reject cookies.

4. Your right

If ECIT processes your personal data, your rights are as follows:

    • Accessibility and correction: You have the right to request access to your data. If we are obliged to provide you with your personal data, this will be done free of charge. Before such provision takes place, we may request identification from you and sufficient details of your interactions with the company to enable us to identify the requested personal data. If our information about you is incorrect, you have the right to request that we correct your personal data.
    • Right to object to processing: You have the right to object to us processing your personal information if we are no longer authorised to use it.
    • Other rights: In addition, you may have the right to request that information about you be deleted if we store the data in question for too long, to request a restriction of its processing in certain cases, and/or to receive a copy of the information we store in electronic form.

You can submit a request or exercise these rights by contacting ECIT at the following email address: ecit@ecit.is and your complaint will be reviewed and an effort will be made to resolve it within one month of receipt. In cases where the complaint is complex or the volume of inquiries is high, you will be notified if resolution will take longer than one month. In such cases, an effort will be made to resolve the complaint within three months of the initial receipt of the complaint.

5. Data security and integrity

ECIT has established a security policy and procedures for the protection and storage of personal information to prevent its loss, misuse, unauthorized alteration or destruction. Despite ECIT's utmost measures, however, it is never possible to protect against all security threats. As far as possible, access to your personal information is limited to those who need to work with the data. Those individuals who have access to the data in question are required to maintain the confidentiality of such information.

We also strive to retain personal data only for as long as (i) the information in question is necessary to comply with an individual's request, (ii) it is necessary for legal, regulatory, internal procedural or operational purposes, or (iii) the data subject has not requested the deletion of the data. However, the retention period of data always depends on the nature of the data and the purpose of the processing.

6. Links to other websites

Please note that ECIT websites often contain links to other websites, including websites operated by other ECIT companies, which are not subject to the terms of this Privacy Statement, but to other privacy statements that may contain slightly different terms. We encourage users of our website to familiarize themselves with the content of the privacy policy of each website they visit before providing any personal information.

By registering on any ECIT website worldwide and moving from there to another ECIT website, without completely logging out of the previous website, you consent to the use and processing of your personal information in accordance with the privacy statement of the ECIT website you are visiting.

7. Changes to the Privacy Statement

ECIT may change the content of this Privacy Statement from time to time in line with changing priorities. When this is done, the date of this document will be updated accordingly. We will inform you of changes to the processing of personal data, as defined in this Privacy Statement, that will affect you, through appropriate communication channels, taking into account the way in which we generally communicate with you.

8. Questions related to privacy policy and its implementation

If you have any questions or comments regarding the handling of your personal information by ECIT or the implementation of this Privacy Policy, please contact ECIT's Privacy Officer via email. ecit@ecit.isECIT's Data Protection Officer is Rósa Kristín Stefánsdóttir.

If you feel that you are not receiving a satisfactory resolution to your issues from ECIT, you are always entitled to file a complaint with the Icelandic Data Protection Authority, www.personuvernd.is

1 “ECIT,” “we,” “us,” and “our” refers to ECIT Bókað ehf. and ECIT Virtus ehf., which is a member of ECIT AS, a Norwegian limited liability company, and/or one or more independent companies that are members of the ECIT global network. ECIT AS itself does not provide any services to customers.

Appendix

Data transfer to third parties

ECIT does not share personal information with any third party unless this is necessary for the legitimate business or professional interests of the company, in order to carry out your instructions, and/or where this is permitted or required by law or professional rules. This includes:

    • Our service providers: It may be necessary to transfer your personal information to service providers such as parties that service ECIT's information systems, hosting providers, commercial banks, consultants (including legal advisors) and other vendors of goods and services. ECIT cooperates with such parties in order for them to process your personal information on our behalf. ECIT will only transfer your personal information to such parties provided that they meet strict requirements regarding the security and processing of personal information. We only share that personal information to the extent necessary to provide the relevant service.
    • Reorganization or sale of the company: ECIT would likely disclose personal information in connection with a potential sale, assignment, or other transfer of ownership of the part of the business to which the information relates.

    • Courts, law enforcement and regulatory authorities: ECIT will share personal information in connection with the requirements of courts, law enforcement or regulatory authorities, or where it is deemed appropriate and necessary to comply with the provisions of law, court orders, government regulations or orders.
    • Security audits: The disclosure of personal information is necessary in connection with internal information security audits and computer audits and/or in connection with research interests or in response to a complaint or security threat.
    • Insurers: Due to professional rules and the nature of its operations, ECIT has operational insurance coverage. This requirement is in place to enable each ECIT member to cover the costs associated with claims that may be made for alleged failures to provide services to clients. The arrangement of such insurance requires the involvement of various parties in the insurance market, such as brokers, insurers and reinsurers, as well as professional advisors to such parties and other third parties involved in the processing of claims. In some cases, such parties may request access to your personal information. In such cases, the information would be used by those parties involved in the company's insurance, to the extent that there is a claim relating to you, and to enable the parties to fulfil their obligations under law and government regulations. Some of the above parties will process this information on our behalf, such as the service providers described above, while others will choose to process information about you without our involvement.