GDPR Compliance Statement
Effective Date: January 1, 2023
Our commitment
KrkBoat is fully committed to compliance with the EU General Data Protection Regulation (GDPR) and Croatian personal data protection laws. All personal data is processed lawfully, transparently, and securely.
Data We Collect
We process the following types of personal data:
Identification Data: We need your data to fulfill booking contracts
Booking Data: Excursion details, passenger count, dietary needs, special requests
Payment Data: Billing information (not credit card numbers—processed by secure payment providers)
Technical Data: IP address, browser type, device info
Usage Data: Pages visited, booking searches, feature usage
Legal Basis for Processing
Contractual Necessity: We need your data to fulfill booking contracts
Legitimate Interests: Improve services, detect fraud, conduct analytics
Consent: Marketing emails (you may opt out any time)
Legal Obligation: Tax, accounting, safety regulations
Data Protection Officer (DPO)
Questions about privacy: [email protected]
Contact our DPO
Email: [email protected]
User Right Under GDPR
Right of access to personal data
Right of correction or rectification
Right of erasure (right to be forgotten)
Right of data portability
Right to restrict processing
Right to object to processing
Right to lodge complaints with supervisory authority
Right to withdraw consent at any time
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify affected individuals and supervisory authorities within 72 hours as required by GDPR Article 33 and 34.
International Data Transfers
Data is primarily stored within the EU. If transferred outside the EU, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions to ensure GDPR-level protection.
Supervisory Authority
Croatian Personal Data Protection Authority
Website: azop.hr
You have the right to lodge a complaint with the supervisory authority if you believe your data protection rights have been violated.
Regular Compliance Reviews
We conduct regular reviews of our data protection practices to ensure ongoing GDPR compliance:
Annual privacy policy audits
Quarterly security assessments
Ongoing staff training on data protection
Regular updates to processing records
Contact for GDPR Questions
For any questions about our GDPR compliance or to exercise your data protection rights:
Email: [email protected]
Phone: +385 51 XXX XXX
