GDPR Compliance Statement

Effective Date: January 1, 2023

Our commitment

KrkBoat is fully committed to compliance with the EU General Data Protection Regulation (GDPR) and Croatian personal data protection laws. All personal data is processed lawfully, transparently, and securely.

Data We Collect

We process the following types of personal data:

  • Identification Data: We need your data to fulfill booking contracts

  • Booking Data: Excursion details, passenger count, dietary needs, special requests

  • Payment Data: Billing information (not credit card numbers—processed by secure payment providers)

  • Technical Data: IP address, browser type, device info

  • Usage Data: Pages visited, booking searches, feature usage

Legal Basis for Processing

  • Contractual Necessity: We need your data to fulfill booking contracts

  • Legitimate Interests: Improve services, detect fraud, conduct analytics

  • Consent: Marketing emails (you may opt out any time)

  • Legal Obligation: Tax, accounting, safety regulations

Data Protection Officer (DPO)

Questions about privacy: [email protected]

Contact our DPO

Email: [email protected]

User Right Under GDPR

Right of access to personal data

Right of correction or rectification

Right of erasure (right to be forgotten)

Right of data portability

Right to restrict processing

Right to object to processing

Right to lodge complaints with supervisory authority

Right to withdraw consent at any time

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify affected individuals and supervisory authorities within 72 hours as required by GDPR Article 33 and 34.

International Data Transfers

Data is primarily stored within the EU. If transferred outside the EU, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions to ensure GDPR-level protection.

Supervisory Authority

Croatian Personal Data Protection Authority

Website: azop.hr

You have the right to lodge a complaint with the supervisory authority if you believe your data protection rights have been violated.

Regular Compliance Reviews

We conduct regular reviews of our data protection practices to ensure ongoing GDPR compliance:

Annual privacy policy audits

Quarterly security assessments

Ongoing staff training on data protection

Regular updates to processing records

Contact for GDPR Questions

For any questions about our GDPR compliance or to exercise your data protection rights:

Email: [email protected]

Phone: +385 51 XXX XXX