Privacy Policy
Last updated: January 24, 2026
Effective Date: February 1, 2026
GDPR Compliant
Introduction & Data Controller
KrkBoat Ltd. ("we," "us," "our") is the data controller responsible for your personal data. Our data protection officer can be contacted at: [email protected]
Types of Data Collected
We collect:
Booking data: Name, email, phone (optional), date of birth, nationality
Payment data: Credit card info (processed via secure payment provider; we don't store full card details)
Communication data: Messages sent via contact forms
Technical data: IP address, browser type, pages visited, cookies
Profile data: Account preferences, language settings, interests
Photo data: Guest photos from trips (with consent)
Purposes of Data Collection
Data used for:
Processing bookings and sending confirmations
Trip reminders and updates
Payment processing
Customer support
Marketing (if opted-in)
Safety & compliance
Legal obligations
Legal Basis for Processing
Contract performance: Bookings and trip delivery
Consent: Marketing communications
Legitimate interest: Service improvement
Legal obligation: Safety records and compliance
Data Sharing & Third Parties
Booking data retained for 7 years (legal requirement)
Account data retained until deletion or account closure
Marketing data retained until unsubscribe
Payment records retained per legal requirements
Data Retention
Booking data retained for 7 years (legal requirement)
Account data retained until deletion or account closure
Marketing data retained until unsubscribe
Payment records retained per legal requirements
Your Data Rights (GDPR)
You have the rights to
Right of access: Request copy of your data
Right of correction: Update inaccurate data
Right of erasure: Request deletion (with exceptions)
Right of portability: Receive data in machine-readable format
Right to restrict processing
Right to object to marketing
To exercise rights, contact: [email protected]
Children's Privacy
Services not intended for under-13 without parental consent. We don't knowingly collect data from children under 13. If discovered, data deleted immediately.
Security Measures
SSL encryption
Secure payment gateways
Access controls
Regular security audits
Staff training
Data backup
Contact & Complaints
Questions about privacy: [email protected]
Complaints may be filed with the Croatian Data Protection Authority.
