Rudan
Privacy Policy

Privacy Policy

DATA CONTROLLER

Rudan d.o.o. 9. rujan 1/H 52341 Žminj Croatia OIB: 84430586938 Tel. +385 52 845 500 E-mail: privatnost@rudan.com Website: www.rudan.com

TOURISM FACILITIES OPERATED BY THE DATA CONTROLLER

Family Hotel Pagus, Pag – www.hotel-pagus.hr Ville Arausana & Antonina, Vodice – www.arausana-antonina.com Hotel Villa Radin, Vodice – www.hotelvillaradin.com Campsite Almissa, Omiš – www.campingalmissa.com Campsite and Hotel Terme Jezerčica, Donja Stubica – www.terme-jezercica.hr Family Hotel Adria, Biograd na Moru – www.hoteladria.hr Holiday Village Sagitta, Lokva Rogoznica – www.sagitta.hr Hotel Nestos, Dugi Rat – www.hotelnestos.com Separate business entities under majority ownership and management of the controller Hoteli Vodice d.d., Grgura Ninskog 1, 22211 Vodice, OIB: 94858559872 Hotel Punta – www.hotelivodice.hr Pine Beach d.d., 9. rujan 1/H, 52341 Žminj, OIB: 39508009387 Pine Beach Resort, Pakoštane – www.pinebeach.hr Angelo d’Oro Heritage Hotel, Rovinj – www.angelodoro.com Facility operated under lease Villa Arausa, Vodice – www.hotelivodice.hr Facilities where the controller manages sales and marketing Punta Longa d.o.o., Kruge 46/A, 10000 Zagreb, OIB: 41070360282 Family Hotel La Luna, Pag – www.laluna.hr Terra Park d.o.o., Primorska 8, 53291 Novalja, OIB: 80944645955 Terra Park Spiritos, Pag – www.terrapark.hr Terra Park Phalaris, Pag – www.terrapark.hr

DATA PROTECTION OFFICER

The Data Controller has appointed a Data Protection Officer (DPO), who can be contacted at any time via e-mail at privatnost@rudan.com or by post at the Controller’s registered address for any matters relating to personal data protection and the exercise of rights under the GDPR.

The Data Controller respects the privacy of all individuals whose personal data are processed (hereinafter: the Data Subject) and is committed to safeguarding personal data. This Privacy Policy provides information on what personal data are collected, for what purposes, how they are protected, and what rights Data Subjects have.

Personal data are processed in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), the Croatian Act on the Implementation of the GDPR (OG 42/2018), and other applicable regulations of the Republic of Croatia.

SCOPE OF APPLICATION

This Privacy Policy applies to all personal data processing activities carried out by the Data Controller. The Data Controller processes personal data relating to the following categories of Data Subjects:

  • employees of the Data Controller and members of their families (children),
  • prospective employees of the Data Controller,
  • business partners of the Data Controller and their employees,
  • customers and users of the Data Controller’s services,
  • guests staying at the Data Controller’s tourism facilities,
  • pupils and students who have entered into a contractual relationship with the Data Controller.

PRINCIPLES RELATING TO THE PROCESSING OF PERSONAL DATA

We process personal data exclusively in accordance with the General Data Protection Regulation. Accordingly, personal data must be processed in line with the following principles (Article 5 of the Regulation):

  • processed lawfully, fairly and transparently in relation to the Data Subject (“lawfulness, fairness and transparency”);
  • collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, in accordance with Article 89(1), shall not be considered incompatible with the initial purposes (“purpose limitation”);
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
  • accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);
  • kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods where they are processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, in accordance with Article 89(1), subject to the implementation of appropriate technical and organisational measures required by the Regulation in order to safeguard the rights and freedoms of the Data Subject (“storage limitation”);
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by applying appropriate technical or organisational measures (“integrity and confidentiality”).

LAWFULNESS OF PERSONAL DATA PROCESSING

Special attention must be given to the lawfulness of processing. Processing is lawful only if and to the extent that at least one of the following conditions is met (Article 6 of the Regulation):

  • the Data Subject has given consent to the processing of his or her personal data for one or more specific purposes;
  • processing is necessary for the performance of a contract to which the Data Subject is party, or in order to take steps at the request of the Data Subject prior to entering into a contract;
  • processing is necessary for compliance with a legal obligation to which the Controller is subject;
  • processing is necessary in order to protect the vital interests of the Data Subject or of another natural person;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
  • processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require the protection of personal data, in particular where the Data Subject is a child. The legitimate interests of the Controller may constitute a legal basis for processing, provided that the interests or fundamental rights and freedoms of the Data Subject do not take precedence, taking into account the reasonable expectations of the Data Subject based on his or her relationship with the Controller. Such a legitimate interest may exist, for example, where there is a relevant and appropriate relationship between the Data Subject and the Controller, such as in situations where the Data Subject is a client of the Controller or is in the Controller’s service.

RIGHTS OF THE DATA SUBJECT

In the course of its regular business activities, the Controller enables Data Subjects to exercise all their rights relating to the processing of personal data. In addition, the Data Subject may submit a request to exercise their rights directly to the Controller or by sending it to the e-mail address of the Data Protection Officer.

The rights of the Data Subject include:

Right of access – The Data Subject has the right to obtain confirmation from the Controller as to whether personal data concerning him or her are being processed, and must be provided with access to such personal data.

Right to rectification – The Data Subject has the right to obtain from the Controller, without undue delay, the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the Data Subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Right to erasure (“right to be forgotten”) – The Data Subject has the right to obtain from the Controller the erasure of personal data concerning him or her, and the Controller is obliged to erase such personal data without undue delay, unless there is a justified reason for retaining them, such as a legal obligation of the Controller.

Right to restriction of processing – The Data Subject has the right to obtain from the Controller the restriction of processing where the conditions set out in Article 18 of the Regulation are met.

Right to data portability – The Data Subject has the right to receive the personal data concerning him or her, which he or she has provided to the Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another Controller without hindrance from the Controller to which the personal data were provided.

Right to object – The Data Subject has the right, on grounds relating to his or her particular situation, to object at any time to the processing of personal data concerning him or her, in accordance with Article 6(1)(e) or (f), including profiling based on those provisions (see Lawfulness of Processing).

Automated individual decision-making, including profiling – The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

CATEGORIES OF PERSONAL DATA PROCESSED

As a rule, the Controller processes personal data of Data Subjects that the Data Subjects provide themselves, for the purposes and to the extent necessary for the fulfilment of their legal and contractual obligations. On the basis of legitimate interest, the Controller processes personal data of Data Subjects provided that the interests or fundamental rights and freedoms of the Data Subjects do not override such interest, taking into account the reasonable expectations of the Data Subjects based on their relationship with the Controller.

The Controller does not process special categories of personal data unless this is necessary for the purpose of processing and unless the conditions set out in Article 9 of the Regulation are met. The Controller processes employees’ data that fall within special categories of personal data, such as data concerning trade union membership, for example when exercising specific rights under relevant regulations; religious or philosophical beliefs, for example when exercising the right to additional non-working days for religious holidays, where the individual has voluntarily disclosed such data for that purpose; or data concerning health, for example in accordance with specific occupational health and safety regulations, for the purpose of keeping employee records, or where specific health certificates are required for certain positions.

Where necessary, the Controller also processes personal data relating to criminal convictions and offences, such as certificates of no criminal record for employees.

DISCLOSURE OF DATA TO THIRD PARTIES

The Controller shares personal data with third parties only where this is permitted.

In fulfilling its legal obligations, the Controller is required to disclose certain data to third parties. This includes, for example, submitting guest data through the eVisitor system and providing employee data to the competent authorities and institutions, such as the Croatian Pension Insurance Institute, the Croatian Health Insurance Fund, the Tax Administration, the Central Registry of Affiliates, and pension companies.

In certain cases, the Controller is also required to provide or make available employment-related data to the Croatian Employment Service, for example for the purpose of including employees in active employment policy measures; to competent police stations or the ministry responsible for internal affairs, for example in the case of stays of high-ranking state officials at the Controller’s facilities or for the purpose of issuing work permits; to the ministry responsible for tourism in the case of employing scholarship holders; to the ministry responsible for economy and entrepreneurship in cases involving the use of investment incentives; to insurance companies, banks, and in other cases where required by applicable regulations.

Certain employee data are also provided to banks or pension funds in connection with salary payments, and data may also be disclosed to creditors in accordance with enforcement regulations. In some cases, data are disclosed due to contractual obligations, for example where data relating to students completing internships are exchanged with schools or faculties.

Certain personal data are also disclosed to business entities for the purpose of providing specific services, such as occupational health examinations for employees, to institutions that organise legally required training, including occupational health and safety, minimum hygiene standards and toxicology training, or to audit firms when conducting mandatory audits. Data may also be disclosed to notaries public when certification is required, to the Financial Agency for the purpose of obtaining business certificates, to public procurement entities when the Controller participates in public procurement procedures, and for the purpose of issuing and using company cards, company mobile devices or fuel cards.

Data may also be disclosed to business entities acting as processors, which process personal data on behalf of the Controller. These are most commonly the Controller’s business partners providing IT services, who store the data in their databases or may have access to personal data until the processing is completed. Data Processing Agreements are concluded with such entities, defining their powers and obligations in relation to the processing of personal data, in accordance with the requirements of the Regulation.

In certain situations, external entities may jointly determine the purposes and means of processing personal data together with the Controller. In such cases, those external partners and the Controller act as joint controllers. In these relationships, the joint controllers transparently determine their respective responsibilities for compliance with the obligations under the Regulation, particularly with regard to the exercise of Data Subjects’ rights and their duties to ensure transparent processing, unless such responsibilities are determined by law.

A specific case of data disclosure to third parties arises from the fact that the Controller has concluded business management agreements with companies under which it manages the tourism segment of their operations. This means that, in certain cases, the Controller’s guests may receive offers from the Controller containing information about other hotels and properties managed by the Controller. In addition, based on such business management agreements, the Controller has certain rights and obligations relating to human resources. In these cases, the Controller has the right to process personal data of the Data Subjects of those companies. All principles set out in this Policy also apply to the Data Subjects of those companies in the areas in which the Controller is involved; however, those companies are also responsible as Controllers for their own processing of the Data Subjects’ personal data.

Where data processing involves the transfer of personal data to third countries, the Controller ensures compliance with high standards of protection in order to maintain the highest possible level of personal data protection, in accordance with the strict requirements of the Regulation. In this respect, where international transfers of personal data apply, the Controller will inform the Data Subject of its intention to transfer personal data to a third country or international organisation, as well as of the existence or absence of an adequacy decision by the European Commission. Any transfer of personal data to third countries shall be carried out in accordance with Chapter V of the Regulation.

RETENTION PERIOD FOR PERSONAL DATA

The personal data of Data Subjects are processed and retained in accordance with applicable legal regulations where a retention obligation is prescribed by law. For example, employees’ personal data and payroll-related data are retained in accordance with the Ordinance on the Content and Method of Keeping Employee Records by Employers and other applicable regulations, while accounting documents on the basis of which data have been entered into the journal, general ledger and subsidiary ledgers are retained for eleven years.

In situations where the Controller is authorised to determine the applicable retention periods independently, personal data are retained only for as long as necessary for the purposes for which they are processed.

SOURCES OF PERSONAL DATA

The Controller most commonly collects personal data directly from the Data Subject. When providing personal data in any manner, such as when booking accommodation, applying for employment, or otherwise, the Data Subject is responsible for the accuracy of the data provided and agrees that the Controller may use and collect such data in accordance with applicable regulations and the terms of this Privacy Policy.

In addition, the Controller may also obtain the Data Subject’s personal data from other natural or legal persons, for example from travel agencies that forward guest data for accommodation purposes, from guests who book accommodation for persons who will stay with them at the properties, or from employment agencies and agencies providing temporary agency workers.

DATA PROTECTION MEASURES

Taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, as well as the risks arising from data processing, the Controller implements appropriate technical and organisational measures to protect personal data.

HANDLING PERSONAL DATA BREACHES

The Controller ensures that, in the event of a personal data breach, it will notify the competent supervisory authority and/or the Data Subjects of the breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of individuals.

STAYS AT THE CONTROLLER’S TOURIST FACILITIES

The Controller collects and processes personal data of Data Subjects who are guests at the Controller’s tourist facilities for various purposes, with the ultimate aim of providing high-quality accommodation and related services in accordance with the highest standards applicable to tourism companies.

The personal data that you are required to provide in order for the accommodation service to be provided are stored by the Controller in its database for the purpose of performing the accommodation contract and fulfilling legal obligations related to hospitality activities. If you do not provide the Controller with the minimum data required for making a reservation and, during your stay, for registration with all competent registers, the Controller will not be able to provide you with the accommodation reservation service or the accommodation service in accordance with the contract and the law.

Certain data are necessary in order to take steps at the request of the Data Subject prior to entering into an accommodation contract. For example, before a reservation is made, and upon the enquiry of potential guests, accommodation offers are sent, for which the Controller requires personal data, such as name and surname and e-mail address, in order to send the offer.

The personal data collected by the Controller when making an accommodation reservation, whether via the website, by telephone or by accepting an offer by e-mail, for the purpose of fulfilling the reservation obligation, include:

  • name and surname of the reservation holder;
  • country;
  • name of the property;
  • date of birth;
  • number, type and place of issue of the identification document;
  • citizenship;
  • accommodation unit number and type of accommodation unit/room type;
  • arrival and departure date;
  • number of persons for whom accommodation is being reserved and room allocation;
  • information on which persons are minors. Depending on the specific request of the person making the reservation, other data may also be collected, such as:
  • e-mail address;
  • language of communication;
  • telephone number;
  • payment method;
  • any additional data necessary for carrying out transactions or securing payment. In the event of cancellation of a reservation, we are required to retain your data for the purpose of proving the reservation and/or its cancellation.

Upon arrival at the property, guests are generally registered at the reception desk, and their data are entered into the guest database, from which the data are submitted to the eVisitor system, a unified online information system for guest check-in and check-out, in order to comply with the Controller’s legal obligations.

The data collected include:

  • name and surname;
  • place, country and date of birth;
  • citizenship;
  • number and type of identification document;
  • place of residence/stay and address;
  • date and time of arrival at and departure from the property;
  • gender;
  • basis for exemption from payment of the tourist tax or reduction of the tourist tax. The above data are processed by tourist boards and public authorities of the Republic of Croatia for the following lawful purposes:
  • monitoring compliance with the obligation of accommodation providers to check in and check out tourists;
  • recording, calculating and collecting the tourist tax;
  • maintaining a guest book or guest list by accommodation providers and monitoring compliance with this obligation by inspection authorities;
  • registering foreign nationals with the ministry responsible for internal affairs and monitoring compliance with this obligation by inspection authorities;
  • maintaining tourist records by tourist boards, as well as statistical processing and reporting;
  • supervising the business operations of accommodation providers in relation to the lawfulness of their activities, the provision of registered services, and compliance with tax and other public levy regulations. Since it is prescribed that guest registration data must be entered on the basis of data from an identity card, passport or another identification document, the guest is required to present such a document to the Controller and provide any other information necessary for entering the data that is not contained in such document.

For the purpose of entering data from an identity card or other appropriate document, the Controller may use a scanner. In such case, the image of the document is not stored; only the necessary data are extracted from the document and stored in accordance with the purpose of processing.

Other data related to the circumstances of the guest’s stay, such as method of travel, travel companions, marital status, number of children, pets and other interests, may also be collected and processed during the stay where they are directly related to the provision of the accommodation service.

Before, during and after the stay, the Controller has the right, on the basis of legitimate interest, to send you, as a guest, so-called service messages by e-mail, including reservation confirmations, stay reminders and other notifications closely related to the specific stay you have reserved.

In addition, during and after the stay, the Controller has the right, on the basis of legitimate interest, to send you, as a guest, satisfaction questionnaires by e-mail, SMS and/or instant messaging services such as Viber, WhatsApp and similar, which it may process itself or through its partners. The primary purpose of satisfaction questionnaires is to collect information about the service in the Controller’s legitimate interest of improving the service. The Controller may also depersonalise the data from such questionnaires and process them for statistical purposes.

The Controller has the right, on the basis of legitimate interest, to collect certain data and use them for direct marketing purposes.

JOB APPLICANTS AND EMPLOYEES

The Controller is the employer of a large number of individuals and processes personal data in connection with employment. In this context, Data Subjects include current and former employees, prospective employees, trainees and apprentices, persons undergoing professional training, students working under student contracts, scholarship holders, and other persons whose data are processed within the scope of employment-related and similar relationships.

As a prospective employer, the Controller collects, processes and stores the personal data of job applicants in its candidate database on the basis of their voluntary application, in the following ways:

  • by submitting an application through the online application form;
  • by applying via e-mail;
  • by attending organised auditions and completing application forms;
  • in another manner. The data generally collected include: name, surname, date of birth, address, citizenship, personal identification number, mobile phone number, e-mail address for contact purposes, gender, level of education, language skills and preferred method of communication.

The Controller may receive candidate data indirectly, from domestic and foreign employment agencies, in which case such agencies are obliged to inform candidates about the processing of their personal data by the Controller.

Candidates submit their job applications:

  • as open applications, in which case we process the data for the purpose of contacting candidates in connection with employment for a period of five years;
  • as applications for specific job vacancies with a stated closing date, in which case we process the data until the end of the recruitment process. Where candidates applying for a specific job vacancy with a stated closing date give separate consent, we process their data for the purpose of contacting them in connection with employment for a period of five years, for the purposes of potential future job vacancies.

EMPLOYMENT AND OTHER COMPARABLE RELATIONSHIPS

As an employer, the Controller processes employees’ personal data in an employee database maintained in an IT system, as well as in physical employee files. Data are collected in accordance with the Labour Act, the Ordinance on the Content and Method of Keeping Employee Records, the Ordinance on the Content of Salary, Salary Compensation, Severance Pay and Compensation for Unused Annual Leave Calculations, and other legal acts regulating employment relationships.

The following personal data of employees are collected and processed:

  • name and surname;
  • personal identification number;
  • gender;
  • date of birth;
  • place of birth;
  • country of birth;
  • citizenship;
  • address of permanent/temporary residence;
  • telephone/mobile phone number;
  • e-mail address;
  • level of education;
  • occupation;
  • data on completed education and professional training, including copies of diplomas and certificates;
  • data on pensionable service;
  • place/municipality of work;
  • agreed working hours;
  • job position;
  • date of employment;
  • insured person number with the Croatian Pension Insurance Institute and the Croatian Health Insurance Fund;
  • salary payment account number/IBAN;
  • protected account number/IBAN, if the employee has one;
  • data on participation in the second pension pillar;
  • personal allowance data from the tax card;
  • data on children and dependent family members;
  • birth certificate if the child is under 15 years of age;
  • data on salary deductions;
  • access card number;
  • data on medical examinations for employees working in positions with special working conditions;
  • trade union membership;
  • data on work permits, if the employee is a foreign national;
  • assessments, performance evaluations and warnings;
  • date of termination of employment;
  • reason for termination of employment;
  • job application and CV;
  • results of medical and psychological examinations carried out during the selection process for the job position, if conducted. The data generally required for concluding student or pupil work contracts include:
  • a certificate from the faculty for the current year as proof of student status or a copy of the student record book showing enrolment in the current year;
  • data from the identity card, with the identity card presented for inspection;
  • certificate/card issued by the Student Centre;
  • personal identification number;
  • account IBAN for the payment of tips, if received by the worker. The data generally required for concluding internship agreements include:
  • the agreement with the school attended by the pupil;
  • the referral document by which the pupil is assigned to the internship;
  • data from the identity card, with the identity card presented for inspection;
  • personal identification number;
  • account IBAN for the payment of tips, if received by the pupil. In addition to the above data, the Controller may also keep in the employee’s file other data collected during the recruitment process, as well as other data collected during the employment relationship as defined by internal regulations, such as awards, warnings, certificates and similar documents.

All employee data are stored in the employee database from the date of commencement of employment and are kept up to date until the termination of employment. Such data are retained as documentation of permanent value in accordance with relevant regulations.

The Controller also keeps data in its database relating to other persons in a business relationship comparable to an employment relationship, as well as persons undergoing internships or professional training. Such data are recorded from the start of work, kept up to date until the end of the relevant engagement, and retained in accordance with applicable regulations.

A special category includes data relating to pupils undertaking internships, who may be minors. Particular care is taken in relation to such data, which are collected and retained in accordance with special regulations and with the approval of the school and the parents.

BUSINESS PARTNERS

In the course of its business activities, the Controller also processes personal data of employees of business partners or potential business partners, as well as personal data of natural persons with whom the Controller has or may have a business relationship.

The categories of personal data of Data Subjects collected include:

  • name and surname;
  • e-mail address;
  • telephone/mobile phone number;
  • information on the position held within the legal entity represented by the Data Subject;
  • occupation, where the Data Subject is a natural person with whom a contractual relationship is being established, for example a singer, painter, photographer, lawyer, doctor, etc.;
  • references and short biographies, where necessary;
  • data stated on forms of blank promissory notes, promissory notes and bills of exchange;
  • bank account number/IBAN, where the business partner is a natural person with whom a contractual relationship is being established;
  • other data depending on the nature of the business relationship. Personal data of Data Subjects are collected in the following ways:
  • through offers or enquiries received from Data Subjects regarding business cooperation;
  • through data received from Data Subjects in the context of the sale of the Controller’s products or services, or the purchase of products or services from a business partner, for example at fairs, congresses and similar events;
  • through business correspondence relating to a previous or current business cooperation, for example correspondence carried out in the course of performing a contract;
  • from publicly available sources, such as court registers, business partners’ websites, magazines, newsletters and similar sources. In addition to the above types of data and sources of collection, personal data may also be processed for other specific purposes, but always within the framework prescribed by law or where the processing is necessary for exercising rights and fulfilling obligations arising from the business relationship.

Data relating to Data Subjects who, as natural persons, are in a business relationship with the Controller are retained in accordance with applicable legal regulations. For example, the Controller is required to retain all invoices, as well as the supporting documentation for issuing invoices, for a period of 11 years in accordance with legal regulations.

In situations where the Controller is authorised to determine the retention periods independently, such periods are determined taking into account the purpose of the processing and the interests of the Data Subject.

PUBLIC ANNOUNCEMENTS

The Controller publishes information for promotional purposes through its websites, social media profiles and similar communication channels. Such publications may contain a limited set of personal data, such as names and surnames, job titles or functions, professional information, videos, statements and photographs.

The legal basis for such processing is the Controller’s legitimate interest, while always taking into account the interests of the Data Subject. Personal data will therefore not be published where it is determined that the interests of the Data Subject override the interests of the Controller. In certain situations, publication may be based on consent in accordance with the Regulation.

Publications are intended to have a lasting character in order to provide information about current events, as well as insight into previous activities.

From a technical perspective, publications on social media may be managed by our contractual partners, such as marketing agencies, who act solely on our instructions and in the capacity of processors.

Processing will cease if, based on an objection submitted by the Data Subject, it is determined that such objection is justified, or if the Data Subject withdraws consent in situations where consent is applicable, to the extent that this can be implemented.

MARKETING COMMUNICATIONS (NEWSLETTERS)

The Controller has a legitimate interest in processing personal data for direct marketing purposes, primarily for sending marketing communications, such as newsletters, by e-mail, SMS and/or instant messaging services, including Viber, WhatsApp and similar. On the basis of legitimate interest, the Controller may send different newsletters depending on the relationship that Data Subjects have with the Controller.

The personal data collected primarily include name and surname, e-mail address, telephone/mobile phone number, address, gender, country/language of communication, as well as basic data related to the Data Subject’s relationship with us.

Data Subjects may request restriction of processing at any time.

On some of its websites, the Controller offers users the possibility to subscribe to newsletters by e-mail. In order to ensure that no error or misuse has occurred when entering an e-mail address, we use a so-called double opt-in process: after an e-mail address is entered in the subscription field, the Controller sends a confirmation link to that e-mail address. Only after the confirmation link has been clicked is the e-mail address added to the database for sending the relevant newsletter.

Such newsletters are sent on the basis of your consent, which you provide by completing and confirming the form on the websites. The content and purpose of the newsletter will be stated at the time of subscription.

The Data Subject may unsubscribe from the mailing list at any time, and the Controller will immediately stop sending the newsletter.

USE OF COOKIES

Cookies are small files that a website visited by a user stores on the user’s computer for its own purposes. These purposes may vary and may include storing information such as the language selected by the user, a list of items in a shopping cart in an online store, the user’s IP address, username and password, e-mail address, geolocation data, and similar information.

Cookies are classified according to their duration, source and function.

According to their duration, cookies may be:

  • Persistent cookies These are cookies that remain on the user’s computer even after the Internet browser has been closed. They allow websites to store information such as login name and password, language settings or cookie preferences, so that the user does not have to enter them again on each subsequent visit. Persistent cookies may remain on the computer for days, months or even years.
  • Temporary cookies or session cookies These are cookies that are deleted from the user’s computer when the Internet browser is closed. They allow websites to store temporary information, such as the last few pages the user opened on the website being visited, or items in the shopping cart in the case of an online store. According to their source, cookies may be:
  • First-party cookies These are cookies stored by the website that the user is primarily visiting.
  • Third-party cookies These are cookies stored by other websites or web services that form part of the primary website visited by the user. They are usually used to monitor user behaviour on the primary website, or may be used by web services in order to provide such services properly. According to their function, there are several types of cookies:
  • Technical/necessary cookies These are cookies that are essential for the functionality of the website and its basic features, such as the session identifier of the user’s current visit or the contents of the shopping cart that the user has filled when purchasing products through an online store.
  • Functional cookies These cookies enable the website to provide enhanced functionality and personalisation, such as remembering the language in which the website content is displayed.
  • Statistical cookies These cookies collect information about how users visit the website. As a rule, the data are collected in aggregated form, without identifying the individual user.
  • Marketing cookies These cookies collect information about user habits and behaviour on the website for the purpose of displaying personalised advertisements. Only technical/necessary cookies will be used without the Data Subject’s consent. Consent will be requested from the Data Subject for all other cookies.

VIDEO SURVEILLANCE

The Controller has a legitimate interest in implementing video surveillance measures for the protection of property and persons. In certain cases, such as exchange offices located at the reception areas of the properties, the Controller also has a legal obligation to install surveillance cameras that record all persons moving within the camera’s perimeter, including guests, employees, business partners and other persons.

The processing of employees’ personal data through the video surveillance system is also carried out under the conditions laid down by occupational health and safety regulations and in accordance with the Controller’s Video Surveillance Policy.

The Controller marks, in the prescribed manner, all areas where video surveillance has been installed.

The Controller is aware that video recordings contain personal data of all persons moving within the camera’s perimeter and therefore stores such recordings with particular care. The Controller has established a security and access system, as well as a deletion policy, regulated by the Controller’s internal security rules.

Video surveillance recordings are retained for a maximum of 30 days from the date of recording. Where extraction or copying of recordings is required, the recordings are retained for a maximum of six months, unless a longer retention period is prescribed by another law or the recordings constitute evidence in judicial, administrative, arbitration or other equivalent proceedings.

In the event of judicial and/or criminal proceedings, the Controller may use the above-mentioned video recordings. Personal data contained in video recordings may also be accessed by third parties, processors and contractual partners of the Controller who are registered and qualified to provide services for the protection of persons and property. Such parties do not use the data independently in any way, but are responsible for the security of central monitoring and alarm systems.

All other matters relating to video surveillance are governed by the special regulations applicable to this area.

USE OF ARTIFICIAL INTELLIGENCE (AI)

The Controller currently does not use artificial intelligence (AI) systems to process the personal data of Data Subjects.

All decisions relating to the processing of personal data are made by authorised personnel in accordance with the applicable personal data protection legislation. The Controller does not carry out automated individual decision-making or profiling within the meaning of Article 22 of the GDPR through the use of artificial intelligence systems.

The Controller may use artificial intelligence tools solely to assist employees in performing business processes. Such AI tools are not used to process personal data, do not make automated decisions that produce legal or similarly significant effects on Data Subjects, and do not replace human decision-making.

Should the Controller implement artificial intelligence systems involving the processing of personal data in the future, it will, prior to such implementation, assess compliance with the GDPR, carry out a Data Protection Impact Assessment (DPIA) where required, and update this Privacy Policy accordingly.

FINAL PROVISIONS

We regularly update this Privacy Policy to ensure that it remains accurate and up to date, and we reserve the right to amend its content if we consider it necessary. You will be informed of any changes and amendments in a timely manner through our website, in accordance with the principle of transparency.

In Žminj, 1 July 2026.