Apartmani Toni

Privacy policy

Last updated: 14 September 2026

We care about protecting your personal data. This policy explains what data we collect when you visit apartmaniduceomis.com and book accommodation with us, why we collect it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the GDPR.

1. Data controller

  • Apartmani Toni, Daniela Tafra
  • Address: Duće Rogač IV, 21311 Duće, Hrvatska
  • E-mail: danielatafra@gmail.com
  • Phone: +385 95 199 9013

For any question about the processing of personal data or to exercise your rights, please contact us at the e-mail address or postal address above.

2. What data we collect

  • Booking form data: name and surname, e-mail address, phone number, country, number of adults and children, dates of stay and your message.
  • Communication data: the content of e-mails, calls or WhatsApp messages you send us.
  • Registration data: on arrival we are legally required to collect data from your identity card or passport (name and surname, date and place of birth, nationality, type and number of document, place of residence) in order to register guests in the Croatian eVisitor system.
  • Payment data: amount and date of the deposit payment and the payer details shown on the bank transfer.
  • Technical data: IP address, browser type and time of access, logged by the server for security and to keep the website working properly.

We do not collect special categories of personal data and we do not use analytics, advertising or profiling tools.

3. Purposes and legal bases

  • Handling your enquiry and booking, communicating with you and performing the accommodation contract: Art. 6(1)(b) GDPR (steps taken at your request before entering into a contract and performance of the contract).
  • Guest registration (eVisitor), tourist tax and keeping records and accounting documents: Art. 6(1)(c) GDPR (legal obligation under Croatian law).
  • Website security, abuse prevention and protection of our legal interests: Art. 6(1)(f) GDPR (legitimate interest).
  • Language cookie and displaying Google Maps: Art. 6(1)(a) GDPR (your consent), which you can withdraw at any time.

4. Is providing data mandatory?

Your name, e-mail and phone number are required to process your booking request. Without them we cannot contact you or confirm the booking. Registration data is required by law, and accommodation cannot be provided without it.

5. Recipients

We do not sell your data or share it with third parties for marketing purposes. Your data may only be accessible to:

  • hosting and e-mail service providers, who process data on our behalf under a data processing agreement;
  • competent authorities where required by law (eVisitor system, tourist board, tax administration, police);
  • our accounting service, if we use one, to meet tax and accounting obligations;
  • Booking.com and Airbnb, which receive only the booked dates, without any personal data, to prevent double bookings;
  • Google, but only if you consent to the map being displayed;
  • Meta (WhatsApp), if you contact us via WhatsApp yourself.

6. Transfers outside the EEA

Some providers (e.g. Google or Meta) may process data outside the European Economic Area. In such cases transfers are based on the European Commission's adequacy decision (EU-US Data Privacy Framework) or on standard contractual clauses.

7. How long we keep data

  • Booking requests that were not confirmed, and rejected or cancelled requests: deleted automatically 12 months after the planned departure date.
  • Confirmed bookings: kept for the duration of the contract and afterwards for as long as required by tax, accounting and guest registration laws.
  • Correspondence: no longer than 2 years after the last contact, unless needed to establish or defend legal claims.
  • Server logs: a short period, as a rule no longer than 30 days.
  • Cookies: as stated in the table below.

8. Cookies

Cookies are small files stored in your browser. We use necessary cookies without consent because the website cannot work properly without them. All other cookies are used only if you agree in the cookie banner. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer.

CookiePurposeDurationType
cookie_consentRemembers your cookie settings.6 monthsNecessary
admin_sessionOwner login to the administration. Never set for visitors.14 daysNecessary
langRemembers the language you selected.12 monthsPreferences (with consent)
NID, AEC and others (google.com)Set by Google when the map is shown on the Contact page.According to Google's policy (up to 13 months)External content (with consent)

Fonts and images are served from our own server, so no data is sent to third parties when the page loads. Links to Facebook and other external websites do not set cookies until you open them.

9. Your rights

Under the GDPR you have the right to:

  • access your personal data and obtain a copy (Art. 15);
  • rectification of inaccurate or incomplete data (Art. 16);
  • erasure, unless we are legally required to keep the data (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7).

You can send your request to danielatafra@gmail.com. We will reply without undue delay and at the latest within one month. To protect your data we may ask you to confirm your identity.

10. Right to lodge a complaint

If you believe we process your data unlawfully, you have the right to lodge a complaint with the supervisory authority: Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka, AZOP), Selska cesta 136, 10000 Zagreb, Croatia, www.azop.hr. You may also complain to the supervisory authority in the EU member state where you live or work.

11. Data security

The website uses an encrypted connection (HTTPS). Only the owner has access to booking data, through a password-protected administration. We apply reasonable technical and organisational measures to prevent unauthorised access, loss or misuse of data.

12. Automated decision-making

We do not make decisions based solely on automated processing, including profiling. Every booking request is decided on personally by the owner.

13. Changes to this policy

We may update this policy from time to time. The current version is always published on this page, with the date of the last change.