Please wait

Privacy policy

Statement on the Collection and Use of Personal Data

Stella Mediterranea d.o.o. is committed to providing protection for customers' personal data by collecting only necessary, basic data about customers/users that are essential for fulfilling our obligations; informing customers about how collected data is used, regularly giving customers the choice regarding the use of their data, including the option to decide whether they want their name removed from lists used for marketing campaigns. All user data is strictly protected and accessible only to employees who need this data to perform their work. All employees of Stella Mediterranea d.o.o. and business partners are responsible for respecting privacy protection principles.

We respect your privacy regardless of whether you are a user of our services or are simply inquiring about them.
You have the right to protection of personal data: name, address, phone number, email address and other data that can directly or indirectly serve to identify you with reasonable effort.

This statement describes the process of collecting your personal data and the purpose for which it is collected, how your personal data is used, with whom your personal data is shared, how it is protected and what your options are regarding personal data protection.

This statement applies to the processing of your personal data on the website tickets.stella-croatica.hr, marketing campaigns that may bring you to this website, sponsored posts on social media, etc. within services managed by us or third parties on our behalf.

Who is responsible for processing your personal data?

Stella Mediterranea d.o.o.
turizam@stella-croatica.hr
+385 99 215 02 50
Andrija Polic

    Who can you contact if you have questions or requests regarding personal data?

    For all questions, requests or complaints related to this statement or to exercise your rights based on this statement, you can contact us at the contact email address in the statement header.

    Basic Principles

    We value the trust you show us by entrusting us with your personal data and we commit to always processing it in a fair, transparent and secure manner. The key principles we respect when processing personal data are as follows:

    • Lawfulness: We will collect personal data in a fair, lawful and transparent manner.
    • Data minimization: We will limit the collection of personal data to that which is appropriate and necessary for the purpose for which it is collected.
    • Purpose limitation: We will collect personal data only for specified, explicit and legitimate purposes and will not process it in a manner inconsistent with that purpose.
    • Accuracy: We will ensure the accuracy and currency of personal data.
    • Security and protection of personal data: We will implement technical and organizational measures to ensure appropriate levels of data protection taking into account, among other things, the nature of your personal data that needs to be protected. These measures provide for preventing any kind of unauthorized disclosure or access, accidental or intentional destruction or accidental loss or alteration and other unlawful forms of processing.
    • Access and corrections: We will process your personal data respecting your rights.
    • Storage limitation: Your personal data will be stored in accordance with applicable personal data protection regulations and only for as long as necessary to achieve the purpose for which it was collected.
    • Protection in international transfers: We will ensure that your personal data, if transferred to countries outside the European Economic Area, will be transferred in accordance with legal regulations and will be appropriately protected during transfer.
    • Protection of personal data when mediating to third parties: We will ensure the forwarding of personal data to third parties and processing by third parties in accordance with applicable legislation and with appropriate contractual protection measures.
    What data do we collect and on what legal basis?

    You will always be clearly informed about what personal data we collect. We will present this information to you with a separate privacy notice that will be included in specific services (including communication services), newsletters, reminders, surveys, offers, event invitations, etc.

    In accordance with applicable personal data protection regulations, we may process your personal data if:

    • you have given consent for specific processing purposes (as specified in the privacy notice relating to specific processing). You have the right to withdraw your consent at any time without giving reasons; or
    • processing of your personal data is necessary for the fulfillment of contract terms of which you are a contracting party; or
    • such processing follows our legitimate interests, e.g. we may process certain personal data for the purpose of preventing abuse or fraud, when establishing rights based on warranty, to check your satisfaction with products and services in certain cases. We will inform you about legitimate interests in the privacy notice related to that specific processing; or
    • it is necessary to fulfill our legal obligations, e.g. if you have purchased a product or service from us, we must process data relating to your identity (name, surname, address, tax number, etc.), the purchased product (type, equipment, price, etc.) and the circumstances of purchase (payment, place and date of collection, etc.).
    For what purposes do we process your personal data

    We process personal data only for specific, explicitly confirmed and legitimate purposes and will not process it in a manner inconsistent with those purposes.

    Such purpose may be fulfilling your order, improving visits to our website, improving products and services in general, offering services or applications, market communications and activities, etc. The purpose of processing your personal data is clearly stated each time in a separate privacy notice that relates to specific processing. The privacy notice is available, for example, on the website, order form, registration form, in newsletters, etc.

    Certain information (such as categories of products you purchase) is used to assess or evaluate content that might be most interesting and useful to you. In this way, we want to increase the possibilities of acquainting you with the most relevant offer of products or services. For this purpose, individuals can be classified into different groups (profiles) with which we communicate differently, i.e. in a customized (individualized) manner.

    This means that different groups (profiles) of individuals receive marketing messages with different content, including special purchase conditions (e.g. discounts or payment terms). When classifying individuals into groups (profiles), we may also track, record and use individual responses to marketing messages, e.g. opening emails, opening links, time an individual spends on a particular website, etc.

    Care for accuracy and currency of your personal data

    It is important to us that your data is always accurate and up-to-date. Please notify us of any changes or errors in our records of your personal data by contacting us via the contact email address. We will determine reasonable measures to ensure that all inaccurate or outdated personal data is deleted or corrected.

    Access to your personal data

    You have the right to access your personal data that we process, and if your personal data is inaccurate or incomplete, you may request correction or deletion of personal data. If you need information about your privacy rights or want to exercise one of your rights, please contact us at the contact email address.

    How long do we keep your personal data

    We keep your personal data in accordance with applicable personal data protection regulations.

    We keep your personal data only as long as necessary to achieve the purpose for which we process your personal data, for the period determined by law (e.g. 10 years for issued invoices) or for the period necessary to fulfill contract terms, including warranty requirements and possible claims (e.g. 5 years from fulfilling contractual obligations or expiration of warranty obligations unless circumstances indicate otherwise).

    Personal data that we process based on your personal consent we keep permanently, until your revocation, unless the purpose for which the personal data was collected has already been achieved.

    Protection of your personal data

    We implement technical and organizational security measures to protect your personal data from illegal or unauthorized access or use, as well as from accidental loss or destruction. These measures are implemented taking into account our IT infrastructure, potential impact on your privacy and implementation costs, and in accordance with current standards and practices in the field of data protection.

    We will entrust the processing of your personal data only to those authorized persons (third parties) who respect the mentioned technical and organizational measures for personal data protection.

    Data security assurance means caring for the confidentiality, integrity and availability of your personal data.

    (a) Confidentiality: We will protect your personal data from unauthorized disclosure to third parties.

    (b) Integrity: We will protect your personal data from changes by unauthorized third parties.

    (c) Availability: We will ensure that your personal data can be accessed only by authorized persons when necessary.

    Use of cookies and similar technologies

    We use cookies on our websites. In this way, we provide you with a better experience while browsing our websites, and we can also improve those websites. For more information about our use of cookies and how you can refuse their use, please read our Cookie Statement.

    Forwarding of personal data

    Regarding the purpose of collecting your personal data, we may forward, disclose or enable access to the categories of users listed below, who process this data in accordance with the stated purpose. We require them to always be in compliance with applicable legal regulations, personal data protection rules and to pay exceptional attention to the confidentiality of your personal data.

    a) Within our organization and within our trademarks/service brands:

    • authorized officers;
    • members of our network of authorized dealers and authorized services that you have designated as selected or are located near you (in relation to your postal code and address) or with whom you are in contact;

    b) business partners:

    • advertising agencies, marketing and PR agencies: who help us implement and analyze the effectiveness of our campaigns and promotional activities (e.g. MailChimp, Google – only cookie identification data for remarketing purposes, email address for displaying ads in Google AdWords program, cookie identification data for analysis purposes in Google Analytics program; Facebook – only cookie identification data for remarketing purposes, email address for displaying ads in Facebook Custom Audiences program);
    • business partners: for example, trusted companies that may use your personal data to provide you with services and/or products you have requested and/or deliver marketing material (provided you have agreed to receive such material).
    • external IT service providers, accounting services, law firms, etc.

    c) other third parties in connection with the following procedures:

    • when required by law, at the request of authorities, court decisions, legal proceedings, reporting and informing obligations to competent bodies, etc.
    • verification or control of our compliance with rules and contracts
    • protection of rights, property or security of the company and/or its clients
    • in connection with corporate transactions: within the transfer or sale of all or part of the business or otherwise in connection with merger, consolidation, changes in control, reorganization or liquidation of all or part of the company's business

    Please note that the recipients listed in points b) and c) of this document, especially service providers who may offer you products and services within the provision of our services or applications or through their own channels, may separately collect your personal data. In that case, these users are solely responsible for supervising this personal data and your relationship with these users is subject to their terms.

    Use of social media

    If you log into our online store from social networks (for example using your Facebook account), we will record your personal data available on those social media, and your use of those media means that you explicitly agree to the forwarding of your personal data.

    We will record only those personal data that we request from you when opening a user account, which are name and surname, email address, phone, postal address, place and country.

    Transfers outside the European Economic Area

    Your personal data may be transferred to users located outside the European Economic Area (EEA) and may be processed by our company and these users outside the EEA. When transferring personal data to countries outside the EEA that generally do not provide the same level of data protection as the EEA, we implement appropriate special measures to ensure an appropriate level of protection for your personal data.

    You will always be notified if your personal data is transferred outside the EEA by a separate privacy notice that will be included in specific services (together with communication services), newsletters, reminders, surveys, offers, event invitations, etc.

    Your options and rights

    We want to be as transparent as possible and therefore offer you the choice of how you want us to use your personal data.

    • Your choice of contact method

    Various options are available to you for choosing how you want us to contact you, i.e. through which channel (for example, email, mail, social media, phone, ...), for what purpose.

    • Your personal data

    You can always contact us via the contact email for personal data protection if you want to know what personal data we process about you and the source of that data.

    • Corrections

    If you find an error in personal data or if it seems to you that the data is not complete or accurate, you can request correction or completion.

    • Processing restriction

    You have the right to request restriction of processing of your personal data (for example, while the accuracy of your personal data is being verified).

    • Your objections

    You may object to the processing of your personal data for direct marketing purposes (if you wish, you can inform us through which channel and how often you want us to contact you) or to your personal data being forwarded to third parties for that purpose.

    Refusing consent to personal data processing does not carry negative consequences or sanctions and is completely voluntary. However, there is a possibility that after revoking consent to personal data processing, we will not be able to provide the user with individual or multiple services that cannot be provided without the use of personal data.

    In addition, you can request that we delete all your personal data (except in certain cases, e.g. for the purpose of proving a transaction or if necessary due to compliance with legal regulations).

    You have the right to file a complaint with the supervisory authority.

    Personal Data Protection Agency (http://www.azop.hr, azop@azop.hr).

    Legal information

    The provisions of these rules supplement and do not override legislative provisions in the field of personal data protection. In case of inconsistency between the provisions of these rules and legislative provisions in the field of personal data protection, legislative provisions apply.

    We may change these rules at any time. In that case, we will notify you and invite you to re-read the latest version of the rules.

    Term definitions

    (a) Data controller means the organization that determines the purpose and means of processing your personal data.

    (b) Data processor means a person or organization that processes personal data on behalf of the controller.

    (c) EEA means the European Economic Area (includes European Union member states as well as Iceland, Norway and Liechtenstein).

    (d) Personal data is any data that directly relates to you or based on which you can be identified, such as your name, phone number, email address, vehicle identification number (VIN), geolocation, etc.

    (e) Processing means collection, access and all other forms of use of your personal data.