Skip to content

Legal

Privacy policy

How we collect, use and store your data, in line with the General Data Protection Regulation (GDPR).

Draft — this text is awaiting legal review before publication.

  1. 01Data controller

    Details of the legal entity acting as data controller are published together with the imprint details.

    • +385 99 600 3048
    • grandisvilla@gmail.com
  2. 02What we collect

    Through the booking and contact forms we collect your name, email address, telephone number, number of guests, requested dates, and the content of your message including any special requests. We never see or store card details — card payments are handled entirely by Stripe.

  3. 03Why we process it

    Solely to process and confirm your booking, to communicate about your stay, to issue invoices, and to meet the statutory guest registration obligations.

  4. 04Legal basis

    Processing is based on performance of the accommodation contract, on the provider's legal obligations, and — for optional analytics cookies — on your consent.

  5. 05How long we keep it

    Booking records are kept for as long as tax and hospitality legislation requires. Messages sent through the contact form are deleted once the enquiry is no longer current.

  6. 06Who we share it with

    With the service providers that process data on our behalf: our hosting platform, our transactional email provider, our payment provider and, where applicable, a calendar synchronisation service. We do not sell your data or pass it to third parties for marketing.

  7. 07Your rights

    You have the right to access your data, and to its rectification, erasure, restriction of processing, portability, and to object. You may withdraw consent at any time. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency.

  8. 08Data protection contact

    Requests concerning personal data should be sent to the contact address published in the imprint.

    • +385 99 600 3048
    • grandisvilla@gmail.com