Legal
Privacy policy
How we collect, use and store your data, in line with the General Data Protection Regulation (GDPR).
Draft — this text is awaiting legal review before publication.
01Data controller
Details of the legal entity acting as data controller are published together with the imprint details.
- +385 99 600 3048
- grandisvilla@gmail.com
02What we collect
Through the booking and contact forms we collect your name, email address, telephone number, number of guests, requested dates, and the content of your message including any special requests. We never see or store card details — card payments are handled entirely by Stripe.
03Why we process it
Solely to process and confirm your booking, to communicate about your stay, to issue invoices, and to meet the statutory guest registration obligations.
04Legal basis
Processing is based on performance of the accommodation contract, on the provider's legal obligations, and — for optional analytics cookies — on your consent.
05How long we keep it
Booking records are kept for as long as tax and hospitality legislation requires. Messages sent through the contact form are deleted once the enquiry is no longer current.
06Who we share it with
With the service providers that process data on our behalf: our hosting platform, our transactional email provider, our payment provider and, where applicable, a calendar synchronisation service. We do not sell your data or pass it to third parties for marketing.
07Your rights
You have the right to access your data, and to its rectification, erasure, restriction of processing, portability, and to object. You may withdraw consent at any time. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency.
08Data protection contact
Requests concerning personal data should be sent to the contact address published in the imprint.
- +385 99 600 3048
- grandisvilla@gmail.com