Legal
Last updated: June 2026
We have prepared this privacy policy in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Croatian Consumer Protection Act (OG 19/2022) to explain what personal data we collect, why we process it, and what rights you have.
This policy applies to all personal data processed through our website trogirboat.com, our email communications, and our social media channels.
The controller responsible for data processing on this website is:
Aetas Aurea d.o.o.
Director: Ing. Mag. Patrick Eiler
Mažuranićevo šetalište 35, 21000 Split, Croatia
OIB: 10132796428
Email: book@trogirboat.com
Phone: +385 99 209 0052
We collect the following categories of personal data:
Booking enquiry data: When you submit a booking request through our contact form, we collect your name, email address, phone number, preferred tour, preferred date, number of guests, departure point, and any message you include. This data is necessary to process your enquiry and confirm your booking.
Payment data: When you pay a deposit or the tour balance, your payment is processed by a third-party payment provider (such as Stripe or Revolut). We do not store your full credit card number. We receive only a transaction reference, the last four digits of your card, and the payment amount for our records.
Communication data: When you contact us by email, phone, or WhatsApp, we store the content of your messages and your contact details to respond to your enquiry and manage your booking.
Technical data: When you visit our website, our web server automatically records your IP address, browser type and version, operating system, referring URL, pages visited, and date and time of access. This data is stored in server log files and is necessary for the technical operation and security of the website.
We process your personal data only when at least one of the following legal bases applies, in accordance with Article 6(1) of the GDPR:
Consent (Art. 6(1)(a)): You have given your consent for a specific purpose, such as accepting non-essential cookies.
Contract (Art. 6(1)(b)): Processing is necessary to fulfil a contract with you or to take steps at your request before entering into a contract. This applies to your booking enquiry and payment processing.
Legal obligation (Art. 6(1)(c)): Processing is necessary to comply with a legal obligation, such as tax record-keeping requirements.
Legitimate interest (Art. 6(1)(f)): Processing is necessary for our legitimate interests, such as website security and fraud prevention, provided these interests do not override your fundamental rights.
We do not sell your personal data to third parties. We share your data only with the following categories of recipients, as necessary to operate our service:
Payment providers: Your payment data is processed by our payment service provider (e.g. Stripe Inc. or Revolut Ltd.) under their own privacy policies and data processing agreements.
Hosting provider: Our website is hosted by easyname GmbH. Server log files containing technical data are stored on their servers within the European Economic Area.
Google Maps: Our website embeds Google Maps to show our departure locations. When the map loads, your IP address and browser data may be transmitted to Google LLC. This processing is based on your consent (Art. 6(1)(a) GDPR). You can learn more at Google's Privacy Policy.
Some of our service providers (such as Google and, depending on the payment provider, Stripe) may process data in the United States. These transfers are safeguarded by the EU-US Data Privacy Framework or by EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). We ensure that any data transferred outside the EEA is protected to the standard required by the GDPR.
Our website uses cookies. Cookies are small text files placed on your device by your browser. We distinguish between:
Essential cookies: These are strictly necessary for the website to function (e.g. session management). They are placed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) and do not require your consent.
Analytics and third-party cookies: If we use web analytics tools or embed third-party services (such as Google Maps), these may set additional cookies. These are only activated with your consent (Art. 6(1)(a) GDPR), which you can give or withdraw at any time via the cookie settings on our website.
You can also manage cookies through your browser settings. Instructions for common browsers: Chrome, Safari, Firefox, Edge.
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected:
Booking and payment records: Retained for the duration required by Croatian and EU tax law (currently up to 11 years for financial records).
Enquiries that do not result in a booking: Deleted after 12 months unless you contact us again.
Server log files: Automatically deleted after 14 days.
If you request deletion of your data, we will comply promptly unless we are legally required to retain certain records.
Under Articles 13 to 22 and Article 77 of the GDPR, you have the following rights regarding your personal data:
Right of access (Art. 15): You may request confirmation of whether we process your data and, if so, receive a copy of that data.
Right to rectification (Art. 16): You may request correction of inaccurate personal data.
Right to erasure (Art. 17): You may request deletion of your personal data, subject to legal retention obligations.
Right to restriction of processing (Art. 18): You may request that we limit the processing of your data in certain circumstances.
Right to data portability (Art. 20): You may request your data in a structured, commonly used, machine-readable format.
Right to object (Art. 21): You may object to processing based on legitimate interests or direct marketing at any time.
Right to lodge a complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority. The relevant authority for Croatia is the Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.
To exercise any of these rights, please contact us at book@trogirboat.com. We will respond within 30 days.
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. All booking and payment transactions are logged and monitored for fraud prevention purposes, in accordance with our legitimate interest under Art. 6(1)(f) GDPR.
We may update this privacy policy from time to time to reflect changes in our services or legal requirements. The current version is always available on this page. We encourage you to review it periodically.
If you have any questions about this privacy policy or your personal data, please contact us at book@trogirboat.com.