Aquatoria Cleaning
GDPR
General Data Protection Regulation
A concise overview of personal data protection, data subject rights, and the core GDPR obligations in the Republic of Croatia.
This page provides a concise overview of the core rules of the General Data Protection Regulation (GDPR) and the way personal data protection applies on this website. For details about specific processing activities, forms and communications, please also review the Privacy statement.
1. What is GDPR
GDPR is the General Data Protection Regulation, namely Regulation (EU) 2016/679. It governs how personal data of natural persons may be collected, used, stored, shared and protected. In the Republic of Croatia, GDPR is applied together with the Act on the Implementation of the General Data Protection Regulation.
2. Who is responsible for data processing on this website
The controller of personal data processed through this website is Aquatoria Cleaning within the scope of providing service information, communicating with users, and handling inquiries or requests. If you have a question about personal data processing, would like to exercise one of your rights, or want to withdraw previously given consent, you may contact us using the contact details published on this page.
- E-mail: cleaning@aquatoria-yachting.com
- Phone: +385 95 2083 333
- WhatsApp: +385 95 2083 333
3. Which principles govern personal data processing
Personal data must be processed lawfully, fairly and transparently. It may be collected only for specific and legitimate purposes, only to the extent necessary for that purpose, it must be accurate and kept up to date, it must not be retained longer than necessary, and it must be protected by appropriate technical and organisational measures.
4. Which legal bases may apply to processing
Depending on the situation, processing may be based on one or more legal grounds provided by GDPR:
- your consent, when consent is required;
- steps taken prior to entering into a contract or the performance of a contract;
- compliance with a legal obligation;
- the legitimate interest of the controller or a third party, if such processing does not override your rights and freedoms.
If processing is based on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
5. Which rights you have as a data subject
GDPR grants you a range of rights regarding your personal data. Depending on the circumstances, you may request:
- the right of access to your personal data;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure where the legal conditions are met;
- the right to restriction of processing;
- the right to data portability, where applicable;
- the right to object to processing based on legitimate interest or carried out for direct marketing purposes;
- the right not to be subject to a decision based solely on automated processing, including profiling, where the GDPR conditions are met.
6. How these rights are exercised
You may submit your request using the contact details published on this page. To protect privacy and data security, additional proof of identity may be required before the request is handled. Requests are answered without undue delay and no later than one month after receipt, unless GDPR allows that period to be extended.
7. How long data may be retained
Personal data may be retained only for as long as necessary for the purpose for which it was collected or as required by applicable regulations. After the purpose has been fulfilled or the statutory retention period has expired, the data is deleted, anonymised, or its processing is otherwise restricted.
8. Security and confidentiality
GDPR requires the implementation of appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or unauthorised disclosure. The level of protection must be proportionate to the nature of the data and the risks of processing.
9. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data is contrary to GDPR or other applicable regulations, you have the right to lodge a complaint with the supervisory authority. In the Republic of Croatia, this is the Croatian Personal Data Protection Agency (AZOP).
10. Additional information
This page serves as a concise explanation of the basic rules of personal data protection. Information about specific categories of data, purposes of processing, cookies, and contact methods is also available in other legal documents published on this website, especially in the Privacy statement.