DATA PROTECTION

PRIVACY POLICY

Polaris Yachting

Controller: Polaris Yachting, vl. Ivana Tomić Kalina

Effective date: 20 May 2026

This Privacy Policy explains how Polaris Yachting collects, uses, shares and protects personal data when you visit https://www.polaris-yachting.com, contact us or ask us to assist with a cruise, charter, boat trip, transfer or another tourism-service booking.

1. Data Controller

The controller responsible for your personal data is:

Polaris Yachting, vl. Ivana Tomić Kalina

Seasonal sole proprietorship (craft) registered for tourist agency activities

A. G. Matoša 1, 21314 Jesenice, Croatia

OIB: 48574245673

Craft registration number: 98495291

Croatian Register of Tourist Agencies: entry no. 1160

Email: [email protected]

Telephone / WhatsApp: +385 91 793 2955

2. Scope of This Policy

This Policy applies to personal data processed through our website, contact form, email, telephone, SMS, WhatsApp and booking-intermediation activities. It does not govern a Provider’s independent processing. Cruise operators, vessel owners, charter companies, transfer providers and other suppliers generally act as separate controllers under their own privacy notices.

3. Personal Data We Collect

  • Identity and contact data, including name, email address, telephone number, postal address and preferred contact method.
  • Enquiry data, including requested dates, destination, budget, group size, preferences and messages.
  • Booking and traveller data, including names, dates of birth, nationality, passport or identity-document information, dietary or accessibility requirements and emergency-contact details when required by the Provider.
  • Business data, including company or agency name, role, billing details, tax identifiers and correspondence.
  • Communication data contained in emails, contact-form submissions, SMS, telephone notes and WhatsApp messages.
  • Technical data, including IP address, device and browser information, approximate location, access time, referring page and website interaction data.
  • Consent and preference data, including cookie choices and any marketing consent.

Please do not send health information, passport copies or other sensitive information unless it is genuinely required for the requested Travel Service. Where such information is necessary, we process only what is required and use an appropriate legal basis.

4. How We Obtain Personal Data

  • Directly from you through the website, email, telephone, SMS, WhatsApp or other communication.
  • From a lead passenger, family member, employer or travel agency making an enquiry or Booking on your behalf.
  • From Providers where needed to administer a Booking, change, cancellation or complaint.
  • Automatically from the website and cookies or similar technologies.
  • From publicly available business sources where relevant to a B2B enquiry.

5. Purposes and Legal Bases

PurposeLegal basis
Answering enquiries and preparing offersSteps requested before a contract; legitimate interests in responding to enquiries
Forwarding and administering Booking requestsContract and pre-contract steps; legitimate interests in providing intermediation
Sharing necessary data with ProvidersContract and pre-contract steps; legal obligations where applicable
Customer service, changes, cancellations and complaintsContract; legal obligations; legitimate interests in resolving issues
Accounting, tax and business recordsLegal obligations; establishment, exercise or defence of legal claims
Website security, fraud prevention and diagnosticsLegitimate interests in secure and reliable operations
Analytics and non-essential cookiesConsent where legally required
Email or electronic marketingConsent, or another lawful basis where expressly permitted by applicable law

Where we rely on legitimate interests, we consider whether our interests are necessary and balanced against your rights. You may object to processing based on legitimate interests in the circumstances described below.

6. Data Required for a Booking

Certain identity, contact and booking information is necessary to request or administer a Travel Service. If you do not provide required information, the Provider may be unable to confirm or perform the service. Optional marketing information is not required for a Booking.

7. Data About Other Travellers

If you provide data about another person, you confirm that you are authorised to do so and that you have shown them this Privacy Policy. For children, data should be provided by a parent, guardian or another properly authorised adult and only where required for the Travel Service.

8. Who Receives Personal Data

We disclose personal data only where reasonably necessary, including to:

  • cruise operators, vessel owners, charter companies, carriers, transfer providers and other suppliers involved in the requested Travel Service;
  • vessel masters, crew, local representatives, ports or competent authorities where required for operations, safety or law;
  • website hosting, email, contact-form, IT-support, cloud-storage and communications providers acting for us;
  • WhatsApp and other communications or social-media providers when you choose those channels;
  • accountants, tax advisers, insurers, banks, legal advisers and public authorities where necessary;
  • a purchaser or successor if the business is sold or reorganised, subject to appropriate safeguards.

We do not sell personal data. A Provider receiving Booking data normally processes it under its own privacy policy and legal obligations.

9. International Data Transfers

Some travellers, Providers or technology services may be located outside the European Economic Area. Where personal data is transferred internationally, we use an applicable legal mechanism, such as an adequacy decision, appropriate contractual safeguards or a limited statutory derogation where the transfer is necessary for the requested contract. Contact us for further information about relevant safeguards.

10. Data Retention

We retain personal data only for as long as necessary for the stated purpose, including:

  • enquiries that do not become Bookings: generally up to 24 months after the last meaningful contact;
  • Booking and customer-service records: generally for the duration of the Booking and up to five years afterwards, unless a longer period is needed for a complaint, claim or legal requirement;
  • accounting and tax records: for the retention period required by Croatian law;
  • complaint records: for at least the legally required period and longer where necessary for a claim;
  • marketing data: until consent is withdrawn, an objection is made or the data is no longer necessary;
  • technical and security records: for a proportionate period determined by security and operational needs.

When data is no longer required, we delete or anonymise it unless continued retention is legally required.

11. Cookies and Similar Technologies

The website may use strictly necessary cookies required for security, functionality and user choices. Analytics, advertising or other non-essential technologies may be used only where a valid legal basis exists and, where required, after you give consent through the cookie banner.

You can accept, reject or change non-essential cookie choices through the website’s cookie settings. Browser settings may also block cookies, although this can affect website functionality.

The website developer must maintain an accurate cookie inventory identifying each cookie or similar technology, its provider, purpose, duration and category. That inventory should be available through the cookie banner or a separate Cookie Policy.

12. Direct Marketing

We send promotional electronic communications only where permitted by applicable law. Where marketing is based on consent, you may withdraw consent at any time by using the unsubscribe option or contacting [email protected]. Withdrawal does not affect earlier lawful processing.

Service messages relating to an enquiry or Booking are not marketing and may continue where necessary to administer the request or contract.

13. Data Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. No internet or email transmission can be guaranteed completely secure. Please avoid sending unnecessary passport, payment-card or health data through unsecured channels.

14. Your Data-Protection Rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • request access to your personal data and a copy of it;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain data in a portable format;
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with a competent supervisory authority.

To exercise a right, email [email protected]. We may request proportionate information to verify identity. We normally respond within one month, subject to lawful extensions for complex or numerous requests.

15. Complaints to the Supervisory Authority

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): Ulica Metela Ožegovića 16, HR-10000 Zagreb, Croatia; email [email protected]; telephone +385 (0)1 4609-000; website https://azop.hr.

If you live in another EEA country, you may also contact the supervisory authority in that country.

16. Third-Party Websites and Services

The website may link to Providers, WhatsApp, Tripadvisor, social-media platforms and other third-party services. Those parties control their own processing. Review their privacy notices before providing data through their services.

17. Automated Decision-Making

We do not currently make decisions producing legal or similarly significant effects about you solely by automated means. If this changes, we will provide the information and safeguards required by law.

18. Changes to This Policy

We may update this Privacy Policy to reflect legal, technical or business changes. The current version and effective date will be published on the website. Material changes will be communicated where required.

19. Contact

Polaris Yachting, vl. Ivana Tomić Kalina

A. G. Matoša 1, 21314 Jesenice, Croatia

Email: [email protected]

Telephone / WhatsApp: +385 91 793 2955

Website: https://www.polaris-yachting.com