DATA PROTECTION
PRIVACY POLICY
Polaris Yachting
Controller: Polaris Yachting, vl. Ivana Tomić Kalina
Effective date: 20 May 2026
This Privacy Policy explains how Polaris Yachting collects, uses, shares and protects personal data when you visit https://www.polaris-yachting.com, contact us or ask us to assist with a cruise, charter, boat trip, transfer or another tourism-service booking.
1. Data Controller
The controller responsible for your personal data is:
Polaris Yachting, vl. Ivana Tomić Kalina
Seasonal sole proprietorship (craft) registered for tourist agency activities
A. G. Matoša 1, 21314 Jesenice, Croatia
OIB: 48574245673
Craft registration number: 98495291
Croatian Register of Tourist Agencies: entry no. 1160
Email: [email protected]
Telephone / WhatsApp: +385 91 793 2955
2. Scope of This Policy
This Policy applies to personal data processed through our website, contact form, email, telephone, SMS, WhatsApp and booking-intermediation activities. It does not govern a Provider’s independent processing. Cruise operators, vessel owners, charter companies, transfer providers and other suppliers generally act as separate controllers under their own privacy notices.
3. Personal Data We Collect
- Identity and contact data, including name, email address, telephone number, postal address and preferred contact method.
- Enquiry data, including requested dates, destination, budget, group size, preferences and messages.
- Booking and traveller data, including names, dates of birth, nationality, passport or identity-document information, dietary or accessibility requirements and emergency-contact details when required by the Provider.
- Business data, including company or agency name, role, billing details, tax identifiers and correspondence.
- Communication data contained in emails, contact-form submissions, SMS, telephone notes and WhatsApp messages.
- Technical data, including IP address, device and browser information, approximate location, access time, referring page and website interaction data.
- Consent and preference data, including cookie choices and any marketing consent.
Please do not send health information, passport copies or other sensitive information unless it is genuinely required for the requested Travel Service. Where such information is necessary, we process only what is required and use an appropriate legal basis.
4. How We Obtain Personal Data
- Directly from you through the website, email, telephone, SMS, WhatsApp or other communication.
- From a lead passenger, family member, employer or travel agency making an enquiry or Booking on your behalf.
- From Providers where needed to administer a Booking, change, cancellation or complaint.
- Automatically from the website and cookies or similar technologies.
- From publicly available business sources where relevant to a B2B enquiry.
5. Purposes and Legal Bases
| Purpose | Legal basis |
| Answering enquiries and preparing offers | Steps requested before a contract; legitimate interests in responding to enquiries |
| Forwarding and administering Booking requests | Contract and pre-contract steps; legitimate interests in providing intermediation |
| Sharing necessary data with Providers | Contract and pre-contract steps; legal obligations where applicable |
| Customer service, changes, cancellations and complaints | Contract; legal obligations; legitimate interests in resolving issues |
| Accounting, tax and business records | Legal obligations; establishment, exercise or defence of legal claims |
| Website security, fraud prevention and diagnostics | Legitimate interests in secure and reliable operations |
| Analytics and non-essential cookies | Consent where legally required |
| Email or electronic marketing | Consent, or another lawful basis where expressly permitted by applicable law |
Where we rely on legitimate interests, we consider whether our interests are necessary and balanced against your rights. You may object to processing based on legitimate interests in the circumstances described below.
6. Data Required for a Booking
Certain identity, contact and booking information is necessary to request or administer a Travel Service. If you do not provide required information, the Provider may be unable to confirm or perform the service. Optional marketing information is not required for a Booking.
7. Data About Other Travellers
If you provide data about another person, you confirm that you are authorised to do so and that you have shown them this Privacy Policy. For children, data should be provided by a parent, guardian or another properly authorised adult and only where required for the Travel Service.
8. Who Receives Personal Data
We disclose personal data only where reasonably necessary, including to:
- cruise operators, vessel owners, charter companies, carriers, transfer providers and other suppliers involved in the requested Travel Service;
- vessel masters, crew, local representatives, ports or competent authorities where required for operations, safety or law;
- website hosting, email, contact-form, IT-support, cloud-storage and communications providers acting for us;
- WhatsApp and other communications or social-media providers when you choose those channels;
- accountants, tax advisers, insurers, banks, legal advisers and public authorities where necessary;
- a purchaser or successor if the business is sold or reorganised, subject to appropriate safeguards.
We do not sell personal data. A Provider receiving Booking data normally processes it under its own privacy policy and legal obligations.
9. International Data Transfers
Some travellers, Providers or technology services may be located outside the European Economic Area. Where personal data is transferred internationally, we use an applicable legal mechanism, such as an adequacy decision, appropriate contractual safeguards or a limited statutory derogation where the transfer is necessary for the requested contract. Contact us for further information about relevant safeguards.
10. Data Retention
We retain personal data only for as long as necessary for the stated purpose, including:
- enquiries that do not become Bookings: generally up to 24 months after the last meaningful contact;
- Booking and customer-service records: generally for the duration of the Booking and up to five years afterwards, unless a longer period is needed for a complaint, claim or legal requirement;
- accounting and tax records: for the retention period required by Croatian law;
- complaint records: for at least the legally required period and longer where necessary for a claim;
- marketing data: until consent is withdrawn, an objection is made or the data is no longer necessary;
- technical and security records: for a proportionate period determined by security and operational needs.
When data is no longer required, we delete or anonymise it unless continued retention is legally required.
11. Cookies and Similar Technologies
The website may use strictly necessary cookies required for security, functionality and user choices. Analytics, advertising or other non-essential technologies may be used only where a valid legal basis exists and, where required, after you give consent through the cookie banner.
You can accept, reject or change non-essential cookie choices through the website’s cookie settings. Browser settings may also block cookies, although this can affect website functionality.
The website developer must maintain an accurate cookie inventory identifying each cookie or similar technology, its provider, purpose, duration and category. That inventory should be available through the cookie banner or a separate Cookie Policy.
12. Direct Marketing
We send promotional electronic communications only where permitted by applicable law. Where marketing is based on consent, you may withdraw consent at any time by using the unsubscribe option or contacting [email protected]. Withdrawal does not affect earlier lawful processing.
Service messages relating to an enquiry or Booking are not marketing and may continue where necessary to administer the request or contract.
13. Data Security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. No internet or email transmission can be guaranteed completely secure. Please avoid sending unnecessary passport, payment-card or health data through unsecured channels.
14. Your Data-Protection Rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- request access to your personal data and a copy of it;
- request correction of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a competent supervisory authority.
To exercise a right, email [email protected]. We may request proportionate information to verify identity. We normally respond within one month, subject to lawful extensions for complex or numerous requests.
15. Complaints to the Supervisory Authority
You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): Ulica Metela Ožegovića 16, HR-10000 Zagreb, Croatia; email [email protected]; telephone +385 (0)1 4609-000; website https://azop.hr.
If you live in another EEA country, you may also contact the supervisory authority in that country.
16. Third-Party Websites and Services
The website may link to Providers, WhatsApp, Tripadvisor, social-media platforms and other third-party services. Those parties control their own processing. Review their privacy notices before providing data through their services.
17. Automated Decision-Making
We do not currently make decisions producing legal or similarly significant effects about you solely by automated means. If this changes, we will provide the information and safeguards required by law.
18. Changes to This Policy
We may update this Privacy Policy to reflect legal, technical or business changes. The current version and effective date will be published on the website. Material changes will be communicated where required.
19. Contact
Polaris Yachting, vl. Ivana Tomić Kalina
A. G. Matoša 1, 21314 Jesenice, Croatia
Email: [email protected]
Telephone / WhatsApp: +385 91 793 2955
Website: https://www.polaris-yachting.com