Skip to main content

Privacy Policy

Last updated:

1. Introduction

Given2Fly, obrt za usluge i turistička agencija, vl. Mariana Andrijašević (“Given2Fly Adventures”, “we”, “us”, “our”) is committed to protecting the privacy and personal data of our customers, website visitors, and tour participants. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the applicable data protection laws of the Republic of Croatia.

Data Controller: Given2Fly, obrt za usluge i turistička agencija, vl. Mariana Andrijašević Plinarska 25, 21000 Split, Croatia Email: given2flyadventures@gmail.com

2. Data We Collect

We may collect the following categories of personal data:

  • Identity data: Full name, date of birth, nationality.
  • Contact data: Email address, phone number, postal address.
  • Identification data: Photo ID number (passport, national ID, or driving licence) – retained only for the duration of the rental.
  • Payment data: Credit/debit card details processed securely through our payment provider. We do not store full card numbers.
  • Health data: Medical conditions disclosed voluntarily through the Medical Waiver, collected for safety purposes only.
  • Booking data: Dates, services booked, preferences, group size.
  • Technical data: IP address, browser type, device information, and cookies when you visit our website.
  • Communication data: Messages sent via email, contact forms, WhatsApp, or social media.

3. How We Use Your Data

We process your personal data for the following purposes:

| Purpose | Legal Basis (GDPR) | |---|---| | Processing bookings and rentals | Performance of a contract | | Safety and medical preparedness | Legitimate interest / Vital interest | | Sending booking confirmations and receipts | Performance of a contract | | Responding to enquiries | Legitimate interest | | Marketing emails and newsletters | Consent (opt-in) | | Website analytics and improvement | Legitimate interest | | Legal compliance and dispute resolution | Legal obligation |

4. Data Sharing

We do not sell your personal data. We may share data with:

  • Payment processors for secure transaction handling.
  • Insurance providers in the event of an accident or claim.
  • Law enforcement or regulatory bodies when required by law.
  • IT service providers who host our website and manage our booking system, under appropriate data processing agreements.

5. Data Retention

We retain personal data only for as long as necessary:

  • Booking and rental records: 5 years (Croatian tax/accounting obligations).
  • ID copies: Deleted within 24 hours of equipment return.
  • Medical waiver data: Duration of the activity plus 3 years (statute of limitations for personal injury claims).
  • Marketing consent records: Until consent is withdrawn.
  • Website analytics data: 26 months (anonymised).

6. Your Rights

Under the GDPR, you have the right to:

  • Access your personal data and request a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”), subject to legal retention requirements.
  • Restrict processing in certain circumstances.
  • Object to processing based on legitimate interest, including direct marketing.
  • Data portability – receive your data in a structured, machine-readable format.
  • Withdraw consent at any time for processing based on consent.

To exercise any of these rights, contact us at given2flyadventures@gmail.com. We will respond within 30 days.

7. Cookies

Our website uses cookies to improve your browsing experience. For details on the cookies we use and how to manage them, please refer to our cookie banner and settings available on the website.

8. Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), secure payment processing, access controls, and regular security reviews.

9. International Transfers

Your data is stored and processed within the European Economic Area (EEA). If any data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.

10. Children’s Privacy

We do not knowingly collect personal data from children under 16 without parental consent. If you believe we have inadvertently collected such data, please contact us immediately.

11. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): azop.hr.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website with the “Last Updated” date shown above.