Island Essence d.o.o. respects your privacy and protects your personal data under EU and Croatian data protection laws. We collect only the information necessary to process your bookings, coordinate island logistics, and communicate with you effectively. We share essential data only with vetted executing suppliers and trusted processors like Stripe and cloud infrastructure providers. We never sell your personal data. You hold full rights to access, correct, or request the deletion of your personal data at any time.
1. Introduction and Data Controller Identity
This Privacy Policy explains how Island Essence d.o.o. collects, uses, stores, and protects your personal data when you use debonda.com or book our travel services. Island Essence d.o.o., registered at Kranjčevićeva 26, 21000 Split, Croatia (OIB 64945300604), acts as the Data Controller under the General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation. Island Essence d.o.o. has not appointed a formal Data Protection Officer, as the scale and nature of our regular processing do not create that statutory obligation. All privacy inquiries are managed directly by our management desk.
2. Personal Data We Collect
We practice strict data minimization, collecting only data relevant to your itinerary. The categories of personal data we process include:
Booking and Guest Data: Full name, email address, telephone number, pickup location, accommodation address, party size, and the ages or weights of children for vehicle safety seat installations.
Voluntary Health and Dietary Notes: Information you voluntarily disclose regarding food allergies, dietary preferences, or mobility limitations to ensure safe gastronomic and touring experiences.
Consultation and Communication Data: Information submitted through our online inquiry forms, video consultation scheduling, or official WhatsApp chat conversations.
B2B Partner Data: Company names, tax identification numbers, and professional contact details for partner travel agencies.
Payment Metadata: Transaction confirmation timestamps, billing addresses, and masked card metadata processed by Stripe. We never capture or store full credit card numbers on our servers.
Digital Usage and Review Data: First-party website analytics events, IP addresses logged for security, and feedback or reviews you submit after your tour.
3. Purposes and Legal Bases for Processing
We process your personal data strictly under valid legal bases defined by Article 6 of the GDPR:
Contract Performance (Art. 6(1)(b)): Processing booking data, coordinating transport schedules, and managing payments is necessary to fulfill our travel contract with you.
Legal Obligation (Art. 6(1)(c)): We process accounting records, invoicing data, and passenger manifests required by Croatian maritime authorities and tax laws.
Legitimate Interests (Art. 6(1)(f)): We log first-party server analytics and security events to prevent fraud, defend against cyber threats, and optimize our website infrastructure.
Explicit Consent (Art. 6(1)(a) and Art. 9(2)(a)): We process optional non-necessary analytical cookies, marketing pixels, and sensitive dietary or health data strictly on the basis of your freely given, explicit consent.
4. Data Processors and Recipients
To execute your travel arrangements seamlessly, we share relevant data with trusted third-party processors and executing suppliers who operate under strict contractual data protection obligations. Our authorized recipients include:
Executing Suppliers: Licensed vehicle drivers, boat captains, professional guides, and farm culinary hosts receive only the guest names, timings, and dietary notes necessary to perform the booked service.
Payment Processors: Stripe processes all online payment transactions under PCI DSS Level 1 compliance.
Communication Infrastructure: Brevo delivers transactional booking emails and system notifications. WhatsApp is utilized for secure, guest-initiated mobile communication.
Cloud and Hosting Providers: Our web platforms are hosted on secure, managed cloud infrastructure operated under strict contractual data protection safeguards.
Scheduling and Productivity Tools: Google Workspace tools, including Google Calendar and Google Meet, are utilized for scheduling video consultations and internal administrative coordination.
5. International Data Transfers
Some of our digital processors, such as Google and Meta, may transfer data to processing centers located in the United States. When international transfers occur outside the European Economic Area, we ensure lawful compliance through authorized transfer mechanisms, including the EU-US Data Privacy Framework and European Commission Standard Contractual Clauses. These frameworks guarantee that your personal data receives a level of legal protection equivalent to EU GDPR standards.
6. Data Retention Periods
We retain your personal data only as long as necessary to fulfill the operational, statutory, and legal purposes for which it was collected:
Operational Activity Logs: Server logs and standard internal communication records are retained for 12 months.
Security Audit Logs: System security records and consent logs are kept for 24 months as compliance proof.
Statutory Accounting Data: Invoices, billing receipts, and official bookkeeping records are retained for 11 years, as prescribed by Croatian accounting and tax regulations.
Health and Dietary Notes: Sensitive dietary disclosures are deleted immediately after the completion of your travel service.
7. Your GDPR Rights and How to Exercise Them
Under the GDPR, you possess comprehensive rights regarding your personal data. You hold the right to access your data, request rectification of inaccurate records, demand erasure (the right to be forgotten), restrict processing, request data portability, and object to processing based on legitimate interests. Where processing is based on your consent, you hold the right to withdraw that consent at any time without affecting the lawfulness of prior processing. To exercise any of your rights, submit a written request to [email protected]. We will process and respond to your request within 30 days.
8. Right to Lodge a Complaint with AZOP
If you believe that our processing of your personal data infringes European or Croatian data protection laws, you have the statutory right to lodge a formal complaint with the national supervisory authority. In Croatia, the competent authority is the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka, AZOP), located at Selska cesta 136, 10000 Zagreb, Croatia, web: azop.hr.
9. Data Security Measures
We implement robust technical and organizational security measures to safeguard your personal data against unauthorized access, accidental loss, modification, or disclosure. Our security protocols include SSL/TLS encryption for all data in transit, strict role-based access controls for internal staff, secure server firewalls, and IP address hashing in consent logs. We conduct regular reviews of our cloud hosting infrastructure to ensure continuous data protection.
10. Children's Data Protection
Our website and booking services are intended for adults. We do not independently collect personal data directly from children. Any data regarding minors, such as passenger ages for vehicle safety seats, must be volunteered exclusively by the accompanying parent or legal guardian during the booking process. We process children's data solely for safety compliance and transport execution.
11. Changes and Versioning
We may update this Privacy Policy periodically to reflect statutory updates or technological improvements. The revised version will be published on our website with an updated version number and publishing timestamp. Your continued use of our services following the posting of changes constitutes your acknowledgment of the updated terms.