PRIVACY
& cookie policy.

1. Introduction

Villa Stina Drvenik, accessible at villa-stina-drvenik.com, respects your privacy and is committed to protecting your personal data. This policy explains what personal data we collect, why we collect it, who we share it with and what rights you have. It also serves as our cookie policy, so that it is clear how your activity on this website is measured.

It applies to this website and to enquiries you send us through it. If you book through Booking.com or another platform, that platform is responsible for its own processing and has its own privacy policy.

2. Data controller

Villa Stina
Donja Vala 194A
21333 Drvenik, Croatia
Email: villastina.drvenik@gmail.com
Phone: +385 98 900 07 46

We have not appointed a data protection officer; questions about this policy go to the address above.

3. What data we collect

Data you give us. When you send an enquiry we process your name, email address, phone number if you provide it, your preferred arrival and departure dates, the number of guests and anything you write in the message field. If we go on to arrange a stay, we also process the details needed for that stay and for the records Croatian law requires us to keep.

Data collected automatically. When you browse the site we may process your IP address, browser and device type, operating system, language, referring page, the pages you open and your cookie preferences. With the exception of strictly necessary technologies, this only happens if you consent.

We do not knowingly collect data from children and we do not process special categories of personal data through this website.

4. Why we use personal data, and on what legal basis

To answer your enquiry and arrange a stay — Article 6(1)(b) GDPR, steps taken at your request before a contract, and the performance of that contract.

To run and secure the website — Article 6(1)(f) GDPR, our legitimate interest in a working, secure site.

To measure traffic and advertising, and to show ads — Article 6(1)(a) GDPR, your consent, given through the cookie banner. You can withdraw it at any time.

To meet legal and tax obligations — Article 6(1)(c) GDPR, including guest registration and accounting duties under Croatian law.

5. The booking enquiry form

The enquiry form is delivered by Netlify Forms. When you submit it, the data is transmitted to Netlify, stored in our account there and forwarded to us so we can reply. Sending an enquiry is not a reservation; it starts a conversation about availability and price.

Please do not put payment card details, identity document numbers or health information into the message field.

6. Cookies and similar technologies

Cookies are small files stored on your device. We group them as follows:

Strictly necessary — needed for the site to work and to remember your cookie choice. These are used without consent because the site cannot function properly without them.

Analytics — help us understand how the site is used, which pages are read and where visitors stop. Used only with consent.

Marketing — used to measure advertising and to show Villa Stina ads on Google, Facebook and Instagram. Used only with consent.

Consent is collected and stored by Cookiebot CMP. Nothing in the analytics or marketing categories is loaded before you accept it, and rejecting them does not limit your use of the site.

Changing your mind. You can reopen the consent banner at any time using the button below and change or withdraw your choices. You can also delete cookies in your browser settings; note that this deletes the record of your preference too, so you will be asked again.

7. Tools we use

The table below lists the third-party tools active on this website, what each is for and on what basis it runs.

Google and Meta act as independent controllers or joint controllers for parts of this processing and publish their own privacy information, which we recommend reading if you want the full detail of what they do with the data.

8. Who else sees your data

Your data may be handled by the providers listed above, by our hosting and email providers, and by an accountant where a stay has been invoiced. We may also disclose data to public authorities where the law requires it, including the guest registration system Croatian accommodation providers are obliged to use.

We do not sell personal data.

9. Transfers outside the EEA

Some of the providers above are based in, or process data in, the United States. Where that happens, the transfer relies on the European Commission's adequacy decision for the EU–US Data Privacy Framework, or on Standard Contractual Clauses together with additional safeguards.

10. How long we keep it

Enquiries that do not lead to a stay — up to 24 months, so that we can recognise a returning guest and follow up on an unanswered question.

Reservation and invoicing records — for the period required by Croatian tax and accounting law.

Consent records — for as long as needed to demonstrate that consent was given, and then deleted.

Analytics data — according to the retention period configured in the tool, and in aggregated form afterwards.

11. Your rights

Under the GDPR you may request access to your personal data, ask for it to be corrected or erased, ask us to restrict how we use it, object to processing based on legitimate interests, and ask for your data in a portable format. Where processing is based on consent, you may withdraw that consent at any time; this does not affect anything done before you withdrew it.

To exercise any of these rights, write to villastina.drvenik@gmail.com. We answer within one month.

If you believe we have handled your data badly, you may complain to the Croatian Personal Data Protection Agency (AZOP, azop.hr) or to the supervisory authority in your own country.

12. Changes to this policy

We update this policy when the website, its tools or the applicable rules change. The current version is always published on this page with the date it was last updated.

CallAsk about dates