Legal

Privacy policy

We collect only the data we need to answer your inquiry and carry out the agreed service.

Last updated: 9 October 2026. The Croatian version of this policy is the authoritative one.

In short: this website uses no analytics or advertising tools. It sets only one strictly necessary security cookie, which does not require consent. We use the data from the form only to answer your inquiry. We do not sell it and we do not send newsletters. You can ask us to delete it at any time.

1. Who processes your data

The controller is Check In Service d.o.o., S. Bušljete 3, 23244 Starigrad Paklenica, Croatia, tax no. (OIB) 57042157706.

For any question about personal data, write to info@checkin.com.hr or call +385 99 5469 030.

2. What data we process and why

PurposeDataLegal basisRetention
Answering an inquiry and preparing a quoteName, e-mail, phone if you give it, content of the messageSteps taken at your request before entering into a contract (Art. 6(1)(b) GDPR)Up to 12 months after the last message, if we do not end up working together
Carrying out the agreed serviceContact details, property address, agreed dates, property access detailsPerformance of a contract (Art. 6(1)(b))For the duration of the cooperation and until statutory limitation periods expire. Access details are deleted when the cooperation ends.
Invoices and bookkeepingName or company name, address, tax number where needed for the invoice, payment detailsLegal obligation (Art. 6(1)(c))11 years, under accounting regulations
Welcoming guests and communicating with them on the owner's behalfGuest's name, contact, arrival and departure datesWe process it as a processor, on the instructions of the property ownerUp to 30 days after the guest's departure, unless the owner instructs otherwise
Booking extra services for guestsName, contact, villa, date and the chosen service; dietary or allergy details only if you give them yourself for the menuSteps before entering into a contract and performance of a contract (Art. 6(1)(b))Up to 12 months after the stay; invoices 11 years
Messages to the owner about the state of the propertyPhotos of the premises, without peoplePerformance of a contractFor the duration of the cooperation
Handling complaintsData from the complaint and our replyLegal obligation under consumer protection regulationsOne year from receipt of the complaint

We do not ask for data that is not needed for these purposes. Only name, e-mail and message are required in the form.

3. What we do not do

  • We do not use analytics, advertising pixels or content embedded from other sites. The only cookie on the site is a strictly necessary security cookie, described in the Cookie policy.
  • We do not build profiles or make automated decisions about you.
  • We do not sell or rent personal data.
  • We do not send newsletters or advertising messages. If we ever introduce them, we will send them only with your consent, and every message will contain an unsubscribe link.

4. Who receives the data

Only our employees who need the data for their work see it. In addition, the data may be received by:

  • our e-mail provider, and the Higgsfield platform and the Cloudflare network through which the site is delivered, as our processors;
  • our bookkeeping service and bank, for invoices and payments;
  • outside tradespeople, who receive only the property address and the contact needed for the repair;
  • partners who provide extra services for guests, who receive only the data needed for the booking;
  • public authorities, where the law requires it.

We do not transfer inquiry data or client data outside the European Economic Area (EEA).

The exception is technical data about a visit to the site, such as the IP address. The site is hosted on the Higgsfield platform and delivered through the Cloudflare network, whose servers are also located outside the EEA. Such transfers are covered by the safeguards of the General Data Protection Regulation: the European Commission's standard contractual clauses or an adequacy decision.

5. Children

Our services and the form are intended for adults. We do not knowingly collect data from children under 16. In Croatia, processing the data of a child under 16 in connection with online services requires the consent of a parent or guardian.

If you believe a child has sent us their data, write to info@checkin.com.hr and we will delete it. We process the data of children staying at a property as guests only where this is necessary for the welcome, on the instructions of the property owner.

6. Your rights

You have the right to request access to your data, its correction, erasure, restriction of processing and portability, and to object to processing. If you have given consent, you can withdraw it at any time.

The request is free of charge. We reply within one month of receipt at the latest. The quickest way is the Data deletion request form; you can also write to us by e-mail or post.

If you believe we are processing your data unlawfully, you can lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.

7. Security and technical logs

Access to data is limited to people who need it for their work. We do not pass keys or property access details to third parties without the owner's approval.

The servers through which the site is delivered may record technical logs of a visit (IP address, time, browser type). They serve the security and proper running of the site and we do not link them to your name.

8. Changes

When we change the way we process data, we will update this page and the date at the top.