Admin
Uncategorised
28 February 2026
Who We Are
Our website address is: www.avantgardeservice.com
Registered office of the travel agency Avangardni Servis d.o.o.
Sv. Križa 3, 20 000 Dubrovnik, Croatia
OIB: 25030544593
MBS: 090024517
Client Personal Data Protection Policy
INTRODUCTORY PROVISIONS
Avangardni Servis d.o.o., Sv. Križa 3, 20 000 Dubrovnik, OIB 25030544593, MBS 090024517, Tel. +385 99 203 46 51, Email:
The purpose of this Policy is to provide all interested parties with the necessary information on how personal data is processed and protected, and on the rights clients/travelers have regarding the processing of their personal data.
SCOPE
This Policy applies to all personal data of travelers/clients collected and processed by Avangardni Servis, as well as data collected and processed by partners on behalf of Avangardni Servis.
A client is any person who has requested a service or service offer from Avangardni Servis.
Personal data means any information relating to an identified or identifiable individual (Article 4 of the GDPR).
Processing means any operation performed on personal data (Article 4 of the GDPR).
PRINCIPLES OF PERSONAL DATA PROCESSING
Lawful, Fair and Transparent Processing
We process data in accordance with applicable data protection laws and best business practices.
Purpose Limitation
Data is processed solely for the purpose for which it was collected.
Data Minimization
We collect and process only the data necessary to achieve the intended purpose.
Accuracy
We ensure the accuracy of collected data. Clients have the right to access and correct their data at any time.
Storage Limitation
Data is processed and stored only as long as necessary for the purpose for which it was collected or as required by law.
Data Security
We apply the highest possible level of personal data protection.
CLIENT RIGHTS
In accordance with the GDPR, clients have the following rights:
Right of Access
Clients may request confirmation as to whether their personal data is being processed and obtain information regarding:
- Purpose of processing
- Categories of personal data
- Recipients of the data
- Storage period
- Right to rectification, erasure, or restriction
- Right to lodge a complaint
- Automated decision-making (including profiling)
- Safeguards for transfers to third countries
Right to Rectification and Erasure
Clients have the right to correct inaccurate data and request deletion unless retention is legally required or necessary for contract execution.
Right to Restriction of Processing
Clients may request restriction of processing under GDPR conditions.
Right to Data Portability
Clients may receive their data in a structured, commonly used, machine-readable format and transfer it to another controller.
Right to Object
Clients may object at any time to data processing, including direct marketing.
Automated Decision-Making
Clients have the right not to be subject to decisions based solely on automated processing, including profiling.
METHODS OF DATA COLLECTION
We collect personal data:
In-Office
When making reservations or preparing offers. Data may be provided in person, by phone, email, or by another person on the client's behalf.
Via Website
Through reservation or inquiry forms on our website.
Client Consent
Consent is any freely given, specific, informed, and unambiguous indication of agreement to process personal data (Article 4 GDPR). Without consent, we will not use personal data where consent is legally required.
TYPES OF PERSONAL DATA COLLECTED
We collect only data necessary for service execution, including:
- First and last name
- Children's dates of birth (for discounts)
- Phone number and email
- Location
- Gender
- Nationality
- Passport or ID number (when legally required)
- Credit card/payment details
Due to the nature of travel services, special categories of personal data (e.g., health information or religious requirements) may be processed strictly for contract execution. Providing such data constitutes explicit consent.
PURPOSE OF DATA COLLECTION
Contract Performance
To provide requested services or prepare service offers.
Marketing (With Consent)
To inform clients about services and products that may be of interest.
Internal Purposes
To protect legitimate interests (e.g., complaint handling, fraud prevention, service improvement, customer support, market research).
Legal Obligations
To comply with legal requirements or official requests from authorities.
TRANSFER OF DATA TO THIRD PARTIES
Data may be shared:
- With hotels, carriers, or service providers to fulfill contracted services
- With third parties based on explicit consent
- With contracted processors/subcontractors under binding agreements ensuring GDPR compliance
DATA SECURITY
We apply best practices in tourism and IT security.
We continuously improve internal procedures and implement organizational and technical measures to prevent unauthorized access, loss, theft, or misuse.
CONTACT
To exercise GDPR rights or report concerns, contact:
Email:
Address: Sv. Križa 3, 20 000 Dubrovnik
Clients may also lodge complaints with the Croatian Personal Data Protection Agency.
WEB SHOP DATA
When purchasing via our web shop, we collect:
- Billing details
- IP address
- Browser user agent string
Data is used for:
- Order processing
- Customer communication
- Fraud prevention
- Legal compliance
- Marketing (if opted in)
If an account is created, personal data is stored for future purchases.
COOKIES
We use cookies for:
- Comment convenience (stored for 1 year)
- Login sessions (2 days or 2 weeks with "Remember Me")
- Screen preferences (1 year)
- Article editing (1 day)
Embedded content from third-party websites may collect additional data and use cookies.
DATA SHARING
We do not publicly share personal data.
Web shop personal data (name, surname, address, phone) is shared only with partner travel agencies when required to execute purchased travel programs.
DATA RETENTION
Registered users may view, edit, or delete their data (except username).
Administrators may access and manage necessary information for order fulfillment and customer support.
YOUR RIGHTS
You may request:
- Export of your personal data
- Deletion of your data (except data required for legal purposes)
- Deletion of your web shop account
DATA BREACH PROCEDURES
In the event of a personal data breach, you will be informed within 24 hours of detection via email.
Additional protective measures may include password resets and phone verification of suspicious transactions.
