This Privacy Policy describes the way in which VISTA SOL d.o.o. (hereinafter: Data Controller) collects, uses, stores and protects personal data of users, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable regulations of the Republic of Croatia.
By using the website and services, the user confirms that they are familiar with this Privacy Policy.
2. Data Controller
- VISTA SOL d.o.o.
- Planinarski put 9 HR-21300 Veliko Brdo, Makarska Croatia
- MB: 4344260
- EUID: HRSR.060325857
- Phone: +385 21 553 077
- OIB:35244550674
3. Purpose and Scope of Processing
Personal data is processed exclusively for the following purposes:
- processing and realization of vehicle reservations
- concluding and executing vehicle rental contracts
- customer support and communication
- maintaining records in accordance with legal obligations
- property protection and prevention of abuse
- sending service-related information (including reservation notifications)marketing promotion (with consent, where required)
4. Legal Basis for Processing
The processing of personal data is based on:
- Art. 6 para. 1. (b) GDPR - contract performance
- Art. 6 para. 1. (c) GDPR - legal obligation
- Art. 6 para. 1. (f) GDPR - legitimate interest
- Art. 6 para. 1. (a) GDPR - user consent (marketing, newsletter)
5. Categories of Personal Data
The following categories of data are processed:
- identification data (name, surname)
- contact data (phone, email, address)
- data on reservations and service usage
- data on driving license and authorization to operate a vehicle
- payment data
- technical data (IP address, system logs)
6. Data Recipients
- Personal data may be available to:
- employees of the Data Controller
- contractual partners and service providers
- financial institutions
- IT and hosting providers
- competent state bodies, when there is a legal obligation
Data is not sold or transferred to third parties without legal basis.
7. International Data Transfer
If data is transferred outside the European Union, an appropriate level of protection is ensured in accordance with GDPR (e.g. standard contractual clauses).
8. Data Retention Periods
Personal data is kept:
- for the duration of the contractual relationship
- for periods prescribed by law (e.g. accounting regulations)
- until consent is withdrawn (for data based on consent)
After the expiration of the period, data is securely deleted or anonymized.
9. Data Subject Rights
The user has the following rights:
- right to access data
- right to correct inaccurate data
- right to erasure ('right to be forgotten')
- right to restriction of processing
- right to data portability
- right to object to processing
- right to withdraw consent at any time
To exercise rights, the user can contact us via email.
10. Right to Object
to the supervisory body The user has the right to submit an objection:
- Personal Data Protection Agency (AZOP)
- Selska cesta 136
- 10000 Zagreb Croatia
11. Data Security
Appropriate technical and organizational protection measures are applied, including:
- access control
- encryption where applicable
- system protection from unauthorized access
- regular security checks
12. Automated Decision Making
Automated decision making or profiling that would have legal effects on the user is not conducted, unless explicitly stated with user consent.
13. Use of Cookies
The website uses cookies in accordance with applicable regulations. Detailed information about cookies is available in a separate Cookie Policy.
14. Changes
to the Privacy Policy The Data Controller reserves the right to change this Privacy Policy at any time. The updated version will be published on the website and enters into force upon publication.
15. Contact
For all questions related to personal data processing, contact us.