Privacy Policy
Last updated: 18 June 2026
Welcome to VisitPula.hr. The protection of your personal data is important to us.
This Privacy Policy explains what personal data may be collected when you visit or
use this website, why the data is processed, the legal bases for processing, how
long it may be retained, who may receive it and what rights you have under the
General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
The controller responsible for the processing of personal data through this website is:
Zvonimir Ažić
Ulica Velog Jože 6
52100 Pula, Croatia
Email: hello@visitpula.hr
Website: https://www.visitpula.hr/
For questions regarding this Privacy Policy or the processing of your personal data,
please contact the controller using the email address above.
2. General Principles and Legal Bases
We process personal data only when there is a valid legal basis and only to the extent
necessary for a specific purpose. Depending on the processing activity, the legal basis
may be:
- Consent under Article 6(1)(a) GDPR;
- Performance of a contract or pre-contractual steps under Article 6(1)(b) GDPR;
- Compliance with a legal obligation under Article 6(1)(c) GDPR; or
- Legitimate interests under Article 6(1)(f) GDPR, provided that those interests are not overridden by your rights and freedoms.
Where processing is based on consent, you may withdraw that consent at any time with
effect for the future. Withdrawal does not affect the lawfulness of processing carried
out before consent was withdrawn.
3. Website Hosting and Server Log Files
This website is hosted by SiteGround. When you access the website, the hosting
infrastructure may automatically process technical information necessary to deliver
the website and maintain its security and stability. This may include:
- IP address;
- Date and time of access;
- Requested page or file;
- Referrer URL;
- Browser type and version;
- Operating system and device information;
- HTTP status and technical error information.
This processing is necessary to provide the website, detect and prevent misuse,
investigate technical problems and protect the website and its visitors. The legal
basis is our legitimate interest under Article 6(1)(f) GDPR in operating a secure,
stable and functional website.
Server log data is retained only for as long as reasonably necessary for security,
diagnostic and operational purposes, unless a longer period is required to investigate
an incident, establish or defend legal claims, or comply with a legal obligation.
SiteGround acts as a service provider and processor where it processes personal data
on our behalf. Further information is available in SiteGround’s privacy documentation.
4. Cookies and Similar Technologies
This website uses cookies and similar technologies. Cookies are small text files stored
on your device or accessed through your browser. They may be used to provide essential
website functions, remember your preferences, measure website usage or enable embedded
third-party content.
4.1 Essential cookies
Essential cookies are required for the technical operation, security and basic
functionality of the website, including the storage of your cookie preferences.
These technologies may be used without consent where they are strictly necessary.
The legal basis is our legitimate interest under Article 6(1)(f) GDPR and, where
applicable, the rules governing storage of and access to information on a user’s device.
4.2 Analytics, functional and third-party cookies
Analytics, functional and other non-essential technologies are used only after you
have provided consent through the cookie banner, where consent is legally required.
The legal basis is Article 6(1)(a) GDPR.
You can accept, reject or manage non-essential cookies through the cookie banner or
the cookie settings available on the website. You may change or withdraw your consent
at any time with effect for the future. You can also delete or block cookies through
your browser settings, although this may affect certain website functions.
The exact cookies and technologies currently used, their providers, purposes and
duration should be displayed in the website’s cookie settings or cookie declaration.
5. Google Tag Manager
We may use Google Tag Manager, a service provided by Google, to manage website tags
and control the loading of services such as Google Analytics. Google Tag Manager is
a tag management system and does not itself create website analytics reports.
However, technical information, including your IP address, may be processed when the
service is loaded.
Where Google Tag Manager is used to load non-essential services, those services are
blocked until you provide the relevant consent. The processing is based on Article
6(1)(a) GDPR where consent is required.
6. Google Analytics
With your consent, this website may use Google Analytics 4, a web analytics service
provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics helps us understand how visitors use the website and improve its
content, structure and performance.
Google Analytics may process information such as:
- Pages viewed and interactions with website functions;
- Approximate location derived from technical information;
- Browser, device and operating system information;
- Date, time and duration of visits;
- Referral source;
- Online identifiers and cookie identifiers, where applicable.
Google Analytics is activated only after you provide consent through the cookie banner.
The legal basis is Article 6(1)(a) GDPR. You may withdraw your consent at any time
through the cookie settings.
We do not intentionally send names, email addresses or other directly identifying
contact information to Google Analytics. Analytics data is retained according to the
retention settings configured in the relevant Google Analytics property and Google’s
applicable retention rules.
Google may process data on servers located outside the European Economic Area. Where
personal data is transferred internationally, Google states that it relies on applicable
transfer mechanisms, which may include adequacy decisions, the EU–U.S. Data Privacy
Framework and Standard Contractual Clauses, as appropriate.
More information is available in Google’s Privacy Policy and in Google’s information
on how it uses data from websites and apps that use its services.
7. Google reCAPTCHA
Where forms on this website are protected by Google reCAPTCHA, the service is used to
distinguish legitimate users from automated submissions and to prevent spam, fraud and
abuse. reCAPTCHA may process technical and usage information such as your IP address,
browser and device information, page interactions and security-related signals.
The legal basis is our legitimate interest under Article 6(1)(f) GDPR in protecting
the website and its forms from misuse. Where the applicable implementation or legal
requirements require consent, reCAPTCHA will be loaded only after consent has been
provided.
reCAPTCHA is provided by Google Ireland Limited. Google’s Privacy Policy and Terms of
Service apply to the service.
8. Contact Forms and Email Communication
You may contact us by email or through forms available on the website. Depending on
the form or your message, we may process:
- Your name;
- Email address;
- Telephone number, if provided;
- The content of your message;
- Any files or other information you voluntarily submit;
- Technical information required to send and protect the form.
The data is used to receive, review and respond to your enquiry. The legal basis is
our legitimate interest under Article 6(1)(f) GDPR in communicating with website
visitors. Where your enquiry relates to a possible agreement, partnership, listing,
advertising service or another contractual relationship, the legal basis may also be
Article 6(1)(b) GDPR.
Contact data is retained for as long as necessary to handle the enquiry and any
reasonable follow-up. Data may be retained longer where required by law or where
necessary to establish, exercise or defend legal claims.
Information submitted through a contact form or email is not sold. It may be shared
with technical service providers only where necessary to operate the website,
communications or form delivery, and subject to appropriate safeguards.
9. Newsletter
Where newsletter subscription is available, we process the email address you provide
and, where requested, your name in order to send VisitPula news, travel information,
events, guides or other content described at the point of subscription.
The legal basis is your consent under Article 6(1)(a) GDPR. Additional technical
information, such as the date of subscription, consent status and IP address, may be
stored where necessary to document consent and prevent misuse.
You may withdraw your consent and unsubscribe at any time by using the unsubscribe
link in a newsletter or by emailing
hello@visitpula.hr. After unsubscribing, your
address will no longer be used to send newsletters. Limited information may be retained
where necessary to document the withdrawal of consent or to ensure that no further
messages are sent.
If a third-party newsletter platform is used, that provider may process subscriber data
on our behalf. Any analytics or tracking within newsletters is used only where permitted
by law and, where required, based on consent.
10. Reviews and User-Submitted Content
Visitors may be able to submit reviews, comments, event information, listing information,
photographs or other content for possible publication on VisitPula.hr.
Depending on the submission, we may process your name or chosen display name, email
address, review or submission content, rating, attachments and related technical
information. Your email address is used for administration, verification or communication
and is not published unless this is clearly stated and you have agreed to it.
Content is reviewed before publication. Where you ask us to publish a review or other
content, the processing and publication are based on your consent under Article 6(1)(a)
GDPR. Where a submission concerns a requested listing, event, partnership or service,
Article 6(1)(b) GDPR or our legitimate interests under Article 6(1)(f) GDPR may also
apply.
Published content may remain online until it is no longer relevant, until the relevant
page is removed or until a valid removal request is accepted. You may withdraw consent
for publication by contacting us. This does not affect processing carried out before
withdrawal and does not require removal where another lawful basis or legal obligation
applies.
Please do not submit sensitive personal data, confidential information or personal data
about another person unless you have a lawful basis and authority to do so.
11. Embedded YouTube Content
Some pages may contain videos embedded from YouTube, a service provided by Google.
Embedded videos may establish a connection with Google or YouTube servers and may
transmit information such as your IP address, the page visited, device and browser
information, cookie identifiers and interactions with the video.
Where required, YouTube content is blocked until you provide consent through the cookie
banner or activate the content. The legal basis is Article 6(1)(a) GDPR. If you are
signed in to a Google or YouTube account, Google may associate your interaction with
that account according to its own privacy settings and policies.
Where available, we may use YouTube’s privacy-enhanced mode. This reduces certain data
processing before a video is played but does not eliminate all processing by Google.
12. Links and Content from Other Websites
VisitPula.hr contains links to third-party websites, booking providers, ticket platforms,
tourism operators, restaurants, attractions, social networks and other external services.
When you follow an external link, the third party becomes responsible for its own
processing of personal data. This Privacy Policy does not govern those external websites.
Please review the privacy information provided by the relevant third party.
13. Social Media Profiles
VisitPula.hr may operate profiles or pages on platforms such as Facebook, Instagram,
YouTube, TikTok or other social networks. When you visit or interact with those profiles,
the platform operator processes personal data under its own privacy policy. This may
include profile information, interactions, messages, device information, cookie data
and usage information.
We process information that you send to us through social media in order to respond to
messages, comments and enquiries and to manage the relevant profile. The legal basis is
our legitimate interest under Article 6(1)(f) GDPR in communicating with visitors and
presenting VisitPula.hr. Where communication concerns a potential contract or service,
Article 6(1)(b) GDPR may also apply.
Platform providers may supply aggregated statistics and insights about visits and
interactions. For certain Page Insights data, VisitPula.hr and Meta Platforms Ireland
Limited may act as joint controllers to the extent described in Meta’s Page Insights
Controller Addendum. Meta remains primarily responsible for providing information about
its processing and enabling the exercise of rights relating to Page Insights data.
Social media providers may process data outside the European Economic Area. Their
privacy policies describe the applicable international transfer safeguards.
14. Recipients and Service Providers
Personal data may be made available, only where necessary, to categories of recipients
such as:
- Hosting, security, backup and content-delivery providers;
- Website, form, email and newsletter service providers;
- Analytics and consent-management providers;
- Professional advisers, where necessary;
- Public authorities, courts or other bodies where disclosure is required by law.
Service providers that process personal data on our behalf are required to process it
only under appropriate instructions and safeguards, including data-processing terms
where required by Article 28 GDPR.
We do not sell personal data.
15. International Data Transfers
Some providers, particularly global technology and social media providers, may process
personal data outside Croatia or the European Economic Area.
Where personal data is transferred to a country outside the European Economic Area,
the transfer must rely on a lawful safeguard under Chapter V GDPR. Depending on the
recipient and circumstances, this may include an adequacy decision, participation in
the EU–U.S. Data Privacy Framework, Standard Contractual Clauses approved by the
European Commission or another legally recognised mechanism.
16. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was
collected. The applicable retention period depends on the type of data, the purpose of
processing, the relevant service configuration and any legal requirements.
When data is no longer required, it is deleted, anonymised or securely restricted,
unless continued retention is required to comply with a legal obligation, resolve a
dispute, prevent misuse or establish, exercise or defend legal claims.
17. Data Security
We use appropriate technical and organisational measures designed to protect personal
data against accidental or unlawful destruction, loss, alteration, unauthorised
disclosure or access. These measures may include encrypted connections, access controls,
software updates, backups, security monitoring and measures provided by our hosting
and technical service providers.
No method of transmission or storage is completely secure. We therefore cannot
guarantee absolute security, but we regularly review the measures appropriate to the
nature and risk of the processing.
18. Your Rights
Subject to the conditions set out in the GDPR, you may have the right to:
- Request access to your personal data under Article 15 GDPR;
- Request correction of inaccurate or incomplete data under Article 16 GDPR;
- Request erasure of your data under Article 17 GDPR;
- Request restriction of processing under Article 18 GDPR;
- Receive certain data in a portable format under Article 20 GDPR;
- Object to processing based on legitimate interests under Article 21 GDPR;
- Withdraw consent at any time under Article 7(3) GDPR;
- Lodge a complaint with a competent supervisory authority under Article 77 GDPR.
Where personal data is processed for direct marketing, you have the right to object to
that processing at any time.
To exercise your rights, contact
hello@visitpula.hr. We may need to request
information necessary to verify your identity before responding. Requests are handled
without undue delay and within the time limits prescribed by the GDPR.
19. Right to Lodge a Complaint
You have the right to lodge a complaint with the competent data-protection authority.
In Croatia, the supervisory authority is:
Croatian Personal Data Protection Agency (AZOP)
Agencija za zaštitu osobnih podataka
Ulica Metela Ožegovića 16
10000 Zagreb, Croatia
Website: https://azop.hr/
You may also contact the supervisory authority in the EU Member State of your habitual
residence, place of work or the place of the alleged infringement.
20. Children’s Data
This website is intended as a general tourism and travel information service and is
not designed to collect personal data directly from children. Children should not
submit personal data through forms, reviews or other website features without the
involvement and consent of a parent or legal guardian where required by law.
21. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the website, services,
technology, legal requirements or data-processing activities. The current version will
always be published on this page, together with the date of the latest update.
