The protection of your personal data is important to us. This privacy policy explains what information we collect when you use the visitbaska.com website, for what purpose we use it, to whom we pass it on and what rights you have in relation to it. The policy has been developed in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the General Data Protection Regulation Implementation Act.
Data Controller
The controller of personal data collected through this website is:
- Name: Ernest Perić (natural person)
- OIB: 87596637525
- Address: Drage Šćitara 34, Rijeka, Republic of Croatia
Contact for privacy issues: [email protected]
For any questions regarding the processing of your personal data, exercising your rights or this privacy policy, you can contact us at the email address provided.
What information we collect
As part of the work of the portal, we collect the following categories of data:
Cookies — we use cookies for the basic functioning of the site and, with your consent, for traffic analytics. A detailed list of cookies is available in our Cookie Policy.
IP address and browser information — when accessing the site, our infrastructure providers (Cloudflare as CDN and protection, and server logs at Kinsta hosting) automatically record the IP address, browser type and version, operating system, and access time. This data is used exclusively for security, misuse prevention and technical diagnostics.
Contact form data — if you contact us via the contact form on the website (where available), we collect data that you voluntarily provide to us (name, email address, message content) in order to respond to your inquiry.
Information sent by your browser when you click on affiliate links — when you click on a link to partner platforms (Stay22 for accommodation, GetYourGuide for activities), your browser sends standard HTTP data (referrer URL, IP address, affiliate link identification parameters) to these platforms for the purpose of tracking referrals and possible commission earnings. Further processing of this data takes place in accordance with the privacy policy of the respective platform.
Legal basis for processing (GDPR Article 6)
The processing of personal data is based on one of the following legal bases, depending on the purpose of the processing:
- A legitimate interest (art. 6th century 1. point f) — for necessary (technical) cookies, site security, prevention of misuse and basic functioning of the portal.
- Consent (Art. 6th century 1. point a) — for analytical and marketing cookies, which are only activated after your explicit consent via a cookie banner.
- Performance of a contract or taking action at your request (Art. 6th century 1. point b) — when you contact us via the contact form or request a specific service.
To whom the data is passed on
For the purpose of the portal’s operation, personal data may be forwarded to the following recipients:
- Google (Google Analytics 4) — after your consent, Google Analytics 4 (measurement ID G-FMEFP5488F) processes pseudonymised statistical data on portal usage. IP address anonymisation is active, and Google Signals and personalised advertising are not enabled.
- Microsoft (Clarity) — after your consent, Microsoft Clarity (project xphncp9rdx) collects anonymous heatmaps and session recordings to identify technical issues and improve user experience. Form field content, passwords and other sensitive text are automatically masked before recording.
- Google (Maps) — we use Google Maps to display interactive maps of locations (accommodation, restaurants, activities), which may process the visitor’s IP address when loading a map.
- Stay22 — when you click on an affiliate link for accommodation, the browser passes the data to the Stay22 platform to process the reservation and record the referral.
- GetYourGuide — when you click on an affiliate link for an activity or excursion, the browser passes the data to the GetYourGuide platform in the same way.
- Cloudflare — we use Cloudflare as a CDN (content delivery network) and protection against malicious access, and for email routing of our contact address.
- Kinsta — our hosting provider, whose servers are located in EU locations, provides the infrastructure on which the site runs and handles technical server logs.
These recipients process the data in their capacity as processors or independent controllers, depending on their own privacy policy.
Transfer of data to third countries
Some of these service providers (primarily Google and Microsoft) are headquartered or have infrastructure outside of the European Economic Area, including the United States. Such data transfers take place on the basis of the mechanisms provided for in the GDPR, including the EU-US Data Privacy Framework (DPF), which is recognized by the European Commission as an adequate level of data protection for certified US companies. We recommend that you check the privacy policies of these third parties for details on your own data processing.
Data retention period
We keep personal data only for as long as necessary to achieve the purpose for which it was collected:
- The data from cookies is stored in accordance with the duration of each cookie (see Cookie Policy).
- Server logs are typically kept for up to 30 days for security analysis, unless a longer period is necessary to investigate a security incident.
- The data from the contact form is stored for a maximum of two years from the last contact, unless otherwise required by law or if there is an ongoing business relationship.
Your rights
As a data subject, in accordance with the GDPR, you have the right to:
- access to your personal data that we process,
- to rectify incorrect or incomplete data;
- to erasure of data (“right to be forgotten”), to the extent permitted by law;
- restriction of processing in certain circumstances,
- to object to processing based on legitimate interest,
- the portability of the data we have collected on the basis of consent or contracts;
- to withdraw consent at any time, without affecting the lawfulness of the previous processing,
- to lodge a complaint with a data protection supervisory authority.
Requests to exercise the above rights can be sent to [email protected]. We will respond within the statutory period of a maximum of one month from receipt of the request.
Supervisory authority
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
Personal Data Protection Agency (AZOP) Selska cesta 136, 10000 Zagreb, Republic of Croatia
Data security
We take reasonable technical and organizational measures to protect personal information from unauthorized access, loss, misuse, or disclosure, including the use of HTTPS encryption, security protection through Cloudflare, and hosting on Kinsta infrastructure with regular security updates.
Despite the measures taken, no data transmission system over the Internet is completely secure, so we cannot guarantee absolute data security.
Changes to this policy
We may update this privacy policy from time to time to comply with legal changes or changes in the way the portal works. The date of the last modification is indicated at the bottom of this page. We recommend that you periodically check this page for any changes.
Last modified: 16 July 2026