Privacy Policy
Dinary Apartments & Dinary Deluxe Apartments – Vir, Croatia
Last updated: 11 August 2026
This Privacy Policy explains how personal data is collected, used, stored and protected in connection with the website
dinaryvir.com, accommodation enquiries, reservations and stays at Dinary Apartments
and Dinary Deluxe Apartments in Vir, Croatia. Personal data is processed in accordance with Regulation (EU) 2016/679
(General Data Protection Regulation – GDPR), applicable Croatian data protection legislation and other applicable European Union law.
1. Data Controllers
Dinary Apartments
Property address: Miljkovica XIV. 17, 23234 Vir, Croatia
The accommodation units at this property are operated by:
Osztheimer Gyöngyi
Address: Miljkovica XIV. 19, 23234 Vir, Croatia
Operator of the top-floor accommodation unit.
Andrey Liebl
Address: Miljkovica XIV. 19, 23234 Vir, Croatia
Operator of the ground-floor and first-floor accommodation units.
Dinary Deluxe Apartments
Accommodation address: Miljkovica XIV. 19, 23234 Vir, Croatia
Operated by: VIR-ADRIA d.o.o.
Registered office: Prezida XVIII. 5-7, 23234 Vir, Croatia
OIB / VAT ID: HR14830582865
Privacy contact: dinaryvir@gmail.com
Where an enquiry or reservation relates to a particular accommodation unit, the operator of that unit is the relevant controller
of the personal data necessary to process the enquiry, reservation and stay.
2. Personal Data We Collect
Depending on how you contact us or make a reservation, we may process personal data including:
- name and surname;
- e-mail address;
- telephone number;
- arrival and departure dates;
- number of guests;
- information included in messages or enquiries;
- reservation and accommodation information;
- information necessary for guest registration under Croatian law;
- billing and payment information where applicable;
- correspondence relating to an enquiry, reservation or stay.
We collect only personal data that is necessary for the relevant purpose.
3. Contact and Enquiry Form
When you submit an enquiry through dinaryvir.com, we may collect your name, e-mail address,
telephone number, requested arrival and departure dates, number of guests, message and other information you voluntarily provide.
This information is used to respond to your enquiry, check availability, prepare an accommodation offer and, where requested,
take steps towards concluding a reservation.
The legal basis is Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract
and, where applicable, Article 6(1)(f) GDPR based on our legitimate interest in responding to enquiries.
4. Reservations and Accommodation Services
When you make a reservation, we process personal data as necessary to administer and confirm the reservation, communicate with you,
provide the accommodation service, process payments, issue invoices or required documentation, fulfil statutory guest-registration,
accounting, tax and tourism obligations, and handle requests, complaints or disputes.
Depending on the purpose, processing is based on Article 6(1)(b) GDPR (performance of a contract) and/or Article 6(1)(c) GDPR
(compliance with a legal obligation).
5. Reservations Through Third-Party Platforms
If you book through an external booking platform such as Booking.com or Airbnb, that platform processes certain personal data under
its own privacy policy. We receive the information necessary to administer your reservation and provide the accommodation service.
The platform is responsible for its own processing; the relevant accommodation operator is responsible for personal data subsequently
processed for your reservation and stay.
6. Legally Required Guest Data
As accommodation providers in Croatia, we may be legally required to collect and process certain guest identification and stay
information and submit required information to competent Croatian authorities or official tourism registration systems. Such data is
processed only to the extent required by applicable law. The legal basis is Article 6(1)(c) GDPR.
7. Payments, Accounting and Tax Documentation
Where necessary, personal data contained in invoices, payment records, contracts and other accounting or tax documentation is processed
and retained in accordance with applicable Croatian accounting, tax and other statutory requirements. Access is limited to persons and
professional service providers who require the information for legitimate accounting, administrative or legal purposes.
8. Video Surveillance (CCTV)
For the protection of guests, persons and property, video surveillance systems are installed at:
- Dinary Apartments – Miljkovica XIV. 17, 23234 Vir, Croatia;
- Dinary Deluxe Apartments – Miljkovica XIV. 19, 23234 Vir, Croatia.
Cameras are located on exterior parts and corners of the buildings and in the vicinity of entrances.
The purpose is the protection and security of persons and property, including prevention and investigation of theft, vandalism,
property damage, unauthorised access and other security incidents.
The legal basis is the legitimate interest of the relevant property operator under Article 6(1)(f) GDPR and applicable Croatian law.
The cameras record video images only. No audio is recorded.
Camera positioning and viewing angles are intended to be limited to areas necessary for the protection of persons and property.
Video surveillance is not intended to monitor neighbouring properties or public areas beyond what may be unavoidable and strictly necessary.
Retention: CCTV recordings are normally retained for a maximum of 7 days and are then automatically overwritten or deleted.
A specific recording may be retained longer where necessary in connection with a security incident, damage, suspected unlawful activity,
the establishment, exercise or defence of legal claims, or a lawful request from a competent authority.
Access: Access to recordings is restricted to authorised persons. Recordings may be disclosed to competent authorities where
required or permitted by law. Appropriate technical and organisational measures are used to prevent unauthorised access. Appropriate
video-surveillance notices are displayed at the monitored properties.
10. Recipients of Personal Data
We do not sell personal data.
Where necessary, personal data may be made available to:
- accounting and professional advisers;
- IT, website-hosting and technical service providers;
- payment and banking service providers;
- booking platforms;
- competent tourism and guest-registration authorities;
- tax, administrative, police, judicial or other competent authorities;
- processors acting on documented instructions where necessary for providing our services.
11. International Data Transfers
Some third-party technology or online service providers may process personal data outside the European Economic Area. Where such transfers
occur, appropriate safeguards required by the GDPR will be applied, where applicable.
12. Data Retention
Personal data is retained only for as long as necessary for the purpose for which it was collected or for the period required by applicable law.
Enquiry information that does not result in a reservation is retained only for as long as reasonably necessary to deal with the enquiry and
related correspondence. Reservation and guest information is retained as necessary to provide the service and thereafter for legitimate
administrative or legal purposes. Accounting, invoice and tax documentation is retained for the period required by Croatian law. CCTV recordings
are normally retained for a maximum of 7 days, subject to the exceptions described in Section 8.
13. Data Security
We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss,
alteration, unauthorised disclosure or access. Access is limited to persons who require the data for the performance of their duties or
provision of the relevant service.
14. Your Rights Under the GDPR
Subject to the conditions established by the GDPR, you may have the right to:
- request access to your personal data;
- request correction;
- request deletion;
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability where applicable;
- withdraw consent where processing is based on consent;
- lodge a complaint with the competent supervisory authority.
Requests concerning personal data may be sent to dinaryvir@gmail.com.
We may request appropriate information to verify your identity before responding.
15. Right to Lodge a Complaint
If you believe that your personal data has been processed in violation of applicable data-protection law, you have the right to lodge a complaint with:
Croatian Personal Data Protection AgencyAgencija za zaštitu osobnih podataka (AZOP)
Ulica Metela Ožegovića 16
10000 Zagreb, Croatia
E-mail: azop@azop.hr
Telephone: +385 (0)1 4609-000
You may also exercise any other remedies available under the GDPR and applicable law.
16. Children’s Personal Data
Where information concerning children is required in connection with an accommodation reservation, guest registration or another legal
obligation, it is processed only to the extent necessary for providing the accommodation service or complying with applicable law.
We do not knowingly use children’s personal data for direct marketing purposes.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website functionality, legal requirements or
data-processing practices. The current version will be published on dinaryvir.com together with the date
of the latest update.