Legal
Privacy Policy
Draft. This text is a working draft prepared for legal review. It is not indexed by search engines and will be replaced by the approved version before launch.
1. Who we are
European River Cruises d.o.o. za turizam i usluge, turistička agencija (“we”, “us”), Vukovarska 26, 20000 Dubrovnik, Croatia, OIB 45810013460, registered with the Trgovački sud u Dubrovniku under MBS 090055156, operates european-river.cruises and acts as the data controller for personal data collected through this website.
2. What data we collect
- Quote and booking requests: name, e-mail address, country, telephone number, preferred travel dates, number of travellers, cabin preferences and any message you send us.
- Bookings: passenger names as they appear on travel documents, dates of birth, nationality and passport details where the cruise operator requires them.
- Payments: we never store card numbers. Payments are processed by a PCI-compliant payment provider (Stripe or WSPay), and we keep only the transaction reference.
- Technical data: IP address, browser type and pages visited, collected through server logs and analytics with your consent (see the Cookie Policy).
3. Why we use it and on what legal basis
- To answer your enquiry and prepare a quote (pre-contractual steps at your request, GDPR Art. 6(1)(b)).
- To make and manage a booking with the cruise operator on your behalf (performance of a contract, Art. 6(1)(b)).
- To meet legal obligations such as accounting and travel-package regulations (Art. 6(1)(c)).
- To send you information about cruises you asked about and, with your consent, occasional offers (Art. 6(1)(a)); you can withdraw consent at any time.
- To keep the website secure and understand how it is used (legitimate interest, Art. 6(1)(f)).
4. Who we share it with
We share only what is needed with the cruise operator you book with, our payment provider, our e-mail and CRM service providers, and professional advisers. Operators outside the EEA receive data under the European Commission’s standard contractual clauses or an adequacy decision.
5. How long we keep it
Enquiry data is kept for 24 months from your last contact. Booking and invoicing records are kept for the period required by Croatian accounting law (currently 11 years). Consent-based marketing data is kept until you withdraw consent.
6. Your rights
You may request access to, correction or deletion of your data, restriction of or objection to processing, and data portability. Write to info@european-river.cruises. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or your local supervisory authority.
7. Security
Data is transmitted over HTTPS and stored on access-controlled systems inside the EU. Card data never touches our servers.
8. Changes
We will post any changes to this policy on this page and update the date above.