Legal information
Privacy policy
This policy explains which personal data we collect when you request a photo session at Erdődy Castle Kerestinec, why we collect it and what rights you have.
Data controller
The controller of your personal data is:
City of Sveta Nedelja (Grad Sveta Nedelja)
Trg Ante Starčevića 5, 10431 Sveta Nedelja, Croatia
- OIB (tax number)
- 24436052952
- Phone
- +385 1 3335 444
- pitanja@grad-svetanedelja.hr
Data protection officer
For any questions about how your personal data is processed, or to exercise your rights, please contact the data protection officer of the City of Sveta Nedelja:
Miroslav Dubić
What data we collect
When you send a photo session request, we collect only the data needed to handle it:
- first name and surname
- e-mail address
- phone number
- number of people
- type of photo session
- preferred language
- selected slot (date, start time and duration)
- time at which you accepted the terms of use and confirmed that you had read the privacy policy
When you send the form, technical data is also processed:
- IP address, to limit the number of requests and to protect against abuse (it is not stored in the booking database)
- technical data about your browser and device collected by Cloudflare Turnstile
You do not need an account, and we do not ask for your OIB or any other identification number. You are not legally required to provide your data, but all fields in the form are required, as we cannot handle the request or book the slot without them.
Purpose and legal basis
Handling your request and booking
We process the data from the form in order to:
- receive and handle your request, and approve or decline it,
- notify you by e-mail that we have received your request, of the City's decision and of any changes to your slot,
- let you cancel your booking through the personal link in the e-mail,
- keep the booking calendar and prevent double bookings.
The legal basis is Article 6(1)(b) of the General Data Protection Regulation (Regulation (EU) 2016/679): processing is necessary to take steps at your request before the booking and to carry out the booking in line with the terms of use.
Protecting the form and keeping the system secure
We process your IP address and technical data about your browser in order to protect the form against automated and malicious requests, to limit the number of requests from the same address, and to keep the system secure and available, including backups. The legal basis is Article 6(1)(e) of the General Data Protection Regulation: processing is necessary for the performance of a task carried out by the City in the public interest, as part of managing the City's property, in connection with the obligation to ensure the security of processing under Article 32 of the Regulation.
Processing is not based on consent. By ticking the box in the form, you confirm that you have read this policy; you are not giving consent. We do not use your data for marketing, we do not sell it, and we do not make automated decisions or create profiles. Every request is reviewed and decided on by an authorised person at the City.
Who processes the data
Only authorised staff of the City of Sveta Nedelja who handle booking requests have access to your data. They sign in to the administration through a protected sign-in (Cloudflare Access). The e-mail notification about a new request, with your name, e-mail address and phone number, is sent to the City's official e-mail address.
The City uses the following processors, which may process the data only on the City's instructions and for the purposes set out in this policy:
- MFB Solutions: MFB Solutions, obrt za digitalne, poslovne i uslužne djelatnosti (sole trader), Klenovec 6, 10431 Jagnjić Dol, Croatia, builds and maintains the website and the booking system, including technical support and fixing faults.
- Cloudflare, Inc. (101 Townsend St., San Francisco, USA), as a sub-processor, for the technical operation of the website:
- Cloudflare Workers: website hosting and request handling
- Cloudflare D1: booking database, located in the European Union
- Cloudflare R2: database backups, located in the European Union
- Cloudflare Email Service: sending booking e-mail notifications
- Cloudflare Turnstile: protecting the form against automated (bot) requests
- Cloudflare Web Analytics: anonymous visitor statistics, without cookies
For Cloudflare Turnstile, Cloudflare also processes some of the technical data as an independent controller, to improve the detection of automated programs. You can read more in Cloudflare's Turnstile privacy notice.
We do not share your data with any other recipients unless the law requires us to (for example at the request of a court or another competent authority). The website is served only over an encrypted connection (HTTPS), and fonts are served from the website itself, without any external font service.
Transfers outside the EU
The booking database and the backups are located in the European Union. Cloudflare is a US company and handles requests on its global network, so some data (for example your IP address when a request is transmitted, sending e-mails and the Turnstile check) may also be processed outside the European Economic Area, including in the USA.
Such transfers are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), under which Cloudflare, Inc. is certified, and on the standard contractual clauses adopted by the European Commission, which form part of Cloudflare's data processing addendum. The list of certified companies is published at dataprivacyframework.gov.
How long we keep the data
We keep the data from your request for 12 months after the date of the session. After that, the personal data is automatically anonymised, and only a record that the slot existed is kept (date, time, type of session and number of people), without any data that could identify you.
Database backups are made once a week and kept for 8 weeks, after which they are deleted automatically. The database also allows a technical restore to any point in the last 30 days. This means that data already anonymised in the database may remain in backups and restore records for up to 8 more weeks. This data is used only to restore the system after a failure.
Technical server logs, which may contain your IP address, are kept for no more than 7 days. E-mail notifications about requests received by the City are kept in the City's official mailbox in line with the law and the City's rules on keeping records.
Cookies
The website does not use analytics, advertising or tracking cookies, which is why there is no cookie notice for you to accept. Only what is strictly necessary for the service you have requested is used, which does not require consent under Article 43(4) of the Croatian Electronic Communications Act (Zakon o elektroničkim komunikacijama, Official Gazette No 76/22):
- Cloudflare Turnstile is loaded only on the booking form page and checks that the request is sent by a person and not by an automated program. In doing so, it may store or read strictly necessary technical data in your browser, solely to protect the form against abuse.
- Signing in to the administration (for authorised City staff only) uses a strictly necessary sign-in cookie.
Cloudflare Web Analytics counts visits without cookies or any other data stored in your browser, and does not track individual visitors.
Your rights
With regard to your personal data, you have the right to:
- access your data and receive a copy of it,
- have inaccurate or incomplete data rectified,
- have your data erased,
- restrict processing,
- data portability for the data you gave us in the form,
- object, on grounds relating to your particular situation, to processing based on Article 6(1)(e).
Please send your request to the data protection officer at miroslav.dubic@grad-svetanedelja.hr. We will reply without undue delay and in any event within one month. You can cancel your request or approved booking at any time through the link in the e-mail you received after sending the request. You can read more about cancellation in the terms of use.
Complaint to the supervisory authority
If you believe that your personal data is being processed unlawfully, you can lodge a complaint with the supervisory authority:
Croatian Personal Data Protection Agency (AZOP)
Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia
- azop@azop.hr
- Website
- azop.hr
Changes to this policy
We may update this policy from time to time, for example when the law or the way the website works changes. The current version is always published on this page, with the date of the last update at the top.
This is a translation. In case of any discrepancy, the Croatian version prevails.