Statement of security, collection and use of personal data
Sideways Ltd. (hereinafter referred to as "the Agency") takes the protection of
the personal data of its users and customers seriously and takes all necessary technical and organizational
measures in accordance with best practices and obligations laid down in Croatian laws and the General Data
Protection Regulation (EC 2016/679) - GDPR. Your personal information is securely stored.
In our business we are guided by the fundamental principles of personal data
protection, which means that we process data lawfully, transparently and fairly. Likewise, processing is
limited to the purpose for which the data was collected and only the data necessary for that purpose is
personal information entered in the registration form or reservation form, and for the purposes and in the ways
You voluntarily submit personal information. You are not required to give them away,
but without them your user profile registration, as well as booking and realization of the service,
cannot be made.
Manager of the personal data processing: SIDEWAYS Ltd., Grge Novaka 13, 23000
Zadar, Republic of Croatia, Personal number: 35603675180
Contact number: +385 91 373 9030
The types of personal data we collect
We primarily collect and process personal data that is part of the execution of
a business relationship, such as: first name, last name, country, mobile phone number, email address.
We collect such personal data during the process of registering a user profile on the website
or during the booking process of each selected service.
In addition, secondarily, and if necessary for the performance of business activities
and unrelated to a specific contractual or business relationship, we may also collect information from publicly
available sources such as the Court Registry or FINA, or in a legitimate manner by third parties.
Purpose and legal basis
Personal data you enter on
, as well as legitimately collected data from third parties or from publicly available sources, is collected and
processed for the following purposes:
• Fulfillment of contractual obligations - when processing is necessary in order to execute the contract in
which you are a party or to take action at your request before concluding the contract itself. This
primarily refers to the registration of a user profile, the realization of a reservation and the processing
of a transaction, which include the following specific purposes:
- • Processing of personal data to register a customer profile at
- • Processing of registered user’s personal data for the purpose of faster checkout
using previously filled booking form;
- • Processing of personal data for the voucher creation, which, when enclosed,
ensures the possibility of consuming a service purchased;
- • Processing of personal data such as first name, last name and email address for
the purpose of transactional email, which is necessary for the customer to be informed of any
changes in the booking process and thus successfully complete it;
- • Processing of personal data such as name, surname and telephone number for the
purpose of a transactional SMS used to successfully complete the booking process, if you decide to
choose this option;
- • Processing of personal data such as first name, last name and email address for
the purpose of informing the customer about the canceled and incomplete booking process, until
he / she declares by email and a button assigned to him that he does not want to receive such notifications;
- • Sharing personal data with a service provider whose service was booked by a
customer. In order to facilitate the booking process and the interaction between the customer and
the service provider, we must share certain customer data, including personal data, with the
service provider. Such an act is necessary in order to complete a reservation and it looks like
the following: When you, as a customer, submit a booking request, some information about you is
shared with the service provider, including your name and citizenship. When the booking is
confirmed by the service provider, we will disclose to him / her the remaining information such as
a telephone number in order for the coordination about the realization of the service can be executed.
- • Use of personal data such as first name, last name, email address and telephone
number for the purpose of contacting you, in case of any change related to your reservation;
- • Use of data on the citizenship of users at the aggregate level for the purpose
of acquaintance with the purchasing habits of the inhabitants of individual countries.
- • Satisfaction of legitimate interests - outside the contractual relationship, in order
to satisfy the legitimate interests of the Agency, such as: conducting court proceedings and keeping records
of them, detecting offenders and preventing fraud and protecting people and property;
- • Fulfilling your requests, to help us develop, deliver and improve our products and
services or for our internal purposes, such as auditing, data analysis and research to improve our products,
services and customer communication.
- • Responding to your queries and comments;
- • Proper compliance with legal obligations - given the variety of business activities,
the Agency must comply with numerous legal obligations. For example, we are obliged to comply with the
Law on Provision of Services in Tourism, etc.
- • The processing of personal data for a specific purpose or for several specific purposes
described by consent through relevant information, such as notification about new products, services or
promotional offers via email, only after we have received your consent to process personal data for a
specific purpose. Your consent is in accordance with the relevant provisions of the Regulation, it is
unconditional and freely given. You also reserve the right to revoke your consent at any time by sending
an email, using the provided button within the email received, or through the user interface at
if you are a registered user.
We do not share your billing information with service providers or other parties.
Use of data
Personal data that we collect and process from our customers and users is
processed only by Agency staff, business partners and contractual partners, which is necessary for the
realization of services. All our partners and employees are responsible for upholding our privacy principles.
We are committed to protecting your personal data.
We will not make personal data available to third parties, with the exception of the
partners listed, except in the case of legitimate interest related to:
- • Competent authorities for the purpose of carrying out activities within their
jurisdiction (for example, Tax Administration and Ministry of the Interior);
- • When the data is needed by a court or the competent public prosecutor's office or other
bodies in equivalent legal proceedings;
- • When the Agency is legally required to provide this data.
Data retention period
We keep your personal data only as long as necessary for the purpose of the
- • In cases where we are bound by certain regulations to store personal data for a longer
period of time, or when our legitimate interests require it (for example, to make, exercise or protect legal claims);
- • In the case of processing personal data on the basis of a consent, when processing
ceases at the time of withdrawal of your consent. Please note that the withdrawal of the consent does not
affect the legality of the consent-based processing prior to its withdrawal.
Personal data protection measures
The data on our site is protected and encrypted with SSL technology, which
enables the secure exchange of information between your browser and
Your data is kept strictly confidential, and in order to protect your personal data,
a multidisciplinary approach is applied, as well as employee education and contracting of appropriate
protection measures with the partners we work with.
Consent withdrawal and data alteration
If you would like to restrict the processing of your personal data, please contact
us in writing using the contact information above.
If you would like to permanently remove your personal information from our database,
all you have to do is contact us in writing.
If you would like to access your personal data for correction or deletion as a
registered user, please go to the User settings page where you can do this, or contact us in writing.
If you believe that there has been an irregularity in the processing of personal data,
please contact the Agency in writing or by telephone.
If you believe that the Agency has no legal basis to process your personal data, you
may file a complaint. In this case, we will no longer process your personal data, nor will we be able to provide
you with your services and be in business with you.
Your rights related to the processing of personal data
Depending on the legal basis of the processing, your rights may be as follows:
- • Transparency: providing data during the process of personal data collecting, when the
processing manager must, among other information, inform the respondent of his / her identity and contact
information, processing purposes and legal basis for processing the data, recipients, transfer to third
countries, storage period, withdrawal options, etc.;
- • Access to data: to obtain from the processing manager confirmation that personal data
relating to her / him are processed and if such personal data is processed - access to personal data and
also information, among other things, about the processed personal data, the purpose of the processing,
storage period, export to other countries etc.;
- • Right to correction: the respondent has the right to request the correction of incorrect
personal data relating to him / her, and taking into account the purposes of processing - the respondent
has the right to supplement incomplete personal data, including by making an additional statement;
- • Deletion: the respondent has the right to have the processing manager delete the
personal data relating to him without undue delay, and the processing manager is obliged to delete the
personal data without undue delay if, among other things, personal data is no longer necessary in the
relationship for the purpose of processing, the respondent has withdrawn his / her consent for processing,
personal data has been illegally processed, etc. This right has limitations, so for example a politician
cannot request deletion of information about himself / herself given in the course of his / her political activity;
- • Right to restriction of processing: In certain situations (for example, when the accuracy
of the data is challenged), the respondent has the right to request that the restriction be restricted with
the exception of storage and some other types of processing;
- • Right to portability: the respondent has the right to receive his or her personal data
previously provided to the processing manager in a structured format and in a commonly used and machine-readable
format and to transfer that data to another processing manager without interruption by the processing manager
to whom personal data has been provided, if the processing is carried out in an automated manner and is
based on a consent or a contract;
- • Right to object: the respondent has the right to object to the processing of personal
data if it is based on tasks of public interest, the exercise of official powers of the processing manager
or the legitimate interests of the processing manager (including profiling). Then the processing manager may
no longer process respondent’s personal data unless he / she proves that his legitimate reasons for
processing go beyond the interests of the respondent and for the protection of legal claims. Also, if the
respondent objects to processing for direct marketing purposes, personal data may no longer be processed;
- • Right to object to automated individual decision making (profiling): the respondent has
the right not to be affected by a decision based solely on automated processing, including the creation of a
profile, which produces legal effects that affect him / her or similarly significantly affect him / her,
except where such a decision is necessary to conclude or execute a contract between the respondents and
the processing manager, if permitted by EU or national law which prescribe appropriate measures for the
protection of the rights and freedoms and legitimate interests of the respondent, or based on the explicit
consent of the respondents.
Cookies and analytics
enable social media features, analyze traffic, and improve the quality of the service we provide through this
site. We also share data about your usage of our site with social media, advertising, and analytics partners,
and they may combine that information with other information you provide or collect while using their services.
Cookies are small text files used by websites to enhance the user experience. The
law allows cookies to be stored on your device if specifically required to operate the site. We need your
permission for all other types of cookies.
These sites use various types of cookies. Some cookies are set by third party
services that are displayed on our site. You may change or withdraw your consent to the Cookie Declaration on
our site at any time.
Links on the
website or within other content provided by the Agency may take you to other websites. These have their own
privacy statements and the ways in which these sites collect and process data are not the responsibility of the
Agency. We recommend that you review their privacy statement by visiting each of these pages.