Protecting your data matters to us. This policy explains which data we process for our website, bookings, guest registration and your stay, why and for how long – and what rights you have.
Korčulaia d.o.o.
Poljička 5/V, 10000 Zagreb, Croatia
OIB 94565411959 · Managing directors: Anna Gutgsell, Christian Gutgsell
E-mail: christian@korculaia.com · anna@korculaia.com
Our website is delivered by Netlify (Netlify, Inc., San Francisco, USA). When you visit, the server processes technically necessary data (IP address, date and time, page requested, browser and operating system) to deliver the site and protect it against misuse. The legal basis is Art. 6(1)(f) GDPR. We do not analyse these logs or combine them with other data.
We do not use tracking or advertising cookies, analytics tools or social media plugins. Fonts are hosted locally on our server – no connection to Google Fonts is made. Links to Instagram and Google Maps only open when you click them; the privacy policies of those providers then apply.
The contact form opens your e-mail program; you send the message directly to us. We process your details (name, e-mail address, content) to answer your enquiry (Art. 6(1)(b) or (f) GDPR). Our e-mail runs on Google Workspace (Google Ireland Limited, Dublin).
When you book through our website, we process your name, e-mail address, phone number, country, travel dates, number of guests, requests and message in order to handle the booking, send you payment details and confirmations and prepare your stay (Art. 6(1)(b) GDPR). Payment is made by bank transfer; our bank (Erste & Steiermärkische Bank d.d.) provides us with the payer's name, account details and the amount.
Booking data is stored in our database at Supabase (Supabase, Inc.; servers in Ireland, EU). Our automatic e-mails contain no tracking pixels or tracking links.
For bookings made on Airbnb, Airbnb (Airbnb Ireland UC, Dublin) is responsible for the processing on its platform. Airbnb passes on to us the details needed for your stay (e.g. name, travel dates, number of guests). The calendar sync between our website and Airbnb only exchanges booked periods, no guest data.
Under Croatian law we must register all guests with the authorities (eVisitor system) and account for the tourist tax. For this purpose, our online form collects from every guest before arrival: first and last name, sex, date and place of birth, nationality, type and number of identity document, home address, travel dates and contact details. The legal basis is Art. 6(1)(c) GDPR (legal obligation). Without these details we cannot accommodate you. Recipients are the eVisitor system of the Croatian National Tourist Board and the competent authorities.
The details are stored only in our database (Supabase, servers in the EU).
ID scan (optional): Instead of typing everything, you can upload a photo of your ID card or passport. The photo is sent encrypted to the AI service of Anthropic (Anthropic, PBC, San Francisco, USA), which reads the details; you then check and confirm them yourself. We do not store the photo. According to Anthropic, data sent through its interface is not used to train AI models and is deleted automatically after a short period. The legal basis is your consent (Art. 6(1)(a) GDPR), given by using the scan and revocable at any time; you can also enter the details without scanning.
Our apartments have digital locks from Nuki (Nuki Home Solutions GmbH, Graz, Austria). We create a personal code for your stay that is only valid from arrival to departure. Your booking reference, last name and the validity period are stored at Nuki; the lock logs when the code was used. The code is deleted automatically after departure. The legal basis is Art. 6(1)(b) GDPR (access to the accommodation) and (f) (security of the house).
We issue an invoice for every stay. Invoices and the related booking data are passed on to our external accounting office in Croatia and, where required, to the tax authorities (Art. 6(1)(c) GDPR).
We use the following processors, who only process your data on our instructions: Netlify (website hosting, USA), Supabase (database, servers in the EU), Google Workspace (e-mail, Google Ireland Limited), Anthropic (ID scan, USA) and Nuki (door lock, Austria). Where data is transferred to the USA, this is based on the EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45, 46 GDPR).
We keep booking and contact data as long as needed to handle your stay and any follow-up questions. Under Croatian law, invoices and accounting records are kept for 11 years. Guest registration data is kept for as long as Croatian registration and tax rules require. Door codes are deleted after departure; ID photos are not stored. After that, the data is deleted.
You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time with effect for the future. Just write to christian@korculaia.com.
You can also lodge a complaint with a data protection authority – in Croatia the Agencija za zaštitu osobnih podataka (AZOP), Zagreb, azop.hr – or with the authority in your country of residence.
This privacy policy was last updated in October 2026. We will update it if our processes or the law change.