Skip to main content

Privacy Policy

Last updated:

1. Introduction

Given2Fly Adventures (“we”, “us”, “our”) is committed to protecting the privacy and personal data of our customers, website visitors, and tour participants. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Croatian data protection laws.

Data Controller:
Given2Fly Adventures
Split, Croatia, 21000
Email: given2flyadventures@gmail.com

2. Data We Collect

We may collect the following categories of personal data:

  • Identity data: full name, date of birth, nationality.
  • Contact data: email address, phone number, postal address.
  • Identification data: photo ID number (passport, national ID card, or driving licence), retained only during the rental period.
  • Health data: health details voluntarily disclosed in a medical waiver, for safety purposes only.
  • Booking data: dates, booked services, preferences, group size.
  • Technical data: IP address, browser type, and device details collected through standard web server logs.
  • Communication data: messages sent by email, contact forms, WhatsApp, or social media.

3. How We Use Your Data

We process personal data for the following purposes:

PurposeGDPR Legal Basis
Booking and rental processingPerformance of a contract
Safety and medical readinessLegitimate interest / vital interest
Booking confirmations and invoicesPerformance of a contract
Customer support and inquiriesLegitimate interest
Legal compliance and dispute handlingLegal obligation

4. Data Sharing

We do not sell personal data. We may share data with:

  • Insurance providers when needed for incident or claim handling.
  • Regulatory or law enforcement authorities where legally required.
  • IT service providers supporting website hosting and reservations, under appropriate data processing agreements.

5. Data Retention

We retain personal data only for as long as necessary:

  • Booking and rental records: 5 years (Croatian accounting and tax obligations).
  • ID copies: deleted within 24 hours after equipment return.
  • Medical waiver data: duration of activity plus up to 3 years for safety and claim purposes.

6. Your Rights

Under GDPR, you have the right to:

  • Access your personal data.
  • Rectify inaccurate or incomplete data.
  • Erase data where legal retention obligations do not apply.
  • Restrict processing in specific cases.
  • Object to processing based on legitimate interests.
  • Data portability in a structured, machine-readable format.
  • Withdraw consent at any time for consent-based processing.

To exercise your rights, contact us at given2flyadventures@gmail.com. We respond within 30 days.

7. Cookies

We do not use cookies. Our website uses self-hosted fonts and a cookieless map, and we do not run analytics, tracking pixels, or third-party trackers.

8. Security

We apply technical and organizational security measures including HTTPS encryption, access controls, and regular security reviews.

9. International Transfers

Personal data is primarily stored and processed within the European Economic Area. If transfers outside the EEA occur, appropriate safeguards (including standard contractual clauses) are applied.

10. Children’s Privacy

We do not knowingly collect personal data of children under 16 without parental consent. If such data has been submitted in error, please contact us for prompt deletion.

11. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): azop.hr.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version is always available on this page with the updated date shown above.