Privacy Policy
Last updated: 17.03.2026.
Villa San Antonio (“we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website villa-sanantonio.com.
1. Data Controller
The data controller responsible for your personal data is:
[YOUR FULL NAME]
[YOUR ADDRESS]
Email: kontakt@villa-sanantonio.com
2. What Data We Collect
We may collect the following types of personal data:
a) Data you provide directly
- Name, email address, and message content — when you submit our contact form
- Name, email, phone number, dates of stay, and number of guests — when you make a booking inquiry or reservation
b) Data collected automatically
- IP address, browser type, device information, pages visited, and referring URL
- Cookies and similar tracking technologies (see Section 6 below)
3. Why We Process Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Responding to your contact form inquiry | Your consent (Art. 6(1)(a)) |
| Processing a booking or reservation | Performance of a contract (Art. 6(1)(b)) |
| Website analytics (Google Analytics) | Your consent (Art. 6(1)(a)) |
| Advertising & remarketing (Facebook Pixel) | Your consent (Art. 6(1)(a)) |
| Ensuring website security and functionality | Legitimate interest (Art. 6(1)(f)) |
4. Third-Party Services
We use the following third-party services that may process your personal data:
a) Google Analytics
We use Google Analytics to understand how visitors interact with our website. Google Analytics uses cookies to collect anonymised usage data such as pages visited, session duration, and traffic sources. Data may be transferred to Google servers in the United States. Google is certified under the EU–US Data Privacy Framework.
You can opt out via our cookie banner or by installing the Google Analytics Opt-out Browser Add-on.
b) Facebook Pixel (Meta)
We use the Meta (Facebook) Pixel for advertising measurement and to create targeted audiences. This tool collects data about your interactions on our website and may transfer data to Meta servers in the United States. Meta participates in the EU–US Data Privacy Framework.
You can manage your ad preferences at Facebook Ad Preferences.
c) Booking System
We use a third-party booking platform to manage reservations. When you make a booking, your personal data (name, contact details, dates, number of guests) is shared with this service provider for the purpose of processing your reservation. This data is processed under a data processing agreement in compliance with GDPR.
5. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described above:
- Contact form submissions: up to 12 months after your last communication
- Booking data: for the duration required by applicable tax and accounting regulations (typically up to 11 years in Croatia)
- Analytics data: as configured in our analytics tools (up to 14 months for Google Analytics)
6. Cookies
Our website uses cookies — small text files stored on your device. We categorise them as follows:
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary | Essential for the website to function | Session cookies, cookie consent preferences |
| Analytics | Help us understand website usage | Google Analytics (_ga, _gid) |
| Marketing | Used for targeted advertising | Facebook Pixel (_fbp, _fbc) |
You can manage your cookie preferences at any time through our cookie banner or your browser settings.
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your data (“right to be forgotten”)
- Restriction — request that we limit how we use your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — withdraw your consent at any time without affecting the lawfulness of prior processing
To exercise any of these rights, please contact us at kontakt@villa-sanantonio.com.
You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): azop.hr.
8. Data Transfers Outside the EU
Some of our third-party service providers (Google, Meta) may transfer your data to servers located in the United States. These transfers are safeguarded by the EU–US Data Privacy Framework and, where applicable, Standard Contractual Clauses (SCCs) approved by the European Commission.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include SSL/TLS encryption on our website and restricted access to personal data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with the updated date at the top. We encourage you to review this page periodically.
11. Contact
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Email: kontakt@villa-sanantonio.com