Privacy Policy

Last updated: June 15, 2025

This Privacy Policy describes how personal data are collected, used, and disclosed by OtoTrak d.o.o., Žlibina 18, 51262 Kraljevica, OIB: 44754487909 entered into the Court Registry of the Commercial Court in Rijeka under registry number 040372098 ("OtoTrak", "We", "Us" or "Our") when using services offered on this website hosted at the domain https://365.tours and its subdomains, as well as all connected offerings (collectively "Platform") and provides information on privacy rights and how to exercise them ("Privacy Notice").

Interpretation and Definitions

Unless expressly provided in this Privacy Notice, terms used herein have the meaning given to them in the "REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC" ("General Data Protection Regulation" or "GDPR").

Terms used herein that are defined in the Terms and Conditions for access to and use of the Platform have the meaning given to them therein.

Data Controller

OtoTrak is the data controller in relation to processing of personal data of the users of its services offered on the Platform (searching and booking sport, leisure and related activities of particular provider and presentation and publishing of offers for booking of these activities by the service providers) and visitors to the Platform, as We are the ones who determine the purposes and means of the processing of your personal data in this regard, all in accordance with applicable provisions of GDPR and Croatian Act on Implementation of GDPR (OG 42/2018).

Personal data We collect and purpose of collecting

Personal data collected for the purpose of registration of users, including service providers and use of Our services on the Platform

For the purpose of registration/creating an account of the users we collect and process the following personal data:

  • First name and last name
  • Email address
  • Password
  • Country
  • Profile picture (optional)

(collectively "Registration data users")

For the purpose of registration/creating an account of the services providers we collect and process the following personal data:

  • First name and last name of the physical person owner of the service provider entity
  • Address (street and number, city, postal code and country; region optional) of the physical person owner of the service provider entity
  • Ownership percentage of the physical person in the service provider entity
  • Date of Birth of the physical person owner of the service provider entity
  • City and country of birth of the physical person owner of the service provider entity
  • Nationality of the physical person owner of the service provider entity
  • Copy of passport and/or personal ID of the physical person owner of the service provider entity

(collectively "Registration data services providers")

We use the Registration data for the purpose of registration of an account and any subsequent log ins to your account on the Platform as well as for the purpose of using of our services of booking sport, leisure and related activities of particular provider and publishing offers for booking of these activities on the Platform.

You may also use our services of booking sport, leisure and related activities of particular provider as a guest, i.e., without registration of an account. In this case, for the purpose of providing said services we will collect and process your following personal data: first name and last name, email address and country.

You can also log in to use our services on the Platform through the following third-party social media services:

  • Google
  • Facebook

If you decide to register through a third-party social media service, We may collect personal data that is already associated with your third-party social media service's account, such as your email address used for log in to your social media user's account. Also, your name, language preference, your profile picture. When logging in through those third-party social media service, particular social media service you use will inform you about additional data it shares with us/gives us access to.

You may also have the option of sharing additional information with Us through your third-party social media service's account. If You choose to provide such information and personal data, during registration or otherwise, you are giving us permission to use, share, and store it in a manner consistent with this Privacy Policy.

Personal data collecting for the purpose of responding to your queries

We use your email address when you contact us/our customer service support in order to respond to your inquiry or request sent to us as well as for sending news and information (promotional and marketing materials, i.e., newsletters), when you have given us your consent for processing for this purpose. You have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You may opt-out of receiving any, or all, of these communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us.

Processing of personal data related to the establishments, exercise, or defence of legal claims

We may also process your Registration data for the purpose of the establishment, exercise, or defence of legal claims. Also, in order to comply with legal obligations of the data controller, we may process your Registration data if necessary to act in accordance with the law or a court order.

Cookies

When you access to or use our Platform and services We offer there, we automatically collect certain data from your browser through so called cookies or similar technologies. A Cookie is a small file that the Platform sends to the user's browser, which then stores it on your computer. Cookies allow us to see what pages you have visited, to determine how often certain pages are visited and to determine which parts of the Platform are the most popular. This helps us to improve our Platform and provide better and personalized services and ensure the security of our Platform.

The information that we may collect through cookies or similar technology are:

  • On line identifiers (IP address, Internet browser you use, operating system you use, type of equipment you use, access point and similar).
  • Information about the access and use of our website (for example, time, duration and number of visits to the site, pages you opened and similar).

To learn more about our use of cookies and how you can change your settings to delete or refuse cookies, please check our cookies policy here.

When you access the Platform and services We offer there by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.

We may also collect information that your browser sends whenever you visit our Platform or when you access the Platform by or through a mobile device.

Further processing for new purposes

If We intend to use any of your personal data for a new purpose, not covered by this Privacy Notice, then We will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent for such new processing.

The legal basis for processing of personal data

  • For Registration data that we process for the purpose of registration/creation of an account of a natural person, subsequent log ins to the same and for the purpose of using of our services on the Platform by registered users natural persons, including the use of the services as a guest, as well as to respond to your inquiry or request sent to us by contacting us/our customer service support, the legal base for processing of personal data is processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, in accordance with Art. 6. Para. 1 Sub. Para. (b) of the GDPR.
  • For Registration data that we process for the purpose of registration/creation of an account of legal persons, subsequent log ins to the same and for the purpose of using of our services on the Platform by registered users legal persons, as well as to respond to your inquiry or request sent to us by contacting us/our customer service support, the legal base for processing of personal data is processing is necessary for the purposes of our legitimate interest as the data controller for performance of a contract with legal entity, in accordance with Art. 6. Para. 1 Sub. Para. (f) of the GDPR.
  • Legal base for processing of your Registration data ‐ email address for the purpose of sending news and information (promotional and marketing materials, i.e., newsletters), is your consent, in accordance with Art. 6. Para. 1 Sub. Para. (a) of the GDPR.
  • For processing of your Registration data for the purpose of the establishment, exercise, or defence of legal claims, the legal base for processing is processing is necessary for the purposes of our legitimate interests as the data controller for the establishment, exercise, or defence of legal claims, in accordance with Art. 6. Para. 1 Sub. Para. (f) of the GDPR.
  • For processing of your Registration data, that we may use for accounting and/or tax purposes, where and when applicable, legal base for processing is processing is necessary for compliance with a legal obligation to which we as the controller are subject, in accordance with Art. 6. Para. 1 Sub. Para. (c) of the GDPR.
  • For processing of data contained in essential cookies, the legal base for processing of personal data is processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, in accordance with Art. 6. Para. 1 Sub. Para. (b) of the GDPR or our legitimate interests as data controller, in accordance with Art. 6. Para. 1 Sub. Para. (f) of the GDPR. In this sense, we are bound by the contract we have with you to ensure the proper provision of our services and the proper functioning of our Platform. On the other hand, we have a legitimate interest in ensuring the security of our Platform. For collection of data contained in other cookies, we ask for your prior consent, so the legal base for processing of personal data is your consent, in accordance with Art. 6. Para. 1 Sub. Para. (a) of the GDPR.

Recipient of personal data

We share your Registration data and other your above personal data collected from you through registration and use of services on our Platform with the following recipients/categories of recipients:

  • Business partners/service providers: We may share your information with Our business partners/service providers that publish offers for booking of sport, leisure and related activities on our Platform.
  • Third-party recipients using personal data for legal reasons. We may disclose your personal data to third parties such as courts, administrative authorities, data privacy supervisory authorities, our legal counsels etc. for legal reasons, if that is required for the purpose of establishment, exercise, or defence of legal claims or is necessary for compliance with our legal obligation to which we as the controller are subject to.
  • External organizations/our data processors: These are external organizations which helps us run our business and/or process personal data in our name and under our instructions (for example, providers of technical support for our systems or "cloud computing services"). Those entities as data processors, and their selected staff, are only allowed to access and use your personal data on our behalf for the specific tasks that they have been requested to carry out, based on our instructions, and are required to keep your personal data confidential and secure.
  • With Your consent: We may disclose your personal information for any other purpose with your prior consent.

Transfer of data to third countries outside of EEA

All personal data that We collect, and process are generally stored within the European Economic Area ("EEA"). However, given that we use a cloud computing service for storage of the collected data, which operates globally but is headquartered in the USA, the data we collect may be transferred to the USA. When this is the case, the processor will ensure that this transfer complies with applicable laws and legislation. For more information, please see the respective privacy policy on the following link: https://privacy.microsoft.com/en-US/data-privacy-notice. In case that we would be required to share your personal data with an entity located outside of the EEA or to countries that are not recognized by the European Commission as countries providing adequate level of protection of personal data, we will, as required by applicable law, ensure that data subject's rights are adequately protected by appropriate safeguards, as envisaged in Art. 46 of the GDPR. These safeguards may include (i) entering into European Commission approved standard contractual clauses to protect your personal data; and (ii) entering into binding corporate rules (and you have a right to ask us for a copy of these clauses or rules by contacting us as set out below). Where permitted by the law, in relation to transfers, we may rely on derogations from Art. 49 of the GDPR, such as your explicit consent. We shall notify you in timely manner about any such transfers outside EEA and safeguards/derogations put in place to protect your personal data.

Retention of Your Personal Data

We will retain your personal data in a form that allows for identification only for as long as is necessary for the purposes set out in this Privacy Policy for which the data were collected or, where applicable where you have withdrawn your consent for processing.

After the personal data is no longer necessary for the purpose for which the same were collected or where applicable, when you have withdrawn your consent for processing, we will destroy or anonymize those personal data, so that they are no longer in a form which permits identification of data subjects, except if:

  • it is necessary to store the data for specific period of time, in accordance with the applicable laws or prescribed statutory periods for the purpose of defending a legal claim or enforcement of our rights in which case the same data shall no longer be processed for other purposes; and
  • an additional 2 months following the end of the applicable statutory period (so we are able to identify any personal data of a person who may bring a claim at the end of the applicable period), and
  • in addition, if any relevant legal claims are brought, we may continue to process your personal data for such additional time necessary in connection with that claim.

Payments

When using our services of booking sport, leisure and related activities of particular provider either through your registered account or as guest, we use third-party services for processing of your payment. Namely, Stripe.

We will not collect or store your payment card details. That information is provided directly to the provider of these services. Collection and processing of your personal data by the subject provider is governed by their privacy policy, which can be viewed at https://stripe.com/en-hr/privacy. However, these providers adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

Your Rights under the GDPR

  • Right of access: At any time you may request from us to obtain confirmation as to whether or not your personal data are being processed, and, where that is the case, you have the right to access to the personal data and receive information on their processing.
  • Right to rectification: You have the right to request that we correct or complete without delay any personal data if it is found to be inaccurate and incomplete.
  • Right to erasure: You have the right to request your personal data be erased, where it is no longer necessary for the purpose for which we are processing the same. In case the request is justified and under condition that there is no such law, which would impose storage obligations on us, personal data will be erased without undue delay. In case there are reasons, which prevent or limits us in fulfilling your request, we will inform you without delay in our response to your request.
  • Right to withdraw consent: The right to withdraw the consent to the processing at any time, if the processing is carried out based on the consent. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to restriction of processing: You have the right to request from us to obtain restriction of processing of your personal data if you contest the accuracy of such personal data (for a period enabling us to verify the accuracy of the personal data), if the processing is unlawful and you oppose the erasure of the personal data, if you have objected to the processing of your data and if we no longer need the data for the purpose of the processing but they are necessary to you for the establishment, exercise or defence of legal claims and therefore you wish that we store further the same.
  • Right to data portability: The right to request that we provide you with your personal data and where possible, to transmit that data directly to another data controller, where applicable.
  • Right to object: The right to object to the processing of personal data, where applicable.
  • The right to lodge a complaint with the supervisory authority

Exercising of your GDPR data protection rights

You may exercise the above your rights by contacting Us at support@365.tours. Please note that we may ask you to verify your identity before responding to such requests. If you make a request, We will try our best to respond to you as soon as possible.

If you will consider that processing of your personal data from our end infringes your rights, you have the right to lodge a complaint with the competent data protection supervisory authority. Contact details for the Croatian data protection supervisory authority are as follows:

  • Croatian Personal Data Protection Agency:
    • Ul. Metela Ožegovića 16, 10000, Zagreb
    • azop@azop.hr
    • 00385 (0)1 4609-000

Links to other websites

Our Platform may contain links to other websites that are not operated by Us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Changes to this Privacy Notice

We conduct regular audits of personal data processing. Because of this as well as because of possible changes in the law and the changing nature of technology, this Privacy Notice may periodically change. We therefore encourage you to check from time to time all changes and updates to this Privacy Notice, which will be published at this website.

This Privacy Notice was last updated on June 15, 2025.

Contact Us

If you have any questions about this Privacy Policy, you can contact us: