This notice explains what personal information we collect when you visit our site or book with us, why we collect it, and what we do with it. We keep this deliberately simple, because we collect very little.
Who we are
Asteria is a private holiday apartment in Pješčana Uvala, Medulin, Istria, Croatia. It is let by its owner, who is the controller of the personal data described here. For anything about your data, contact us at info@asteria-pula.com. Our registration details are in the Legal Notice.
What we collect, and why
- When you send an enquiry: your name, your email address, the details of the stay you are asking about, such as your dates or the length of stay, how many of you there are and whether you are travelling with a small child, and anything else you choose to write to us. We use these only to reply to you and to arrange a possible booking. The legal basis is that we are taking steps at your request before entering into a contract.
- When you book and stay: the details we need to manage your booking and your stay, including your contact details and the bank transfer details that appear when you pay us. The legal basis is performance of our contract with you.
- Guest registration: the identity details of each guest, including full name, date and place of birth, citizenship, and identity document type and number, which Croatian law requires us to submit to the national eVisitor guest-registration system within 24 hours of arrival. The legal basis is our legal obligation under Croatian law.
- Tax and accounting records: we keep records of bookings and payments as tax law requires. The legal basis is our legal obligation.
- When you simply visit the site: our site is delivered and protected through Cloudflare, which sets strictly necessary cookies and processes basic technical request data to keep the site secure and working. The legal basis is our legitimate interest in a secure, functioning website.
Who we share it with
We do not sell your information, and we do not share it for marketing. We share guest-registration details with the eVisitor system because the law requires it. Your enquiry reaches us by email through our email service providers, and our site is served through Cloudflare; both process data on our behalf. Our bank processes your payment. That is the extent of it.
Where your data goes
Some of the service providers we rely on are established outside the European Economic Area. Cloudflare, which delivers and protects our website, is established in the United States. Our email is handled by two providers: the service that sends our automated replies is established in the United States, and the mailbox that receives your messages is in Switzerland. This means some of your data may be processed outside the EEA. These transfers are covered by the safeguards permitted under EU data protection law: for the United States, the EU-US Data Privacy Framework and, where applicable, the European Commission's standard contractual clauses; for Switzerland, the European Commission's decision that it provides an adequate level of data protection.
How long we keep it
We keep enquiry messages only as long as needed to deal with your enquiry and any resulting stay. We keep booking, payment and accounting records for 11 years from the end of the year in which they were issued, as Croatian accounting and tax law requires, after which we delete them.
Your rights
You have the right to ask us for a copy of the personal data we hold about you, to have it corrected if it is wrong, to have it deleted where we are not required to keep it, to ask us to restrict how we use it, to object to our use of it where we rely on legitimate interests, and to receive certain data in a portable form. To exercise any of these, email info@asteria-pula.com. If you believe we have handled your data improperly, you may also complain to the Croatian data protection authority, the Agencija za zaštitu osobnih podataka (AZOP). We do not make automated decisions about you, and we do not carry out profiling.
Cookies
We use only strictly necessary cookies, set by Cloudflare, which keep the site secure and allow it to load correctly. These are principally __cf_bm, used for bot management, and cf_clearance, used when a security check has been passed; both are short-lived, typically expiring after around thirty minutes. We do not use analytics, advertising, or tracking cookies of any kind. Because the only cookies we use are strictly necessary, no consent banner is shown; that is normal and permitted for cookies of this type.
Last updated 01.08.2026. We may update this notice from time to time; the current version always lives on this page.