Information on collecting and processing of personal data
Super Tours Ltd. travel agency (hereinafter: “the Agency”) dedicates a lot of attention to the protection and processing of personal data. The Agency processes personal data in scope of its registered activities and in respect of all applicable rules and regulations.
(1) The responsible party for data processing is the Controller:
Super Tours Ltd. travel agency, Dr Ante Starčevića 24, Dubrovnik, OIB: 96426752089 www.supertours.eu /email: firstname.lastname@example.org
(2) If we use the services of external providers for the processing of your personal data (Data Processors), we are then refering to processing of personal data on demand. We are in that case also responsible for the protection of your personal data. However, there is also a possibility that the before mentioned personal data is going to be transferred and processed outside of the EU. Therefore mentioned transfer shall be performed only if we have contracted appropriate guarantees with the service provider as the processor, or if the customer has provided us with explicit consent.
The purpose of this Information on collecting and processing of personal data (hereinafter: “Information”) is to inform you about all the relevant features of the collection of your personal data, as well as its processing and storage. The listed applies to all personal data you have transferred to us via this web-page, electronic, written or verbal communication or that we have received through a travel
agency and other businesses with whom you are in a contractual or other similar relationship, as well as data collected from other sources.
Upon making the reservation or offer, we request the personal data necessary for the reservation or offer. The customer can provide us with the personal data personally, or via reservation form or mail, or it can be provided by a third person, in name of the customer.
Personal data that we collect
We process the following personal data:
a. your basic personal data made available to us by you or by third parties – first name, family name, country, city, address, nationality, e-mail, telephone number, name, surname and date of birth of child, special demands and habits, and the data regarding your co-passengers; data required to fulfil the reservation – credit card number; contact information in emergency cases – first name and family name, telephone number; other necessary data – e-mail address health data – in case of requests for a special dietary regime or a doctor; data related to web use – IP address, visits to the website, social network data, and similar data related to Internet browser use.
b. customer’s rights in regard of travel, arrangement or other services – name and family name, date of birth, place of birth, nationality, sex, number of official document (personal identification, passport, drivers licence), date of issuance, place of issuance, expiry date of passport or other personal document, visa number if client under visa regime, credit card number of number of other means of payment
The purpose of collecting personal data and period during which the personal dana will be stored The Agency determines the purpose of the processing of personal data and is therefore considered to bet the Data Controller. Upon written request based on applicable regulations, the Agency shall deliver or give access to certain personal data of customer to competent state authorities (such as police, tourist inspection, courts etc.). The legal basis for processing the data for these purposes is fulfilling the legal obligations of the Agency.
The basic purpose of collecting personal data is concluding and executing contracts on travel organization or intermediary travel organization and providing touristic services or so that actions may be taken at your request before and during the contract. The scope of the personal data collected depends on the purpose of the contract that you intend to conclude or that you are concluding, or the request to exercise rights (the type of service provided and price). Actions at your request before the conclusion of the contract mean checking your requests and needs, checking the appropriateness or applicability of our products and services to your special circumstances, as needed, all with the goal of creating an offer and/or an informative price figure. In this case, the scope of the personal data collected by us depends on the type of the request we received, and the information necessary to fulfil the request. The purpose of the processing of the personal data may be the obligation to fulfill contracted services with such a service provider. In that case the collecting of personal data upon that defined purpose may represent a contractual obligation and a condition necessary for the execution of the contract. If you refuse to provide certain personal data, we shall not be able to fulfill our contractual obligations, which shall result in the inability to execute the contract and touristic service. The personal data required for the execution of contractual obligations are necessary due to internal Agency regulations, and it is not possible to make a reservation or execute therefore mentioned contract without disclosing personal data, which are stored until contract expiry.
The credit card number is collected because it is required for concluding and executing the contract with the customer. It is used as insurance for the payment of accommodation costs and costs of other services that might be incurred if the customer does not settle his or her debt towards the Agency. The mentioned data is also used for service payment.
Emergency contact information are processed on the basis of legitimate interest, i.e. potential situations where it is necessary and urgent to transmit certain relevant information to your close ones (in case of extraordinary circumstances, such as sickness, accidents, etc.). Other required data, i.e. email address, is processed based on a legitimate interest in good communication between the contractual parties for the purpose of fulfilling all aspects of the contract, i.e. easier communication in the sense of organizing your arrival and reserving the accommodation itself, and this data is also erased when the accommodation service contract expires.
The personal data from the customer is being stored to protect the clients’ legitimate interests or our legitimate interests, in accordance with applicable regulations. That can for instance include storage of customer data so we can respond to eventual complaints in the best possible manner, use of customer data in order of prevention, detection and processing the misuse and possible damage conducted to the customer or the Agency, providing security of employees, customers, products and services of Agency, creating services and offers which are adequate in regards of the needs and wishes of customers, providing great user experience, personalized user support, research and analysis of the market, optimization of sales channels. The legal basis for the processing in these purposes is the legitimate interest of the Agency, except when the interest of the customer or basic rights and liberties in regard of data protection prevail. The exception is when the legal basis is consent.
Special personal data categories
Due to the nature of the travel services, special categories of personal data in regards of customer’s health may need to be processed, for the sole purpose of executing the contract between the Agency and customer, or between the travel organizers in case of travel packages, or in regard of activities which precede the execution of the contract. If the customer provided the Agency with special personal data categories, it is deemed that the customer gave his explicit consent in regard of that data.
In principle, the following types of personal data are not processed: data related to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of the unique identification of individuals, and data related to health, sex life and an individual’s sexual orientation. The above-mentioned personal data categories are nevertheless processed by the Agency in the following situations:
1) if the customer has provided explicit consent to the processing of this personal data, and for one or several determined purposes, except if applicable regulations state that such a consent does not have an effect;
2) processing is important for the protection of a vitally important interest for the customer or another individual, if the guest cannot physically or legally provide consent;
3) processing is related to personal data obviously made public by the customer,
4) processing is required for the establishment, fulfilment, or defense of legal requirements, or whenever courts act in their capacity as courts;
5) processing is necessary for the purpose of significant public interest, on the basis of applicable regulations and in proportion to the desired goal, with respect to the essence of data protection rights, and ensured appropriate and special measures for the protection of the Subject’s basic rights and interests;
6) processing is required for the purpose of preventive medicine, medical diagnosis, the provision of health or social care or treatment, or management of health or social systems and services, pursuant to applicable regulations. All your personal data transferred to us by you or by a Third Party is processed in accordance with the goal of
their processing (whereby we mention that, if you are travelling with children under 16 years of age, their personal data, regardless of the basis, is only processed with your explicit consent).
Links to websites and Third Parties services
Our website and our mobile programs and Wi-Fi network record your usage data and contain links to Third Party websites. Bear in mind that we are not responsible for the collection, usage, maintenance, exchange or publishing of data and information by these Third Parties. If you provide data to Third Party websites i.e. use them, the privacy rules and terms and conditions of these websites apply. We recommend that you read the privacy rules of the website you are visiting before providing personal data.
The Agency will conduct all reasonable measures to protect your personal data from unauthorized access, disclosure, modification or erasure, and will keep the personal data precise and updated as far as possible. We request our partners and service providers with whom we share personal data to invest reasonable efforts into maintaining the confidentiality of your personal data. For network transactions, we apply a reasonable level of technological measures in order to protect the personal data you share with us via our website. However, it should be noted that no security system or internet data transfer system can guarantee complete safety.
Legitimate interests of the Company as the purpose of processing personal data
Your personal data will be processed for the purpose of our legitimate interests, except when your interests or your basic rights and freedoms, requiring personal data protection, take precedence. The legitimate interest of the Agency in that sense is processing personal data so that our service may completely adapt to your needs and wishes (e.g. special family packages etc.). The mentioned data may also be used for our internal statistical and analytical purposes.
You can object to this legitimate interest of the Agency at any moment and, in that case, we will no longer process your data for that purpose, which will not affect the legality of the processing until the day of withdrawal. In any case, we require your explicit consent for direct marketing.
Consent is the legal basis for collecting personal data on monitoring the quality of our travel arrangements. The Agency cares about your opinion on the services provided and, for that purpose, we ask you to fill in so-called quality surveys so that you can rate us. This allows us to analyze various aspects of our service, so that we can develop it and improve it even more.
The survey informs the customer that providing any personal data is voluntary. The customers decide for themselves whether or not they will fill in the survey, and they decide for themselves whether they will list personal data and, if so, which ones. If the processing of the previously mentioned data is based on your consent, the data mentioned is processed until you withdraw your consent or request its erasure. In accordance with the above, based on your consent, we may also process other personal data outside of those listed in this Information. Related to the above, please note that, in accordance with the applicable regulations, the Agency nevertheless does not conduct erasure, despite the request of the Subject, if the processing of this personal data is necessary:
a) to comply with a legal obligation that requires processing, and the Agency being subject to this obligation,
b) to exercise the right to freedom of expression and information;
c) for a public interest in the area of public health;
d) for the purpose of public interest, historical or scientific research, or for statistical purposes, i.e. for compliance with or defense of legal requirements.
In processing your personal data based on your consent, we partially apply automated processes for processing or profiling, so that contact with you may be of a more individual nature and so that we can adapt our service completely to your needs and wishes (e.g. special family packages etc.).
In case of providing marketing consent, for which we request your explicit approval, your personal data may, in exceptional cases, be involved in automated processing, based on which your profile will be created for the purpose of analysing the services provided and your rights, as well as for the purpose of improving the quality of the business relationship. Automated decision-making, including profile creation, will be conducted in cases of creating your customer profile for the purpose of analysing the services provided and your rights, as well as to improve the quality of the business relationship and to process data based on an approval for marketing purposes, with the goal being to improve the quality of the business relationship and marketing, and so that we can specifically inform you about benefits and new features of our offer. If such processing of personal data is not required for the conclusion or execution of the contract, you have the right to request that a person employed by the Agency decides on the outcome of the processing, the right to express your own viewpoint, and the right to object to a decision made through automated processing. We also hereby mention that the usage of your personal data for marketing purposes is only possible pursuant to your explicit consent. Should you provide such consent to us, we will duly provide information about all benefits, discounts, events and associated services that we believe might be of interest to you. You can withdraw this consent at any moment by notifying us via the contact information listed in the introductory section of this Information.
To whom will your personal data be disclosed
The Agency ensures that your personal data is processed exclusively for the purposes listed in this document. The purpose of personal data processing will require that your personal data is disclosed and that, in addition to the Agency, other companies and persons process it as processors. Processor categories receiving your data include: government and public authorities, in accordance with the Company’s legal obligations, health care institutions, information or legal services providers, delivery service providers etc.
Personal data processors, with the exception of government and public authorities, process data exclusively according the Company’s instructions, thereby abiding by the technical and organizational measures in order to ensure the protection of your rights.
The Agency transfers the personal data to Third parties when it is necessary to provide the contractual services or requested information to the customer (airline schedule, buses, insurance, banks, accommodation, other touristic agencies, embassies or visa offices), as well as when the Agency acts as an intermediary in package travels. In that case we transfer therefore mentioned personal data to the organizer, so the customer may receive the contractual service.
Where will your personal data be processed
Processing of your personal data may be conducted within or outside of the European Economic Area, but will in any case be performed by processors whose responsibilities and obligations to protect personal data, as well as applicable technical and organizational security measures prescribed by the contractual relationship, are in conformity with all legal regulations governing the protection of personal data. However, the Agency cannot guarantee that the level of data protection in third countries shall be the same as in the EU. The before mentioned shall be conducted only when it is necessary in regards of the contract, and if appropriate guarantees regarding data protection have been contracted, or if the customer provided his explicit consent, upon understanding the ris
Period during which the personal data will be stored
Your personal data will be stored only for as long as necessary to fulfil the purpose of its processing. The period of storing personal data depends on the aim of the collection. If it is contract or providing tourism services, this period shall be defined by the duration of the contract itself, i.e. by charging for these services, in the sense of legal obligations to keep records. An extension of this period is prescribed by the internal rules of the Agency, which in turn depend on legally prescribed statutes of limitations for claims, or this time may be extended considering the legally defined storage periods, such as in the case of accounting documents.
Rights related to the collected personal data
In relation to the data you have disclosed to us, you have (I) the right to access the personal data being processed, (II) the right to modify or erase personal data, (III) the right to limit processing, (IV) the right to object to processing, (V) the right to transfer data to another controller, (VI) the right to withdraw consent, (VII) the right to submit a complaint to a supervisory authority. To exercise all of the rights listed herein, simply inform us in accordance with the contact information from the introduction to this Information.
The right to submit a complaint to a supervisory authority
At any moment, you may submit a complaint concerning the processing of your personal data to the competent supervisory authority, in accordance with the Act on the Implementation of the General Data Protection Regulation, or other legislation governing the protection of personal data and defining supervisory authorities regarding the processing of personal data.
This Information may change from time to time. When significant changes are made to this Information, we will publish a link to the modified Information on the homepage of our website. All changes to the Information will enter into force after the publication of the modified Information on the website.
This Information on collecting and processing personal data is applied as of 23 Mar 2020 in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR)