Privacy Policy
S.H.A.R.K. d.o.o. is committed to protecting the personal data of customers by collecting only the necessary information required to fulfill our obligations. Customers are informed about how their data is used and are regularly given options to decide on the usage of their data, including the option to opt out of marketing lists. All customer data is strictly safeguarded and accessible only to employees who need it to perform their duties. All S.H.A.R.K. d.o.o. employees and business partners are responsible for respecting privacy protection principles.
We respect your privacy, whether you are a user of our services or simply seeking information. You have the right to protection of your personal data: name, address, phone number, email address, and other data that can directly or indirectly identify you.
This statement explains how we collect your personal data, the purposes for which we collect it, how we use your data, with whom we may share it, how we protect it, and what rights and choices you have regarding your personal data.
This policy applies to the processing of your personal data on the website shop.diving-shark.hr, marketing activities leading to this site, sponsored posts on social media, and similar activities managed by us or by third parties on our behalf.
Who Is Responsible for Your Data?
Davor Buršić
S.H.A.R.K. d.o.o. for diving tourism, trade, and travel agency
Osipovica 30, Medulin, Croatia
VAT ID: 19892555288
Email: info@diving-shark.hr
Phone: +385 52 894 27 41
Who to Contact Regarding Your Data
For any questions, requests, or complaints regarding this privacy statement or your data rights, contact us using the email address above.
Core Principles
- Lawfulness: We collect personal data fairly, legally, and transparently.
- Data Minimization: We collect only the data necessary for the specified purpose.
- Purpose Limitation: Data is used only for specific, legitimate purposes and not further processed in a manner incompatible with those purposes.
- Accuracy: We maintain accurate and up-to-date personal data.
- Security: We implement technical and organizational measures to ensure appropriate data protection levels.
- Access and Correction: We respect your rights regarding your data.
- Storage Limitation: We store personal data only as long as necessary or legally required.
- International Transfers: We protect personal data transferred outside the EEA in accordance with applicable laws.
- Third-party Sharing: Data shared with third parties is protected through legal and contractual safeguards.
What Data We Collect and Legal Basis
You will always be informed about the data we collect, typically provided via a specific privacy notice linked to the service, newsletter, survey, or marketing campaign. We process your data if:
- you have given consent (which can be withdrawn at any time),
- processing is necessary for a contract you are party to,
- processing is based on our legitimate interests (e.g., fraud prevention or customer satisfaction surveys),
- processing is required by legal obligations (e.g., invoicing details, product purchase information).
Why We Process Your Data
We process data for specific, legitimate purposes such as order fulfillment, improving our website and services, sending marketing materials, or running events. This includes content personalization and profiling for relevant marketing messages and offers based on purchase behavior.
Accuracy and Updates
Please inform us of any data changes to keep records accurate and up-to-date. Contact us via email for corrections.
Access to Your Data
You have the right to access and request corrections or deletion of your data. Contact us for such requests.
Retention Period
Data is stored only as long as needed to fulfill the purpose or required by law (e.g., invoices for 10 years, contracts for 5 years). Data based on your consent is kept until you revoke consent.
Data Security
We apply adequate security measures to prevent unauthorized access, accidental loss, or destruction of personal data. These measures include confidentiality, integrity, and availability safeguards.
Cookies and Tracking Technologies
We use cookies to enhance website usability and experience. For more information, refer to our Cookie Statement.
Data Sharing
Data may be shared with internal staff, authorized dealers, advertising agencies (e.g., MailChimp, Google, Facebook), IT providers, accountants, and legal advisors, and in cases of legal obligation or corporate restructuring.
Use of Social Media
If you log in using social media (e.g., Facebook), we collect data made available through that platform such as name, email, phone, address, etc., with your explicit consent.
International Transfers
If your data is transferred outside the EEA, we apply safeguards to ensure it remains protected, and you'll be notified accordingly in specific privacy notices.
Your Rights
You have the right to control how we contact you, access your data, request corrections, limit processing, object to marketing, and request data deletion. You may file a complaint with the Croatian Data Protection Agency (azop.hr, azop@azop.hr).
Legal Information
This privacy policy supplements but does not override applicable data protection laws. In case of discrepancies, legal provisions prevail. We may update this policy, and you'll be informed accordingly.
Definitions
Data Controller: The entity that determines the purpose and means of processing personal data.
Data Processor: A person or organization processing data on behalf of the controller.
EEA: European Economic Area.
Personal Data: Any information that can identify you directly or indirectly.
Processing: Any operation on personal data, including collection and use.