Privacy Policy
Last updated: October 28th, 2025
By taking care of our customers, we believe that we have a chance to provide high-quality service, which is a key to a pleasant journey. This is where we take the first step – take a few minutes and check out our new privacy policy below.
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information in pursuance of the General EU Data Protection Regulation 2016/679 / EC (hereinafter: the Regulation) and the Act Implementing the General Data Protection Regulation NN 42/2018.
When You register via our Website in order to search, browse data, publish or book holiday accommodation, we need to collect some personal information about You, such as first name, last name, phone number, postal address, email address, date of birth, and profile photo, some of which will depend on the features you use. This information is used, for example, to process your booking and travel or hotel arrangements. Some of this information is shared with our trusted partners such as travel agencies, accommodation providers, hotels, tour operators and airports to ensure that You arrive safely at Your destination.
Inquires and accommodation reservations can be made on the Website or via email, contact number, in writing or in person at any of the Agency’s offices as well as at the offices of our partner travel agencies. By confirming a reservation, You confirm that You are aware of the General Terms and conditions of the travel services and fully comprehend and accept these terms which are binding for both You as a traveller and us as the Agency.
We use Your Personal data to provide and improve Our website. By using the Litto website, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation
The following definitions shall have the same meaning regardless of whether they appear in singular or plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access our Website or its parts.
- Company (referred to as either “the Company”, “Litto Agency”, “We”, “Us” or “Our” in this Agreement) refers to Litto d.o.o., Lovački put 7, 21000 Split.
- Contractor (referred to as either “the Traveler”, “User” or “You” in this Agreement).
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
- Country refers to: Croatia
- Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
- Personal Data is any information that relates to an identified or identifiable individual.
- Service refers to the Website.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- Website refers to Litto, accessible from https://www.litto.co/
- ”You” means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
We collect and process the following categories of personal data depending on how you interact with our website:
| Category | Examples | Purpose | Legal Basis |
|---|---|---|---|
| Identification and contact data | Name, surname, email address, phone number | Communication with customers, responding to inquiries, managing bookings | Performance of a contract (Art. 6 (1)(b)) |
| Booking data | Accommodation details, dates, number of guests, preferences | Reservation management, customer support | Performance of a contract |
| Payment data | Stripe transaction ID, payment amount, partial card data (processed via Stripe) | Processing and confirming payments | Performance of a contract / Legal obligation (accounting) |
| Technical and usage data | IP address, browser type, device ID, time of visit, pages viewed | Site analytics, service improvement, security | Legitimate interest (Art. 6 (1)(f)) |
| Cookies and analytics data | Google Analytics cookies | Website usage analysis and optimisation | Consent (Art. 6 (1)(a)) |
| Marketing data (future use) | Email address (if you subscribe) | Sending newsletters and promotional offers | Consent |
We do not intentionally collect or process sensitive personal data (e.g. health, ethnicity, political opinions).
When You access the Website by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Website or when You access the Website by or through a mobile device.
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Website and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Website. More about cookies and other technologies you may find in our Cookie Policy.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
To provide and manage bookings – fulfilling your reservation requests.
→ Legal basis: Performance of a contract.
To communicate with you – responding to questions, confirming bookings.
→ Legal basis: Performance of a contract / Legitimate interest.
To process payments via Stripe – ensuring secure online transactions.
→ Legal basis: Performance of a contract / Legal obligation.
To improve our website – analysing user behaviour and optimizing services.
→ Legal basis: Legitimate interest.
To send marketing communications (when available).
→ Legal basis: Consent (you may withdraw at any time).
Retention of Your Personal Data
The Agency will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
We retain personal data only as long as necessary for the purposes outlined in this Policy or to comply with legal obligations:
| Data Type | Retention Period |
|---|---|
| Booking & payment data | 5 years after service completion (or longer if required by law) |
| Customer inquiries | up to 12 months |
| Marketing subscriptions | until consent is withdrawn or after 3 years of inactivity |
| Analytics data | up to 12 months (aggregated and anonymised thereafter) |
After these periods, data will be securely deleted or anonymised.
The Agency will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place, including the security of Your data and other personal information.
Disclosure of Your Personal Data
We may share your personal data only with:
- Service providers and processors (e.g. Stripe, hosting, analytics providers);
- Accommodation partners where necessary for booking execution;
- Legal authorities, if required by applicable law or court order;
- Business transfers, in case of merger or acquisition (with safeguards).
All third parties are bound by confidentiality and data protection agreements consistent with GDPR.
Security of Your Personal Data
We apply appropriate technical and organisational measures to protect your personal data, including:
- TLS encryption during transmission,
- restricted access to authorised staff only,
- regular system audits and security updates,
- data backups in EU-based servers.
However, no internet transmission is 100 % secure, and we cannot guarantee absolute protection.
Children’s Privacy
Our Website does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. Suppose We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent. In that case, We take steps to remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent’s consent before We collect and use that information.
Links to Other Websites
Our Website may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Website, prior to the change becoming effective and update the “Last updated” date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Your rights
We provide you with the conditions to decide on the processing of your data. First of all, we grant You the following rights:
The right to access data
You have the right to request confirmation that we are processing Your data and if so, to gain access to that data. If we process a large amount of data relating to You, we may ask You to specify Your request to provide certain specific groups of data that we process about You.
Right to correction
If You notice that we are processing inaccurate or incomplete data about You or You want to change them, You have the right to request the correction of the same or the addition of incomplete personal data. To ensure that we continuously process only accurate personal data about You, You need to notify Us without delay of any changes to them.
Right to erase (“right to forget”)
Deleting Your personal data may be requested, for example, if You have withdrawn Your consent to the processing of Your data, when Your data is illegally processed or when Your information is no longer necessary for the purposes for which it was collected or processed in any way. However, please note that We will not be able to delete Your data if necessary to fulfil legal obligations, contractual obligations and other legal bases from the General Data Protection Regulation.
The right to limit processing
You have the right to restrict the processing of Your personal data, which may be required, for example, if You have objected to the processing of data, doubt the accuracy of personal data processed or the legality of their processing, do not want this data deleted, or still need in order to meet legal requirements.
The right to data portability
Suppose the processing is based on Your consent or is performed for the purpose of executing a contract concluded with You, and at the same time, is performed by automated means. In that case, You have the right to receive the personal data that we have received from You. If You request, we will transfer Your personal data directly to another controller, if technically feasible.
The right to object
At any time, given Your particular situation, You are authorized to object to the processing of personal data relating to You, which is why we will limit their processing. We will also delete the above data and stop processing it unless we prove reasonable and justified legal grounds for retaining it. In addition, You have the right to object at any time to the processing of Your personal data for the purpose of direct marketing. After submitting a complaint, Your data will cease to be processed for the stated purpose.
The right to complain to the supervisory authority
If you consider that the processing of Your personal data is contrary to the General Data Protection Regulation, You have the right to lodge a complaint with the competent supervisory authority.
The right to withdraw consent
If the processing of your personal data is based on consent, you have the right to withdraw it at any time, without any consequences. You can request the fulfilment of the stated rights:
By registered letter (marked “Data protection”) or
By personal arrival at the address on weekdays 09:00 – 17:00 at Litto d.o.o., Lovački put 7, 21000 SPLIT.
You can obtain more information on fulfilling your rights electronically by email: gdpr@litto.co.
Please note that when enclosing a complaint, it is necessary to identify Yourself.
If you are sending us a request by letter, please enclose a legible copy of a valid ID card and, if necessary, a proper power of attorney.
If you are coming in person, please bring your ID card and, if necessary, a valid power of attorney.
Identification is required to protect you as the owner of your personal information.
Contact Us
If you have any questions about this Privacy Policy, You can contact us:
Litto d.o.o. turistička agencija
Lovački put 7, 21000 Split, Croatia
E-mail: gdpr@litto.co
Website: https://www.litto.co