Privacy Policy
Last updated: 9 August 2026
At Parenzana Transfers, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and protect your personal information when you use our website, contact us or submit a transfer request.
This Privacy Policy is prepared in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Croatian data protection legislation.
1. Data Controller
The controller responsible for your personal data is:
GOAT Adventures
Poreč, Istria, Croatia
Email: parenzanabikeshop@gmail.com
Phone: +385 99 502 0293
For any questions regarding your personal data or this Privacy Policy, please contact us using the details above.
2. What Personal Data We Collect
Depending on how you use our website and services, we may collect:
-
First and last name
-
Email address
-
Telephone number
-
Preferred transfer date and time
-
Pick-up and drop-off locations
-
Number of passengers
-
Information about bicycles, including type and number of bikes
-
Information you voluntarily provide in messages or transfer requests
-
Information necessary to arrange and provide your transfer
We only collect information that is reasonably necessary for the purposes described in this Privacy Policy.
3. How We Use Your Personal Data
We may use your personal data to:
-
Respond to your enquiries and transfer requests
-
Check availability and provide you with a transfer quotation
-
Arrange and provide passenger, bicycle and luggage transfers
-
Communicate with you regarding your booking or request
-
Manage and administer our services
-
Process payments where applicable
-
Comply with legal and accounting obligations
-
Protect our legal rights and prevent misuse of our services
We do not sell your personal data.
4. Legal Basis for Processing
We process your personal data on one or more of the following legal bases under Article 6 of the GDPR:
Performance of a contract or steps taken at your request before entering into a contract – for example, when you submit a transfer request and we need your information to check availability, provide a quotation or arrange the requested service.
Legal obligation – where processing is necessary for compliance with applicable legal, tax or accounting requirements.
Legitimate interests – where necessary for the operation, security and improvement of our business, provided that our interests do not override your fundamental rights and freedoms.
Consent – where we specifically ask for your consent, such as for certain optional marketing communications or non-essential cookies. You may withdraw consent at any time.
5. Transfer Request Forms
When you submit a transfer request through our website, the information you provide is used to assess and arrange your requested transfer.
This may include your contact details, travel date, preferred pick-up time, locations, number of passengers and bicycle information.
Submitting a transfer request does not automatically guarantee a booking. We will first check availability and contact you with the relevant information and price.
6. Who May Receive Your Personal Data
We may share personal data only where necessary to provide our services or comply with legal obligations.
This may include:
-
Service providers who help us operate our website, email, hosting or booking systems
-
Payment service providers, where applicable
-
Accounting and professional service providers
-
Public authorities where disclosure is required by law
Where we use third-party service providers to process personal data on our behalf, we take appropriate steps to ensure that they process the data in accordance with applicable data protection requirements.
We do not sell or rent your personal data to third parties.
7. International Data Transfers
Some of our website, hosting, communication, analytics or other service providers may process personal data outside the European Economic Area (EEA).
Where personal data is transferred outside the EEA, we will ensure that the transfer is made in accordance with the GDPR and using an applicable legal safeguard, such as an adequacy decision or appropriate contractual safeguards where required.
8. How Long We Keep Your Data
We keep personal data only for as long as necessary for the purposes for which it was collected.
Transfer enquiries and booking-related information may be retained for as long as reasonably necessary to manage the enquiry, provide the service, resolve potential disputes and meet legal, accounting or tax obligations.
Where a longer retention period is required by law, we will retain the relevant information for the period required by applicable legislation.
When personal data is no longer required, it will be securely deleted or anonymised where appropriate.
9. Data Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration or disclosure.
Access to personal data is limited to people and service providers who need it for legitimate business purposes.
However, no method of transmission or storage over the internet can be guaranteed to be completely secure.
10. Cookies
Our website may use cookies and similar technologies.
Some cookies are necessary for the website to function properly. Other cookies, such as analytics or marketing cookies, may only be used where legally permitted and, where required, after obtaining your consent.
You can manage or withdraw your cookie preferences through the cookie settings available on our website or through your browser settings.
11. Your Rights Under the GDPR
Depending on the circumstances and applicable legal requirements, you have the right to:
-
Request access to your personal data
-
Request correction of inaccurate or incomplete data
-
Request deletion of your personal data
-
Request restriction of processing
-
Object to certain processing
-
Request data portability
-
Withdraw consent where processing is based on consent
-
Lodge a complaint with a supervisory authority
To exercise your rights, please contact us using the contact details provided in Section 1.
We may need to verify your identity before fulfilling certain requests.
12. Right to Lodge a Complaint
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent data protection supervisory authority.
In Croatia, the supervisory authority is:
Croatian Personal Data Protection Agency (AZOP)
Ulica Metela Ožegovića 16
10000 Zagreb, Croatia
Email: azop@azop.hr
Website: www.azop.hr
AZOP is the Croatian supervisory authority responsible for monitoring the application of the GDPR and Croatian data protection legislation.
13. Children
Our website and transfer services are not specifically directed at children.
We do not knowingly collect personal data from children through our website unless such information is provided by a parent, guardian or another person lawfully authorised to provide it.
14. Third-Party Websites
Our website may contain links to third-party websites or services.
We are not responsible for the privacy practices, content or security of third-party websites. We recommend reviewing their privacy policies before providing them with personal information.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, technology, legal requirements or data processing practices.
The latest version will always be published on this page, together with the date of the most recent update.
16. Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
[LEGAL BUSINESS NAME]
[BUSINESS ADDRESS]
Croatia
Email: [EMAIL ADDRESS]
Phone: +385 99 502 0293
We will respond to privacy-related enquiries within the timeframe required by applicable data protection law.