1. Controller
KARLO LEONE d.o.o. za uslugePut stare Duće 33, 21310 Duće, Croatia
OIB: 75342528626
Email: info@almissum-residences.com
Telephone: +385 91 505 9548
KARLO LEONE d.o.o. is the controller for personal data processed through this website, direct enquiries and accommodation bookings, except where a third-party provider acts as an independent controller for its own service.
2. Scope
This policy applies when you visit the website, contact us, make or manage a booking, submit a consumer complaint, use the Lodgify availability module, use the stay-enquiry form or follow links to external services.
3. Hosting, access logs and website security
The website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When the website is requested, hosting and security systems may process the IP address, date and time, requested URL, referrer, browser and device information, transferred data volume, response status, error logs and security events.
The purposes are to deliver the website, maintain availability and security, diagnose errors and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of the website. Where processing is necessary to take steps at your request before a booking, Article 6(1)(b) GDPR also applies.
Further information: IONOS privacy information .
4. Enquiries and communications
If you contact us, we process the information you provide, such as name, email address, telephone number, travel dates, group composition, residence preferences and message content. We use it to answer the enquiry, prepare or perform a booking and document relevant communications.
The stay-enquiry form is processed on the IONOS-hosted website and delivered to the operator’s email account. The form includes technical abuse-prevention fields. Submitting it does not create a reservation.
The legal basis is Article 6(1)(b) GDPR for pre-contractual steps and contract performance. Article 6(1)(f) GDPR applies to general communication, service quality, abuse prevention and the establishment, exercise or defence of legal claims.
5. Written consumer complaints
When you submit a written consumer complaint, we process your contact details, booking reference, complaint content, supporting documents and our response. The purpose is to acknowledge, investigate and answer the complaint and to keep the legally required complaint record. The legal bases are Article 6(1)(c) GDPR and applicable Croatian consumer law, and Article 6(1)(f) GDPR for legal claims.
6. Lodgify availability and booking services
Availability and direct booking functions are supplied through Lodgify. The module is loaded on the Private Stays and Winter Residence booking sections and sends search results to the branded booking host book.almissum-residences.com. Its technical delivery may transmit the IP address, date and time, referrer, browser and device information to Lodgify. If you search or book, dates, number of guests, name, contact details, booking details, messages and payment-related information may also be processed.
For guest data processed on our instructions, Codebay Solutions Limited, Magma House, 16 Davy Court Way, Castle Mound Way, Rugby, Warwickshire CV23 0UZ, United Kingdom, acts as a processor. Lodgify or connected providers may act as independent controllers for particular functions that they determine themselves.
The legal basis for availability requests, pre-contractual steps and bookings is Article 6(1)(b) GDPR. Article 6(1)(f) GDPR applies to the technically secure provision of the booking function and fraud prevention. Any non-essential cookie or comparable device storage requires consent under Article 6(1)(a) GDPR and applicable electronic-communications law.
Further information: Lodgify privacy policy .
7. Payments
If an online payment is offered, the payment provider shown in the booking process receives the information needed to process the payment. KARLO LEONE d.o.o. normally receives payment status, amount, date, transaction reference and limited payer details rather than complete card data. The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR for accounting and tax duties. Fraud prevention may be based on Article 6(1)(f) GDPR.
8. Guest registration, accounting and legal duties
For confirmed stays, we may be legally required to collect and record identity, nationality, identification-document, arrival, departure and accommodation data and to submit required information through Croatian guest-registration or tourism systems. Booking, invoice and payment records may also be retained for accounting, tax and regulatory purposes. The legal basis is Article 6(1)(c) GDPR.
Required data may be disclosed to competent Croatian authorities, tourist boards, tax authorities, courts or law-enforcement bodies where the law requires it.
9. Instagram, Google Reviews, Google Maps and external links
The Instagram area uses locally hosted property images and an ordinary link; no live Instagram feed is loaded on the initial page. Google Reviews and Google Maps are also provided as ordinary links rather than embedded live feeds. No personal data is sent to those providers merely because such a local image or link is displayed.
If you follow an external link, the destination provider receives technical connection data and processes information under its own privacy policy. The provider is responsible for that processing. We recommend reviewing the destination policy before submitting data or signing in.
10. Cookies and similar technologies
The operator does not currently use confirmed advertising pixels or audience-analytics tools on this website. Strictly necessary cookies or local storage may be used to deliver requested functions, maintain security and remember privacy choices.
Lodgify and connected payment providers may use cookies, local storage or similar technologies when their functions are loaded or used. Strictly necessary storage may be used without consent where permitted by law. Non-essential storage is permitted only after prior consent. Consent may be withheld or withdrawn without affecting the basic website or the lawfulness of processing before withdrawal.
11. Recipients and processors
Personal data may be made available, as necessary, to:
- hosting, IT-security, email and technical-support providers;
- Lodgify and its approved subprocessors;
- the payment provider selected in the booking process;
- accountants, tax advisers, legal advisers and insurers;
- cleaning, maintenance, transfer or other service providers where needed to perform a requested stay;
- competent authorities and statutory tourism or guest-registration systems where legally required.
Service providers acting as processors are bound by contractual data protection duties. We do not sell personal data.
12. International transfers
Some providers or their subprocessors may process data outside the European Economic Area, including in the United Kingdom or the United States. Where required, transfers rely on an applicable European Commission adequacy decision or appropriate safeguards such as the European Commission’s standard contractual clauses, together with supplementary measures where necessary. You may request information about the safeguard relevant to your data using the controller contact details above.
13. Retention
- Server and security logs are retained only for the period needed for delivery, troubleshooting and security, unless an incident requires longer preservation.
- Unsuccessful enquiries are normally retained for up to 24 months after the last substantive communication, unless a shorter period is requested or a legal claim requires longer retention.
- Written consumer-complaint records are retained for one year from receipt, and longer only where required for a live dispute or legal claim.
- Booking, invoice, payment, guest-registration and tax records are retained for the applicable statutory periods and limitation periods.
- Consent records are retained for as long as reasonably necessary to demonstrate compliance and until relevant claims are time-barred.
Data is deleted or anonymised when no longer needed, subject to legal retention duties and the establishment, exercise or defence of claims. Independent providers apply their own retention periods.
14. Whether data is required
You are not required to provide data merely to browse the basic website. Contact and booking data marked as required is necessary to answer a request, conclude or perform a booking, process payment or meet guest-registration duties. Without it, we may be unable to answer, accept or perform the booking. Optional information is identified as such where appropriate.
15. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing and data portability. You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. If processing is based on consent, you may withdraw that consent at any time for the future.
Send requests to info@almissum-residences.com . We may request information needed to verify identity. Requests are handled without undue delay and normally within one month, subject to lawful extensions.
16. Complaint to the supervisory authority
You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the alleged infringement. The Croatian supervisory authority is:
Agencija za zaštitu osobnih podataka (AZOP)
azop.hr
Information on lodging a complaint
17. Automated decision-making
KARLO LEONE d.o.o. does not make decisions producing legal or similarly significant effects solely by automated means and does not carry out profiling for advertising on this website. A payment or fraud- prevention provider may apply its own automated checks under its own privacy information.
18. Security
Appropriate technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. No internet transmission or storage system can be guaranteed to be completely secure.
19. Changes to this policy
This policy will be updated when processing activities, providers or legal requirements materially change. The current version and update date are published on this page. Where required, material changes will be communicated by additional appropriate means.