Privacy Policy (GDPR)
Last updated: 9 February 2026
This Privacy Policy explains how MASTER CHARTER d.o.o. (“we”, “us”, “our”) collects, uses, discloses, and protects personal data when you visit our website, subscribe to our newsletter, or make a booking request.
1) Data Controller (Voditelj obrade)
MASTER CHARTER d.o.o.
Registered office: Klis, Prugovo, Bezine 14, Croatia
OIB: 27750254102
Email: info@mastercharter.com
For privacy-related questions or requests, contact us at info@mastercharter.com.
2) Personal data we collect
A) Data you provide directly
- Identity & contact data: name, surname, email address, phone number
- Inquiry/communication data: message content and any attachments you send us
- Booking data: information needed to handle your booking request (e.g., dates, destination/route preferences, number of guests, special requests)
- Billing/invoicing data (if applicable): details necessary to issue an invoice or confirm a reservation (e.g., company name, address, OIB/VAT number)
B) Data collected automatically on the website
- Technical data: IP address, browser type, device type, operating system
- Usage data: pages visited, actions taken, referring URL, approximate location (derived from IP)
- Cookie identifiers and event data (see Section 9)
C) Payment data (important)
We do not process payment card details on our website and we do not use an online card payment provider. Payments (if applicable) are typically arranged offline (e.g., bank transfer/invoice) based on the booking agreement. We may process limited data required to confirm payment status (e.g., invoice number, payment confirmation).
3) Why we process personal data (purposes)
We process personal data to:
- Respond to inquiries and communicate with you
- Handle booking requests and provide services (including pre-contractual steps and contract management)
- Issue invoices and keep accounting records where legally required
- Send newsletters and marketing communications (where permitted)
- Operate, secure, and improve our website and user experience
- Prevent fraud/abuse and maintain IT security
- Establish, exercise, or defend legal claims where necessary
4) Legal bases for processing (GDPR)
We rely on the following legal bases:
- Contract / pre-contractual measures (Art. 6(1)(b)) – to handle booking requests and provide services.
- Legal obligation (Art. 6(1)(c)) – e.g., accounting/tax and statutory record-keeping obligations.
- Legitimate interests (Art. 6(1)(f)) – website security, preventing abuse, improving website and services (balanced against your rights).
- Consent (Art. 6(1)(a)) – for newsletter marketing and for non-essential cookies (analytics/marketing), including Google Analytics and Meta Pixel, where required.
You can withdraw consent at any time (see Sections 8–10).
5) Who we share personal data with
We may share personal data only as needed with:
- IT and hosting providers (hosting, maintenance, security)
- Analytics/marketing providers (Google Analytics, Meta Pixel) — only after cookie consent where required
- Email marketing provider (Mailchimp) to manage newsletter subscriptions and send emails
- Professional advisers (legal/accounting) where necessary
- Authorities where required by law or to protect rights and safety
We do not sell personal data.
6) Key third parties / processors we use
Google Analytics (Google)
Used to measure website usage and improve performance (analytics cookies; see Section 9).
Meta Pixel (Meta)
Used to measure advertising effectiveness and build/measure audiences (marketing cookies; see Section 9).
Mailchimp (newsletter)
We use Mailchimp (The Rocket Science Group LLC / Intuit group company) to manage newsletter subscriptions and send marketing emails. Mailchimp processes subscriber data on our instructions as our processor, including email address, optional name, and campaign interaction data (e.g., delivery, opens, clicks), depending on settings.
7) International transfers
Some providers (e.g., Google, Meta, Mailchimp) may process data outside the EEA (including in the United States). Where this occurs, we use appropriate safeguards under GDPR (such as Standard Contractual Clauses and/or other lawful mechanisms) to protect your personal data.
8) Your rights (GDPR)
Subject to legal conditions, you have the right to:
- Access your personal data
- Rectify inaccurate/incomplete data
- Erase data (where applicable)
- Restrict processing
- Data portability
- Object to processing based on legitimate interests
- Withdraw consent at any time (where processing is based on consent)
To exercise your rights, contact info@mastercharter.com. We may request identity verification to protect your data.
Right to complain
You can lodge a complaint with the Croatian supervisory authority:
Agencija za zaštitu osobnih podataka (AZOP)
Ulica Metela Ožegovića 16, 10 000 Zagreb, Croatia
9) Cookies, Google Analytics, and Meta Pixel
Master Charter uses both our own cookies and cookies from third parties to be able to improve your experience on the website. We also use the information to evaluate the use of various functions on the site and to support the marketing of our services.
Cookies are small text files stored on your device. We use cookies and similar technologies (including pixels) to ensure the website works properly, to understand how it is used, and to support our marketing.
Where required by law, we will ask for your consent before placing non-essential cookies. You can accept, reject, or customize your cookie choices via our cookie banner. You can also withdraw or change your choices at any time using the cookie settings (if available) and through your browser settings.
Cookie categories we use
Strictly necessary cookies
Necessary cookies help you make a website useful by enabling basic functions such as page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Legal basis: our legitimate interests in providing a functional and secure website and, where applicable, the performance of a contract / providing the service you request.
Analytics cookies (Google Analytics)
These cookies are used to collect information about how visitors use the website (e.g., pages visited, time spent, navigation). We use this information to improve website performance and user experience.
Tool used: Google Analytics (Google).
Legal basis: consent (where required).
Note: Google may process data (including cookie identifiers and IP-related data) and may store/process it outside the EEA, with appropriate safeguards (see Section 7).
Personalization cookies
These cookies allow the website to remember your choices (e.g., language preferences) and provide enhanced, more personalized features.
Legal basis: consent (where required) and/or legitimate interests depending on whether the cookie is strictly necessary for a feature you request.
Marketing & ads cookies (Meta Pixel)
These cookies (and similar technologies such as pixels) are used to track users across different websites and provide personalized ads, measure the effectiveness of advertising, and understand campaign performance.
Tool used: Meta Pixel (Meta).
Legal basis: consent (where required).
Note: Meta may process data outside the EEA with safeguards (see Section 7).
Managing cookies
You can manage cookies in several ways:
- Use our cookie banner to accept/reject categories or customize preferences (where available).
- Adjust your browser settings to delete or block cookies (note: blocking some cookies may affect site functionality).
- If you withdraw consent, this will not affect the lawfulness of processing carried out before withdrawal.
10) Newsletter and marketing communications (Mailchimp)
If you subscribe to our newsletter, we process:
- your email address (and optionally name),
- subscription metadata (e.g., time of signup, consent record),
- campaign interaction data (e.g., delivery, opens, clicks) depending on settings.
Legal basis: your consent (Art. 6(1)(a)).
You can unsubscribe at any time via the unsubscribe link in any newsletter email or by contacting info@mastercharter.com.
We may keep a minimal record of your unsubscribe request to ensure we respect your opt-out.
11) Data retention
We retain personal data only as long as necessary:
- Inquiries/contact requests: typically up to 24 months after last communication
- Bookings/contracts and related correspondence: for the duration of the relationship and as needed for legal claims
- Invoices/accounting records: retained as required by applicable law
- Newsletter subscription data: until you unsubscribe (then minimal suppression record may be kept)
- Analytics/marketing cookie data: according to cookie choices and the retention settings in our tools
12) Security
We implement appropriate technical and organizational measures to protect personal data (access controls, secure service providers, and reasonable safeguards). No method of transmission or storage is completely secure, but we work to reduce risks.
13) Third-party links and embedded content
Our website may include links to third-party websites or embedded services (e.g., maps, videos, social media). These third parties process your data under their own privacy policies.
14) Children
Our website and services are not intended for children, and we do not knowingly collect children’s personal data.
15) Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will be posted on this page with an updated “Last updated” date.