Privacy Policy

Last updated: 15 September 2026

This Privacy Policy explains how personal data is handled when you visit CroatiaPortal.com or contact us.

1. Data controller

The data controller is Croatia Portal, the operator of CroatiaPortal.com. Privacy enquiries and requests can be sent to hello@croatiaportal.com.

2. Data we may collect

  • Contact information: your name, email address, subject and message when you use the contact form or email us.
  • Technical and security information: IP address, browser and device information, requested pages, timestamps, diagnostic records and security logs generated when the site is accessed.
  • Consent and preference information: the choices recorded through the consent banner, the policy version, banner status and, where used, language preferences. See our Cookie Policy.
  • Analytics information: only after the relevant consent, Google Analytics 4 may collect pseudonymous client and session identifiers, page views, interactions and enhanced-measurement events, approximate location, referral information, and browser and device characteristics. CroatiaPortal does not intentionally send names, email addresses or contact-form content to Google Analytics.

3. Why we use personal data

  • To reply to questions, corrections and collaboration enquiries.
  • To operate, secure, troubleshoot and deliver the website.
  • With consent, to understand how visitors use the site and improve content, navigation and performance.
  • To prevent spam, abuse and unauthorised access.
  • To comply with legal obligations and establish or defend legal claims when necessary.

4. Legal bases

Depending on the circumstances, processing is based on steps taken at your request, our legitimate interests in operating and protecting the site, your consent for optional analytics and related technologies, or compliance with a legal obligation. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.

5. Service providers and sharing

We do not sell personal data. Data may be processed by service providers that support hosting, WordPress operation, security, form and email delivery, and by Google when Google Analytics 4 or externally hosted Google Fonts are permitted by your consent settings. Google Site Kit connects the site to Analytics and Search Console; authorised WordPress users are excluded from Analytics tracking.

Google describes how it uses information from sites that use its services at policies.google.com/technologies/partner-sites and in the Google Privacy Policy. Service providers may process data only as needed to provide their services or where required by law.

6. International transfers

If a service provider processes personal data outside the European Economic Area, an applicable adequacy decision or another safeguard recognised by data-protection law, such as standard contractual clauses, is used where required. Google states that Analytics traffic from the EEA, Switzerland and the United Kingdom is collected through regional domains and servers before onward processing.

7. Retention

  • Contact enquiries are normally kept no longer than 12 months unless a longer period is required for legal or security reasons.
  • Technical and security logs are kept for the shortest period reasonably necessary for operation, troubleshooting and protection.
  • Complianz consent records are normally stored for up to 365 days; WP Consent API category records are normally stored for up to 30 days.
  • In the current Google Analytics property, event-level data linked to cookies or identifiers is retained for 2 months and user-level data for 14 months. The user-data period resets when new user activity is recorded. These settings do not affect most standard reports based on aggregated data.

8. Your choices and rights

You can accept, deny or configure optional technologies in the consent banner and change the choice later using Manage consent. Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal data, object to certain processing, and withdraw consent. Send requests to hello@croatiaportal.com. We may need to verify your identity.

You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority.

9. Security

We use reasonable technical and organisational measures to protect personal data. No internet transmission or storage method is completely secure, so absolute security cannot be guaranteed.

10. External links

Our articles may link to third-party websites. Their privacy practices are controlled by those third parties, and we recommend reviewing their policies before providing personal data.

11. Changes and contact

We may update this policy when the site, its services or applicable requirements change. The current version and update date will be published on this page. Questions can be sent to hello@croatiaportal.com.