Privacy policy

How Nini Tours collects, uses, and protects personal data for bookings and enquiries. GDPR rights, cookies, retention, processors, and AZOP contact for data requests in Split, Croatia.

Last updated: 10 July 2026

1. Introduction

This Privacy Policy explains how NINI TOURS d.o.o. and NINI TOURS LUXURY j.d.o.o., trading as Nini Tours / Nini Travel Agency (“we”, “us”, “our”), collect, use, store, and share personal data when you use https://ninitours.com, contact us, or book transfers or tours (including via WooCommerce checkout).

We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the Croatian Act on the Implementation of the General Data Protection Regulation, and other applicable laws.

2. Data controller

For personal data processed in connection with booking requests, passenger details, itinerary fulfilment, customer support, and the travel service itself, the controller is:

NINI TOURS d.o.o. Address: Vrlička 27, 21000 Split, Croatia OIB: 16246966048 · MB: 02170906 Email: info@ninitours.com Phone: +385 95 569 6566 Privacy contact: info@ninitours.com

Payment-related data (for example card checkout metadata, transaction identifiers, billing details required for payment, and records needed for payment confirmation, refunds, chargebacks, and accounting) may be processed by:

NINI TOURS LUXURY j.d.o.o. Address: Vrlička 27, 21000 Split, Croatia OIB: 49887955927 · MB: 05939356

depending on the payment flow: (i) as a separate controller for payment collection and related compliance; and/or (ii) as a processor acting on documented instructions of NINI TOURS d.o.o. for payment steps that form part of booking fulfilment. Where both companies determine purposes and means of a specific processing activity together, they may act as joint controllers for that activity and will ensure that the essence of the arrangement is made available as required by Article 26 GDPR.

We have not appointed a Data Protection Officer because we are not required to do so under Article 37 GDPR. Privacy requests may be sent to info@ninitours.com.

3. Personal data we collect

Depending on your interaction with us, we may process identity and contact data (name, email, phone, billing details); booking and travel data (pickup and drop-off locations, travel dates and times, passenger count, flight or ferry numbers, special requests, booking reference, communications); payment data (payment status, partial card metadata such as last digits and card brand, transaction IDs — full card data is processed by payment providers and is not stored by us in full); technical and usage data (IP address, device and browser information, pages viewed, cookie identifiers); and marketing preferences if you subscribe.

We do not intentionally collect special-category data. If you voluntarily share health or accessibility information to arrange assistance, we process it only as needed to provide the requested service.

4. How we collect data

We collect data directly from you (forms, checkout, email, phone, messaging); automatically via cookies and similar technologies; from payment providers and WooCommerce order processing; and occasionally from travel companions or a booking agent acting on your behalf.

5. Purposes and legal bases

We process data to provide bookings and services (GDPR Art. 6(1)(b) — contract); to process payments and prevent fraud (contract and legitimate interests; legal obligation where applicable); for legal and accounting compliance (legal obligation); to operate and secure the website (legitimate interests); for analytics if enabled (consent and/or legitimate interests where permitted); for marketing emails if any (consent, or soft opt-in where legally allowed); and for accessibility or special assistance notes you disclose (contract and/or consent).

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

6. Who we share data with

We share data only as needed with website hosting and infrastructure providers; WooCommerce / WordPress-related service providers supporting order processing; NINI TOURS LUXURY j.d.o.o. for deposit and card checkout; payment service providers configured at checkout; email and communications tools if used; analytics or advertising tools if enabled and consented; professional advisers under confidentiality; public authorities where legally required; and operational partners strictly necessary to perform the booking (for example an assigned driver or guide under our instructions).

We require processors to protect personal data under GDPR Article 28 contracts where applicable.

7. International transfers

Some providers may process data outside the EEA. Where that occurs, we use appropriate safeguards such as adequacy decisions of the European Commission, Standard Contractual Clauses (SCCs), and/or other lawful transfer mechanisms. Details for specific tools are available on request via info@ninitours.com.

8. Retention

We retain personal data only as long as necessary. Booking and contract data are typically retained for the duration of the booking and thereafter for about 7 years (or the statutory period required for accounting, tax, and legal claims in Croatia). Customer support correspondence is typically retained for 2–3 years after closure unless needed longer for disputes. Marketing lists are retained until you unsubscribe, plus a short suppression period. Cookie and analytics data follow lifetimes in the Cookie Policy. Server logs are typically retained for 30–90 days unless needed for security investigations.

When retention ends, data is deleted or anonymised.

9. Your rights

Subject to GDPR conditions and exceptions, you have the right to access your data; rectification; erasure; restriction of processing; data portability; object to processing based on legitimate interests; withdraw consent at any time; and lodge a complaint with a supervisory authority.

Croatian supervisory authority: Agencija za zaštitu osobnih podataka (AZOP), https://azop.hr

To exercise rights, email info@ninitours.com with enough information to verify your identity and locate your data (for example a booking reference).

10. Cookies, children, and security

We use cookies and similar technologies as described in our Cookie Policy. Essential cookies are required for site and checkout function. Analytics or marketing cookies, if used, require consent where required by law.

Our services are aimed at adults booking travel. We do not knowingly collect personal data from children for marketing. Passenger details for minors may be processed only as needed for a booking made by a parent, guardian, or adult booker.

We implement appropriate technical and organisational measures. No method of transmission or storage is 100% secure.

We do not use solely automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 GDPR.

11. Changes and contact

We may update this Privacy Policy periodically. The “Last updated” date will change when revisions are published.

Privacy requests: info@ninitours.com Postal: Vrlička 27, 21000 Split, Croatia Phone: +385 95 569 6566