Legal information and Privacy Policy

Legal Information

APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela

St. Spasa Street 21

21000 SPLIT

Croatia

OIB: 69579669113
Mobile: 99359871

Phone: +385 95 8042 739

E-mail: igor@apexhospitality.hr

Copyright

All content of this website (images, videos, texts, documents) is subject to the copyright protection of APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela Content may not be copied without written consent. The basis of the site is based on the WordPress platform which is subject to GPL licensing, the WordPress theme was made to order by APEX HOSPITALITY, service trade, owner Igor Pavela

Privacy Policy

the APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela website is possible without any indication of personal data; however, if the visitor wants to use specific company services via our website, the processing of personal data may become necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we generally accept the consent of the visitor.

The processing of personal data, such as the name, address, e-mail address or telephone number of the data subject is always in accordance with the General Data Protection Regulation (GDPR) and in accordance with the specific data protection regulations applicable to APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela With this data protection declaration, our company would like to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, data subjects are informed through this data protection declaration about the rights to which they are entitled.

As the controller, APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed via this website. However, Internet-based data transfers may in principle have security gaps and absolute protection may not be guaranteed. For this reason, each data subject is free to transmit personal data to us via alternative means, e.g. by telephone.

1. Definitions

The data protection declaration of APEX HOSPITALITY, service trade, owned by Igor Pavela is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our data protection declaration should be readable and understandable for the general public, as well as for our customers and business partners. To ensure this, we would like to start by explaining the terminology used.

In this data protection declaration, we use, among others, the following terms:

Personal data

Personal data means any information relating to an identified or identifiable natural person (“data subject”). An identified natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Data subject

A data subject is any identified or identifiable natural person whose personal data are processed by the controller responsible for the processing.

Processing

Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Processing restriction

Restriction of processing refers to the storage of personal data with the aim of limiting their processing in the future.

Profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to the natural person’s employment, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

Pseudonymization

Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

Controller or controller responsible for the processing

The controller or controller responsible for the processing is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for his appointment may be provided for by Union or Member State law.

Processor

Processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient

A recipient is a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether or not a third party. However, public authorities which may receive personal data in the context of a specific investigation in accordance with Union or Member State law shall not be considered recipients; the processing of such data by those public authorities shall comply with the applicable data protection rules in accordance with the purposes of the processing.

Third party

A third party is a natural or legal person, public authority, agency or body other than the subject, controller, processor and persons who are under the direct supervision of a superior or processor authorized to process personal data.

Consent

The consent of the data subject is any freely given information or wish of the data subject who, by his/her statements or clear affirmative actions, signifies agreement to the processing of personal data relating to him/her.

2. Name and address of the controller

Controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in the member states of the European Union and other provisions related to data protection:

APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela

St. Spasa Street 21

21000 SPLIT

Croatia

Phone: +385 95 8042 739

E-mail: igor@apexhospitality.hr

Internet location: apexhospitality.hr

3. Name and address of the data protection officer

The Personal Data Protection Officer is:

Igor Pavela

APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela

St. Spasa Street 21

21000 SPLIT

Croatia

Phone: +385 95 8042 739

E-mail: igor@apexhospitality.hr

Internet location: apexhospitality.hr

Any data subject may contact our Data Protection Officer at any time with any questions and suggestions related to data protection.

4. What information do we collect about you and how?

We collect information about you when you fill out any of the forms on our website, that is, by sending an inquiry. Data about the use of websites is collected using cookies.

If you are under 16 years of age, you must obtain parental consent before completing any form on our website.

When you submit a form on our website, we use a third-party software provider for automated data collection and processing. The provider will not use your data for any purpose and will only retain it in accordance with our data retention policy.

5. Cookies

Cookies are text files placed on your computer to collect standard Internet log information and visitor behavior information. This information is then used to track visitors’ use of the website and to compile statistical reports on website activity.

For more information, visit www.aboutcookies.org or www.allaboutcookies.org.

You can set your browser not to accept cookies, and the websites listed above provide information on how to remove cookies from your browser. Please note that in some cases some of the features on our website may not function as a result.

Cookies can be “First Party”, i.e. set by us, or “Third Party” – set by another company to perform this function, for example Google Analytics or our advertising cookies. Some of these third parties use their own anonymous cookies to track how many people have seen a particular ad or to track how many people have seen it multiple times. The companies that generate these cookies have their own privacy policies and we do not have access to read or write these cookies. These organisations may use their cookies to anonymously target advertising on other websites, based on your visit to this website.

Our use of cookies

We use the following cookies:

– Strictly necessary cookies : help the website to function and improve the look and feel of the website. They also help to improve navigation on our website and allow you to return to pages you have previously visited. This type of cookie only lasts for the duration of your visit to the website. When you leave the website, they are automatically deleted.

– Analytical cookies : allow us to recognize and count the number of visitors and to see how visitors move around our website when using them. This helps us improve the way our website works, for example, so that users can more easily find what they are looking for and what interests them.

– Functionality cookies : used to recognize when you return to our website. This allows us to customize our content, personalize it and remember your preferences (for example, your choice of language or region).

6. Data protection provisions on the application and use of Google Analytics

On this website, the controller has integrated a component of the Google Analytics service. Google Analytics is a web analysis service. Web analysis collects and analyzes data about the behavior of visitors on websites. The web analysis service collects, among other things, data about the website from which a person came (the so-called Referrer), which subpages were visited or how often and for what time subpages were viewed. Web analysis is mainly used to optimize the website and to conduct an analysis of the costs and benefits of online advertising.

The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States.

The purpose of the Google Analytics service component is to analyze the traffic on our website. Google collects collected data and information, among other things, to evaluate the use of our website and provide online reports that show the activities on our website and provide other services related to the use of our website for us.

Google Analytics places a cookie on the information technology system of the data subject. The definition of a cookie is explained above. The cookie is used to store personal data, such as the time of access, the location from which the access is made and the frequency of visits to our websites by the data subject. With each visit to our website, such personal data, including the IP address of the Internet access used by the data subject, will be transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may transfer this personal data collected by the technical process to third parties.

The data subject may, as stated above, prevent the setting of cookies through our website at any time by making a corresponding adjustment to the Internet browser used and thus permanently deny the setting of cookies. Such an adjustment to the Internet browser used would also prevent Google Analytics from setting cookies on the information technology of the data subject. In addition, cookies already used by Google Analytics can be deleted at any time via the Internet browser or other software programs.

In addition, the data subject has the possibility of objecting to the collection of data generated by Google Analytics, which relates to the use of this website, as well as the processing of this data by Google and the possibility of preventing it. For this purpose, the data subject must download the browser add-on under the link https://tools.google.com/dlpage/gaoptout and install it. This browser add-on tells Google Analytics via JavaScript that all data and information about visits to the website will not be transmitted to Google Analytics. The installation of the browser add-on is considered an objection to Google. If the information system of the data subject is subsequently deleted, formatted or newly installed, the data subject must reinstall the browser add-on in order to disable Google Analytics. If the browser add-on has been uninstalled by the data subject or any other person attributable to him or her or has been disabled, it is possible to reinstall or reactivate the browser add-on.

Further information and the applicable data protection provisions from Google can be downloaded at https://www.google.com/intl/en/policies/privacy/ and http://www.google.com/analytics/terms/us.html Google Analytics is further explained at the following link: https://www.google.com/analytics/

7. Data protection provisions on the application and use of Facebook

On this website, the controller has integrated components of the company Facebook. Facebook is a social network.

A social network is a place for social gatherings on the Internet, an online community that typically allows users to communicate and interact with each other in a virtual space. A social network can serve as a platform for exchanging opinions and experiences, or allow the online community to provide personal or business information. Facebook allows users of the social network to include creating private profiles, uploading photos, and networking through friend requests.

The Facebook operating company is Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, United States of America. If a person lives outside the United States of America or Canada, the controller is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

If the person is logged in to Facebook at the same time, Facebook detects with each call-up to our website by the data subject and for the entire duration of his/her stay on our website – which specific sub-pages of our website the data subject has visited. This data is collected via the Facebook component and linked to the respective Facebook account of the data subject. If the user clicks on one of the Facebook buttons integrated into our website, e.g. the “Like” button, or if the data subject submits a comment, then Facebook associates this data with the personal Facebook user account of the data subject and stores the personal data.

The data protection guideline published by Facebook, available at https://facebook.com/about/privacy/, provides information on the collection, processing and use of personal data by Facebook. In addition, it explains which settings Facebook offers to protect the privacy of data subjects. In addition, various configuration options are available to enable the removal of data transmission to Facebook, e.g. the Facebook blocker from the service provider Webgraph, which can be obtained under http://webgraph.com/resources/facebookblocker/. This application can be used by the data subject to remove the transmission of data to Facebook.

8. Data protection provisions on the application and use of Youtube

We embed videos from our YouTube channel. You do not need to register with either YouTube or Google (the owner of YouTube) to watch embedded videos. When you watch these videos, YouTube may record non-personally identifiable information about your use of the website, such as channels used, videos viewed, and data transfer data, in order to improve its services. If you log in to the YouTube website before watching a video, YouTube may associate information about your use of the website with your YouTube account. If you log in to YouTube and comment on an embedded video, any personal information you provided when registering for your account will be visible to visitors who click on the comment.

If you do not log in to YouTube before watching an embedded video, your use of the website will not be associated with you or your YouTube account. For details on YouTube’s collection and management of your personal data and related rights, please refer to YouTube’s privacy policy at the following link: https://www.youtube.com/static?template=privacy_guidelines

9. Access to your information, correction, portability and deletion of data

What is a data access request?

This is your right to request a copy of the information we hold about you. If you want a copy of some or all of your personal data, send us an e-mail to: igor@apexhospitality.hr or write to us at the address: Igor Pavela, APEX HOSPITALITY, obrt za usluge, vl. Igor Pavela, Ulica Sv. Spasa 21, 21000 SPLIT.

We will respond to your request within 30 days of receiving it.

We want to ensure that your personal information is accurate and up to date. You can request that we correct or remove information that you consider to be incorrect, by e-mail to: igor@apexhospitality.hr or by writing to the above address.

Data transfer

You also have the right to receive the personal data you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without undue delay from the current controller if:

(a) The processing is based on consent or a contract, and

(b) The processing is carried out by automated means.

Right to erasure (Right to be forgotten)

If you want us to completely delete all information related to you, send us a Data Deletion Request in the following ways:

Email: igor@apexhospitality.hr

In writing: Igor Pavela, APEX HOSPITALITY, service business, owned by Igor Pavela, Ulica Sv. Spasa 21, 21000 SPLIT.

10. Final provisions

Our website contains links to other websites. This privacy policy applies only to this website. apexhospitality.hr is not responsible for the content and privacy policies of other websites.

If you believe that your personal data has been processed in a manner that does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority.
The supervisory authority will inform you about the progress and outcome of your complaint. The supervisory authority in the Republic of Croatia is the Personal Data Protection Agency.

We regularly review our privacy policy and post any updates on this website. This privacy policy was last updated on 25.9.2026.