Privacy Policy
Last updated: 22 June 2026
Baš Nas d.o.o. ("we", "us", "Data Controller") is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and applicable Croatian data protection law (Act on Implementation of the General Data Protection Regulation, NN 42/2018). This Privacy Policy explains what personal data we collect, why, how we process it, and what rights you have.
1. Data Controller
The data controller is Baš Nas d.o.o., tax ID (OIB): —, registered address: —, Republic of Croatia. You may contact us at: info@byrubinic.com.
2. Data We Collect and How
We collect only data that is strictly necessary to provide the table reservation service:
- Contact details: full name, email address, phone number — collected when you submit a reservation; necessary to send a confirmation and communicate about your booking.
- Reservation data: event date, table label, guest count, selected drinks and quantities, notes — necessary for contract performance.
- Payment data: transaction identifier provided by our payment processor (Stripe). We do not store credit or debit card details; those are entered exclusively on Stripe's secure, PCI DSS certified pages.
- Company tax data for VAT invoice (optional): Croatian tax ID (OIB), company name and address — only if you request a VAT invoice (R1 račun). OIB is used solely for fiscal invoicing purposes under the Croatian Fiscalisation Act (NN 133/12 and amendments) and the VAT Act (NN 73/13 and amendments).
- Technical data: IP address, browser type and version, date and time of access — collected automatically for system security and abuse prevention.
We do not collect special categories of personal data under Art. 9 GDPR (health data, religious beliefs, racial origin, biometric data, etc.).
3. Purpose and Legal Basis
We process your data on the following legal bases (Art. 6 GDPR):
- Contract performance (Art. 6(1)(b)) — processing and managing your reservation, sending confirmations and reminders, enabling payment, communicating about your attendance.
- Legal obligation (Art. 6(1)(c)) — retaining fiscal records and accounting documentation under Croatian tax law (minimum 11 years under the Accounting Act, NN 78/15 and amendments, and the Fiscalisation Act); disclosing data to competent authorities when required by law.
- Legitimate interest (Art. 6(1)(f)) — protecting our information systems, preventing fraud, and maintaining venue security records. You may object to processing based on this ground; see Your Rights below.
- Consent (Art. 6(1)(a)) — sending promotional emails (only with your explicit consent). You may withdraw consent at any time by clicking the unsubscribe link in any marketing email or contacting info@byrubinic.com, without affecting the lawfulness of prior processing.
4. Data Sharing and International Transfers
We do not sell your personal data and do not use it for purposes other than those stated in this Policy. We share data only as follows:
- Stripe Inc. (payment processor) — for payment processing. Stripe is PCI DSS certified. Stripe, Inc. is incorporated in the United States; transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR. Stripe also operates within the EU via Stripe Payments Europe, Ltd. (Ireland). Further information: stripe.com/privacy.
- Email / SMS service provider — for transactional messages (confirmations, reminders, fiscal invoices). Processing takes place within the European Economic Area (EEA).
- Competent Croatian and EU authorities — when required by law (e.g., Tax Administration, courts, law enforcement).
- IT infrastructure providers (hosting, cloud) — under a written Data Processing Agreement (DPA) ensuring equivalent protection under GDPR.
All recipients are bound by Data Processing Agreements and may not use your data for their own purposes.
5. Retention Periods
- Reservation and customer data — retained for 3 years from the event date, then deleted or anonymised.
- Fiscal records and accounting documentation — retained for 11 years from the end of the business year to which they relate, as required by the Croatian Accounting Act and Fiscalisation Act.
- Technical logs — retained for up to 90 days, then automatically deleted.
- Marketing data (with consent) — retained until consent is withdrawn, then deleted within 30 days.
6. Your Rights
Under GDPR and applicable Croatian law you have the following rights:
- Right of access (Art. 15) — you may request confirmation that we process your data and obtain a copy of the data we hold.
- Right to rectification (Art. 16) — you may request correction of inaccurate or completion of incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17) — you may request deletion when data is no longer necessary for the purpose for which it was collected, subject to mandatory legal retention obligations (e.g. fiscal records).
- Right to restriction of processing (Art. 18) — in certain circumstances you may request that we temporarily restrict processing of your data.
- Right to data portability (Art. 20) — you may receive your data in a structured, machine-readable format or request its transfer to another controller.
- Right to object (Art. 21) — you may object to processing based on legitimate interest or for direct marketing purposes; in the latter case we will cease processing immediately.
- Right to withdraw consent — you may withdraw consent for consent-based processing at any time with no adverse consequences and without affecting the lawfulness of prior processing.
Submit a request in writing to info@byrubinic.com. We respond within 30 days of receipt. In justified and complex cases the deadline may be extended by a further 60 days, of which we will notify you. We may request identity verification to prevent unauthorised access to third-party data.
7. Cookies
We use only technically necessary cookies required for the website to function (e.g. session management). These cookies do not require your consent under Art. 5(3) of the ePrivacy Directive (2002/58/EC) and applicable Croatian e-communications law.
We do not use tracking cookies, third-party analytics cookies (e.g. Google Analytics), or advertising cookies without your explicit consent. If we implement such cookies in the future, we will update this Policy and seek your consent.
8. Data Security
We implement appropriate technical and organisational security measures in accordance with Art. 32 GDPR, including:
- TLS/HTTPS encryption for all communications between your browser and our servers
- Encryption of sensitive data at rest in our database
- Access controls and authentication for all administrative functions
- Regular security audits and software updates
- Limiting data access to employees who require it to perform their duties
In the event of a personal data breach likely to jeopardise your rights and freedoms, the supervisory authority (AZOP) will be notified within 72 hours of our becoming aware of the breach, and you will be notified without undue delay, in accordance with Art. 33 and 34 GDPR.
9. Automated Decision-Making and Profiling
We do not use automated decision-making that would produce legal or similarly significant effects on you, nor do we engage in profiling within the meaning of Art. 22 GDPR.
10. Protection of Minors
Our service is intended exclusively for persons aged 18 and over. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected data from a minor, we will delete it without delay and, where possible, notify a parent or guardian.
11. Supervisory Authority
If you believe we are processing your personal data unlawfully or have infringed your rights, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP):
- Address: Selska cesta 136, 10 000 Zagreb, Republic of Croatia
- Tel.: +385 (0)1 4609 000
- Email: azop@azop.hr
- Web: azop.hr
We encourage you to contact us before lodging a formal complaint so that we may resolve your concern directly.
12. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. We will notify you of material changes by email or a notice on the website at least 14 days in advance. The date of the most recent revision is always shown at the top of this page. Continued use of the service after changes constitutes acceptance of the updated Policy.