1. Who is responsible for your data
The controller of personal data collected for enquiries and arranging our services is Obrt za prijevoz putnika Vector, vlasnik Stipo Vukoja, a Croatian passenger transport sole proprietorship at Primorska 74, 21213 Kaštel Gomilica, Croatia, OIB 24540779324. For privacy questions and requests to exercise your rights, contact info@fromsplit.com or write to the postal address above. Phone: +385 95 574 9490.
This policy covers fromsplit.com and communications with us concerning the services presented on the website.
2. Data we process
- Enquiries and service arrangements: your name, contact details you provide, message content, selected service, pickup location and destination, date, time, passenger count and other information necessary to answer or arrange transport.
- Service delivery and invoicing: confirmed booking details, necessary passenger and luggage information, payment and invoice information, and related correspondence. Do not send a full payment card number or security code through the form or by email.
- Complaints and requests: information in a complaint or a request to exercise your rights, information needed to investigate, and our response.
- Website security: technical information such as an IP address, request time, requested page address and information the browser sends to the server. This is used to deliver the website, identify errors and prevent abuse.
We usually obtain information directly from you. If another person arranges transport for you, we may receive information necessary to organise the journey from that person. We ask the organiser to share this policy with the other passengers. Please do not send identity document copies, diagnoses or other sensitive information unless we have a justified reason to request it. For accessibility requests, initially describing the assistance or equipment needed is sufficient.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answering your request for a quote, arranging and providing transport | Steps at your request before entering a contract and performance of a contract, Article 6(1)(b) GDPR |
| Issuing and retaining invoices, handling written complaints and complying with binding authority requests | Legal obligation, Article 6(1)(c) GDPR |
| Website security, abuse prevention, troubleshooting and establishing or defending legal claims | Legitimate interests in protecting the business, users and legal rights, Article 6(1)(f) GDPR, subject to an assessment of necessity and your rights |
If another person arranges transport for you and you are not a contracting party, we may process the information necessary to organise your journey on the basis of legitimate interests in safely and properly providing the agreed transport, subject to assessing your rights and limiting the data to what is necessary.
We do not require consent to process data necessary for your enquiry or contract as a condition of submitting the form. Required fields are identified in the form; without necessary contact and service details, we may be unable to reply or provide transport. Other information is optional.
This website currently has no optional analytics, advertising tracking or marketing newsletter signup. We do not use enquiry information for promotional messages without an appropriate legal basis and prior information.
4. Who may access the information
Access is limited to authorised people who handle enquiries and organise services, and drivers or other confirmed service providers, to the extent needed for their task. If a service is contracted with a separate independent provider, we identify that provider and its role before sharing the necessary data and arranging the service.
We use technical providers for hosting, website protection, storage and message delivery. Cloudflare supplies the website infrastructure, security functions and related data storage. A technical maintainer has access only where needed for maintenance and support, subject to appropriate data protection obligations.
Information submitted through the form is stored in our enquiry database on Cloudflare D1 infrastructure. We use Resend to deliver an enquiry notification to info@fromsplit.com; Resend processes the message content, recipient address and your reply-to email address for this purpose. We use Lark Mail for our business mailbox and subsequent email correspondence. An email sent directly to us does not pass through the website form or Resend. We do not enable open or click tracking for messages sent from the form. Deleting an enquiry in the website administration does not automatically delete its copies in email systems; we manage retention and deletion of those copies separately under the criteria in this policy. The form and the administrator sign-in are protected by Cloudflare Turnstile: during the check Cloudflare processes technical browser signals, such as the IP address, TLS connection details, user agent and page address, to distinguish people from automated requests. For this protection Cloudflare acts as our processor; according to its own notice it also processes some signals as an independent controller to improve bot detection. Information about these providers’ data processing terms and safeguards is available in their data processing addenda: Cloudflare, Resend and Lark. Cloudflare’s separate Turnstile privacy notice explains its processing of security signals and its different roles in that processing.
Information may be shared with accounting providers, legal advisers or competent authorities where needed for a specific obligation or justified legal claim. We do not sell personal data.
5. Processing outside the European Economic Area
Technical providers, including Cloudflare, may use infrastructure or support outside the European Economic Area. Where personal data is transferred to such a country, the transfer must be covered by an applicable adequacy decision or appropriate safeguards, such as European Commission standard contractual clauses and any necessary supplementary measures. You can request information about the safeguards for a particular transfer and how to obtain a copy by contacting us about privacy. Details of Cloudflare's contractual safeguards are available in its Data Processing Addendum.
Resend stores customer data, including message content and delivery logs, in the United States. The selected European sending region does not determine where that data is stored. Resend’s data processing addendum describes the standard contractual clauses it uses for these transfers.
6. How long we retain data
| Data | Period or criterion |
|---|---|
| An enquiry that does not lead to a booking | Until communication about the enquiry ends and the quote expires. We then delete the data, except any part subject to a separate legal retention duty or a specific need to protect a legal claim. |
| A booking and completed service | For contract performance and afterwards only for as long as individual records are needed for statutory retention or relevant periods for establishing and defending legal claims. |
| Invoices and accounting documents | For the period required for the particular type of record by applicable accounting and tax law. |
| Written consumer complaints | One year from receipt; longer only where another lawful basis applies to specific data, such as ongoing proceedings. |
| Technical and security records | For as long as needed to operate the security measure, investigate an error or resolve a specific incident. Relevant records may be retained separately for ongoing proceedings or an applicable legal claims period. |
Access to records requiring longer retention is restricted to the purpose for which they are kept. Cookie lifetimes are set out in our Cookie Policy.
7. Your rights
Subject to applicable conditions, you may request access to and a copy of your data, rectification, erasure or restriction of processing. Data portability may apply where processing is automated and based on a contract or consent. You may object to processing based on legitimate interests on grounds relating to your particular situation. Where processing is based on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Send requests to our privacy contact. We may ask for proportionate additional information where needed to verify the requester's identity. We respond without unnecessary delay, normally within one month. Where complexity or the number of requests requires a lawful extension of up to two further months, we notify you and explain the reasons within the first month.
Erasure is not unconditional, for example where the law requires us to retain a document. If we cannot comply with a request, we will explain the reason and available remedies.
You may complain to the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority. You do not have to contact us first.
8. Security, children and automated decisions
We apply appropriate technical and organisational measures, including encrypted transmission and restricted access. Services through this website are arranged by adults; we process only the child information necessary for transport and safety equipment. We do not carry out profiling or solely automated decisions that produce legal or similarly significant effects on individuals.
9. Policy changes
We update this policy when processing practices or relevant rules change. The version date appears at the top. If a change requires additional information or consent, we provide or obtain it before the relevant processing.