Privacy Policy

Privacy Policy

This Privacy Policy explains how Wing Museum processes personal data when you use the website and related services. It applies to visitors, prospective clients, and business contacts who interact with the site in a professional context.

Data collected only as described in this policy
Your rights and options are detailed below
Questions handled via our contact channel
Privacy Contact

Contact Information

Privacy email
Telephone
+385 92 249 9161
Postal address
Salonitanska Cesta 13, 21210 Solin
Privacy contact
Why we process data

Purposes of Processing

We use personal data to respond to enquiries, provide and manage services, communicate with business contacts, maintain website functionality, monitor security, improve performance, keep records, meet legal and regulatory obligations, and support the establishment or defence of legal claims where necessary.

Note
Processing is limited to operational, contractual, security, and compliance needs.
Third-party sharing

Service Providers

We may share personal data with hosting providers, technical support providers, analytics services, security providers, and other professional partners that assist in operating the website or delivering services. These parties act under contractual or equivalent confidentiality and data protection obligations and may process data only for the purposes we specify.

Note
Service providers receive only the information needed to perform their assigned functions.
GDPR
Regulation

GDPR Overview

Where GDPR applies, we process personal data on a lawful basis such as consent, contract performance, legal obligation, or legitimate interests, depending on the activity involved. We apply data minimisation, purpose limitation, and storage limitation principles and use appropriate safeguards for the processing we carry out.

Regulatory context
Because Wing Museum operates in an EU context and targets users in Croatia and other EEA locations, GDPR rules apply where the regulation governs the processing.
This section explains the GDPR framework relevant to covered users.
GDPR Compliant

GDPR Rights

Where GDPR applies, you may have rights of access, rectification, erasure, restriction, objection, and data portability, as well as the right to withdraw consent where processing is based on consent. You may also object to processing based on legitimate interests in circumstances recognised by law.

The rights described below apply subject to the conditions and exceptions in the GDPR.
Data category

Data We Collect

We may process identification and contact details, company and role information, inquiry content, account or service records, technical identifiers, device and browser data, usage data, and any other information you choose to submit through forms, messages, or other interactions with the site.

The categories collected depend on how the site is used and which services are requested.
Collection source

Sources of Data

We collect personal data when you submit forms, communicate with us, request services, or otherwise interact with the site. We also receive technical and usage information automatically through the operation of the website and from third parties that support hosting, analytics, security, or related functions.

Information may come directly from users, from site activity, or from service providers acting on our behalf.
Cookie type

Types of Cookies

We may use strictly necessary cookies to operate the site, functional cookies to remember preferences, and analytics cookies to understand how the site is used. Cookies may be session-based or persistent, depending on their purpose. We do not rely on cookies for purposes that are incompatible with this policy.

Cookie use is limited to standard categories needed for operation, preferences, and measurement.
User control

Cookie Controls

You can manage cookies through your browser settings and, where available, through the cookie controls presented on the site. Blocking some cookies may affect site functionality, security features, or preference settings. Where consent is used as the legal basis, you may withdraw it at any time for future processing.

Browser settings and cookie tools may be used to limit non-essential cookies.
User Rights

Your Rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate information, deletion where appropriate, restriction of processing, and objection to certain processing activities. You may also request information about how your data is used and, where relevant, ask for a copy in a portable format.

Available rights depend on the legal basis and the nature of the processing.
Requests

How to Make a Request

To protect privacy and security, we may need information to verify your identity before acting on a request. We will review the request, respond within the period required by law, and explain any refusal or limitation where the law allows us to do so.

Requests are handled through a verification process before any disclosure or correction is made.
Data Retention

Data Retention

We retain personal data for the period necessary to provide the requested service, manage our relationship, meet legal or accounting obligations, resolve disputes, and maintain security records. When data is no longer needed, we delete it, anonymise it, or restrict it in line with applicable law and internal retention practices.

Data is kept only for as long as needed for the relevant purpose or legal requirement.
Policy Updates

Policy Updates

If we make material changes, we will update the policy text and take reasonable steps to draw attention to the revised version where appropriate. The date of the latest update should be reviewed periodically.

We may revise this policy to reflect legal, technical, or operational changes.