Privacy Policy
Last updated: June 2026
This policy describes how Villa Amarande collects, uses, and protects your personal data when you visit our website, send an inquiry, or book a stay. We operate in accordance with the EU General Data Protection Regulation (GDPR) and the applicable laws of Bosnia and Herzegovina.
Data controller
The controller of personal data is Velimir Čović, registered at Ljuti Dolac b.b. 88223, Široki Brijeg, Bosnia and Herzegovina. Contact: info@villa-amarande.com, +387 63 996 994.
What data we collect
We collect only the data needed to provide our services:
For inquiries and reservations: first and last name, email address, phone number (optional), preferred dates, number of guests, message content.
For payment (once active): the card data required for the transaction is processed by Stripe — we do not store card numbers.
Technical data: IP address, device and browser type, time of visit, pages viewed. These are collected anonymously via Google Analytics.
How we use the data
We use your data exclusively to:
· Process your inquiries and reservations;<br/>· Communicate about your stay (confirmations, arrival steps, support);<br/>· Issue invoices and receive payment;<br/>· Improve the website and understand how guests use it (anonymous analytics);<br/>· Send updates and special offers — only if you have explicitly subscribed to the newsletter.
Legal basis
We process data under the following legal bases from Art. 6 GDPR:
· Performance of a contract — for data needed to book and host you;<br/>· Consent — for the newsletter and analytics cookies;<br/>· Legitimate interest — for website security and abuse prevention;<br/>· Legal obligation — for invoicing and guest registration under BiH law.
Sharing with third parties
We do not sell or rent your data. We share it only with trusted partners who help us deliver our services:
· Resend (email delivery) — recipient address and message content;<br/>· Beds24 (reservation calendar) — stay dates and contact details;<br/>· Stripe (payment, once active) — transaction data;<br/>· Google Analytics (analytics) — anonymous usage data;<br/>· Hetzner (hosting) — physical data storage in the EU.
All partners have data processing agreements and comply with GDPR.
Your rights
Under GDPR you have the right to:
· Access your data;<br/>· Rectify inaccurate data;<br/>· Erase data ("right to be forgotten");<br/>· Restrict processing;<br/>· Portability to another controller;<br/>· Object to processing;<br/>· Withdraw consent at any time;<br/>· Lodge a complaint with a supervisory authority (in BiH: Agency for the Protection of Personal Data).
For any of these rights, contact us at info@villa-amarande.com. We respond within 30 days.
Cookies and analytics
The website uses a minimal set of cookies:
· Functional cookies — for language selection, authentication, and basic operation;<br/>· Analytics cookies (Google Analytics) — anonymously track visits so we can understand how guests use the site.
You can accept or refuse analytics cookies. Functional ones are required for the site to work.
How long we keep data
· Reservation data: 5 years after the end of the stay, in line with BiH tax law;<br/>· Inquiries that did not result in a booking: 12 months;<br/>· Newsletter subscription: until you unsubscribe;<br/>· Analytics data: 14 months (Google Analytics default).
International data transfers
Our servers are located in Germany (Hetzner). Some partners (Stripe, Google) are headquartered outside the EU but operate under EU-grade data protection standards (Standard Contractual Clauses, EU-US Data Privacy Framework).
Changes to this policy
This policy may be updated from time to time. For material changes we will notify you by email if you are a registered guest or newsletter subscriber. The date of the latest revision appears at the top of the page.
Contact
For privacy questions, to exercise your rights, or to file a complaint:
· Email: info@villa-amarande.com<br/>· Phone: +387 63 996 994<br/>· Address: Ljuti Dolac b.b. 88223, Široki Brijeg, BiH