Legal
Privacy Policy
This Privacy Policy explains which personal data we collect through the website wellar.hr and at our centre, why we collect it, how we protect it and what your rights are. We process data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the GDPR (NN 42/18).
Data controller: TODO: legal company name d.o.o., TODO: address, 31000 Osijek, Croatia, OIB (tax ID): TODO: OIB, e-mail: info@wellar.hr, phone: TODO: phone (hereinafter "Wellar" or "we").
1. Data we collect
- Contact form: name, e-mail address, phone (optional), message content, time of submission and IP address (to prevent abuse).
- Bookings: bookings are made via the external Zoyya system (app.zoyya.com). Data you enter there (name, e-mail, phone, chosen service and time) is processed under Zoyya's privacy rules; Wellar uses it solely to provide the booked service.
- Loyalty club: name, e-mail, date of birth (optional, for the birthday perk), treatment history and points balance.
- Cookies and analytics: technical data about your visit (device type, browser, pages visited) – only with your consent, as described in the Cookie Policy.
2. Purposes and legal basis
- answering your enquiry – consent (Art. 6(1)(a) GDPR) and steps prior to entering a contract (Art. 6(1)(b));
- providing and charging for services and managing bookings – performance of a contract (Art. 6(1)(b));
- running the Loyalty programme – performance of the membership agreement and consent;
- accounting and tax obligations – legal obligation (Art. 6(1)(c));
- website analytics – consent (Art. 6(1)(a));
- abuse prevention (rate limiting, spam protection) – legitimate interest (Art. 6(1)(f)).
3. Retention
- contact form messages: 12 months from the last communication;
- booking and invoice data: 11 years, under the Croatian Accounting Act;
- Loyalty data: for the duration of membership and 24 months after the last visit;
- analytics data: per cookie settings, at most 26 months.
4. Recipients
We do not sell your data. We share it only with processors providing services essential to our operation: hosting provider (TODO: name), the Zoyya booking system, accounting service (TODO: name) and, with consent, Google (Google Analytics). Data processing agreements are in place with all of them. Data is generally processed within the EU/EEA; transfers to third countries rely on the European Commission's Standard Contractual Clauses.
5. Your rights
You have the right at any time to: access your data, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection, and withdrawal of consent without affecting the lawfulness of prior processing. Send requests to info@wellar.hr – we reply within 30 days.
If you believe we are processing your data unlawfully, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.
6. Security
We apply technical and organisational measures: encrypted connection (HTTPS), access restricted to authorised staff, hashed passwords and regular backups.
7. Minors
Our services are intended for adults. Persons under 16 may use treatments with the consent of a parent or guardian, who also gives consent for data processing on their behalf.
8. Changes
We may update this Policy from time to time. The current version is always published on this page with the date of the last change.
Last updated: TODO: date
This text is a template – have it reviewed by a lawyer before publishing.
Published: 11 September 2026
