01 Who we are and how to contact us
↑ Back to topThe data controller is UNINE j.d.o.o., registered at Put Grgura Ninskog 46, 23232 Nin, Croatia, VAT ID (OIB) 00548513933, registration number (MBS) 110147524.
For any questions about the processing of your personal data, to exercise your rights, or to make a complaint, contact us at privacy@tidy.hr or +385 91 509 3354. We are not required to appoint a Data Protection Officer (DPO).
02 What data we collect
↑ Back to topWe collect only the data needed to deliver the service and meet our legal obligations. The categories of data we process are:
- Identification data: first and last name, company name (where applicable).
- Contact data: email address, phone number / WhatsApp.
- Property data: address, square metres, number of rooms and bathrooms, access method (lockbox code, key handover, in-person).
- Booking data: date, time, scope of work, special notes.
- Payment data: payment method and amount. We do not store credit card numbers.
- Technical data: IP address, device and browser type, pages visited - collected via cookies (see Cookie policy).
03 Legal basis for processing (Art. 6 GDPR)
↑ Back to topWe process your data only when we have a valid legal basis to do so:
- Contract performance (Art. 6(1)(b)) - processing necessary to prepare and deliver the cleaning service you ordered.
- Legal obligation (Art. 6(1)(c)) - issuing invoices, keeping business and tax records as required by Croatian law.
- Legitimate interest (Art. 6(1)(f)) - improving the service, preventing fraud, and defending legal claims.
- Consent (Art. 6(1)(a)) - for optional marketing communications and analytics cookies. You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
04 Who we share your data with
↑ Back to topWe do not sell your data to third parties. We may share it with the following categories of recipients, only to the extent necessary for the stated purpose:
- Members of our cleaning team who deliver the service - only the data needed for access and execution.
- An external accounting service - to keep business records.
- Our hosting provider, which stores website data.
- Google Ireland Limited - Google Analytics and Google Tag Manager services (analytics, only with your consent).
- Competent authorities upon their request, where required by law.
05 International transfers
↑ Back to topMost processing takes place within the European Economic Area (EEA). Some service providers (e.g. Google) may process data in third countries, including the United States. In those cases we rely on Standard Contractual Clauses approved by the European Commission, as an appropriate safeguard under Art. 46 GDPR.
06 How long we keep the data
↑ Back to topWe keep your data no longer than necessary for the purpose of processing. Indicative periods:
- Booking and service delivery records: 1 year after the service is completed.
- Invoices and tax records: 11 years, in line with the Croatian General Tax Act.
- Marketing contacts: until consent is withdrawn.
- Technical and analytics data: up to 14 months (Google Analytics defaults).
07 Your rights (Art. 15-22 GDPR)
↑ Back to topYou may ask us at any time to:
- Access your data (Art. 15).
- Rectify inaccurate data (Art. 16).
- Erase your data, the so-called „right to be forgotten” (Art. 17).
- Restrict processing (Art. 18).
- Receive your data in a commonly used, machine-readable format (Art. 20).
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent at any time.
Send the request to privacy@tidy.hr. We will respond without undue delay and within 30 days of receipt of the request.
08 Right to lodge a complaint with a supervisory authority
↑ Back to topIf you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP):
- Address: Selska cesta 136, 10000 Zagreb, Croatia
- Phone: +385 1 4609 000
- Email: azop@azop.hr
- Web: www.azop.hr
09 Data security
↑ Back to topWe apply reasonable technical and organisational safeguards - TLS encryption in transit, least-privilege access controls, regular backups, and training collaborators on data protection rules. While no system is absolutely secure, we take the protection of your data seriously.
10 Automated decision-making
↑ Back to topWe do not carry out automated decision-making or profiling that produces legal effects on you or similarly significantly affects you. The price calculator on our site only displays an estimate - the final price and the acceptance of a booking are confirmed by us manually.
11 Changes to this policy
↑ Back to topWe may update this policy from time to time for legal, technical, or operational reasons. The date of the last update is shown at the top of this page. We will highlight material changes via the website or by email before they take effect.
— Last updated —
May 12, 2026
We may update this document from time to time. The version published on this page at the moment of service is the binding one.
— Related documents —
Related documents
Together, the three documents form the full legal framework of our service - we recommend reviewing all three.