PRIVACY POLICY
1. General Information
This Privacy Policy explains how the City of Rab (hereinafter: “Data Controller”) collects, uses, and protects users' personal data when using the mobile application and the associated web portal (hereinafter: the “Application”).
The City of Rab processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable legislation of the Republic of Croatia.
By using the Application, users confirm that they have read and understood this Privacy Policy.
2. User Login via NIAS System
To access certain functionalities of the Application, users authenticate via the National Identification and Authentication System (NIAS).
When logging in through the NIAS system, the City of Rab may receive a limited set of identification data required for user authentication and for enabling the use of the Application.
The data that may be processed includes:
first and last name
unique user identifier provided by the NIAS system
authentication level
technical login data (time of login and logout)
The City of Rab does not collect additional personal data from the NIAS system other than what is necessary for authentication and use of the Application.
3. Types of Data That May Be Collected
When using the Application, the following categories of data may be processed:
Identification data
first and last name (obtained via the NIAS system)
unique user identifier
Technical data
time of access to the application
IP address or technical device identifiers
system usage logs
Application usage data
data necessary for the functioning of specific application features
The Application does not collect or process special categories of personal data.
4. Purpose of Data Processing
Personal data is processed exclusively for the following purposes:
enabling secure user authentication via the NIAS system
enabling the use of application functionalities
maintaining and improving the functionality of the application
ensuring the security of the information system
fulfilling legal obligations of the Data Controller
Personal data is not used for marketing purposes and is not used for user profiling.
5. Legal Basis for Processing
The processing of personal data is based on the following legal bases under Article 6 of the General Data Protection Regulation:
performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller
compliance with legal obligations of the Data Controller
ensuring the functioning of a digital public service
6. External Service Providers
For the functioning of the Application, external service providers may be used to support technical operation and maintenance of the system.
User authentication is carried out through the National Identification and Authentication System (NIAS), operated by the competent authority of the Republic of Croatia.
External service providers may access data only to the extent necessary for the technical operation of the system and are required to implement appropriate personal data protection measures.
Personal data is not sold or shared with third parties for marketing purposes.
7. Data Retention
Personal data is stored only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable legislation.
Technical system logs may be stored temporarily for security purposes, system maintenance, and prevention of misuse.
8. Data Security
The City of Rab implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or unauthorized disclosure.
These measures include protection of communication between the Application and the server infrastructure, as well as access control mechanisms.
9. Automated Decision-Making
The Application does not perform automated decision-making or profiling that would produce legal or similarly significant effects for users.
10. User Rights
Users have the right to:
request information about whether their personal data is being processed
request access to their personal data
request correction of inaccurate personal data
request deletion of personal data in cases provided by law
request restriction of data processing
object to the processing of their personal data
lodge a complaint with the competent data protection supervisory authority
The supervisory authority in the Republic of Croatia is the Croatian Personal Data Protection Agency (AZOP).
11. Changes to This Privacy Policy
The City of Rab reserves the right to amend this Privacy Policy. Any changes will be published within the Application or on the official website.
12. Contact
For questions, support, or requests related to personal data processing, you may contact the Data Controller:
City of Rab
Trg Municipium Arba 2
51280 Rab
Croatia
Phone: +385 51 777 460
Email: tajnica@rab.hr