Privacy statement

Hrvatska verzija: Izjava o privatnosti (authoritative in case of any difference).

This statement explains how we process personal data within the evisitor.ai service, an assistant that helps hosts register their guests in Croatia's eVisitor system via WhatsApp and account-owned guest-entry links. For cookies, see the cookie policy.

Controller

Screen Guide, obrt za web i marketing, vl. Matej Jelić
OIB (tax id): 24456564688
Registered office: Rebro II 1A, Sesvete, Croatia
E-mail: [email protected]

We have not appointed a data protection officer, as this is not a legal obligation for us; for any privacy question, write to the address above.

Our role

For host (account) data we are the controller. For guest data that a host registers, the host (accommodation provider) is the controller — registering guests is their legal obligation — and we act as their processor, under documented instructions.

What we process and why

CategoryDataPurposeLegal basis
Operators and connected eVisitor accountsThe operator's verified communication channel (currently a WhatsApp number), memberships and permissions for connected accounts, the official facility name from the connected eVisitor account, or the neutral label “Guest check-in” when eVisitor supplies no facility name, optional host name and contact details the administrator chooses to show guests, the eVisitor username, the AES-256-GCM encrypted password, accommodation units, guest links and each account's usage state. We do not automatically show the verified WhatsApp number to guests.Providing the service, verifying operator identity, managing access and filing through the exact selected eVisitor account.Contract (Art. 6(1)(b) GDPR)
GuestsData required for eVisitor, entered manually by the guest or host through the registration link, written to Vito by the host in a message, or extracted by Vito from a photo the guest optionally chose: identity and identity-document details, residence, stay details and, where applicable, tourist-tax information. The public form does not ask for a border crossing or date of entry into Croatia. The responsible operator may add them afterwards only if eVisitor explicitly rejects the prepared registration and requests that exact addition, not merely because a guest resides outside the EU.Registration in the eVisitor system.For registration data: the host's legal obligation (Art. 6(1)(c) and (e), as the official eVisitor notice also cites). Optional transient photo reading is a privacy-by-design method for fulfilling the same obligation (Art. 25), supported where needed by the host's legitimate interest in accurate and efficient entry (Art. 6(1)(f)). Consent is not the legal basis for transient reading or for keeping a document copy. We process as the host's processor under documented instructions.
Technical anti-abuse dataHMAC-derived limiter identifiers for an IP address, eVisitor account or draft, and request counters. Limiter keys contain none of the raw identifiers. IP- and ordinary draft-derived counters expire after at most 15 minutes; account-derived counters expire after at most one hour. The single exception is the document-reading attempt counter for one draft: it may remain for up to seven days from the first attempt. An expired draft can no longer be used, while the counter prevents the allowance from resetting during the same entry.Service security, preventing abuse and controlling automated-processing costs.Our legitimate interests in those purposes (Art. 6(1)(f) GDPR).
Host (marketing)Phone number (WhatsApp) and e-mail of existing hosts.Direct marketing — occasional promotional messages about our own service.Legitimate interest (Art. 6(1)(f) GDPR)

A document photo is not required. The guest or host may enter every required field manually through the registration link, and the guest may also give the details to the host verbally or in a message. A guest can choose a photo directly in the form. If the host takes a photo or sends one to Vito through WhatsApp, the host must explain how it is processed, offer the no-photo route and confirm that the guest freely chose this method. The bilingual guest notice is an optional template, not a required notice method. Refusing a photo does not affect the statutory registration; the process continues through manual entry.

The photo is not written to the application database. A photo the guest selects in the web form is processed transiently in memory during that request and sent to the model under the conditions described below, then discarded. It never enters WhatsApp or the Redis buffer. After download, a photo sent to Vito through WhatsApp may remain in our temporary Redis buffer for no more than 15 minutes from the latest transfer into that buffer. When registration completes, we request its earlier deletion. After transfer to that buffer, we request deletion of the WhatsApp media from our messaging provider's (Twilio's) infrastructure, with a daily sweep that retries failed deletions.

The 15-minute limit applies only to our temporary Redis buffer. We sweep Twilio message records, including Vito's outbound messages, daily and normally delete them within about 1–2 days. Twilio states that deleted content may remain in backups for up to 30 days. Copies in WhatsApp and on participants' devices are governed by those systems.

Document reading and artificial intelligence

Vito is a conversational AI assistant. When a host talks to Vito on WhatsApp, an Anthropic model (Claude), through the Vercel AI Gateway, processes the host's message and prepares Vito's reply. This includes any guest data the host types into the message. Data a guest enters manually through the guest link is not sent to the AI model unless the guest optionally chooses a document photo.

When a photo is chosen in the guest link, the same model reads it transiently and we transfer only the prescribed fields into the form. A host's WhatsApp photo is read transiently by the model so Vito can prepare the registration. Every textual and photo request Vito sends to the model carries a zero data retention condition: after the request, the model provider stores neither input nor output and uses neither for training. This condition governs Anthropic's processing, not the separate technical Vito conversation history described under Retention. If zero-retention processing is unavailable, the request is rejected. When the document's machine-readable zone (MRZ) is visible, the extracted document number and birth date are additionally checked against its check digits. Extracted and manually entered guest-link data is shown to the responsible operator authorised by the host for that link. The operator can correct it, and filing is technically bound to their explicit confirmation of the reviewed version. In a direct WhatsApp conversation, Vito's service rules require the current operator's confirmation before filing. We make no automated decisions with legal or similarly significant effect (Art. 22 GDPR).

Recipients and processors

Guest data is transmitted to eVisitor, operated by the Croatian National Tourist Board (HTZ) — the statutory destination of the registration. To process guest data on the host's behalf, we use these sub-processors:

  • Anthropic — processing Vito's text conversations and transiently reading an optional photo
  • Neon — database
  • Vercel — application hosting, Vito's technical conversation history and AI Gateway (routing requests to the AI model)
  • Twilio — WhatsApp messaging
  • Meta Platforms — Twilio's sub-processor for the WhatsApp channel; it processes phone numbers and message content for inbound and outbound delivery
  • Upstash — temporary state storage (Redis)

Meta is engaged in this chain as a sub-processor through Twilio, not through a direct contract with us. We use Stripe to bill the host's subscription; Stripe receives no guest data and is not a guest-data sub-processor under the Terms. Card data is handled directly by Stripe and never reaches evisitor.ai.

We previously used Clerk for host sign-in. It no longer provides account access and receives no new application data or guest data. Until deletion of the retired Clerk tenant is confirmed and recorded, it may retain legacy host profile data: e-mail, name and phone number.

With your consent, the website uses Meta Pixel and Google Ads for advertising measurement and remarketing — details in the cookie policy. We do not sell personal data.

Direct marketing

We occasionally send existing hosts short promotional messages about our own service via WhatsApp (for example a reminder of the app's features or of subscription benefits). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in informing our own customers about a related service; these messages never include guest data. You can opt out at any time by replying STOP. STOP pauses every proactive WhatsApp message from Vito, including operational notifications about new guest-link submissions, and prevents a paused link from being enabled while notifications remain stopped. An already-enabled link can still receive submissions until its responsible operator pauses it separately. You can still message Vito and use the service; reply START to resume proactive notifications.

Transfers outside the EU

Some of the listed providers may process data outside the European Economic Area (for example in the USA). Such transfers are protected by appropriate safeguards — the European Commission's Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework.

Retention

Document photos are not written to the application database. A photo selected in the web form is processed transiently in memory during that request and sent to the model under the conditions described above, then discarded. Only a WhatsApp photo is subject to the maximum 15-minute buffer.

The identity details entered for each person in a guest-link draft are encrypted. Stay dates and the technical entry state are stored separately. A draft expires after 24 hours of inactivity and no later than seven days after it is created. After the guest sends the form, identity data is kept only for review, correction and filing. We erase each person's identity data as soon as successful filing has been reliably confirmed and recorded. If the guest deletes the draft before sending it, we erase all entered identity data. Data from an unsuccessful or unfinished registration, or one with an uncertain outcome, is erased no later than 30 days after the form is sent; reviews, checks, edits and retries do not extend that deadline. The WhatsApp “Decline” button stops that confirmation but does not erase the entry, so the operator can correct it. The responsible operator can cancel the submitted entry in the dashboard; we then immediately erase all remaining identity data. If successful filing has already been reliably confirmed and recorded for some people, their identity data has already been erased from our database, while the official record remains in eVisitor. A closed technical record without names, document numbers or other entered identity details is kept for up to 90 days for reliability, troubleshooting and proof of erasure.

Messages a host sends to Vito, results returned by Vito's tools and Vito's replies enter the technical history of that WhatsApp session, maintained by the Eve framework on Vercel infrastructure. This may include typed guest data and an extracted result, but not the document photo itself. After a successful registration the session is retired from the active conversation, so that content is not carried into future conversations. The current Eve version does not yet provide the application with a confirmed mechanism for selective automatic deletion of already-retired session history. For a route with defined deletion deadlines, we therefore recommend the guest link. We will add the applicable period as soon as the provider confirms an enforceable retention and deletion mechanism.

To provide the service to the host we keep a record of completed registrations with stay dates and guest counts, without any data on guest identity. To prevent the same free registration from being spent or sent twice, we keep an unreadable pseudonymous technical key and filing state, with no name, document number or other readable guest detail. A reservation that never reaches the provider expires after one minute. If sending to eVisitor started but the outcome is uncertain, the record is never released by a timer and remains until the outcome is checked manually. After a confirmed free registration, the technical key remains with the account to prevent double charging and is erased with the account; a request concerning that exact record is handled only after any possible filing is reconciled and according to applicable law. The registration record itself lives in the eVisitor system, operated by HTZ, where it is kept for 10 years as prescribed; we do not manage that retention. Host data is kept while the account is active and as long as tax and other regulations require, after which it is deleted or anonymised. A host may request disconnection of an individual eVisitor account. Once no filing is active for that account, we delete the stored username, encrypted password and its decryption value. Disconnecting does not delete the connected eVisitor account record, operator memberships or its subscription; those records follow the retention periods described here.

Your rights

Depending on the legal basis and circumstances, you may have rights of access, rectification, erasure, restriction, portability and objection. You may refuse the optional photo; the guest or host will then enter the data manually. Refusal does not stop the statutory registration, which is based on the host's legal obligation, not consent. Send requests to [email protected]. For guest data, requests are as a rule addressed to your host as the controller, and we assist them.

Complaints to the supervisory authority

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb — azop.hr.

Changes

We may update this statement from time to time. Last updated: 23 July 2026.

Bok Vito! Trebam prijaviti gosta