Book a massage

Choose a salon to call. We'll find a time that suits you.

Choose a salon and send us your booking request by e-mail. We'll reply to confirm your time.

Opatija+385 91 307 8889
Rijeka+385 99 548 8074 · Robna kuća Ri
Mali Lošinj+385 99 292 2758
Rab+385 91 195 5558

Payment in cash only.

Thai Touch Massage
Your privacy

Privacy policy

How Thai Touch Massage collects, uses and protects your personal data, in plain words.

Last updated 29.9.2026.

At a glance

Your data, respected

No tracking

No analytics, advertising or tracking cookies on this website.

Maps on request

Google Maps loads only when you click Show map.

Never sold

We use your details only for your booking, never for marketing.

Health stays private

What you tell your therapist is not written down or stored.

01Who is responsible for your data

Thai Touch Massage salons in Opatija, Rijeka, Mali Lošinj and Rab are run by the two businesses below. Together they decide how personal data is handled on this website and in our salons, so they are joint controllers under Article 26 of the General Data Protection Regulation (GDPR).

KANCHANA, obrt za masažu tijelavl. Nejro BilajacViktora Cara Emina 3, 51410 Opatija, CroatiaMB: 98109677
Finim s.r.o., Podružnica Sveti JakovRepresented by Kanchana WongraseeSv. Jakov 80a, 51554 Nerezine, CroatiaOIB: 30341187912

What this means for you: you can send any privacy question or request to either business, using any of the contacts in section 14. We pass it on to each other when needed and answer it together. For bookings, the salon you booked with takes care of your data.

We are a small business and are not required to appoint a Data Protection Officer. The contacts in section 14 handle all privacy matters.

02What this policy covers

This policy explains how we process personal data when you:

  • visit www.thai-touch-massage.com,
  • contact us or book a treatment by phone, email or social media,
  • visit one of our salons,
  • follow or message our Facebook and Instagram pages.

It is based on the GDPR (Regulation (EU) 2016/679), the Croatian Act on the Implementation of the GDPR (Zakon o provedbi Opće uredbe o zaštiti podataka, NN 42/2018) and the Croatian Electronic Communications Act (Zakon o elektroničkim komunikacijama, NN 76/2022), which covers cookies.

03What we collect and why

We collect only what we need. The website has no contact form, no user accounts, no newsletter and no online payments, and we do not use analytics, advertising or tracking tools.

Visiting the website

Data
IP address, date and time, pages requested, browser and device type, referring page. Our host records this automatically in server logs.
Why
To deliver the website and keep it secure (for example, to detect attacks and fix errors).
Legal basis
Our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).
How long
Kept only for a short period for security purposes, then deleted automatically by our host.

Booking and contacting us

Data
Your name, phone number and/or email address, the salon, treatment, date and time you want, and anything you write in your message.
Why
To answer you, arrange and confirm your appointment, and let you know about changes (for example, if a therapist is unavailable).
Legal basis
Steps you ask us to take before providing a service, and providing it (Art. 6(1)(b) GDPR).
How long
Up to 12 months after our last contact with you, unless we need it longer to handle a complaint or legal claim.

Your visit to the salon

Data
The name for your appointment and, if you tell us, health information relevant to your massage (see section 04).
Why
To give you the treatment you booked, safely.
Legal basis
Providing the service (Art. 6(1)(b) GDPR); for health information, your explicit consent (Art. 9(2)(a) GDPR).
How long
Appointment details as above. Health information is not stored (see section 04).

Payments and invoices

Data
Payment is in cash only. Our fiscalised receipts do not contain your personal data. If you ask for an invoice to your company, it contains the company name, address and OIB/VAT number.
Why
To meet our accounting and tax obligations.
Legal basis
Legal obligation (Art. 6(1)(c) GDPR), under Croatian accounting, tax and fiscalisation laws.
How long
For as long as Croatian accounting and tax law requires (generally 11 years).

Google Maps on our pages

Data
Only after you click Show map: your IP address and browser data are sent to Google, which may set cookies.
Why
To show where our salons are.
Legal basis
Your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time in section 05.
How long
Your choice is remembered in your browser until you withdraw it. Google keeps its data under its own policy.

Fonts and page files

Data
Your IP address and browser data, which your browser sends when it downloads our fonts from the jsDelivr network. No cookies are set.
Why
To display the website with the right fonts, quickly and reliably.
Legal basis
Our legitimate interest in a working, fast website (Art. 6(1)(f) GDPR).
How long
jsDelivr keeps usage data briefly and does not link it to individual people.

Social media and sharing

Data
Our Facebook, Instagram, WhatsApp and Pinterest buttons are plain links. Nothing is sent to these networks until you click one. If you message or follow our pages, Meta also processes your data under its own policy.
Why
To let you follow us, share articles and contact us where you prefer.
Legal basis
Answering your messages (Art. 6(1)(b) GDPR). For page statistics that Meta gives us, we are joint controllers with Meta Platforms Ireland Ltd.
How long
Messages as for bookings. Anything on Meta's platforms is kept under Meta's policy.

04Health information

Before a massage your therapist may ask about injuries, pain, pregnancy, blood pressure, skin conditions or allergies (for example to oils). The GDPR treats health information as a special category of data.

  • Telling us is your choice. We use this information only to adapt your treatment or to advise you not to have it.
  • We ask for it in person, in the salon. It is not written down or stored in any system, and it is never shared.
  • Please do not send health details by email or social media. Tell your therapist in the salon instead.

05Cookies and similar technologies

A cookie is a small file a website stores in your browser. Under Croatian and EU law we may set cookies that the website needs to work without asking you. We need your consent for any other cookies.

This website does not set any advertising, analytics or tracking cookies. The Google Maps on our salon, contact and home pages are switched off until you click Show map. Only then does Google load and may set its own cookies.

NameSet byPurposeDurationType
ttm-mapsThis website (browser storage)Remembers that you chose to show Google MapsUntil you withdraw consent or clear your browser dataNecessary
wordpress_*, wordpress_logged_in_*, wp-settings-*This websiteLog-in and settings for our staff who manage the website. Not set for visitors.Session – 1 yearNecessary
NID, AEC, SOCS and similarGoogle (google.com)Set by Google Maps after you click Show map: remembers preferences, security, and Google's own purposesUp to 13 monthsThird-party, with consent

You can also delete cookies and site data at any time in your browser settings. Google's cookies are described at policies.google.com/technologies/cookies.

06Who receives your data

We never sell your data or share it for marketing. We use these trusted service providers, which process data for us under data processing agreements or their own GDPR-compliant terms:

  • Hostinger International Ltd.61 Lordou Vironos, 6023 Larnaca, Cyprus (EU). Website hosting and server logs.
  • Google Ireland Ltd.Gordon House, Barrow Street, Dublin 4, Ireland. Email (Gmail) for our salon mailboxes, and Google Maps if you allow it.
  • jsDelivr (Volentio JSD Ltd.)England and Wales, United Kingdom. Content delivery network for our fonts.
  • Meta Platforms Ireland Ltd.Merrion Road, Dublin 4, Ireland. Only if you contact or follow us on Facebook, Instagram or WhatsApp.
  • Our accountants and public authoritiesThe Croatian Tax Administration (Porezna uprava) and other authorities, only where the law requires it. Our accountants are bound by confidentiality.

07Transfers outside the EU

Most data stays in the European Union. Some providers may process data in other countries:

  • United States (Google, Meta): these companies are certified under the EU–US Data Privacy Framework, which the European Commission recognises as providing adequate protection. Where needed, they also use the EU Standard Contractual Clauses.
  • United Kingdom (jsDelivr): covered by the European Commission's adequacy decision for the UK.

08How long we keep your data

DataKept for
Booking messages, emails and call historyUp to 12 months after our last contact
Health information you tell us in the salonNot recorded or stored
Company invoices and accounting recordsAs required by Croatian law (generally 11 years)
Server logsA short period for security, then deleted automatically
Your Google Maps choiceIn your browser until you withdraw it
Data needed for a complaint or legal claimUntil the matter is closed and legal deadlines have passed

09Your rights

Under the GDPR you have the right to:

AccessAsk what data we hold about you and get a copy (Art. 15).
RectificationHave incorrect or incomplete data corrected (Art. 16).
ErasureHave your data deleted when we no longer need it or have no legal basis for it (Art. 17).
RestrictionAsk us to limit how we use your data, for example while we check a complaint (Art. 18).
PortabilityGet data you gave us in a common format, or have it sent to someone else (Art. 20).
ObjectionObject to processing based on our legitimate interests (Art. 21).
Withdraw consentAt any time, for example for Google Maps. This does not affect what we did before (Art. 7).
ComplainTo the Croatian data protection authority (see section 10).

To use a right, contact us (see section 14). It is free of charge. We will reply within one month. In complex cases we may extend this by up to two more months and will tell you why. We may ask you to confirm your identity so that we never give your data to someone else.

10Right to complain

If you think we have not handled your data correctly, please tell us first so we can put it right. You can also complain to the supervisory authority in Croatia, or in the EU country where you live or work:

Agencija za zaštitu osobnih podataka (AZOP) Croatian Personal Data Protection Agency Selska cesta 136, 10000 Zagreb, Croatia azop@azop.hr · azop.hr

11Other important information

  • Do you have to give us your data? No. But to book an appointment we need a name and a way to contact you. You are always welcome to walk in without booking.
  • Automated decisions: we do not make decisions about you by automated means, and we do not profile you.
  • Marketing: we do not send newsletters or marketing messages.
  • Children: this website is not aimed at children, and we do not knowingly collect personal data online from anyone under 16.

12How we protect your data

The website uses an encrypted HTTPS connection. Access to our website, mailboxes and salon phones is limited to the people who need it, and is protected with passwords. Our providers use industry-standard security. If a data breach puts your rights at risk, we will inform you and AZOP as the law requires.

13Changes to this policy

We may update this policy when our services, the website or the law change. The latest version is always on this page, with the date it was last updated. This version is valid from 29.9.2026.

14Contact us about privacy

For any question about your personal data, or to use your rights, contact us by email, by phone, or by post to either business address in section 01.

You can also use the phone number or email of any of our salons, listed on the contact page.