One router, two subnets +wireless

Need some help to (re)setup my network.
My old network was based on a Linksys with Tomato and a simple VLAN. I need a better/faster router and to separate my network in a better way.
I’ve bought a new router, Mikrotik CRS109-8G-1S-2HnD-IN.

The attachment shows the network and possible solution from my understanding. Private on 192.168.1.x and Guests on 192.168.10.x. Guests for internet only.

Building A is strictly Private (net 1). A Nanostation M2 is wired to the router and are sending wireless to building B and C.
Building B is both private (net 1) and guests (net 2). A M2 is recieving from Building A and are wired to an indoor accesspoint. Both private and guests are on the same net today. I need to separate these two. How is the best way to do that? Can I use VLAN in the Nanostation? Or is it best to add another Nanostation here? (and possible in building A also??, and put the VLAN on the router)
Building C is for guests (net 2). Here is a Nanostation for recieving from building A, wired to a outdoor Mikrotik Groove A-52HPn with a 12 dBi omni antenna.

The Nano’s are bridged WDS. First Nano as Accespoint, the other two as Station.

How is the best way to do this net?
Add VLAN’s in the router first? Do I need more than two? (in some examples I see people are using 3 Vlans for systems like this)
Or is it a way to do this without VLAN? What’s best speedwise?

Private-net about 1 – 10 users. Guests about 1 – 35 users.
Also, the OS in the router is very hard to configure for a newbie like me. Perhaps a lot to ask, but could someone guide me to a good setup?
Preferred setup.jpg

Create and assign your vlans to the desired subnets at your router. Then assign the vlans to the advertised ssid’s that are being broadcast by the AP’s (not the airmax radios) within the buildings.
I hope this helps…

I meant to say *and the airmax radios. In other words, assign the allowed vlans to each of the airmax radios as desired.