PRIVACY POLICY

Version: 1.0 (interim, pending business registration) Effective date: 26 July 2026


1. Who is the controller of your data

The controller of personal data within the meaning of the Law on Personal Data Protection of Bosnia and Herzegovina ("Official Gazette of BiH", no. 12/25, applicable since 4 October 2025) is:

The platform is currently operated by a natural person in the process of registering a business in Sarajevo. Immediately upon registration, this policy will be updated with the full details of the controller (registered name, address and identification number), and you will be notified of the change within the application. Until then, you may exercise all rights listed in section 9 through the e-mail address above.

In this document, "we", "us" and "the platform" refer to the controller named above.

By using Sarajevo Nightlife you confirm that you have read and understood this Privacy Policy.


2. Who this policy applies to

This policy applies to individuals who use the platform as guests, meaning users who create an account and make reservations at venues.

Processing of data belonging to venue staff who use the business dashboard is governed by a separate agreement with the venue.


3. What data we collect

3.1. Data you provide yourself

  • First and last name, used to identify your reservation at the door
  • Phone number in international format, used to verify your account and to communicate about your reservation
  • Password, stored only in encrypted form and not visible to us
  • Preferred language of communication
  • Party size, date and time of the reservation, and any notes you choose to add

3.2. Data generated through use of the service

  • Reservation history and status (confirmed, cancelled, arrived, no-show)
  • The content of WhatsApp messages exchanged about your reservation
  • The content of in-app support messages, including any support rating you give
  • Labels a venue may record against your reservation, such as spend amounts or guest status
  • A record of no-shows and, where applicable, a restriction on booking at an individual venue

3.3. Technical data

  • IP address, device type, operating system and browser
  • Access and error logs

We do not collect payment card details, precise device location, or special categories of data (health, biometric, religious or political data).


4. Why we process your data and on what legal basis

PurposeLegal basis
Creating and maintaining your account, verifying your phone numberPerformance of a contract (Art. 8(1)(b))
Creating, confirming, reminding about and cancelling reservations, including WhatsApp communicationPerformance of a contract
Passing reservation details to the venuePerformance of a contract
Customer support, including processing of messages by the AI assistantPerformance of a contract
Preventing abuse, recording no-shows, system securityLegitimate interest (Art. 8(1)(f))
Improving the service, in aggregated or pseudonymised formLegitimate interest
Sending promotional messages about events and offersSeparate, voluntary consent (Art. 8(1)(a))
Meeting legal obligations and responding to requests from competent authoritiesLegal obligation (Art. 8(1)(c))

Consent to promotional messages is voluntary and is not a condition for using the platform. You may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.


5. Who has access to your data

5.1. Venues

The venue where you made a reservation can see your first and last name, party size, date and time of arrival, your notes, and your phone number for contact regarding that reservation. The venue can also see your reservation history at that venue, including any recorded no-shows.

The venue is contractually required to use this data solely to fulfil the reservation and maintain its guest records.

5.2. Technical service providers

We use the following providers to operate the platform. They process data on our instructions and under signed data processing agreements:

ProviderPurposePlace of processing
SupabaseDatabase, authentication, storageEuropean Union
VercelApplication hostingEuropean Union (Frankfurt)
Meta Platforms (WhatsApp Business Cloud API)Sending and receiving reservation messagesUnited States and EU
AnthropicAI support assistantUnited States
ResendSending e-mailUnited States
TwilioSMS verification of phone numbersUnited States
TelegramInternal notifications about support requestsGlobal
CloudflareDomain and abuse protectionGlobal

5.3. Other recipients

We may disclose data to competent authorities where we are legally required to do so.

We do not sell your data and do not share it with third parties for marketing purposes.


6. Transfers outside Bosnia and Herzegovina

Some of the providers listed above process data outside Bosnia and Herzegovina. For such transfers we apply the safeguards set out in Articles 48 to 51 of the Law, primarily standard contractual clauses agreed with each provider.

You may request a copy of the applicable safeguards at the e-mail address in section 1.


7. How long we keep your data

CategoryRetention period
Account dataFor as long as the account exists, and 30 days after a deletion request
Reservation data24 months from the reservation date, after which it is anonymised
WhatsApp communication about reservations12 months
Support messages12 months after the case is closed
No-show records and access restrictionsNo more than 24 months from the last event
Technical logs12 months
Records of consentFor the duration of the consent and 24 months after withdrawal

Once these periods expire, data is deleted or irreversibly anonymised.


8. Automated processing

The platform uses automated processes in the following cases:

  • Automatic cancellation. If you do not reply to the reminder sent before the event within the stated window, or if you reply negatively, the reservation is cancelled automatically and the place is released.
  • No-show records. If you do not turn up for a confirmed reservation you did not cancel, the venue may record this. Repeated no-shows may lead an individual venue to refuse you the ability to book through the platform.
  • Guest status. A venue may assign you an internal label, such as regular guest status, in order to grant benefits.
  • AI support assistant. Your support messages are processed by a language model that has no authority to change, confirm or cancel reservations. Where the assistant cannot help, a person takes over the case.

You have the right to object to any of these processes and to request human intervention using the contact details in section 1.


9. Your rights

As a data subject you have the right to:

  • access your data and receive information about the purpose of processing, recipients and retention period
  • rectification of inaccurate data and completion of incomplete data, most of which you can change yourself in your profile
  • erasure where the data is no longer necessary, where you withdraw consent, or where processing is unlawful
  • restriction of processing
  • portability of the data you provided to us, in a machine-readable format
  • object to processing based on legitimate interest, including the processes described in section 8
  • withdraw consent at any time, without affecting the lawfulness of earlier processing
  • lodge a complaint with the supervisory authority

Requests should be sent to admin@sarajevonightlife.com. We respond within 30 days at the latest. To protect your data, we may ask you to confirm your identity.

Supervisory authority: Personal Data Protection Agency in Bosnia and Herzegovina Vilsonovo šetalište 10, 71000 Sarajevo www.azlp.ba


10. Data security

We apply technical and organisational measures appropriate to the risk, including:

  • encrypted transmission (HTTPS/TLS) and encrypted storage of passwords
  • row level access control in the database, so each venue sees only its own reservations
  • a limited number of people with administrative access
  • regular system updates and access logging

No system can guarantee absolute security. We take all reasonable protective measures and are liable in accordance with the Law. Please use a unique password and report any suspicion of unauthorised access to your account immediately.


11. Personal data breaches

In the event of a personal data breach we will notify the Personal Data Protection Agency without undue delay, and no later than 72 hours after becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay as well.


12. Age limit

The platform is intended for adults only, as it facilitates reservations at venues serving alcohol. By creating an account you confirm that you are at least 18 years old.

We do not knowingly collect data from persons under 18. If we learn that we have done so, we will delete it without delay.


13. Cookies

Our use of cookies is described in the Cookie Policy.


14. Changes to this policy

We may amend this policy to reflect changes in legislation or in how the platform works. We will notify you of any significant change within the application at least 15 days before it takes effect.

Where a change concerns processing based on your consent, we will ask for fresh consent. Continued use of the platform is not treated as consent to new purposes of processing.


15. Contact