PRIVACY POLICY
Version: 1.0 (interim, pending business registration) Effective date: 26 July 2026
1. Who is the controller of your data
The controller of personal data within the meaning of the Law on Personal Data Protection of Bosnia and Herzegovina ("Official Gazette of BiH", no. 12/25, applicable since 4 October 2025) is:
- Controller: Sarajevo Nightlife
- Website: www.sarajevonightlife.com
- Contact e-mail: admin@sarajevonightlife.com
- Place of business: Sarajevo, Bosnia and Herzegovina
The platform is currently operated by a natural person in the process of registering a business in Sarajevo. Immediately upon registration, this policy will be updated with the full details of the controller (registered name, address and identification number), and you will be notified of the change within the application. Until then, you may exercise all rights listed in section 9 through the e-mail address above.
In this document, "we", "us" and "the platform" refer to the controller named above.
By using Sarajevo Nightlife you confirm that you have read and understood this Privacy Policy.
2. Who this policy applies to
This policy applies to individuals who use the platform as guests, meaning users who create an account and make reservations at venues.
Processing of data belonging to venue staff who use the business dashboard is governed by a separate agreement with the venue.
3. What data we collect
3.1. Data you provide yourself
- First and last name, used to identify your reservation at the door
- Phone number in international format, used to verify your account and to communicate about your reservation
- Password, stored only in encrypted form and not visible to us
- Preferred language of communication
- Party size, date and time of the reservation, and any notes you choose to add
3.2. Data generated through use of the service
- Reservation history and status (confirmed, cancelled, arrived, no-show)
- The content of WhatsApp messages exchanged about your reservation
- The content of in-app support messages, including any support rating you give
- Labels a venue may record against your reservation, such as spend amounts or guest status
- A record of no-shows and, where applicable, a restriction on booking at an individual venue
3.3. Technical data
- IP address, device type, operating system and browser
- Access and error logs
We do not collect payment card details, precise device location, or special categories of data (health, biometric, religious or political data).
4. Why we process your data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account, verifying your phone number | Performance of a contract (Art. 8(1)(b)) |
| Creating, confirming, reminding about and cancelling reservations, including WhatsApp communication | Performance of a contract |
| Passing reservation details to the venue | Performance of a contract |
| Customer support, including processing of messages by the AI assistant | Performance of a contract |
| Preventing abuse, recording no-shows, system security | Legitimate interest (Art. 8(1)(f)) |
| Improving the service, in aggregated or pseudonymised form | Legitimate interest |
| Sending promotional messages about events and offers | Separate, voluntary consent (Art. 8(1)(a)) |
| Meeting legal obligations and responding to requests from competent authorities | Legal obligation (Art. 8(1)(c)) |
Consent to promotional messages is voluntary and is not a condition for using the platform. You may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. Who has access to your data
5.1. Venues
The venue where you made a reservation can see your first and last name, party size, date and time of arrival, your notes, and your phone number for contact regarding that reservation. The venue can also see your reservation history at that venue, including any recorded no-shows.
The venue is contractually required to use this data solely to fulfil the reservation and maintain its guest records.
5.2. Technical service providers
We use the following providers to operate the platform. They process data on our instructions and under signed data processing agreements:
| Provider | Purpose | Place of processing |
|---|---|---|
| Supabase | Database, authentication, storage | European Union |
| Vercel | Application hosting | European Union (Frankfurt) |
| Meta Platforms (WhatsApp Business Cloud API) | Sending and receiving reservation messages | United States and EU |
| Anthropic | AI support assistant | United States |
| Resend | Sending e-mail | United States |
| Twilio | SMS verification of phone numbers | United States |
| Telegram | Internal notifications about support requests | Global |
| Cloudflare | Domain and abuse protection | Global |
5.3. Other recipients
We may disclose data to competent authorities where we are legally required to do so.
We do not sell your data and do not share it with third parties for marketing purposes.
6. Transfers outside Bosnia and Herzegovina
Some of the providers listed above process data outside Bosnia and Herzegovina. For such transfers we apply the safeguards set out in Articles 48 to 51 of the Law, primarily standard contractual clauses agreed with each provider.
You may request a copy of the applicable safeguards at the e-mail address in section 1.
7. How long we keep your data
| Category | Retention period |
|---|---|
| Account data | For as long as the account exists, and 30 days after a deletion request |
| Reservation data | 24 months from the reservation date, after which it is anonymised |
| WhatsApp communication about reservations | 12 months |
| Support messages | 12 months after the case is closed |
| No-show records and access restrictions | No more than 24 months from the last event |
| Technical logs | 12 months |
| Records of consent | For the duration of the consent and 24 months after withdrawal |
Once these periods expire, data is deleted or irreversibly anonymised.
8. Automated processing
The platform uses automated processes in the following cases:
- Automatic cancellation. If you do not reply to the reminder sent before the event within the stated window, or if you reply negatively, the reservation is cancelled automatically and the place is released.
- No-show records. If you do not turn up for a confirmed reservation you did not cancel, the venue may record this. Repeated no-shows may lead an individual venue to refuse you the ability to book through the platform.
- Guest status. A venue may assign you an internal label, such as regular guest status, in order to grant benefits.
- AI support assistant. Your support messages are processed by a language model that has no authority to change, confirm or cancel reservations. Where the assistant cannot help, a person takes over the case.
You have the right to object to any of these processes and to request human intervention using the contact details in section 1.
9. Your rights
As a data subject you have the right to:
- access your data and receive information about the purpose of processing, recipients and retention period
- rectification of inaccurate data and completion of incomplete data, most of which you can change yourself in your profile
- erasure where the data is no longer necessary, where you withdraw consent, or where processing is unlawful
- restriction of processing
- portability of the data you provided to us, in a machine-readable format
- object to processing based on legitimate interest, including the processes described in section 8
- withdraw consent at any time, without affecting the lawfulness of earlier processing
- lodge a complaint with the supervisory authority
Requests should be sent to admin@sarajevonightlife.com. We respond within 30 days at the latest. To protect your data, we may ask you to confirm your identity.
Supervisory authority: Personal Data Protection Agency in Bosnia and Herzegovina Vilsonovo šetalište 10, 71000 Sarajevo www.azlp.ba
10. Data security
We apply technical and organisational measures appropriate to the risk, including:
- encrypted transmission (HTTPS/TLS) and encrypted storage of passwords
- row level access control in the database, so each venue sees only its own reservations
- a limited number of people with administrative access
- regular system updates and access logging
No system can guarantee absolute security. We take all reasonable protective measures and are liable in accordance with the Law. Please use a unique password and report any suspicion of unauthorised access to your account immediately.
11. Personal data breaches
In the event of a personal data breach we will notify the Personal Data Protection Agency without undue delay, and no later than 72 hours after becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay as well.
12. Age limit
The platform is intended for adults only, as it facilitates reservations at venues serving alcohol. By creating an account you confirm that you are at least 18 years old.
We do not knowingly collect data from persons under 18. If we learn that we have done so, we will delete it without delay.
13. Cookies
Our use of cookies is described in the Cookie Policy.
14. Changes to this policy
We may amend this policy to reflect changes in legislation or in how the platform works. We will notify you of any significant change within the application at least 15 days before it takes effect.
Where a change concerns processing based on your consent, we will ask for fresh consent. Continued use of the platform is not treated as consent to new purposes of processing.
15. Contact
- E-mail: admin@sarajevonightlife.com
- In-app support: available to logged in users

