Last updated: 19.08.26
This privacy policy explains how uncover071 collects, uses, and protects your personal data when you visit our website at uncover071.ba or book one of our experiences. We care about your privacy and only collect what we need to run our tours and answer your questions.
Who we are
uncover071 is a tour and experience provider based in Sarajevo, Bosnia and Herzegovina, owned and operated by Custom Concept d.o.o.. For the purposes of data protection law, uncover071 is the data controller responsible for your personal data.
You can reach us at:
- Email: hello@uncover071.ba
- Website: https://uncover071.ba
Which law applies
We are based in Bosnia and Herzegovina and follow the B&H Law on Protection of Personal Data, overseen by the Personal Data Protection Agency. Because we welcome visitors from the European Union, the EEA, and the United Kingdom, we also apply the standards of the EU General Data Protection Regulation (GDPR) and the UK GDPR to the personal data of those visitors.
What we collect and why
We only collect personal data in a few specific situations.
When you contact us through the website. Our contact form collects your name, email address, the type of inquiry you choose, your message, and a timestamp recording your consent. We use this to reply to you and keep a record of the conversation.
When you book an experience. Bookings are taken through EZ Booker, our booking platform. To confirm a booking we need your name, email address, telephone number, and the details of the experience you choose (date, group size, and similar). Payments are processed by Monri, our payment provider. We do not see or store your full card details on our website — that information goes directly to Monri, which is built for handling payments securely. Booking and payment data is held within EZ Booker and Monri rather than on the uncover071 website itself.
Analytics and how the site is used. We use Google Analytics (GA4) and Google Search Console through the Site Kit tool to understand, in aggregate, how people find and use the site — for example which pages are most visited. This helps us improve the website. Where required, this only runs after you accept analytics cookies.
Cookies and consent. When you first visit, a consent banner (provided by Complianz) lets you accept or decline non-essential cookies, and records your choice. Non-essential scripts, including analytics, are blocked until you consent. Full details of the individual cookies are in our separate Cookie policy.
Technical and server data. Like most websites, our host keeps standard server logs (for example IP address, browser type, and the time of a request) for security and to keep the site running. Our website is hosted by Globalhost on servers in the EU region.
Legal bases for using your data
We rely on the following legal bases for processing personal data:
- Performance of a contract — to take and fulfil your booking and provide the experience.
- Consent — for analytics and non-essential cookies, and for any optional marketing; you can withdraw consent at any time.
- Legitimate interests — to respond to your inquiries, keep the website secure, and improve our services, balanced against your rights.
- Legal obligation — where we must keep certain records (for example for tax or accounting).
Who we share data with
We do not sell your personal data. We share it only with the service providers that help us run the business, each acting as a processor on our behalf or as an independent controller for their own platform:
- EZ Booker – booking platform (based in the EU/Croatia).
- Monri – payment processing (based in Sarajevo, B&H; part of the Payten/Asseco SEE group).
- Google – site analytics.
- Globalhost – website hosting (EU region).
We may also disclose data where required by law, or to protect our rights and the safety of our guests.
International transfers
Some of the providers above may process data outside Bosnia and Herzegovina, including within the EU/EEA and, in the case of Google, potentially outside the EEA. Where data leaves the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
How long we keep your data
We keep personal data only as long as we need it:
- Contact form messages — kept while we handle your inquiry and for a reasonable period afterward, then deleted.
- Booking and payment records — kept as long as needed to provide the service and to meet legal, tax, and accounting obligations.
- Analytics data — retained according to the settings in Google Analytics.
Your rights
Depending on where you are, you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate data;
- ask us to delete your data;
- restrict or object to how we use it;
- request a copy of your data in a portable format;
- withdraw consent at any time, where we relied on consent.
To exercise any of these, email us at hello@uncover071.ba. We will respond within the time the law allows.
If you are in the EU/EEA or UK and believe we have mishandled your data, you may complain to your local data protection authority. In Bosnia and Herzegovina, you may contact the Personal Data Protection Agency.
Personal data gathering and protection statement
We are committed to provide service of protection of our customer’s personal data in a way that we collect only essential basic information about our buyers that are necessary for fulfilling our obligations. We also inform our customers about the way we collect information and regularly give customers an option about how their information will be used, including the possibility to decide whether their name should be included or omitted from the lists used for marketing campaigns. All user information is strictly guarded and are available only to the employees who need that information for completing the job. All our employees and business partners are responsible to follow the principles of confidentiality protection.
Credit card purchase security statement
Confidentiality of your information is protected and secured by using latest TLS encryption. Pages for web payment are secured by using Secure Socket Layer (SSL) protocol with 128-bit data encryption. SSL encryption is a data coding procedure for prevention of unauthorized access during data transfer. This enables a secure data transfer and prevents unauthorized data access during communication between user and Monri WebPay Payment Gateway and vice versa. Monri WebPay Payment Gateway and financial institutions exchange data by using their virtual private network (VPN) which is also protected from unauthorized access. Monri Payments is PCI DSS Level 1 certified payment service provider. Credit card numbers are not stored by Merchant and are not available to unauthorized personnel
Children
Our website and bookings are intended for adults. We do not knowingly collect personal data from children. Where a booking includes minors, it is made by a responsible adult on their behalf.
Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows when it last changed. Significant changes will be reflected on this page.
Contact
Questions about this policy or your data? Email hello@uncover071.ba.