Legal
Security policy
Last updated: 14/09/2026
Last updated: 31.8.2026.
Purpose
The security of user data, transactions and the Godi.ba platform is a fundamental principle of our operations.
VanillCore d.o.o. applies technical and organizational measures designed to protect:
- users’ personal data;
- user accounts;
- reservation information;
- payment transaction information;
- communications between users and partners;
- business information;
- infrastructure and systems supporting the platform.
Security measures are continuously adapted to technological developments, identified risks and the nature of the data being processed.
Secure Communication
Godi.ba uses secure HTTPS communication for the transmission of data between users’ devices and the platform.
Secure communication is intended to protect information from interception and unauthorized modification during transmission.
Users are advised to verify that they are accessing the official godi.ba domain before entering account or other sensitive information.
Payment Transaction Security
Payments on Godi.ba are processed through a secure payment gateway.
Card transactions are processed through the Moore payment gateway, with Raiffeisen Bank d.d. Bosnia and Herzegovina acting as the acquiring bank.
VanillCore d.o.o. does not store full payment card numbers or users’ CVV/CVC security codes.
Information required to authorize card payments is processed within the infrastructure of payment service providers and other authorized participants in the payment system.
Godi.ba may retain information necessary to record and monitor transactions, including transaction identifiers, amounts, currencies, dates, times and transaction statuses.
User Account Security
User accounts are protected through appropriate authentication and access-control mechanisms.
Users are advised to:
- use a unique and sufficiently strong password;
- not share account credentials with other persons;
- avoid reusing the same password across multiple services;
- immediately notify Godi.ba if they suspect unauthorized access to their account.
VanillCore d.o.o. will never ask users to provide passwords or full payment card details by email.
Access Control
Access to data and systems is restricted according to business needs and authorization levels.
Employees and authorized personnel should only have access to information necessary for the performance of their duties.
Administrative access to systems is additionally protected through appropriate authentication and access-control mechanisms.
Personal Data Protection
Users’ personal data is processed in accordance with our Privacy Policy and applicable personal data protection legislation.
We apply appropriate technical and organizational measures designed to reduce the risk of:
- unauthorized access;
- data loss;
- accidental destruction;
- unauthorized modification;
- unauthorized disclosure;
- other unlawful processing.
Reservation and Transaction Data Security
Reservation and transaction information is treated as business- and user-relevant information, and access is restricted to authorized persons and systems.
Transaction information may be used for:
- reservation confirmation;
- payment processing;
- accounting;
- customer support;
- refunds;
- fraud prevention;
- handling complaints and disputes;
- compliance with legal obligations.
Fraud and Abuse Prevention
Godi.ba may apply security controls designed to detect and prevent fraud, account abuse and unauthorized transactions.
Such controls may include analysis of technical information, transaction information, account activity and other relevant risk indicators, in accordance with applicable law.
Where fraud or misuse is suspected, Godi.ba may temporarily restrict certain account functions or a transaction and conduct additional verification.
Third-Party Service Providers
Godi.ba uses third-party services for certain parts of its infrastructure, including payment services, hosting, analytics, marketing, communications and other technical functions.
Where a third party processes data on behalf of VanillCore d.o.o., we seek to ensure appropriate contractual, technical and organizational safeguards.
The security practices of third-party providers are taken into consideration when selecting and using their services.
Security Logs and Monitoring
For platform security purposes, certain technical and security events may be logged, including logins, access attempts, errors, transaction events and other relevant activities.
Such information may be used to:
- detect security incidents;
- investigate misuse;
- maintain systems;
- improve security;
- comply with legal obligations.
Backups and Availability
Where technically applicable, systems and data important to the operation of the platform may be protected through backups and other measures designed to preserve data availability and integrity.
Backups are subject to appropriate access and retention controls.
Security Incident Management
VanillCore d.o.o. maintains procedures for identifying, assessing and responding to security incidents.
Depending on the circumstances, incident response may include:
- identifying and assessing the incident;
- containing its impact;
- protecting systems and data;
- investigating the cause;
- mitigating consequences;
- documenting the incident;
- implementing preventive measures;
- notifying competent authorities and affected individuals where required by law.
User Responsibilities
Platform security also depends on responsible user behavior.
Users are responsible for protecting their account credentials and should exercise caution when opening links or providing information through unverified channels.
Godi.ba will never ask users to provide full payment card numbers, CVV/CVC codes or passwords by email or other insecure communication channels.
Limitation of Security Guarantees
Although VanillCore d.o.o. applies reasonable technical and organizational safeguards, no system operating over the internet can be guaranteed to be completely secure.
In the event of a security incident, VanillCore d.o.o. will act in accordance with applicable law and its incident response procedures.
Changes to this Security Policy
VanillCore d.o.o. may update this Security Policy to reflect changes in technology, infrastructure, business processes or applicable legal requirements.
The current version of the Policy will be published on this page.
VanillCore d.o.o.
Kromolj 31, 71000 Sarajevo, Bosnia and Herzegovina
info@godi.ba