Skip to content
godi godi
  • Explore
  • For Partners
EN BS
Sign In Join

Your booking

Your cart is empty.

Go to cart
godi godi
  • Explore
  • For Partners
EN BS
Sign In Join

Legal

Security policy

Last updated: 14/09/2026

On this page

  1. 01 Purpose
  2. 02 Secure Communication
  3. 03 Payment Transaction Security
  4. 04 User Account Security
  5. 05 Access Control
  6. 06 Personal Data Protection
  7. 07 Reservation and Transaction Data Security
  8. 08 Fraud and Abuse Prevention
  9. 09 Third-Party Service Providers
  10. 10 Security Logs and Monitoring
  11. 11 Backups and Availability
  12. 12 Security Incident Management
  13. 13 User Responsibilities
  14. 14 Limitation of Security Guarantees
  15. 15 Changes to this Security Policy

Last updated: 31.8.2026.

Purpose

The security of user data, transactions and the Godi.ba platform is a fundamental principle of our operations.

VanillCore d.o.o. applies technical and organizational measures designed to protect:

  • users’ personal data;
  • user accounts;
  • reservation information;
  • payment transaction information;
  • communications between users and partners;
  • business information;
  • infrastructure and systems supporting the platform.

Security measures are continuously adapted to technological developments, identified risks and the nature of the data being processed.

Secure Communication

Godi.ba uses secure HTTPS communication for the transmission of data between users’ devices and the platform.

Secure communication is intended to protect information from interception and unauthorized modification during transmission.

Users are advised to verify that they are accessing the official godi.ba domain before entering account or other sensitive information.

Payment Transaction Security

Payments on Godi.ba are processed through a secure payment gateway.

Card transactions are processed through the Moore payment gateway, with Raiffeisen Bank d.d. Bosnia and Herzegovina acting as the acquiring bank.

VanillCore d.o.o. does not store full payment card numbers or users’ CVV/CVC security codes.

Information required to authorize card payments is processed within the infrastructure of payment service providers and other authorized participants in the payment system.

Godi.ba may retain information necessary to record and monitor transactions, including transaction identifiers, amounts, currencies, dates, times and transaction statuses.

User Account Security

User accounts are protected through appropriate authentication and access-control mechanisms.

Users are advised to:

  • use a unique and sufficiently strong password;
  • not share account credentials with other persons;
  • avoid reusing the same password across multiple services;
  • immediately notify Godi.ba if they suspect unauthorized access to their account.

VanillCore d.o.o. will never ask users to provide passwords or full payment card details by email.

Access Control

Access to data and systems is restricted according to business needs and authorization levels.

Employees and authorized personnel should only have access to information necessary for the performance of their duties.

Administrative access to systems is additionally protected through appropriate authentication and access-control mechanisms.

Personal Data Protection

Users’ personal data is processed in accordance with our Privacy Policy and applicable personal data protection legislation.

We apply appropriate technical and organizational measures designed to reduce the risk of:

  • unauthorized access;
  • data loss;
  • accidental destruction;
  • unauthorized modification;
  • unauthorized disclosure;
  • other unlawful processing.

Reservation and Transaction Data Security

Reservation and transaction information is treated as business- and user-relevant information, and access is restricted to authorized persons and systems.

Transaction information may be used for:

  • reservation confirmation;
  • payment processing;
  • accounting;
  • customer support;
  • refunds;
  • fraud prevention;
  • handling complaints and disputes;
  • compliance with legal obligations.

Fraud and Abuse Prevention

Godi.ba may apply security controls designed to detect and prevent fraud, account abuse and unauthorized transactions.

Such controls may include analysis of technical information, transaction information, account activity and other relevant risk indicators, in accordance with applicable law.

Where fraud or misuse is suspected, Godi.ba may temporarily restrict certain account functions or a transaction and conduct additional verification.

Third-Party Service Providers

Godi.ba uses third-party services for certain parts of its infrastructure, including payment services, hosting, analytics, marketing, communications and other technical functions.

Where a third party processes data on behalf of VanillCore d.o.o., we seek to ensure appropriate contractual, technical and organizational safeguards.

The security practices of third-party providers are taken into consideration when selecting and using their services.

Security Logs and Monitoring

For platform security purposes, certain technical and security events may be logged, including logins, access attempts, errors, transaction events and other relevant activities.

Such information may be used to:

  • detect security incidents;
  • investigate misuse;
  • maintain systems;
  • improve security;
  • comply with legal obligations.

Backups and Availability

Where technically applicable, systems and data important to the operation of the platform may be protected through backups and other measures designed to preserve data availability and integrity.

Backups are subject to appropriate access and retention controls.

Security Incident Management

VanillCore d.o.o. maintains procedures for identifying, assessing and responding to security incidents.

Depending on the circumstances, incident response may include:

  • identifying and assessing the incident;
  • containing its impact;
  • protecting systems and data;
  • investigating the cause;
  • mitigating consequences;
  • documenting the incident;
  • implementing preventive measures;
  • notifying competent authorities and affected individuals where required by law.

User Responsibilities

Platform security also depends on responsible user behavior.

Users are responsible for protecting their account credentials and should exercise caution when opening links or providing information through unverified channels.

Godi.ba will never ask users to provide full payment card numbers, CVV/CVC codes or passwords by email or other insecure communication channels.

Limitation of Security Guarantees

Although VanillCore d.o.o. applies reasonable technical and organizational safeguards, no system operating over the internet can be guaranteed to be completely secure.

In the event of a security incident, VanillCore d.o.o. will act in accordance with applicable law and its incident response procedures.

Changes to this Security Policy

VanillCore d.o.o. may update this Security Policy to reflect changes in technology, infrastructure, business processes or applicable legal requirements.

The current version of the Policy will be published on this page.

VanillCore d.o.o.
Kromolj 31, 71000 Sarajevo, Bosnia and Herzegovina
info@godi.ba

Previous Privacy and personal data protection policy Next Terms & conditions

Subscribe to get information, latest news and other interesting offers about Godi.ba


    Godi.ba

    Book your trip in minutes, get full control for much longer.

    Company

    • Explore
    • For Partners

    Legal

    • Privacy and personal data protection policy
    • Security policy
    • Payment policy
    • Cancellation policy
    • Terms & conditions

    All rights reserved © godi.ba