Privacy policy
Last updated 20 August 2026 · Controller: Vanilla Core d.o.o., Sarajevo · privacy@vanillacore.io
Who we are
Vanilla Core d.o.o., Sarajevo, Bosnia and Herzegovina, is the controller of the personal data described in this policy. For privacy matters write to privacy@vanillacore.io.
This policy covers vanillacore.io and the enquiries, proposals and contracts that follow from it. Data we process on behalf of a client inside a product we built for them is covered by that client’s own policy and our data processing agreement with them.
What we collect
When you contact us: your name, email address, company, phone number if you give it, and the content of your message. When you become a client: billing details, contract documents and the contact details of the people we work with.
When you browse: anonymised traffic statistics — pages viewed, referring site, approximate region, device and browser type. We do not build advertising profiles and we do not sell data.
Why we process it, and on what legal basis
To answer your enquiry and prepare a proposal (legitimate interest, or steps toward a contract). To deliver and support a project, invoice it and keep accounting records (contract and legal obligation). To improve the website through aggregate statistics (legitimate interest).
We send no marketing emails unless you explicitly ask to receive them, and every such email carries a one-click unsubscribe.
Who we share it with
Service providers who help us operate: email and hosting providers, an accountant, and cloud infrastructure vendors. Each acts on our instructions under a written agreement, and we choose providers who host in the EU wherever practical.
We disclose data to authorities only where legally required. We never sell personal data or share it for advertising.
International transfers
Some providers process data outside Bosnia and Herzegovina or the EEA. Where they do, transfers rely on adequacy decisions or standard contractual clauses, and we keep a record of the mechanism used for each provider. Ask us and we will tell you which providers touch your data.
How we protect it
Access to client data is limited to the people who need it, over encrypted connections, with multi-factor authentication on our accounts and encrypted storage for documents and backups.
Development and test environments use anonymised or synthetic data wherever the project allows. If a breach affects your data we notify you and, where required, the supervisory authority without undue delay.
Your rights
You can request access to your data, correction of inaccuracies, deletion, restriction of processing, portability, or object to processing based on legitimate interest. Where processing relies on consent you may withdraw it at any time.
Contact privacy@vanillacore.io — we respond within 30 days, free of charge. You also have the right to complain to your local data protection authority.
Children and changes to this policy
Our services are for businesses; we do not knowingly collect data from children. If you believe we hold such data, tell us and we will delete it.
We may update this policy as our tools or obligations change. The current version is always on this page, with the date of the last change at the top.
Email privacy@vanillacore.io and we will respond within 30 days. You can ask for a copy of your data, a correction, deletion, or that we stop contacting you.