1. Introduction
NEXVisibility is a brand and digital service operated by COMP-IT d.o.o. Sarajevo, with its registered office at Derviša Numića 9, 71000 Sarajevo, Bosnia and Herzegovina.
COMP-IT d.o.o. Sarajevo respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share and protect personal data when you visit nexvisibility.com, contact us, submit an enquiry, request information or use our services.
For the purposes of applicable data protection legislation, COMP-IT d.o.o. Sarajevo acts as the data controller for the personal data described in this Privacy Policy.
Data Controller
COMP-IT d.o.o. Sarajevo
NEXVisibility
Derviša Numića 9
71000 Sarajevo
Bosnia and Herzegovina
Email: [email protected]
2. Applicable Legislation
We process personal data in accordance with:
- the applicable Law on Personal Data Protection of Bosnia and Herzegovina;
- the General Data Protection Regulation (GDPR), where it applies to our activities;
- other applicable laws and regulations governing privacy, electronic communications, marketing and information security.
3. Personal Data We May Collect
The personal data we collect depends on how you interact with our website and services.
3.1 Information You Provide Directly
When you contact us, submit a form or request information, we may collect:
- first and last name;
- business email address;
- telephone number;
- company or organisation name;
- job title or professional role;
- country or general location;
- website address;
- the service in which you are interested;
- information included in your message;
- information about your business, website or digital visibility requirements;
- information provided when requesting an audit, consultation, proposal or service;
- attachments or documents you voluntarily provide;
- communication preferences;
- any other information you choose to share with us.
Please do not provide sensitive personal data or confidential information through our website unless it is necessary and we have specifically requested it.
3.2 Information Collected Automatically
When you visit our website, certain technical information may be collected automatically, including:
- IP address;
- browser type and version;
- device type;
- operating system;
- screen resolution;
- language preferences;
- approximate geographic location;
- date and time of access;
- pages visited;
- time spent on individual pages;
- referring website or traffic source;
- links and buttons clicked;
- cookie and online identifiers;
- diagnostic, security and error-log information.
This information may be collected through server logs, cookies, Google Analytics 4 and similar technologies. Optional analytics technologies are used only after the required consent has been provided.
3.3 Information Obtained from Third Parties
We may receive information from:
- analytics and website-performance providers;
- social media platforms;
- advertising and marketing platforms;
- business partners and professional networks;
- publicly available business sources;
- referrals from existing clients or professional contacts;
- service providers that help us detect spam, fraud or security threats.
Where required by law, we will inform you that your personal data was obtained from another source.
4. How and Why We Use Personal Data
We may process personal data to:
- respond to enquiries and messages;
- process information submitted through our contact form;
- arrange consultations, meetings or presentations;
- prepare proposals, offers and contracts;
- provide AI visibility, search visibility, digital strategy and related services;
- manage client and business relationships;
- perform contracts and deliver agreed services;
- process payments and maintain accounting records;
- provide customer support;
- analyse website traffic and visitor behaviour;
- improve our website, content and services;
- measure the effectiveness of campaigns;
- send marketing communications where permitted and separately authorised;
- protect our website, systems and business operations;
- detect and prevent spam, fraud, misuse or cyberattacks;
- establish, exercise or defend legal claims;
- comply with legal, tax, accounting and regulatory obligations.
We will not use personal data for a purpose that is incompatible with the purposes described above unless the processing is permitted or required by law.
5. Legal Bases for Processing
Depending on the circumstances, we process personal data on one or more of the following legal bases.
5.1 Consent
We rely on consent when:
- you accept optional analytics or marketing cookies;
- you request or agree to receive marketing communications;
- consent is otherwise required by applicable law.
You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5.2 Contractual Necessity
We may process personal data when necessary to:
- take steps at your request before entering into a contract;
- prepare an offer or proposal;
- enter into or perform a contract;
- deliver and manage requested services.
5.3 Legitimate Interests
We may process personal data where necessary for our legitimate business interests, provided that those interests do not override your rights and freedoms.
Our legitimate interests may include:
- responding to relevant business enquiries;
- managing client and professional relationships;
- improving our website and services;
- ensuring website and system security;
- preventing misuse, spam or fraud;
- promoting our services to relevant business contacts;
- managing and protecting our legal rights.
5.4 Legal Obligation
We process personal data when necessary to comply with legal, accounting, tax, regulatory, court or other mandatory obligations.
5.5 Legal Claims
Where necessary, we may process information to establish, exercise or defend legal claims.
6. Contact Forms and Enquiries
When you contact NEXVisibility through our website contact form, email, telephone or another communication channel, we use the information you provide to respond to your request and take any requested pre-contractual steps.
Our contact form may request:
- full name;
- business email address;
- company name;
- website URL;
- service of interest;
- your message;
- confirmation that you have read this Privacy Policy.
Information submitted through the contact form will be delivered to [email protected] and used to respond to your enquiry.
Submitting a contact form does not subscribe you to a newsletter or other marketing communications.
Mandatory fields will be clearly indicated. If you do not provide required information, we may be unable to process or fully respond to your request.
The contact form may use security or anti-spam technologies. Where these technologies use optional cookies or collect data for non-essential purposes, they will be managed through the applicable consent settings.
7. Marketing Communications
NEXVisibility does not currently operate a newsletter through this website.
If newsletters or regular marketing communications are introduced in the future, we will provide clear information at the point of collection and obtain consent where required.
Where legally permitted, we may contact existing clients or relevant business contacts about related services. You may object to direct marketing at any time by contacting: [email protected] .
Administrative, contractual, security and service-related messages are not marketing communications and may still be sent where necessary.
9. Google Analytics 4
Subject to your cookie choices, we use Google Analytics 4 to understand how visitors find and use our website.
Google Analytics 4 may help us understand:
- how visitors reach our website;
- which pages are visited;
- how long visitors remain on the website;
- which devices and browsers are used;
- general visitor interactions with website content;
- whether website features operate correctly;
- how our content and campaigns perform.
Analytics information may include technical data, online identifiers and general usage information. We use data-minimisation measures, restricted access and appropriate retention settings where available.
Google Analytics 4 will not be activated before the visitor provides consent for analytics cookies through CookieYes.
Google may process information on servers located outside Bosnia and Herzegovina or the European Economic Area. Such processing is subject to Google’s own privacy terms and the applicable international data transfer safeguards.
11. AI Tools and Service Delivery
As part of our professional services, NEXVisibility may use artificial intelligence, analytics, research, content, search visibility and automation tools.
Where personal data is involved, we seek to:
- limit the information submitted to what is necessary;
- avoid entering unnecessary sensitive or confidential information;
- use professional or business versions of tools where appropriate;
- review providers and their applicable privacy terms;
- implement contractual and security safeguards;
- use anonymised or aggregated information wherever reasonably possible.
We do not make decisions that produce legal or similarly significant effects about website visitors solely through automated processing.
Client-specific use of AI tools may be further governed by a separate proposal, service agreement, data processing agreement or project documentation.
12. Sharing Personal Data
We do not sell, rent or trade personal data.
Where necessary for the purposes described in this Privacy Policy, we may share personal data with:
- website hosting and infrastructure providers;
- cloud storage and IT service providers;
- email and communication providers;
- analytics and consent-management providers;
- CRM and project-management providers;
- payment, accounting and invoicing providers;
- professional advisers, accountants, auditors and legal representatives;
- authorised contractors and providers involved in service delivery;
- public authorities, courts or regulators where legally required;
- potential buyers, investors or professional advisers in connection with a lawful business restructuring.
Providers processing personal data on our behalf are expected to use it only for agreed purposes and to implement appropriate confidentiality, privacy and security safeguards.
13. International Data Transfers
Some of our service providers may process or store information outside Bosnia and Herzegovina or the European Economic Area.
Where an international transfer takes place, we will use an appropriate legal mechanism where required, which may include:
- an applicable adequacy decision;
- standard contractual clauses;
- contractual, technical and organisational safeguards;
- another transfer mechanism permitted by applicable data protection law.
We will also consider the type of personal data, the destination country, the provider’s security practices and the risks associated with the transfer.
14. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected and to meet applicable legal, contractual, accounting and security requirements.
Indicative retention periods include:
- General enquiries and contact-form messages: up to 24 months after the last meaningful communication;
- Unsuccessful proposals and pre-contractual discussions: up to 24 months;
- Client and contractual records: for the duration of the relationship and applicable statutory limitation periods;
- Invoices and accounting documentation: for the period required by applicable tax and accounting laws;
- Marketing information: until consent is withdrawn, an objection is received or the information is no longer required;
- Cookie consent records: for as long as reasonably necessary to demonstrate compliance;
- Security and server logs: normally for a limited period unless longer retention is required to investigate an incident;
- Legal claims: until the relevant proceedings and limitation periods have ended.
Information may be retained longer where required by law, a court order, a regulatory obligation, a dispute or a security investigation.
After the applicable period expires, personal data will be deleted, anonymised or securely archived where continued retention is legally required.
15. Data Security
We apply appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.
These measures may include:
- access controls and user permissions;
- secure hosting and system configurations;
- encryption during transmission;
- password and authentication controls;
- backup and recovery procedures;
- security logging and monitoring;
- software updates and vulnerability management;
- confidentiality obligations;
- data minimisation;
- incident-response procedures;
- periodic review of service providers.
No method of internet transmission or electronic storage can be guaranteed to be completely secure. However, we take reasonable measures proportionate to the type of information and associated risks.
16. Personal Data Breaches
If a personal data breach occurs, we will assess its nature, scope, cause and possible consequences.
Where required by applicable law, we will notify the competent supervisory authority and affected individuals within the prescribed time limits.
17. Your Data Protection Rights
Subject to applicable legal requirements, limitations and exceptions, you may have the right to:
- receive information about the processing of your data;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing at any time;
- withdraw consent at any time;
- request data portability where applicable;
- request information about automated decision-making where applicable;
- lodge a complaint with the competent authority;
- seek judicial protection and compensation where provided by law.
We may need to verify your identity before responding to a request. This helps us prevent unauthorised disclosure or alteration of personal data.
To exercise your rights, contact: [email protected] .
We will respond within the period prescribed by applicable law. Where permitted, the response period may be extended if a request is particularly complex or numerous requests are submitted.
18. Complaints
If you have concerns about how we process your personal data, you may contact us first so that we have an opportunity to review and address the issue.
You also have the right to lodge a complaint with the competent data protection authority:
Agency for Personal Data Protection in Bosnia and Herzegovina
Dubrovačka 6
71000 Sarajevo
Bosnia and Herzegovina
Website: azlp.ba
19. Children’s Privacy
The NEXVisibility website and services are intended primarily for businesses and adult professionals.
We do not knowingly collect personal data from children through this website. If you believe that a child has provided personal data to us without appropriate authorisation, please contact us so that we can investigate and delete the information where required.
20. Third-Party Links
Our website may contain links to websites, tools or services operated by third parties. This Privacy Policy does not apply to those third-party services.
We are not responsible for the content, privacy practices, security or availability of external websites. We recommend reviewing the privacy policy of each third-party service before providing personal data.
21. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- changes to our website or services;
- new technologies or service providers;
- changes in legal requirements;
- changes to our data-processing practices.
The updated version will be published on this page with a revised “Last updated” date. Material changes may also be communicated through an additional website notice or another appropriate method.
22. Contact Us
For questions about this Privacy Policy, the processing of your personal data or the exercise of your rights, contact:
COMP-IT d.o.o. Sarajevo
NEXVisibility
Derviša Numića 9
71000 Sarajevo
Bosnia and Herzegovina
Email: [email protected]
10. Social Media and External Platforms
Our website may contain links to social media profiles, third-party websites or external digital platforms.
When you follow an external link or interact with third-party content, the relevant provider may process information about you in accordance with its own privacy policy.
We do not control the privacy, security or cookie practices of third-party platforms. We recommend reviewing their policies before providing personal data or using their services.