Agencija Nova Vizija – Novka Samac

Last updated: 1 September 2026
Application: Nova Vizija CRM (Android package / iOS bundle identifier: ba.novavizija.nv_crm)

Ova politika je dostupna i na bosanskom jeziku →

Introduction

This Privacy Policy explains how Agencija Nova Vizija — Novka Samac (“Nova Vizija”, “we”, “us”, “our”) collects, uses, stores and protects personal data in connection with the Nova Vizija CRM mobile application (the “App”) and the related functions of our CRM system, including the temporary web form through which a client can enter data for their own case.

Nova Vizija is a visa consultancy agency based in Prnjavor, Bosnia and Herzegovina. The App is the mobile client for our internal case-management system, which we use to manage client files for work, seasonal, student and family-reunification visa applications for Germany and Austria.

Nova Vizija is the data controller for the personal data it processes through the App in the course of its business.

Scope — who uses the App and its related functions

The Nova Vizija CRM is an internal business tool intended solely for authorised Nova Vizija agents and other authorised staff. It may be distributed through the Google Play Store and the App Store, but it has no public sign-up. Opening the App gives you a login screen; without a valid account issued by Nova Vizija, no function or data in the CRM is accessible.

Alongside the mobile App, the CRM allows an authorised agent to send a client a temporary web link through which the client can enter the information their own case requires. No account and no mobile application are needed for that.

This policy therefore covers:

  • Our agents and other authorised users, who use the App and whose account and activity data we process in connection with their engagement at Nova Vizija.
  • Our clients and their family members, whose data our agents record in the system, or which clients enter themselves through the temporary form, so that Nova Vizija can prepare and manage their case.

Information we collect

Agent account data

When an agent signs in, we process their name, work email address or username, the role and permissions assigned to their account, their unique identifier in our authentication system, and the session tokens issued to their device. We also log sign-in events and the actions an agent performs in the system, so that changes to a client file can be traced to the person who made them.

Client and case data

Our agents enter and access client information through the App, in the same way they would through our web application. Depending on the case, this can include:

  • Identity and contact details: full name, date and place of birth, citizenship, address, telephone number and email address.
  • Identity document details required by embassies and consulates, such as passport and identity card data.
  • Family details where the visa category requires them, for example spouse and children in a family-reunification file.
  • Education and employment details: qualifications, diploma recognition status, employer and employment contract details.
  • Case administration data: case status, appointment dates, notes written by the agent, tasks, correspondence history and payment status.
  • Documents and photographs attached to a case, including scans or photographs of supporting documents.

Some of this information is sensitive. We treat every client file as confidential and restrict access to the agent handling the case and to authorised staff who need it to do their work.

Temporary link for client self-entry

For a given case, an authorised agent can generate a temporary link and send it to the client at the contact details the client gave us. Through that link the client can enter the information their case requires.

The link is time-limited and valid for at most one hour from the moment it is generated. It also expires earlier, as soon as the client completes and confirms the form. Once the hour has passed or the form has been submitted, the link can no longer be used.

The link gives no access to an agent’s account, to other cases, or to anything else held in the CRM. It opens the form for that one case and nothing else.

What the client enters is sent to our server and attached to the corresponding case. The type and amount of information requested depends on the case and may include the data described under “Client and case data” above.

We use this method so that clients can supply their details directly, without an agent transcribing them by hand, which reduces the risk of errors in the prepared documentation.

Photographs and files

The App can open your device’s camera or photo library so that an agent can attach a photograph of a document to a client file. This happens only when the agent taps the relevant control. The image is uploaded to our own server and attached to the case. The App does not scan your photo library, does not read images in the background, and does not send images to any third party.

We use uploaded documents and photographs solely to read from them the information a case requires. The documents themselves stay in our CRM system and are not sent to anyone outside the agency.

Technical and log data

Our server records standard technical information for every request the App makes: the IP address of the device, the date and time, the endpoint that was called, the response status and the application version. We use these logs to keep the system secure and to diagnose faults.

What we do not collect

The App contains no analytics, advertising, attribution, crash-reporting or tracking software of any kind. Specifically, we do not:

  • collect your location;
  • read your address book, calendar, call log, SMS messages or other applications’ data;
  • use the microphone;
  • use cookies or advertising identifiers, or profile you for advertising;
  • sell, rent or trade personal data, or make it available to data brokers;
  • use client data to train artificial-intelligence models.

Device permissions

  • Internet access — required. The App communicates only with the Nova Vizija server over an encrypted connection.
  • Camera and photo library — optional, requested at the moment an agent chooses to attach a photograph. If you decline, the rest of the App continues to work.
  • Secure storage (Android Keystore / iOS Keychain) — used to store the session token on the device. The token is removed when the agent signs out.
  • Opening the dialler and mail application — tapping a telephone number or email address in the App hands the number or address to your device’s own phone or mail application. The App does not place calls, does not send messages by itself, and does not record calls or their content.

How we use the data

  • To authenticate agents and keep their sessions secure.
  • To prepare, manage and track client visa files, including appointment booking, document collection and submission to the relevant embassy or consulate.
  • To communicate with clients about their case.
  • To let clients supply the information their case requires themselves, through a time-limited web form.
  • To reduce transcription errors in the data needed to prepare documentation and process a case.
  • To keep an internal audit trail of who changed what in a client file.
  • To operate, secure, back up and troubleshoot the system.
  • To meet our legal, accounting and record-keeping obligations.

Legal basis for processing

We process personal data in accordance with the Law on the Protection of Personal Data of Bosnia and Herzegovina and, where it applies to us, the EU General Data Protection Regulation (GDPR). Our legal bases are:

  • Performance of a contract — processing a client’s file is the service the client engaged us to provide; processing an agent’s account data is necessary for their employment or engagement.
  • Legal obligation — retention of business records and compliance with requirements imposed on us by law or by the authorities we submit files to.
  • Legitimate interests — securing the system, preventing misuse and maintaining an audit trail, balanced against the rights of the people concerned.
  • Consent — where we ask for it separately, for example before processing categories of data that are not strictly necessary for the case. Consent can be withdrawn at any time.

Sharing and disclosure

We do not sell personal data and we do not share it with unrelated parties. Data entered in the App is disclosed only in the following situations:

  • Hosting. Our backend and database run on dedicated infrastructure rented from Hetzner Online GmbH, a German hosting provider, which acts as our processor under a data processing agreement. Hetzner provides and maintains the infrastructure; it does not use the data stored on it for its own purposes.
  • Preparing and submitting a visa application. Where a client has engaged us to prepare their case, we use the information in their file to complete application forms, book appointments and correspond with the relevant embassy or consulate, and only to the extent the procedure requires. Documents and photographs uploaded to the system stay in our CRM: we use them solely to read the information we need from them, and we do not forward them to an embassy, a consulate or any third party.
  • Legal requirements. Where we are obliged to disclose data by law, by a court, or by a competent authority.

Data an agent enters or views through the mobile App is processed on our own server. Data a client enters through the temporary web form is likewise sent to our server and attached to the corresponding case in the CRM.

The App uses no analytics, advertising or other third-party components for user tracking, advertising or advertising profiles.

Where data is stored and how it is protected

All data is stored on our server infrastructure at Hetzner, in the European Union. We apply the following measures:

  • Traffic between the App and the server is encrypted in transit using TLS (HTTPS). The App refuses unencrypted connections.
  • Authentication and session management are handled by Keycloak. Every request is authorised; there are no anonymous endpoints serving client data.
  • Access is granted per account and per role, on a need-to-know basis, and is revoked when an agent leaves.
  • Session tokens are kept in the operating system’s secure storage — Android Keystore or the iOS Keychain — and never in ordinary application preferences.
  • Temporary self-entry links are time-limited, stop working once the form has been submitted, and give no access to other data or cases in the CRM.
  • Backups are taken regularly and are protected to the same standard as the live system.

No system can be guaranteed to be completely secure, but we review these measures and adjust them as needed.

Data retention

We keep client case data for as long as the client relationship requires it and thereafter for as long as we are obliged to keep business records under applicable law, or for as long as a file may be needed to defend a legal claim. Agent account data is kept for the duration of the engagement and for the period required by employment and accounting rules. Technical server logs are kept for a short period and then overwritten. When data is no longer needed for any of these purposes, it is deleted or anonymised.

Your rights

If we hold personal data about you, you have the right to:

  • be told what data we hold and obtain a copy of it;
  • have inaccurate or incomplete data corrected;
  • have your data deleted, where we are not required to keep it;
  • ask us to restrict processing, or object to it;
  • receive your data in a portable format, where that right applies;
  • withdraw consent, where processing is based on consent.

The App has no self-service registration. Accounts are created, changed and closed by Nova Vizija, and an agent’s account is disabled when their engagement ends. To ask us to delete an account, or to delete data we hold about you, write to the address below.

To exercise any of these rights, contact us using the details below. We will verify your identity before acting on a request, and we will respond within the period required by law. You also have the right to complain to the Personal Data Protection Agency of Bosnia and Herzegovina, or — if you are in the EU or EEA — to your national supervisory authority.

International transfers

Our servers are located in the European Union, while our office and most of our clients are in Bosnia and Herzegovina, so data moves between BiH and the EU in the ordinary course of our work. Where a visa procedure requires it, we supply the relevant embassy or consulate with the information that application asks for — and only that. Uploaded documents and photographs are not transferred to other countries and do not leave our system. Every transfer is limited to what the procedure requires and is made under the safeguards required by applicable data protection law.

Children

The App is a professional tool and is not directed to children, nor may it be used by them. Data about minors may appear in a client file — for example, children named in a family-reunification application — and is entered by our agents on the instruction of the parent or legal guardian, and protected in the same way as all other case data.

Changes to this policy

We may update this Privacy Policy from time to time. The current version is always published on this page, with the date of the last change at the top. Where a change materially affects how we handle personal data, we will draw attention to it.

Contact

Agencija Nova Vizija — Novka Samac
Laze Lazarevića 14a, 78430 Prnjavor, Bosnia and Herzegovina
Email: admin@novavizija.org
Telephone: +387 65 626 726

Scroll to Top