Privacy Policy

Last updated: April 21, 2026

This Privacy Policy explains how the ATV & Dirty Bike’s Velika Kladusa Messenger assistant ("the Service", "we", "our") handles information when you message our Facebook Page. The Service is operated by ATV & Dirty Bike’s Velika Kladusa, based in Bosnia and Herzegovina.

1. What we collect

When you send a message to our Facebook Page, we receive and store:

We do not collect or store your name, email address, phone number, profile picture, friends list, location, or any other personal information from your Facebook profile.

2. Why we collect it

We use the information above solely to:

3. Third parties we share data with

To generate replies in natural Bosnian, the text of your messages — together with recent conversation context — is sent to OpenAI (gpt-4o-mini model) for language understanding. OpenAI acts as a sub-processor. We send only the message text; we do not send your PSID or any other identifier. OpenAI's handling of this data is governed by their API terms and privacy policy (openai.com/policies/privacy-policy).

We do not sell, rent, or share your data with advertisers or any other third party.

4. Where and how long we store it

Messages and PSIDs are stored in a PostgreSQL database hosted on a private server. We retain conversation data for up to 12 months, after which it is deleted. Aggregated, non-identifying statistics (e.g. total number of messages per month) may be kept longer.

5. Your rights

You can request a copy of the data we hold about you, or request that we delete it, at any time. To do so, email info@autokrajina.ba from the Facebook account you used to message us, or include enough information for us to locate your PSID (for example, the approximate date of your conversation). We will respond within 30 days.

You can also stop the Service from receiving further messages by blocking our Page in Messenger.

6. Security

Access to the database and server is restricted to authorised personnel. Access tokens (the Facebook Page Access Token and the OpenAI API key) are stored as server environment variables and are never exposed to end users. All traffic between Facebook, our server, and OpenAI is transmitted over HTTPS.

7. Children

The Service is intended for users aged 13 and over (the minimum age for a Facebook account). We do not knowingly process data of children under 13.

8. Changes to this policy

If we materially change how we handle data, we will update this page and change the "Last updated" date above.

9. Contact

Questions or requests related to this policy: info@autokrajina.ba