Legal

Privacy Policy

How we collect, use, and protect your data — and the data of businesses and users that interact with our services.

Last updated: April 2025  ·  DevHeist, Bihać, Bosnia and Herzegovina

Contents

  1. Who We Are
  2. What Data We Collect
  3. How We Use Platform Data
  4. Messenger & Instagram
  5. Data Sharing & Third Parties
  6. Data Retention
  7. Security
  8. Your Rights
  9. Cookies
  10. Contact Us
01

Who We Are

DevHeist is an IT company based in Bihać, Bosnia and Herzegovina. We develop web applications, chatbot systems, and messaging automation solutions for businesses, with a focus on Messenger and Instagram integrations built on the Meta Platform.

This Privacy Policy applies to:

02

What Data We Collect

We collect and process only the data that is necessary to provide our services. This may include:

03

How We Use Your Data

We use the data we collect for the following purposes:

  1. To respond to enquiries and provide the services requested by our business clients
  2. To automate and manage customer conversations on behalf of our clients
  3. To improve and maintain our products and services
  4. To comply with legal obligations

We collect and process data only as necessary to provide our services. We do not use data for advertising, profiling, or any purpose beyond the services agreed with our clients.

04

Messenger & Instagram Data

Some of our services involve integration with Meta platforms — specifically Facebook Messenger and Instagram Direct — through the Meta Platform APIs. In this context:

Messaging data accessed through Messenger and Instagram is used solely to provide and improve our messaging automation service. It is never sold, shared, or used for any advertising purpose.

05

Data Sharing & Third Parties

We do not sell or share personal data with third parties, except in the following limited circumstances:

In all cases, we share the minimum data necessary and require recipients to handle it in accordance with applicable law.

06

Data Retention

We retain personal data only for as long as necessary to provide the agreed services, meet legal obligations, or resolve disputes. When data is no longer needed, it is securely deleted or anonymised.

Messaging data accessed via Meta APIs is retained only as long as required to operate the messaging service for our client. Clients may request deletion of their data at any time by contacting us.

07

Security

We take data security seriously and implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These include:

No system is completely secure. If you believe your data has been compromised, please contact us immediately at info@devheist.com.

08

Your Rights

Depending on your location, you may have the following rights in relation to your personal data:

To exercise any of these rights, please contact us using the details in Section 10. We will respond within 30 days.

09

Cookies

Our website uses cookies to improve functionality and understand how visitors use the site. We use:

You can manage cookie preferences through your browser settings. Disabling cookies may affect some functionality of the site.

10

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or need to report a data concern, please contact us:

DevHeist – Data Contact

Address: Bihać, Bosnia and Herzegovina