Privacy Policy

Last updated: August 18, 2025

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Mobile Banking application (m-ba) and tells You about Your privacy rights and how the law protects You.

We use Your Personal data to provide and improve the Mobile Banking application (m-ba). By using the Mobile Banking application (m-ba), You agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

 

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Mobile Banking application (m-ba), we may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

Usage Data

Usage Data is collected automatically when using the Mobile Banking application (m-ba).

Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Mobile Banking application (m-ba) that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Mobile Banking application (m-ba) by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

We may also collect information that Your browser sends whenever You visit our Mobile Banking application (m-ba) or when You access the Mobile Banking application (m-ba) by or through a mobile device.

Use of Your Personal Data

The Bank may use Personal Data for the following purposes:

We may share Your personal information in the following situations:

Retention of Your Personal Data

The Bank will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

The Bank will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Mobile Banking application (m-ba), or We are legally obligated to retain this data for longer time periods.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Bank's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.

Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.

The Bank will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.

 

 

Disclosure of Your Personal Data

Business Transactions

If the Bank is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law enforcement

Under certain circumstances, the Bank may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other legal requirements

The Bank may disclose Your Personal Data in the good faith belief that such action is necessary to:

Security of Your Personal Data

As part of its internal protection system and for the purpose of ensuring the security of your personal data, and in accordance with relevant regulations and defined obligations, the Bank applies and undertakes appropriate organizational and technical measures, i.e. measures against unauthorized access to personal data, alteration, destruction or loss of data, unauthorized transfer, and other forms of unlawful processing or misuse of personal data.

Children's Privacy

Our Mobile Banking application (m-ba) does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.

If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.

We will let You know via email and/or a prominent notice on Our Mobile Banking application (m-ba), prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, You can contact us:

Every person whose personal data is processed by the Bank has, as a primary and fundamental right, access to all personal data provided, as well as the right to correction and deletion of personal data (to the extent permitted by law), the right to restriction of processing, all in the manner defined by applicable legal regulations.

The Bank's employees are at your disposal in all branches of the Bank and the Personal Data Protection Officer can be contacted in writing at the address: UniCredit Bank dd, Personal Data Protection Officer, Kardinala Stepinca bb, 88000 Mostar or via e-mail: dpo@unicreditgroup.ba

For more detailed information on how the Bank processes personal data, please visit UniCredit Bank zaštita podataka where detailed "Information on the processing of personal data of UniCredit Bank d.d." is published.