Privacy Policy
1. Data Controller
Jiřina Brázdová, Na Skalce 1516, 396 01 Humpolec, Czech Republic, Company ID: 23874597, email: info@babyapp.cz, website: babyapp.cz.
Personal data is processed in accordance with GDPR and Czech legal regulations.
2. Who the Application Is Intended For
The application is intended exclusively for individuals over 18 years of age, primarily parents and legal guardians who store child-related health information.
3. What Personal Data We Process
Account Data
- email address
- user account identifier
- authentication data via Firebase Authentication
Users may log in via email/password, Google account, or Apple account.
Data Created by the User
Users may store calendar records, dietary information, allergens, reaction records, notes, favorite articles/recipes, and uploaded photos. Such data may include health-related information and is stored solely to provide app functionality.
Special Categories of Data
Health data under Article 9 GDPR is processed only on the basis of explicit consent.
Technical and Analytical Data
Anonymized analytics may be processed via Firebase Analytics, including device type, app version, usage statistics, and diagnostics.
4. Purpose of Data Processing
- account creation and management
- storing user records in the app
- providing app functionality and personalization
- improving app stability and functionality
- sending system notifications and user communication
5. Legal Basis for Processing
Personal data: Article 6(1)(a) GDPR (consent). Special categories (health data): Article 9(2)(a) GDPR (explicit consent).
6. Data Retention
Data is retained only while the user has an active account. If the account is deleted, personal data is removed from the application database without undue delay; some technical data may remain temporarily in backups.
7. Where Data Is Stored
Data is stored using Google LLC cloud infrastructure (1600 Amphitheatre Parkway, Mountain View, CA, USA), including Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Analytics, and Firebase Cloud Messaging.
8. Transfer Outside the EU
Because Google cloud services are used, personal data may be transferred outside the EU. Google relies on Standard Contractual Clauses approved by the European Commission.
9. Security
The controller applies appropriate technical and organizational measures, including secure cloud services, encrypted communication, and authentication mechanisms. Absolute internet transmission security cannot be guaranteed.
10. Newsletter
Users may voluntarily subscribe to a newsletter distributed via Brevo. Email addresses are processed based on consent, which can be withdrawn at any time via the unsubscribe link in each email.
11. User Rights
Users may request access, correction, deletion, restriction, object to processing, and file a complaint with a supervisory authority.
Supervisory authority in the Czech Republic: Office for Personal Data Protection, www.uoou.cz.
12. Changes to This Policy
This policy may be updated in the future. The current version will always be published on babyapp.cz.
13. Contact
Questions: info@babyapp.cz.
14. Account Deletion
Users can request deletion of their account directly within the application:
- Open the application
- Navigate to Profile
- Select "Delete account"
When an account is deleted:
- All personal data associated with the account (email, user ID, stored records, notes, photos, and other user-generated content) is permanently deleted.
- Data stored in Firebase services (Authentication, Firestore, Storage) is removed without undue delay.
- Subscription and billing data are managed by Google Play and are not deleted automatically. Users must manage or cancel subscriptions directly via Google Play.
- Some technical data (e.g. logs or backups) may be retained temporarily for legal, security, or operational purposes.
If users are unable to access their account, they may request deletion by contacting: info@babyapp.cz.
15. Data Deletion Without Account Deletion
Users may delete certain personal data directly within the application without deleting their account.
This includes:
- calendar records
- dietary and testing data
- notes
- uploaded photos
- other user-generated content
Users can manage and delete this data in the app interface, for example by editing or removing individual records.
When such data is deleted, it is permanently removed from the application database and cannot be recovered.
Some technical data (e.g. logs or backups) may be retained temporarily for operational, legal, or security purposes.