BabySOS

← Back to BabySOS

Data protection

Privacy Policy

What data we process, why, who receives it and what rights you have.

Effective from: Wersja polska

1. Data controller

  1. The controller of personal data processed in the BabySOS Service is LifeNexa (the “Controller”).
  2. For anything concerning personal data, write to: servicetunfiles@gmail.com. We have not appointed a data protection officer; the address above handles all enquiries.

2. What data we process

  1. Parent account: e-mail address, password (we store only a cryptographic hash, never the password itself), and optionally name, phone number and country (used to pick the right emergency number).
  2. Child profile: name, date of birth and – only if you enter it – blood type, allergies, medication, chronic conditions and other important health notes, an optional photo and instructions for caregivers. Health data is a special category of data (Art. 9 GDPR).
  3. Daily schedule and events: planned and recorded activities (feeding, sleep, diapers, bath, etc.), times, amounts and notes – entered by the parent, or by a caregiver within the access granted to them.
  4. Emergency contacts: label, name and phone number of people named by the parent (third-party data – the parent declares they may provide it).
  5. Caregiver access: the caregiver's name and relationship given by the parent, scope of permissions, validity period, last-used time, and a hash of the access token and code – the token and code themselves are shown to the parent only once and are not stored by us in plain form.
  6. Notifications (mobile app): a device token for push notifications, if you enable notifications.
  7. Technical and security data: IP address, browser and request time in server logs, and an account security event log (e.g. sign-in, creating or revoking access, password-reset request).
  1. Providing the Service – creating and running the account, daily schedule, sharing information with caregivers, SOS mode and emergency card, exporting and deleting data (Art. 6(1)(b) GDPR – performance of a contract).
  2. Children's health data – we process it solely on the basis of your explicit consent, given by voluntarily entering that data (Art. 9(2)(a) GDPR). You can withdraw consent at any time by deleting the data or the whole child profile; this does not affect lawfulness of processing before withdrawal. A caregiver sees it only if you separately allow it.
  3. Security and abuse prevention – server logs, login attempt limits, protection against attacks (Art. 6(1)(f) GDPR – the Controller's legitimate interest).
  4. Handling enquiries and defending claims – correspondence with you, defence against claims (Art. 6(1)(f) GDPR).
  5. Push notifications – sent only after you consent in your phone's system settings (Art. 6(1)(a) GDPR); you can withdraw consent in the phone settings.
  6. Legal obligations – where the law requires it (Art. 6(1)(c) GDPR).

Providing the data marked as required (e-mail, password, child's name and date of birth) is voluntary but necessary to create an account. All other data is optional.

4. Children's data

The Service is intended for adults: parents and legal guardians. We do not create accounts for children. A child's data is entered by a parent or legal guardian, who is responsible for its accuracy and scope. Access by other people to a child's data requires a deliberate action by the parent and is limited by them and revocable at any time.

5. Recipients

Data is not sold or shared for advertising. We use the following categories of recipients (processors):

  • server infrastructure provider – OVHcloud (server located in Poland; hosting of the application, database and backups);
  • e-mail server – sending system messages (e.g. password reset);
  • Expo Push Notification Service (Expo Technologies, Inc.) together with the Google and Apple system notification services – only if you enable notifications in the mobile app; the device token and the notification content (child's name, caregiver's name and type of recorded activity) are transmitted;
  • public authorities and entitled entities – only where required by law.

We use no analytics, advertising or third-party tracking tools. Fonts and site resources are served from our own server.

6. Transfers outside the EEA

We store data in Poland. Only the data needed to deliver push notifications (Expo and the Google and Apple system services) may reach a third country (the United States), and only if you enable notifications in the mobile app. This is done under GDPR-compliant mechanisms (including standard contractual clauses or an adequacy decision).

7. How long we keep data

  • Account and children's data – until you delete the account (or, respectively, the child's profile). Deleting the account permanently removes child profiles, schedules, events, contacts, instructions and caregiver access grants from the production system.
  • Backups – data removed from the production system may remain in automatic backups for up to 30 days and is then overwritten; backups are used only to restore the system after a failure.
  • Password-reset token – valid for 1 hour and single-use.
  • Caregiver access – until it expires or is revoked, after which it stops working; the entry stays visible to the parent until the account is deleted.
  • Server logs – for as long as needed for security and diagnostics, after which they are automatically rotated and deleted.
  • Correspondence and data needed to defend against claims – until the claims become time-barred.

8. Your rights

You have the right to access your data, rectify it, erase it, restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent at any time.

You can exercise most of these rights yourself: edit data in the app or panel, download a full copy in JSON format (“Account” tab), delete individual data, a child profile or the whole account. For anything else write to servicetunfiles@gmail.com – we will reply within one month.

You also have the right to lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl).

9. Automated decision-making

We do not take decisions about you by solely automated means and we do not profile users.

10. Data security

We apply measures appropriate to the risk, including: an encrypted connection (HTTPS/TLS), passwords stored only as hashes, caregiver access tokens stored only as hashes, sessions in an HttpOnly cookie, login attempt limits, separate permissions for health data (invisible to caregivers by default), a security event log and regular backups.

11. Cookies and similar technologies

The site uses only one strictly necessary session cookie (babysos_session), set after sign-in to keep you signed in (HttpOnly, Secure, SameSite=Lax, valid for up to 30 days or until sign-out). We use no analytics, marketing or advertising cookies, so no consent banner is shown. The mobile app keeps the session token in the system's secure storage.

12. Changes to this policy

We will announce material changes to this policy in the app, in the panel or by e-mail. The current version is always available on this page; its effective date is shown at the top of the document.