Privacy and Personal Data Protection Policy
This English version of the policy is a translation provided for convenience. If it differs from the Ukrainian original, the Ukrainian version prevails.
1.GENERAL PROVISIONS
1.1. This Privacy Policy (hereinafter — the “Policy”) sets out the procedure for the collection, processing, storage, use and protection of the personal data of users of the Yummo mobile application (hereinafter — the “Application”).
1.2. The owner of the personal data and the party responsible for processing it is the Limited Liability Company “YAMMO” (hereinafter — the “Company”).
1.3. This Policy applies to all users of the Application regardless of the method of registration, place of residence or means of access to the service.
1.4. The purpose of this Policy is:
- to ensure transparency in the processing of personal data;
- to inform users about what data is collected and for what purpose;
- to define users’ rights regarding their personal data;
- to establish measures for protecting personal information.
1.5. By registering in the Application, using its features and/or continuing to use the service, the user confirms that they:
- have read this Policy;
- understand its contents;
- give voluntary, informed consent to the processing of their personal data in accordance with the terms of this Policy.
1.6. The Company processes personal data on the following principles:
- lawfulness and good faith;
- purpose limitation of the processing;
- data minimization;
- proportionality;
- security and confidentiality;
- limitation of storage periods.
1.7. The Company processes users’ personal data solely to the extent necessary for:
- the functioning of the Application;
- the provision of services;
- the personalization of content;
- ensuring technical stability;
- compliance with the requirements of the legislation of Ukraine.
1.8. This Policy is an integral part of the legal framework for using the Application and applies together with the Public Offer posted in the Application and/or on the Company’s official website.
2.METHODS OF REGISTRATION AND AUTHENTICATION
2.1. To use the features of the Application, the user creates an account by registering in one of the following ways:
- with an email address and a password;
- through a Google account;
- through an Apple account using the Sign in with Apple feature.
2.2. When registering by email, the user is obliged to provide a valid email address and create a password for access to the account.
2.3. When registering through a Google or Apple account, the Company receives and processes the data provided by the respective service, in particular the user’s email address, which is used to create the account in the Application.
2.4. The Company does not gain access to users’ passwords for third-party authentication services (Google, Apple) and does not store such data in its systems.
2.5. The data received during registration and authentication is used solely for:
- creating and maintaining the user’s account;
- providing access to the features of the Application;
- identifying the user in the system;
- ensuring the security of the account.
2.6. The Company does not process biometric data, geolocation data or other special categories of personal data in the course of registration and authentication.
2.7. All actions carried out in the Application using the user’s account are deemed to have been carried out by the user themselves, unless proven otherwise in accordance with the law.
3.CATEGORIES OF PERSONAL DATA
The Company processes users’ personal data to the extent necessary for the functioning of the Application, the provision of services and the personalization of content.
3.1. User data (parents / guardians)
The user’s personal data may include:
3.1.1. Identification and contact data:
- email address (email);
- user’s name (provided optionally).
3.1.2. Account data:
- interface language;
- system account identifiers;
- account status.
3.1.3. Data related to use of the service:
- subscription information (status, pricing plan, payment dates, activation history);
- information about access to the features of the application.
3.2. Data about the child (entered voluntarily by the user)
Data about the child that may be processed in the Application includes:
- the child’s name (at the user’s discretion);
- date of birth and/or age;
- sex (at the user’s discretion);
- information about foods introduced;
- data on dietary restrictions or particular features of the diet;
- notes on reactions to foods;
- food tracking data;
- other information that the user voluntarily enters within the features of the Application.
3.2.1. The Company does not independently collect data about children beyond the information voluntarily provided by the user.
3.3. General provisions on categories of data
3.3.1. The Company does not process special categories of personal data within the meaning of the law (in particular biometric data, precise geolocation data, racial or ethnic origin, political views, religious beliefs, etc.).
3.3.2. The volume of personal data is limited by the principle of minimum sufficiency and corresponds to the purposes of the functioning of the Application.
4.TECHNICAL AND AUTOMATICALLY COLLECTED DATA
4.1. When you use the App, the Company may automatically collect and process technical information needed to ensure the service works correctly, securely and stably.
4.2. Technical and automatically collected data may include:
- the user’s IP address (at the server infrastructure level);
- technical server access logs (server logs);
- device type and model;
- operating system and its version;
- App version;
- the push device token needed to send push notifications;
- technical device identifiers used for the correct operation of the App.
4.3. The App:
- does not collect the user’s precise geolocation (GPS);
- does not use cookies (as a mobile app);
- does not carry out advertising profiling of users;
- does not carry out behavioral advertising tracking.
4.4. Technical identifiers and automatically collected data are used solely for the following purposes:
- ensuring the App functions;
- maintaining technical stability;
- detecting and fixing errors;
- performance analytics;
- protection against abuse and unauthorized access.
4.5. The processing of technical data is not aimed at identifying the user beyond the operation of their account.
5.PURPOSE OF PERSONAL DATA PROCESSING
5.1. The Company processes users’ personal data solely for specified, lawful and justified purposes necessary for the App to function and for services to be provided.
5.2. Personal data is processed for the purpose of:
- registering the user and creating an account;
- authorizing and identifying the user in the system;
- providing access to the App’s features;
- providing the services offered by the app’s features;
- personalizing content, recommendations and the interface;
- adapting information materials to the data entered;
- enabling the subscription and access to paid features;
- processing payments and managing subscriptions (through third-party payment services);
- technical support for users;
- communicating with users on matters relating to the operation of the service;
- sending service and information messages;
- improving the quality of the service and developing the App’s features;
- analytics of App usage;
- ensuring information security;
- complying with the requirements of the applicable legislation of Ukraine.
5.3. All purposes of personal data processing are proportionate, necessary and directly related to the functioning of the App.
6.ANALYTICS AND TECHNICAL SERVICES
6.1. To ensure the App runs stably, to analyze its performance and to improve its features, the Company uses third-party technical and analytics services.
6.2. The App integrates the SDKs of Google Firebase services, in particular for:
- analytics of app usage;
- monitoring technical stability;
- detecting and handling errors (Crashlytics);
- analyzing performance and load.
6.3. The data processed through these services is exclusively technical and analytical in nature and is used only for:
- improving the App’s functionality;
- optimizing the user experience;
- increasing the stability of the service;
- fixing technical failures and errors.
6.4. The Company:
- does not use third-party services for advertising profiling of users;
- does not carry out behavioral marketing tracking;
- does not share analytics data for advertising purposes;
- does not use data to build advertising profiles.
6.5. Analytics and technical data is processed in anonymized or aggregated form, to the extent necessary to achieve the purposes set out in this Policy.
6.6. Data processing through analytics services is carried out in line with the principles of confidentiality, data minimization and security, in accordance with the applicable legislation of Ukraine.
7.PUSH NOTIFICATIONS
7.1. The App may send users push notifications to inform them about events relating to the operation of the service and the use of the App.
7.2. Push notifications may include, in particular:
- information messages about updates to the App’s features;
- service messages relating to the operation of the account;
- reminders relating to the use of the app’s features;
- messages needed to ensure the service works correctly.
7.3. The user has the right to opt out of receiving push notifications at any time by changing the settings on their mobile device.
7.5. Turning off push notifications may affect the service information you receive about the operation of the App and your account.
8.EMAIL COMMUNICATION
8.1. The user’s email address is used by the Company to send messages relating to the operation of the App and the servicing of the account.
8.2. Email messages may include, in particular:
- service messages (registration, account confirmation, access recovery, password change);
- messages about the subscription, payments and account status;
- information messages about the operation of the service;
- messages about technical changes or updates to the App.
8.3. Marketing, advertising or promotional mailings are sent solely with the user’s prior consent.
8.4. The user has the right to opt out of receiving marketing or advertising emails at any time by:
- using the relevant unsubscribe link in the email; or
- contacting the support service email address.
8.5. Opting out of marketing mailings does not affect the receipt of service and mandatory informational messages necessary for the functioning of the Application and the servicing of the account.
9. TRANSFER OF DATA TO THIRD PARTIES
9.1. General principle. The Company ensures the confidentiality of the User’s personal data and does not transfer it to third parties, except in the cases specified by this Policy and by the legislation of Ukraine.
9.2. Categories of recipients. Users’ data may be transferred to third parties solely for the purpose of ensuring the operation of the Application, in particular to the following categories of recipients:
- Hosting providers and infrastructure suppliers (for hosting the server side, databases and ensuring the availability of the service).
- Payment services / distribution platforms (for making and administering payments): Apple App Store and/or Google Play (as well as the payment mechanisms associated with them).
- Analytics and technical services (for usage analytics, stability and error processing — for example, Firebase/Crashlytics).
- Email services (for sending service and informational messages, as well as marketing ones — only with the User’s consent).
9.3. Grounds for transfer. Transfer of data to third parties may be carried out:
- if this is necessary for the performance of the agreement with the User (for example, transfer of data to payment systems in order to make a payment to provide technical support, analytics and improvement of the Application’s functionality (subject to security and confidentiality measures);
- in the event of compliance with the requirements of the legislation of Ukraine or with the lawful requests of authorized bodies.
9.4. Principles of transfer and limitations.
- We transfer only the minimum amount of data necessary to achieve the relevant purpose.
- Transfer to service providers is carried out, as a rule, on the basis of agreements and/or terms that provide for confidentiality and data protection requirements.
- Apple and Google (within the App Store/Google Play and “Sign in with Apple”/Google account) may process certain data as independent controllers in accordance with their own policies; the Company does not control such processing outside the functionality of the Application.
10.DATA STORAGE
10.1. Place of storage. Users’ personal data is stored in a database hosted on Amazon Web Services (AWS) servers.
10.2. Access control. Access to personal data is limited and controlled: it is held only by authorized employees and/or engaged contractors of the Company to the extent necessary to perform their functions (the “need-to-know” principle). The Company also takes the necessary technical and organizational measures to protect data from unauthorized access, loss, damage or disclosure.
10.3. Purpose-based use. Data is processed and stored solely for purposes related to the functioning of the Application (in particular authorization, personalization, provision of the subscription, technical stability and communication), in accordance with this Policy.
11.DATA PROTECTION
11.1. General approach. The Company implements the necessary technical and organizational measures to protect Users’ personal data from accidental loss, unlawful destruction, unauthorized access, alteration, disclosure or other unlawful use, in compliance with confidentiality and security requirements.
11.2. Technical security measures. Depending on the nature of the data and the risks, the Company applies, in particular, the following measures:
- access control to infrastructure and databases (restriction of access rights);
- journaling (logging) of technical events and monitoring of stability/errors;
- measures to protect against unauthorized access at the level of the server infrastructure;
- data backup to minimize the risks of loss (more details — in section 12).
11.3. Organizational measures.
- Access to personal data is granted only to authorized employees and/or contractors of the Company to the extent necessary to perform their functions.
- The Company maintains internal rules and procedures for working with data and monitors compliance with the confidentiality regime.
11.4. Important disclaimer. No method of storing or transferring data can guarantee absolute security. At the same time, the Company makes reasonable efforts to ensure an appropriate level of data protection, taking into account the nature of the processing and the risks.
12.BACKUP
12.1. Backup procedures. The Company carries out regular backup of data for the purpose of:
- ensuring the continuity of the Application’s operation and restoring the availability of the service in the event of technical failures;
- protecting against loss or damage to data as a result of errors, infrastructure failures or other incidents.
12.2. Access to backups. Access to backups is limited and controlled and is granted only to authorized persons to the extent necessary to perform their functions (the “need-to-know” principle).
12.3. Use of backups. Backups are used solely to restore data and/or to keep the service running, and are not used for any other purposes incompatible with this Policy.
13.ACCOUNT AND DATA DELETION
13.1. Initiating account deletion. The User may initiate deletion of their account within the App’s functionality (where such an option is available) or contact the Company via the contact for personal data protection matters: contact@yummo.app.
13.2. Consequences of account deletion. After an account is deleted:
- access to the account is blocked, and the User loses the ability to use functionality that requires authorization;
- the User’s personal data is deleted or anonymized in accordance with this Policy and within the periods set out in Section 14;
- data stored in backups may remain there temporarily until the next overwrite/update cycle, but is not used for any purposes other than restoring the service, and is subject to deletion/overwriting as part of standard backup procedures (see Section 12).
13.3. Exceptions. The Company may store certain data longer if this is necessary to comply with legal requirements (in particular, regarding financial reporting) or to protect the rights and legitimate interests of the Company (for example, in the event of disputes).
14.DATA RETENTION PERIODS
14.1. General retention period. Personal data is stored for as long as necessary to achieve the processing purposes defined in this Policy, and within the periods established by the legislation of Ukraine.
14.2. After account deletion. If an account is deleted, the User’s personal data is deleted or anonymized within 30 (thirty) calendar days from the date of account deletion.
14.3. Exceptions to the retention periods. The Company may store certain categories of data longer than stated in clause 14.2 if this is necessary:
- to comply with legal requirements (in particular, regarding financial/tax reporting and confirmation of payments);
- to establish, exercise or defend the Company’s legal claims (for example, in the event of disputes);
- in the form of anonymized (de-identified) data — for example, analytical information that does not allow a specific User to be identified.
14.4. Backups. Data may be temporarily stored in backups in accordance with backup procedures (see Section 12) and is deleted/overwritten as part of standard backup cycles.
15.USER RIGHTS
15.1. General rights. The User has rights in relation to their personal data under the legislation of Ukraine, in particular the right:
- to receive information about the processing of their personal data and to access it;
- to request correction of inaccurate or outdated data;
- to request deletion of personal data in the cases provided for by law and by this Policy;
- to request restriction of the processing of personal data in the cases provided for by law;
- to withdraw consent to data processing — in cases where the processing is based on consent (withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal);
- to opt out of marketing messages at any time (mailings are sent only with prior consent).
15.2. How to exercise these rights. To exercise their rights, the User may contact the Company via the contact for personal data protection matters: contact@yummo.app (see Section 19).
15.3. Identifying the request. To protect data, the Company may ask for additional information to confirm the identity of the person making the request and/or that the request relates to the relevant account.
15.4. Managing communications.
- The User may not be able to opt out of service email messages (for example, about registration, security or payments), as they are necessary to provide the service.
- The User may opt out of marketing email mailings at any time (via the instructions in the email or by contacting the Company).
- Push notifications can be turned off in the device settings (see Section 7).
16.PROCESSING OF CHILDREN’S DATA
16.1. Who enters the child’s data. The App is intended for use by parents/the mother/other legal representatives (guardians). Data about the child is entered directly by the User.
16.2. Voluntary nature and purposes. Data about the child (in particular, name, date of birth/age, sex, foods introduced, dietary restrictions, notes on reactions to foods, and food tracking data) is entered voluntarily and is used solely to personalize the functionality and content of the App (for example, to generate recommendations and display information in line with the parameters entered).
16.3. Responsibility for accuracy. The User confirms and agrees that they have the proper authority as the child’s legal representative and are responsible for the accuracy and currency of the data they enter about the child.
16.4. No commercial exploitation. The Company does not commercially exploit children’s data, does not create advertising profiles, and does not carry out behavioral tracking of children for targeted advertising.
17.INTERNATIONAL DATA TRANSFERS (FUTURE-PROOF)
17.1. Possibility of processing outside Ukraine. Given the use of cloud infrastructure and technical/analytics services, Users’ personal data may be processed (stored and/or transferred) outside Ukraine — solely to the extent necessary to keep the Application running.
17.2. Safeguards for an adequate level of protection. In the event of a cross-border transfer (international processing), the Company takes measures to ensure an adequate level of protection of personal data, in particular it:
- transfers data only where there are grounds provided for by law and by this Policy;
- where possible, concludes agreements/terms with service providers that set out confidentiality and security obligations;
- applies technical and organizational data protection measures in line with this Policy and internal procedures.
17.3. Link to acceptance of the terms. By using the Application, the User confirms that they have read this Policy and agree to the terms of personal data processing, including the possibility of cross-border processing within the limits set by this Policy.
18.CHANGES TO THE PRIVACY POLICY
18.1. Right to amend the document. The Company has the right to change or supplement this Privacy Policy from time to time, or to issue it in a new version.
18.2. How Users are notified. The Company may notify the User of changes to the Privacy Policy, in particular by:
- push notifications in the Application;
- a notice in the profile/interface of the Application;
- sending a message to the email address provided by the User;
- any other method the Company considers sufficient.
18.3. Effective date. A new version of the Privacy Policy takes effect from the moment it is published in the Application and/or on the Company’s website, unless the relevant version expressly states otherwise.
18.4. Acceptance of changes. Continued use of the Application after a new version of the Privacy Policy takes effect means that the User has read the updates and agrees to them.
19.CONTACT FOR THE RESPONSIBLE PERSON (DATA PROTECTION CONTACT / DPO)
19.1. Contact for personal data protection matters (DPO / Data Protection Contact):
contact@yummo.app
19.2. Official communication channel with the Company (general inquiries/support):
hello@yummoapp.com