2. Data Protection Officer
For any questions or concerns regarding the processing of your personal data, you may contact our Data Protection Officer at:
- Email: [email protected]
- Subject line: "Data Protection Inquiry"
3. Data Categories Collected
We collect and process the following categories of personal data:
Account Information:
- Name and email address
- Profile picture (if provided)
- Authentication credentials (encrypted)
- Account preferences and settings
Aquarium Data:
- Aquarium profiles (names, descriptions, images)
- Water parameters and chemistry records
- Equipment, plants, and animal inventory
- Maintenance schedules and notes
- Dosing and event logs
Usage Data:
- Pages visited and features used
- Interaction patterns and session duration
- Error logs and performance metrics
Device Information:
- Browser type and version
- Operating system
- IP address
- Device identifiers
4. Legal Basis for Processing
We process your personal data based on the following legal grounds (Article 6 GDPR):
- Consent (Art. 6(1)(a) GDPR): For optional communications such as marketing emails, newsletters, and non-essential cookies. You may withdraw your consent at any time.
- Performance of Contract (Art. 6(1)(b) GDPR): To provide the Aqua Diary application services, manage your account, and process your aquarium data.
- Legitimate Interest (Art. 6(1)(f) GDPR): For application security, fraud prevention, service improvement, and analytics to enhance user experience.
5. Data Recipients
Your personal data may be shared with the following categories of recipients:
- Hosting Providers: Cloud infrastructure services that store and process data on our behalf
- Analytics Services: Tools used to understand application usage and improve our services
- Authentication Providers: Third-party OAuth providers (e.g., Google, Facebook) if you choose social login
We do not sell your personal data to any third parties. All data processors are bound by data processing agreements ensuring GDPR compliance.
6. Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account data: Retained for the duration of your active account, plus 30 days after account deletion
- Aquarium data: Retained for the duration of your active account
- Usage data: Retained for up to 12 months
- Server logs: Retained for up to 90 days
You may request deletion of your data at any time through the Data Deletion page or by contacting us at [email protected].
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): You may request a copy of all personal data we hold about you
- Right to Rectification (Art. 16): You may request correction of inaccurate personal data
- Right to Erasure (Art. 17): You may request deletion of your personal data ("right to be forgotten")
- Right to Restriction (Art. 18): You may request restriction of processing under certain conditions
- Right to Data Portability (Art. 20): You may request your data in a structured, machine-readable format
- Right to Object (Art. 21): You may object to the processing of your personal data based on legitimate interests
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
8. Right to Lodge a Complaint
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. In Poland, the supervisory authority is:
- UrzΔ
d Ochrony Danych Osobowych (UODO) - The President of the Personal Data Protection Office
- ul. Stawki 2, 00-193 Warszawa, Poland
- Website: https://uodo.gov.pl
9. International Data Transfers
Your personal data is primarily processed within the European Union / European Economic Area (EU/EEA). In cases where data is transferred to countries outside the EU/EEA, we ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission for the recipient country
- Binding Corporate Rules where applicable
10. Policy Changes and Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When material changes are made, we will notify users through their account homepage (aqua-diary.com/my) and update the "Last updated" date at the top of this policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
11. Contact Information
If you have any questions about this Privacy Policy or our data processing practices, please contact us at [email protected].
By using Aqua Diary, you acknowledge that you have read and understood this Privacy Policy.