Privacy policy

Preface

With this privacy policy, we inform you or the user (m/f/d) in particular about the nature, scope and purpose of the processing of personal data (hereinafter referred to as “data”) when installing and using the app MyBuddyGuard ©.

At the end you will find information about the status and changes of the privacy policy.

Please note: You are not obligated to provide us with your personal data (even if this is partially marked as “mandatory” in this statement). However, you may not be able to use our products and services or functionalities may not be available to you or only to a limited extent if you do not provide us with your personal data.

Table of Contents:

Part A: General

  1. person responsible
  2. Terms
  3. Purpose limitation, no aggregation, no user profiles, disclosure to third parties
  4. Legal basis of data processing
  5. Data deletion and storage period
  6. Cooperation with order processors; in particular hosting
  7. Storage in Germany / no transfer of personal data to third countries
  8. Legal obligation to transfer certain data
  9. Data security / Securing of services
  10. Your rights

Part B: App

Part A: General

1. person responsible

The controller for the processing of your personal data within the meaning of Article 4 No. 7 DS-GVO (Basic Data Protection Regulation) is:

HandHelp UG (limited liability)
Sachsendorfer Street 5
03051 Cottbus
Germany
Managing Director: Andreas Jürgen Muchow
Phone: +49 (0) 355 54788905
Fax: +49 (0) 355 86697930
E-Mail: support@my-buddyguard.de

and

App-Sec-Network UG (limited liability)
Gradestrasse 36
12347 Berlin
Germany
Managing Director: Andreas Jürgen Muchow
Phone: +49 (0) 3022321574
Fax: +49 (0) 3022321537
E-Mail: support@my-buddyguard.de

2. terms

This data protection declaration is based on the following definitions (cf. Art. 4 DS-GVO):

  • “Personal data” (Art. 4 No. 1 DS-GVO) means any information relating to an identified or identifiable natural person (“data subject”).
  •  “Processing” (Art. 4 No. 2 DS-GVO) means any operation which involves the handling of personal data, whether or not by automated (i.e. technology-based) means.
  •  “Controller” (Art. 4 No. 7 DS-GVO) means the natural or legal person, entity or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
  •  “Third party” (Art. 4 No. 10 DS-GVO) means any natural or legal person, entity or other body other than the data subject, the controller, the processor and the persons who are authorized to process the personal data under the direct responsibility of the controller or processor.
  •  “Processor” (Art. 4 No. 8 DS-GVO) means a natural or legal person, entity or other body that processes personal data on behalf of the controller, in particular in accordance with the controller’s instructions (e.g. IT service provider). In terms of data protection law, a processor is not a third party.
  • “Consent” (Art. 4 No. 11 DS-GVO) of the data subject means any freely given indication of intention for the specific case, in an informed manner and unambiguously in the form of a statement or other unambiguous affirmative act by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.

3. purpose limitation, no consolidation, no user profiles, disclosure to third parties

Data collected by us will only be used for its intended purpose as described in this privacy policy. Processing of your personal data for purposes other than those described will only be carried out if a legal regulation permits this or if you have consented to the changed purpose of the data processing.

In the event of further processing for purposes other than those for which the data was originally collected, we will inform you about these other purposes prior to further processing and provide you with all other relevant information.

We do not merge different sets of data for different purposes at any time. We do not use your data for automated decision-making processes and do not create usage profiles of our users.

We do not share personal data with third parties, except as described in this Privacy Policy and as necessary to achieve a legitimate purpose stated herein, e.g. when triggering an emergency call with activated emergency call centers.

4. Legal basis for data processing

In principle, any processing of personal data is prohibited by law and only permitted if the data processing is covered by a justification.

In the following, we specify the legal grounds we use. For the processing operations we carry out, we indicate in Part B the applicable legal basis in each case. A processing operation may also be based on several legal bases.

  • Art. 6 (1) p. 1 lit. a DS-GVO with regard to health data, if applicable in conjunction with Art. 9 (2) lit. a DS-GVO (“consent”): When the data subject has voluntarily, in an informed manner and unambiguously indicated by a statement or other unambiguous affirmative act that he or she consents to the processing of personal data relating to him or her for one or more specific purposes;
  • Art. 6 (1) p. 1 lit. b DS-GVO: If the processing is necessary for the performance of a contract to which the data subject is a party or for the performance of pre-contractual measures taken at the data subject’s request;
  • Art. 6 (1) p. 1 lit. c DS-GVO: If the processing is necessary for compliance with a legal obligation to which the controller is subject (e.g., a legal obligation to keep records);
  • Art. 6 (1) p. 1 lit. f DS-GVO (“Legitimate Interests”): If the processing is necessary to protect legitimate (in particular legal or economic) interests of the controller or a third party, unless the conflicting interests or rights of the data subject prevail (in particular if the data subject is a minor).

5. data deletion and storage period

In Part B, you will find information for each of the processing operations carried out by us as to how long the data will be stored by us and when it will be deleted or blocked. Unless an explicit storage period is specified below, your personal data will be deleted or blocked as soon as the reason for storing it no longer applies.

However, storage may take place beyond the specified time in the event of a (threatened) legal dispute with you or if storage is provided for by legal regulations to which we are subject as the responsible party. According to legal requirements in Germany, the storage takes place in particular for 10 years according to §§ 147 Abs. 1 AO, 257 Abs. 1 Nr. 1 und 4, Abs. 4 HGB (books, records, management reports, accounting vouchers, commercial books, documents relevant for taxation, etc.) and 6 years according to § 257 Abs. 1 Nr. 2 und 3, Abs. 4 HGB (commercial letters).

If the storage period prescribed by legal regulations expires, the personal data will be blocked or deleted unless further storage by us is necessary and there is a legal basis for this.

If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. I.e. the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for reasons of commercial or tax law.

6. cooperation with processors; in particular hosting.

We use external domestic service providers to process our business transactions (e.g. for IT, hosting, logistics, telecommunications, sales and marketing). These will only act on our instructions and have been contractually obligated to comply with data protection regulations in accordance with the requirements of Art. 28 DS-GVO.

The hosting services used by us serve to provide the following services: Infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services, which we use for the purpose of operating this online offer.

In doing so, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta data and communication data of customers, interested parties and visitors to our online offers.

Our order processors (service providers) are:

STRATO AG
Pascal Street 10
10587 Berlin
Telephone: (030) 300 146 0
Fax: (030) 886 15 111
E-mail: impressum@strato.de

snafu Society for Interactive Networks mbH
Knesebeckstrasse 59-61
10719 Berlin
Phone: (030) 25430-0
Fax: (030) 25430-101
E-mail: info@snafu.de

retarus GmbH
Global Headquarters
Aschauer Street 30
81549 Munich
Phone: +49 89 5528 1111
Fax: +49 89 5528 1919
E-Mail: marketing@de.retarus.com

CM.com Germany GmbH
German Office
Dr.-Eugen-Schön-Strasse 35
97332 Volkach
Phone: +49(0)9302 657 0 888
E-mail: support.de@cm.com

7. storage in germany / no transfer of personal data to third countries

Your data collected and processed by us is only stored on our servers in Germany. In the context of our business relationships, personal data is processed exclusively within the European Economic Area (EEA).

8. legal obligation to transfer certain data

We may be subject to a specific legal or statutory obligation to provide lawfully processed personal data to third parties, in particular public bodies (Art. 6 para. 1 p. 1 lit. c DS-GVO).

9. data security / securing of services

We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties, taking into account the state of the art, implementation costs and the nature, scope, context and purpose of the processing, as well as the existing risks of a data breach (including its likelihood and impact on the data subject). Our security measures include, for example, the use of high-performance hardware, regular updates, secure passwords and encryption, and backup plans, and are continuously reviewed and improved in line with technological developments.

We will provide you with more detailed information on this upon request, within reason. We cannot disclose precise information about how we and our service providers secure hardware and software in order to avoid the risk of our security concepts being undermined.

10. your rights

You may assert your rights as a data subject regarding your processed personal data at any time by contacting us using the contact details provided in A.1. above.

You have the following rights as a data subject:

  • The right to information (Art. 15 DS-GVO),
  • The right to rectification or erasure (Art. 16, 17 DS-GVO),
  • The right to restriction of processing (Art. 18 DS-GVO),
  • The right to data portability (Art. 20 DS-GVO),
  • The right to object to processing (Art. 21 DS-GVO),
  • The right, in accordance with Art. 7(3) DS-GVO, to revoke your consent given once (even before the DS-GVO came into force, i.e. before 25.5.2018) at any time vis-à-vis us, if you have given such consent. This has the consequence that we may no longer continue the data processing based on this consent for the future. The lawfulness of the data processing carried out on the basis of the consent until the revocation is not affected,
  • The right to complain to a data protection supervisory authority about the processing of your personal data by us in accordance with Art. 77 DS-GVO, such as the data protection supervisory authority responsible for us:
    Data Protection and Information Security Officer:

    Address
    Neumarkt 5
    03046 Cottbus
    Telephone: 0355 612-2126
    E-mail address: datenschutz@cottbus.de (for information on e-mail traffic, see imprint)

Please note that the aforementioned rights are in some cases subject to further requirements (see the aforementioned articles of the GDPR) and may be restricted by other laws, which means that we are not always able to fulfill your request.

Please also note that in the course of the duty to provide information, we are also obliged to verify your identity, so we may need more detailed information from you.

Part B: App

The data collected and processed when you download the app.

When you download our app, certain data required for this purpose (e.g., e-mail address, user name, customer number of the downloading account, the individual device identification number, and the time of the download) are transmitted to the corresponding app store (Apple App Store or Google Play).

We have no influence on the collection and processing of this data, which is carried out exclusively by the app store selected by you. Accordingly, we are not responsible for this collection and processing; the responsibility for this lies solely with the App Store of Google or Apple.

Privacy policy Google: https://policies.google.com/privacy?hl=en&gl=de

Apple privacy policy: https://www.apple.com/legal/privacy/data/en/itunes-store/

Data collected and processed when using the app

Verification of the app

When you first launch the app, you will be asked to verify yourself using your mobile phone number or email address. Details that are mandatory to enter in order to use the app are:

Salutation
First name
Last name
Date of birth
Nationality
E-mail address
Mobile phone number

We collect this information in order to protect the police or fire department / rescue services as well as embassies / consulates / foreign offices from false alarm messages (Art. 6 para. 1 p. 1 lit. c DS-GVO or Art. 6 para. 1 p. 1 lit. f DS-GVO). We reserve the right to block the app from your device in the event of a complaint from the police or fire department / rescue services as well as embassies / consulates / foreign offices due to intentionally false emergency call messages, in order to be able to ensure a smooth operation of the emergency call services.

For more information about the emergency call V for Germany see https://www.gesetze-im-internet.de/notrufv/.

Verification takes place via our partner CM.com Germany GmbH, which acts as our processor.
Other collection and processing when using the app.

Other collection and processing when using the app.

Device information: Access data includes the IP address, device ID, device type, device-specific settings and app settings and app properties, the date and time of the retrieval, time zone the amount of data transferred and the message whether the data exchange was complete, crash of the app, browser type and operating system. This access data is processed to technically enable the operation of the app.

In particular: Use of location data.

Except in the case of an alarm triggering, our app does not collect and process any location data of the app users. This means in particular that the app does not use a so-called location tracker (i.e. a function that reads the location data of your smartphone permanently or at regular intervals and transmits it to the app manufacturer).

However, in order to be able to use the app functions described in more detail below, the processing of location data (strictly limited to the described use) is required in the event of an alarm being triggered.

To use the location data, this function must be activated in your mobile operating system. When using the app for the first time, you will therefore be asked for permission to access the location data. Your confirmation will result in the app having access to your location information in order to be able to help you with your location (emergency location) when an alarm is triggered.

The current location is only transmitted when the alarm is triggered. You can also subsequently specify in the settings of both the Google (Android) and Apple (iOS) operating systems that our app is no longer allowed to receive information about your location. In this case, however, the app will only function to a very limited extent, because access to the location data is necessary in order to be able to send a meaningful alarm message (e.g. to the person you trust).

Personal and health information in the app

In order to provide quick and effective assistance, we give users the option to voluntarily provide additional information in the app. The following is a list of the data that is voluntarily submitted (hereinafter referred to as voluntary) and the data that is mandatory submitted (hereinafter referred to as mandatory):

  • Time of emergency / date & time (mandatory).
  • Location of the position / location via GPS, GSM, WLAN (mandatory)
  • Type of emergency / what happened (voluntary)
  • How many people are affected (voluntary)
  • Mobile phone number (mandatory)
  • E-mail address (mandatory)
  • Salutation (mandatory)
  • First name (mandatory)
  • Last name (mandatory)
  • App version (required)
  • Battery level (mandatory)
  • Emergency call recording (photo and sound documentation) (voluntary)
  • Video chat address (voluntary)
  • Home address (voluntary)
  • Work address (voluntary)
  • Vacation/foreign address (voluntary)
  • Deposit of door key / door code (voluntary)
  • Personal preferences for emergency call (voluntary)
  • Basic diseases (voluntary)
  • Restrictions / disabilities (voluntary)
  • Other obstacles (voluntary)
  • Important medications (voluntary)
  • Blood group (voluntary)
  • Rhesus factor (voluntary)
  • Health insurance (voluntary)
  • Allergies (voluntary)
  • Body size (voluntary)
  • Body weight (voluntary)
  • Hearing passport (voluntary)
  • Spectacle wearer (voluntary)
  • Living will (voluntary)
  • Organ donor card (voluntary)
  • Implants (voluntary)
  • Degree of care (voluntary)
  • Pregnancy (voluntary)
  • Other individual personal information (voluntary)

This information remains stored on the end device (smartphone / tablet / wearable) as long as no emergency call or test alarm is executed and can be protected from third parties by entering a password. Only in the event of an emergency call / test alarm will this information be transmitted to the user’s stored and activated helper network as desired.

Our app is delivered without activated emergency call centers and without trusted third parties. By selecting the emergency call centers and by selecting his trusted third parties, the user expressly agrees that information that he has stored in the app and information resulting from the emergency call will be forwarded to the police or fire department / rescue services and abroad to embassies / consulates / foreign offices (foreign missions) and his trusted third parties.

The information is transmitted individually according to the user’s wishes.

Transmission channels

The following transmission paths are possible and can be configured in the app:

  • Via SMS to trusted third parties & user
  • Via e-mail to trusted third parties & users
  • Via call to emergency call centers (worldwide)
  • Via e-mail to emergency call centers
  • Via fax to emergency call centers
  • Via voice SMS to emergency call centers
  • Via video telephony to trusted third parties
  • Via chat to trusted third parties

Furthermore, the PSAPs have the possibility to contact the user via phone call, SMS, chat and videotelephony.

Die folgenden Angaben werden auf folgende Weise an die vom Nutzer gewünschten Stellen übermittelt:

Test alarm

Via direct encrypted connection to the server of Strato AG and snafu Gesellschaft für interaktive Netzwerke mbH

  • Time / Date
  • Position / Location
  • Type of emergency call / What happened
  • How many people are affected
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)
  • Video chat address
  • Home address
  • Work address
  • Vacation/foreign address
  • Deposit of door key / door code
  • Personal preferences for emergency call
  • Underlying diseases
  • Restrictions / Disabilities
  • Other obstacles
  • Important medications
  • Blood group
  • Rh factor
  • Health insurance
  • Allergies
  • Body size
  • Body weight
  • Hearing passport
  • Spectacle wearer
  • Living will
  • Organ donor card
  • Implants
  • Degree of care
  • Pregnant
  • Other individual personal information

Information that is transmitted to deposited trusted persons:

Via SMS to trusted persons / first responders:

  • Mobile phone number
  • Position / location
  • Time / date

Via e-mail to trusted third parties / first responders:

  • Time / Date
  • Position / Location
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)

Information that will be sent to the user:

Via SMS to user:

  • Mobile phone number
  • Position / location
  • Time / date

Via e-mail to user:

  • Time / Date
  • Position / Location
  • Type of emergency call / What happened
  • How many people are affected
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)
  • Home address
  • Work address
  • Vacation/foreign address
  • Deposit of door key / door code
  • Personal preferences for emergency call
  • Underlying diseases
  • Restrictions / Disabilities
  • Other obstacles
  • Important medications
  • Blood group
  • Rh factor
  • Health insurance
  • Allergies
  • Body size
  • Body weight
  • Hearing passport
  • Spectacle wearer
  • Living will
  • Organ donor card
  • Implants
  • Degree of care
  • Pregnant
  • Other individual personal information

Via chat program:

  • Contact
  • Position / Location
  • Time / Date
  • Video chat address

The emergency call centers are not informed / alerted in case of a test alarm!

In case of an emergency call (as a self-affected person)

The following data will be sent via encrypted connection to the server of Strato AG and snafu Gesellschaft für interaktive Netzwerke mbH. There is also an encrypted transmission to retarus AG, which converts the emergency protocol into a PDF – fax, as well as forwarding an e-mail to the services of the police and / or fire / rescue services and optionally to sign language interpreter centers. Transmitted information includes:

  • Time / Date
  • Position / location
  • Type of emergency call / What happened
  • How many people are affected
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)
  • Home address
  • Work address
  • Vacation/foreign address
  • Deposit of door key / door code
  • Personal preferences for emergency call
  • Underlying diseases
  • Restrictions / Disabilities
  • Other obstacles
  • Important medications
  • Blood group
  • Rh factor
  • Health insurance
  • Allergies
  • Body size
  • Body weight
  • Hearing passport
  • Spectacle wearer
  • Living will
  • Organ donor card
  • Implants
  • Degree of care
  • Pregnant
  • Other individual personal information

Information transmitted to trusted third parties

Via SMS to trusted third parties:

  • Mobile phone number
  • How many people are involved
  • Type of emergency call / What has happened
  • Position / Location
  • Time / Date

Via e-mail to trusted persons:

  • Time / Date
  • Position / Location
  • Type of emergency call / What has happened
  • How many people are affected
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)

Data transmitted to the user:

Via e-mail:

  • Time / Date
  • Position / Location
  • Type of emergency call
  • How many people are involved
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)
  • Home address
  • Work address
  • Vacation/foreign address
  • Deposit of door key / door code
  • Personal preferences for emergency call
  • Underlying diseases
  • Restrictions / Disabilities
  • Other obstacles
  • Important medications
  • Blood group
  • Rh factor
  • Health insurance
  • Allergies
  • Body size
  • Body weight
  • Hearing passport
  • Spectacle wearer
  • Living will
  • Organ donor card
  • Implants
  • Degree of care
  • Pregnant
  • Other individual personal information

Via chat program:

  • Contact
  • Position / Location
  • Video chat address

In case of an emergency call (as a witness)

The data described below is sent via encrypted connection to the server of Strato AG and snafu Gesellschaft für interaktive Netzwerke mbH. There is also an encrypted transmission to retarus AG, which converts the emergency protocol into a PDF – fax as well as forwarding an e-mail to the services of the police and / or rescue services. Transmitted data includes:

  • Time / date
  • Position / location
  • Type of emergency call / What happened
  • How many people are involved
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)
  • Home address
  • Work address
  • Vacation/abroad address

Information sent to trusted third parties

Via SMS to trusted third parties:

  • Mobile phone number
  • How many people are affected
  • Type of emergency call / What has happened
  • Position / Location
  • Time / Date

Via e-mail to trusted persons:

  • Time / Date
  • Position / Location
  • Type of emergency call / What has happened
  • How many people are affected
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)

Data that will be transmitted to the user:

Via email:

  • Time / Date
  • Position / location
  • Type of emergency call
  • How many people are involved
  • Mobile phone number
  • E-mail address
  • Salutation
  • First name
  • Last name
  • Video chat address
  • App version
  • Battery status
  • Emergency call recording (photo and sound documentation)
  • Home address
  • Work address
  • Vacation/foreign address

Via chat program:

  • Contact person
  • Position / Location
  • Video chat address

Legal basis

We generally collect and process data via the app because this is necessary for the fulfillment of the contract between you and us (Art. 6 (1) lit. b DS-GVO), unless a specific legal basis is mentioned above.

Furthermore, we collect and process this data if this is necessary for the functionality of the app (Art. 6 para. 1 lit. f DS-GVO).

We process your voluntarily deposited health data on the basis of your consent (Art. 6 (1) p. 1 lit. a DS-GVO in conjunction with Art. 9 (2) lit. a DS-GVO).

Termination / transmission / storage / deletion periods

An emergency call or a test alarm, if executed in the app, can be canceled within a visible expiring countdown by clicking on the large logo button. If the emergency call is canceled, no data will be transmitted. In case the user uses the Bluetooth emergency button (MyBuddyGuard Button), once a transmission has been started, it cannot be canceled. In case of an accidentally triggered emergency call, the user should immediately inform the police or fire / rescue services.

The data transmitted to us will not be further analyzed, sold or used in any way. They are used exclusively for the purpose of fast and effective help by the authorities responsible for this.

If we do not receive a request to keep this data, your data will be automatically deleted as follows:

Data from test emergency calls – 14 days
Data from emergency calls – 90 days

All emergency call data is stored under an individually generated link with password protection on a secure server of snafu Gesellschaft für interaktive Netzwerke mbH. The servers are protected against unauthorized access by state-of-the-art software and hardware.

Status / Changes to the data protection declaration

In the context of the further development of data protection law as well as technological or organizational changes, our data protection statement is regularly reviewed to determine whether it needs to be adapted or supplemented. In each case, the data protection declaration published on this website applies.

This data protection declaration has the status: June 2022

With the assistance / preparation of the data protection statement: Attorney Thorsten Reh (MEDIAS REHS)

Danke

Wir informieren dich, sobald der MyBuddyGuard verfügbar ist.