PRIVACY POLICY - KIDOOMAP

Mobile Application for Families

Effective Date: January 23, 2025
Last Updated: January 23, 2025
Version: 1.0.0

1. DATA CONTROLLER

Controller Information:

Floriano Fraccastoro
Via San Marco 28/a, 37138 Verona (VR), Italy
Tax Code: FRCFRN89M18G482Z
Email: flodev89@gmail.com

This Privacy Policy explains how we collect, use, and protect your personal data when you use the KidooMap mobile application.

2. DATA COLLECTION

2.1 Personal Data We Collect

  • Account Information: Username, email address, profile picture
  • Location Data: GPS coordinates when you enable location services
  • User Content: Reviews, photos, place submissions, comments
  • Device Information: Device type, operating system, app version
  • Usage Data: App interactions, search queries, preferences
  • Payment Information: Subscription details (processed by App Store/Google Play)

2.2 Automatic Data Collection

We automatically collect certain information when you use the App:
  • Log data (IP address, access times, pages viewed)
  • Crash reports and performance data
  • Analytics data to improve the service

3. DATA PROCESSING PURPOSES

3.1 Primary Purposes

  • Provide and maintain the KidooMap service
  • Process user registrations and manage accounts
  • Enable location-based services and recommendations
  • Moderate and publish user-generated content
  • Process premium subscriptions and payments
  • Send important service notifications

3.2 Secondary Purposes

  • Improve app functionality and user experience
  • Analyze usage patterns and trends
  • Develop new features and services
  • Ensure app security and prevent fraud
  • Comply with legal obligations

4. LEGAL BASIS

4.1 Consent

We process your data based on your explicit consent for:
  • Location services
  • Marketing communications (if applicable)
  • Analytics and tracking

4.2 Contract Performance

We process data necessary to provide the service you requested:
  • Account management
  • Service delivery
  • Payment processing

4.3 Legitimate Interest

We process data for our legitimate interests in:
  • Improving our services
  • Ensuring security
  • Preventing fraud
  • Legal compliance

5. DATA RETENTION

5.1 Retention Periods

  • Account Data: Until account deletion or 3 years of inactivity
  • User Content: Until account deletion or content removal
  • Location Data: 30 days from collection
  • Log Data: 12 months
  • Analytics Data: 24 months
  • Payment Data: As required by law (typically 7 years)

5.2 Data Deletion

When you delete your account or request data deletion, we will:
  • Remove your personal data within 30 days
  • Anonymize or delete your user-generated content
  • Cancel any active subscriptions
  • Provide confirmation of deletion

6. DATA SHARING

6.1 Third-Party Services

We may share data with trusted third-party services:
  • App Stores: Apple App Store and Google Play for payments
  • Analytics: Google Analytics for usage statistics
  • Cloud Services: AWS for data storage and hosting
  • Maps Services: Google Maps for location features

6.2 Legal Requirements

We may disclose your data if required by law or to:
  • Comply with legal obligations
  • Protect our rights and safety
  • Prevent fraud or security threats
  • Respond to government requests

6.3 Business Transfers

In case of merger, acquisition, or sale of assets, your data may be transferred to the new entity. You will be notified of any such changes.

7. USER RIGHTS

7.1 Your Rights Under GDPR

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a structured format
  • Objection: Object to certain processing activities
  • Restriction: Limit how we process your data
  • Withdrawal: Withdraw consent at any time

7.2 How to Exercise Your Rights

To exercise your rights, contact us at flodev89@gmail.com. We will respond within 30 days and may request additional information to verify your identity.

8. SECURITY MEASURES

8.1 Data Protection

  • Encryption of data in transit and at rest
  • Secure authentication and access controls
  • Regular security audits and updates
  • Employee training on data protection
  • Incident response procedures

8.2 Data Breach Response

In case of a data breach, we will:
  • Notify affected users within 72 hours
  • Report to relevant authorities as required
  • Take immediate steps to contain the breach
  • Investigate and implement preventive measures

9. COOKIES AND TRACKING

9.1 Types of Cookies

  • Essential: Required for app functionality
  • Analytics: Help us understand usage patterns
  • Preferences: Remember your settings
  • Marketing: Show relevant content (if applicable)

9.2 Cookie Management

You can control cookies through your device settings or browser preferences. Disabling certain cookies may affect app functionality.

10. CHILDREN'S PRIVACY

10.1 Age Requirements

KidooMap is designed for families but requires users to be at least 13 years old. We do not knowingly collect data from children under 13.

10.2 Parental Consent

For users between 13 and 16 years old, we require parental consent. Parents can contact us to review, modify, or delete their child's data.

11. INTERNATIONAL TRANSFERS

11.1 Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through:
  • Adequacy decisions by the European Commission
  • Standard contractual clauses
  • Certification schemes
  • Other approved transfer mechanisms

12. CHANGES TO POLICY

12.1 Policy Updates

We may update this Privacy Policy from time to time. Significant changes will be notified through the App or email.

12.2 Continued Use

Continued use of the App after policy changes constitutes acceptance of the new Privacy Policy.

13. CONTACT INFORMATION

For privacy-related questions or requests:

Email: flodev89@gmail.com
Address: Via San Marco 28/a, 37138 Verona (VR), Italy

Data Protection Officer: Floriano Fraccastoro
Response Time: We will respond to privacy requests within 30 days.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).