SOCIALMAMA PRIVACY, COOKIES AND TECHNOLOGIES POLICY
Current version: Version 1.0 · Effective from July 29, 2026
1. Scope of the Privacy Policy
1.1. This Privacy, Cookies and Technologies Policy (the “Policy”) explains how Lazy Mama Ltd. processes personal data and uses cookies and similar technologies in connection with the SocialMama mobile application, the SocialMama website, the legal portal and the electronic messages we send.
1.2. SocialMama is a mobile application for iOS and Android that helps “Parents”, as defined in the Terms of Service, to discover and connect with other Parents who are nearby and at a similar parenting stage.
1.3. This Policy applies to: creating and managing a profile; use of the Finder; profile photo and profile information; information about pregnancy, children and parenting stage; approximate location; private conversations and the exchange of messages through the chat; posting and interacting with content in Community Buzz; use of Current Status (“Available for walks” / “Just browsing”); push notifications; marketing messages; analytics; reports, blocking and moderation; account deletion; communication with us.
1.4. For the purposes of this Policy, the term “cookies and similar technologies” covers both classic cookies used through an internet browser and technologies with a functionally similar purpose used in the mobile application. These may include local and secure storage, session tokens, notification tokens, analytics identifiers, events transmitted through software tools and development kits (“SDKs”), local cache, the status of system permissions, tracking pixels and tracking links.
1.5. This Policy applies together with: the SocialMama Terms of Service; the Community Guidelines; any additional terms for campaigns, promotions or paid features, if introduced.
1.6. Accepting the Terms of Service does not constitute general consent to all personal data processing operations or to the use of all technologies described in this Policy. Where consent is required, SocialMama requests it separately, for a specifically defined purpose, and provides the ability to withdraw it.
2. Data Controller
2.1. The controller of personal data is: Lazy Mama Ltd., UIC: 208288161, with registered seat and management address and address for official correspondence: Sofia (1715), Studentski district, 102A Nikola Gabrovski St, fl. 5, apt. 9, represented by: Delyana Ivanova Samolova. Contact email for questions relating to personal data: info@socialmama.app. The legal page of our website, where you can find all terms and policies: https://www.socialmama.app/legal. As at the date of this Policy, no data protection officer has been appointed.
2.2. In this Policy, “SocialMama”, “we” or “us” means Lazy Mama Ltd.
3. Brief summary of this Policy
3.1. SocialMama processes data in order to provide the core functions of the application: profile; finding Parents nearby; connecting Parents at a similar parenting stage; chat; the Community Buzz function; safety and moderation.
3.2. We do not sell personal data, we do not use chat data for advertising, we do not use PostHog analytics without consent, we do not send marketing emails without consent, and we do not store exact GPS coordinates. If you allow GPS access, your coordinates are used momentarily on your mobile device only, in order to calculate an approximate area.
3.3. SocialMama uses strictly necessary technologies to provide registration, login, security, maintenance of the user session, saving of selected settings and the delivery of features you have requested. Optional analytics and marketing technologies are used only under the conditions and in the manner described in this Policy.
3.4. Pregnancy information may constitute health data. We process it only for a clearly stated purpose.
3.5. Children may not use SocialMama and may not create profiles. Data about children is provided only by an adult Parent and is limited to approximate age and optional sex.
3.6. Private conversations in SocialMama are not protected by end-to-end encryption. Message content is stored within the technical infrastructure used by SocialMama. Access to it by authorised persons may take place only where necessary for technical support, security, review of a report, moderation, protection of rights or compliance with a legal obligation. The transmission and storage of data are protected by the technical and organisational measures described in this Policy.
3.7. You can manage certain consents and settings, exercise your rights under the GDPR, and request or carry out deletion of your account in the ways described in this Policy. Uninstalling the application does not, by itself, delete your account or the data stored for it.
4. Key concepts
4.1. “Personal data” means any information relating to an identified or identifiable natural person.
4.2. “Processing” means any operation performed on personal data — collection, recording, storage, use, disclosure, erasure and so on.
4.3. “Controller” means the person who determines the purposes and means of the processing of personal data.
4.4. “Processor” means a person who processes personal data on behalf of the controller.
4.5. “Special categories of personal data” means data that benefit from heightened protection, including health data.
4.6. “Health data” means personal data relating to a person’s physical or mental health.
4.7. “Biometric data” means personal data resulting from specific technical processing which allow or confirm the unique identification of a natural person.
4.8. “Cookies and similar technologies” means technologies by which information is stored on the user’s terminal device or by which access is gained to information already stored on it. The term covers both classic internet browser cookies and technologies with a functionally similar purpose used in mobile applications, including local and secure storage, session tokens, notification tokens, analytics identifiers, SDK events, local cache, the status of system permissions, tracking pixels and tracking links. The specific technologies used in connection with SocialMama are described in this Policy.
5. Who may use SocialMama
SocialMama is intended only for persons aged 18 or over who are “Parents” as defined in the Terms of Service. The application is not directed at children. We do not permit the creation of profiles by children or minors. If we establish that a profile has been created by a person under 18, we may delete or restrict the profile. SocialMama may process limited data about children, provided by the Parent, solely for the purposes of connecting with Parents at a similar parenting stage.
6. What data we collect
6.1. Registration and login data
We process: email address; name, if provided through Apple/Google or entered in the profile; Apple/Google identifier, where you use such a login; OTP codes and login logs; date and time of login; IP address; technical device information; session token and other data necessary to maintain the login.
We use this data for: creating a profile; logging into the application; protecting the account; preventing abuse; evidencing acceptance of legal documents.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(f) GDPR — legitimate interest in security and in evidencing actions; Art. 6(1)(c) GDPR, where storage is necessary for a legal obligation.
6.2. Data on acceptance of legal documents and consents
We process: anonymous identifier of the accepting person; the user’s email address; type of document (Terms of Service; Community Guidelines; Privacy Policy); version of the document (Terms of Service; Community Guidelines; Privacy Policy); language version of the document (Terms of Service; Community Guidelines; Privacy, Cookies and Technologies Policy); date and time the registration process started; date and time registration was completed; date and time of acceptance of and consent to each document (Terms of Service and Community Guidelines; Privacy, Cookies and Technologies Policy); IP address and technical browser/application identification (user agent) at the time of the action; registration method used — Apple, Google or email OTP; operating system used; confirmation of access from a mobile device, make and model of the device; separate consents — marketing, analytics, push marketing, future verification, where applicable; withdrawals of consent.
We use this data for: evidencing the contractual relationship; evidencing consents; evidencing withdrawals; complying with legal obligations; defence against legal claims.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(c) GDPR — legal obligations; Art. 6(1)(f) GDPR — legitimate interest in evidencing and protecting rights; Art. 7 GDPR, where the processing relates to demonstrating consent.
6.3. Profile data
We process: name; profile photo; biography; selected application language; pregnancy, counted in months, where relevant to the User; approximate age of each child, stated in years and months, where relevant to the User; date and time the User entered the pregnancy data and the approximate age of each child, if and when such data is entered; biological sex of each child, stated optionally by the Parent; approximate location and its source (GPS/IP); address area (“Narrow area” / “Wide area”); date and time of the update of the approximate location; Current Status (“Available for walks” / “Just browsing”); profile settings (Language; Notifications; Helpful content; consent to data analytics).
We use this data for: creating and displaying a profile; finding mothers nearby; connecting mothers at a similar parenting stage; displaying relevant profiles; safety and trust within the community; providing the core functions of SocialMama.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(f) GDPR — legitimate interest in safety and the prevention of abuse, where applicable.
7. Pregnancy data
7.1. SocialMama requires, as a mandatory condition, that the user be a current or expectant Parent in order to register and use the features of the application. In that case, if you indicate that you are pregnant, SocialMama processes information about the month of the pregnancy.
7.2. We do not require: the exact week of pregnancy; the due date; medical documents; diagnoses; laboratory results; data from Apple HealthKit, Google Fit or other health platforms.
7.3. Pregnancy information is used for: connecting with other pregnant women or mothers at a similar stage; ordering and displaying profiles; providing the core SocialMama functionality relating to parenting stage.
7.4. Pregnancy information may constitute health data.
7.5. Legal basis: Art. 6(1)(b) GDPR — the processing is necessary in order to provide the feature that connects users according to parenting stage.
7.6. If you stop using the application, you may exercise your rights under the GDPR by contacting us at the relevant contact details set out in this Policy. You will be provided with information and a request form for exercising data subject rights.
8. Children’s data
8.1. SocialMama does not create standalone profiles or user accounts for children and does not offer its services directly to children. The information described in this section is provided solely by a registered user in connection with her own profile.
8.2. In order to create and use a SocialMama profile, the user enters information about at least one child born or expected. For a child who has been born, the approximate age is entered, expressed in completed years and months, without stating the exact date of birth. For an expected child, information about the approximate stage of pregnancy is entered, expressed in months. The sex of a child born or expected may be stated optionally. The user may add information about more than one child born or expected.
8.3. Within this functionality, SocialMama neither requires nor provides dedicated fields for entering the child’s name; a personal identification number (EGN) or other identification number; exact date of birth; exact address; the school, nursery or kindergarten attended; medical documents; diagnoses; health data or the child’s medical history. Stating the age in years and months constitutes approximate information and does not require the entry or storage of the exact date of birth. Users should not enter the information listed in this clause in free-text fields, posts or other parts of the profile intended for presenting the child.
8.4. We use information about children born and expected for: establishing and presenting the user’s parenting stage; connecting users who are expecting a child or who have children of a similar age; displaying approximate parenting-stage information in the profile; ordering and suggesting profiles in the Finder according to the applicable criteria; providing the core SocialMama functions for finding and communicating with users at a similar life and parenting stage.
8.5. Legal bases: In so far as the information describes the user’s parenting stage and is necessary for creating a profile and providing the core functions of SocialMama, the processing is based on Art. 6(1)(b) GDPR — taking steps at the user’s request prior to entering into, and performing, the contract for the use of SocialMama. In so far as the information about approximate age and sex constitutes personal data of a child who has been born, the processing is based on Art. 6(1)(f) GDPR — the legitimate interest of SocialMama and its users in enabling users at a similar parenting stage to find and connect with one another. In carrying out this processing, we give priority to the rights and best interests of the child and apply measures to reduce the data to the necessary minimum.
8.6. When you add information about a child who has been born, you confirm that you are that child’s parent or legal representative, or that you are otherwise entitled to provide this information. You undertake not to enter the child’s name, exact date of birth, address, health information or other data by which the child could be directly identified. This confirmation serves an informational and evidentiary function and does not constitute consent as a legal basis for processing by SocialMama.
8.7. We receive information about a child who has been born from the user who enters it in her profile, and not directly from the child. The child, or the child’s parent or legal representative, may request access to, rectification of or erasure of this processing. Before fulfilling the request, SocialMama may carry out appropriate verification of the requester’s identity and authority to represent. In the event of a dispute regarding the user’s right to provide the information, SocialMama may temporarily restrict its visibility or processing until the verification is complete. Information about an expected child is received directly from the user herself and relates to her as the data subject.
If the processing of a child’s data is based on consent and the child is under 14, the consent must be given by the parent exercising parental rights or by the guardian.
8.8. We do not use information about children born or expected for behavioural advertising; for marketing directed at children; for direct contact with a child; for creating a standalone profile of the child’s interests or behaviour; for facial recognition; or for making decisions that produce legal or similarly significant effects for the child.
9. Profile photo
9.1. SocialMama is a community built on trust and real social contact. A profile photo is mandatory for every user of the application. The profile photo is necessary for the purposes of: visual identification; trust between users; limiting fake profiles. Legal basis: Art. 6(1)(b) GDPR — performance of the contract, where the photo is necessary for the feature; Art. 6(1)(f) GDPR — legitimate interest in security and the prevention of abuse, where applicable.
9.2. The profile photo IS NOT USED for: facial recognition; biometric identification; automated identity verification; marketing; behavioural advertising, unless we introduce such a feature in future following separate notice and separate consent where the law requires it.
9.3. An ordinary profile photo is not treated as biometric data unless it is processed by specific technical means for the purpose of unique identification, which we confirm is not currently the case.
10. Future selfie verification and biometric data
As at the date of this Policy, SocialMama does not use Amazon Rekognition, facial recognition, liveness detection and/or any other biometric verification. If we introduce selfie verification, facial comparison, liveness detection or another technology for unique identification in future, this may constitute processing of biometric data. Any such feature will be introduced only after: a prior update of this Policy; a clear explanation in the application; separate explicit consent, where necessary; a risk assessment and appropriate security measures; information about the provider, for example Amazon Rekognition, if used; information as to whether a photo, a biometric template, a similarity score or only the result of the check is stored; retention periods; the availability of an alternative procedure where this is necessary to ensure free choice. Biometric data will not be used for marketing, advertising or incompatible purposes.
11. Location
11.1. Why we use location data
SocialMama was created to help you discover and connect with other Users located near you. For this reason, providing an approximate location is necessary in order to create a profile and to use the core functionalities of the Application, including the Finder.
You do not need to provide SocialMama with your exact address or your exact geographic coordinates. SocialMama’s systems store only an approximate area, represented as a “Grid cell”.
In so far as the approximate location is linked to your profile, it constitutes personal data, notwithstanding that it does not allow your exact address to be determined.
11.2. What the “Grid cell” is
Before your location is sent to SocialMama’s servers, it is converted into a short code designating an approximate cell within a coordinate grid. Depending on the setting you have selected, the cell may be:
- “Narrow area” (approximately precise location) — a cell approximately 150 metres wide. This setting makes it possible to find Users in the immediate vicinity;
- “Wide area” — a cell approximately 1 kilometre wide. With this setting, other Users can find you within a more general area, without receiving the closest distance label, “Very nearby”.
The name “Narrow area” in the Application’s settings means the narrower of the two approximate areas. It does not mean that SocialMama stores or displays your exact address or your exact coordinates.
You may change the selected area at any time using the toggle in the “Settings” section. When you switch to “Wide area”, the stored cell is replaced by the wider cell and the previous, narrower cell is not retained as part of any location history.
When switching from “Wide area” to “Narrow area”, the application requires the address to be entered again (manually or automatically).
11.3. Home location
On registration, you must set a home location. This is the primary approximate location that SocialMama uses by default to show you Users nearby and to display your profile in the corresponding searches of other Users.
The home location may be set: automatically, through your device’s location services; or by manually searching for and selecting an address. You may change your home location at any time using the corresponding function in your profile.
The full selected address is stored solely in the secure storage of your device, for example the iOS Keychain or Android Keystore, and is not stored on SocialMama’s servers. Only the corresponding approximate grid cell is saved in the profile on the server.
11.4. Automatic determination through the device
When you select “Detect My Location” (during registration or from “Edit Home Address” in your profile) or activate “Current Location” (from the “Finder” or from your profile), the device’s operating system may ask for your permission to access your location.
Once permission is granted, the Application: reads the position converted by the device into a grid cell; and sends only the code of the resulting cell to SocialMama.
In this process, the exact coordinates are used momentarily to calculate the approximate area and are not sent to or stored on SocialMama’s servers.
Location access permission is managed through the operating system settings. The permission granted through iOS or Android is not the standalone legal basis on which SocialMama processes the resulting approximate location.
11.5. Manual address entry
When you search for an address manually, the text you enter is sent to the Nominatim service of the OpenStreetMap Foundation, in order to find and display suitable suggestions. Once you select a suggestion, the resulting location is converted into an approximate grid cell.
SocialMama does not store on its servers the text you enter into the search field, nor the full selected address. The provider of the Nominatim service may, however, independently receive technical data necessary to process the query, including the text entered and the IP address from which the query was made. Further information about this provider and the applicable privacy rules is set out in the section of this Policy concerning recipients and external providers.
11.6. Fallback determination of a general area through the internet connection
Where access to the device’s location has not been granted and no other selected location is available, SocialMama may use the ipapi.co service to determine an approximate area on the basis of the IP address of the internet connection.
This determination is approximate and is usually limited to city level or a larger area. The resulting location is always treated as a “Wide area” and does not allow another User to see you with the “Very nearby” label.
SocialMama does not add the IP address to the location data in your profile and does not store it for matching purposes. The provider ipapi.co inevitably receives the IP address in the technical performance of the query and may process certain technical data in accordance with its own privacy rules.
11.7. Current location
In the Finder for mothers, you can switch from “Home Address” to “Current Location”.
While this feature is enabled and you are using the Finder, the Application may update your approximate cell, but no more often than once per hour. The determination is carried out in the same way as with automatic determination through the device: the position is converted into a cell on the device and only the cell code is sent to SocialMama.
SocialMama stores only one active location for each profile. When a new home or current location is determined, the new cell replaces the previous one. SocialMama does not create a history of the places you have visited and does not track your location when the Application is running in the background.
Other Users do not receive information as to whether the distance label displayed for you was calculated on the basis of your home or your current location.
11.8. What information we store
For your active location, SocialMama may store: (1) the code of the approximate grid cell; (2) the manner in which the cell was determined — through the device or through the internet connection; (3) the area you have selected — “Narrow area” or “Wide area”; and (4) the date and time of the last update.
SocialMama does not store in your profile: (1) your exact geographic coordinates; (2) your full address; (3) a list or history of your previous locations; or (4) your routes and movements between different locations.
Every cell received is checked technically and limited to the maximum permitted format and length.
11.9. What we use the approximate location for
SocialMama uses your approximate location for: (1) displaying Users located near you; (2) determining and ordering suitable profiles in the Finder; (3) including your profile in the relevant searches of other Users; (4) calculating a general label for the distance between Users; and (5) protecting the Application and preventing abuse, where the processing is necessary for that purpose.
Location data is not provided to advertising or marketing profiling tools.
11.10. What other Users see
Other Users do not receive access to your grid cell. Matching is carried out on SocialMama’s servers, and the other User is shown only a general distance label, for example:
| Label | General meaning |
|---|---|
| „Very nearby“ | Immediate vicinity, roughly up to a 15-minute walk |
| „Nearby“ | A distance suitable for a longer walk or a short bicycle ride |
| „Close“ | The same general area or town, a short ride away |
| „Same region“ | The same city or its surroundings |
| „Far away“ | Outside the defined wide area |
The “Very nearby” label may be displayed only where both Users are using “Narrow area” determined through the device’s location.
Other Users do not see: (1) a distance in metres or kilometres; (2) an exact position on a map; (3) an address, street or building number; (4) exact coordinates; (5) the grid cell code; or (6) information as to whether you are using a home or a current location.
11.11. Legal bases
SocialMama processes your approximate location on the basis of Art. 6(1)(b) of the General Data Protection Regulation — where the processing is necessary in order to provide the agreed core functionality of finding and connecting with Users nearby.
Where certain data is used to protect the Application, prevent fraud or abuse and ensure the security of Users, the processing may be based on SocialMama’s legitimate interests under Art. 6(1)(f) of the Regulation, following an assessment of the necessity and the balance of the interests concerned.
11.12. Retention period
The active grid cell is stored until:
- it is replaced by a new location;
- you change the selected area (“Narrow area” / “Wide area”); or
- you delete your profile.
On deletion of the profile, the active location data is removed from SocialMama’s active systems. Data may remain for a limited period in secure backups where this is technically necessary, without being used for matching or other operational purposes.
11.13. Your control over location
At any time you may:
- change your home location;
- switch between home and current location;
- select “Narrow area” or “Wide area”;
- withdraw the Application's location access permission through your device settings; and
- delete your profile and the approximate location associated with it.
Where you do not grant access to the device’s location, you can use a manually entered address or, where applicable, approximate determination at city level through the internet connection. In that case, results may be less local and certain functionalities may be limited.
12. Finder and profile recommendations
The Finder displays the profiles of other Parents. In the current version of the application, ordering is based primarily on: approximate location; age of the child/children; stage of motherhood; month of pregnancy, where applicable. Other criteria may be added in future (for example, shared interests). If such a change is made, we will update this Policy where necessary.
The Finder does not make decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. The logic behind suggested profiles is designed to display more relevant profiles, not to evaluate your worth, reliability or personality.
13. Current Status
Current Status is a social availability indicator, where (a) the green status “Available for walks” means that you are open to contact or to meeting, and (b) the red status “Just browsing” means that you prefer only to browse. Current Status is not a location feature. Current Status does not share exact location, address or GPS coordinates.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract.
14. Chat and the data processed
14.1. SocialMama provides 1:1 chat between users. The chat may include: text messages; voice messages; sending photos (.jpeg, .png, .webp, .heic up to 10 MB); technical data about the conversations.
14.2. The following are stored on the server: sender identifiers (sender ID); identifier of the connection created between users (conversation ID); date and time the chat was created; date and time for each message sent; date and time for each message opened and read; date and time for each message edited; date and time for each message deleted in the chat; message delivery status; message read status; number of unread messages; number of unanswered messages; the type (text, audio, photo) and format of the message (corresponding to the type); length of the audio message sent, in minutes and seconds; size of the audio message sent, in MB; size of the photo sent, in MB; technical metadata; data necessary for security and functioning.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(f) GDPR — security, prevention of abuse and protection of rights.
14.3. If you submit a report about a chat and send us a screenshot, text, voice message or description, that content may be reviewed by SocialMama for moderation and safety purposes. Other than as set out in this clause, we do not read the content of the messages sent by you or to you.
14.4. In the event of a request for access to data, we may provide the data we actually hold, including metadata and encrypted data (if any). Upon a valid request from a competent authority, we may provide only the data we actually hold.
15. Community Buzz and public content
15.1. Community Buzz is a community wall for posts, questions, answers, reactions and discussions. Posts and answers are visible to other users, and for that reason you should not publish medical documents; diagnoses; personal identification numbers (EGN); exact addresses; telephone numbers of third parties; photos of other people’s children without permission; sensitive information about other people; information that you do not wish to be visible to other users. If you publish such or similar data, you declare by your actions that you have done so voluntarily and that you understand that the published information becomes visible to other users in accordance with the settings and functionality of the application. SocialMama may remove content that breaches the Community Guidelines, the Terms of Service or the law.
15.2. The data we process includes: posts; answers to posts; reactions; tags; date and time; the author’s profile; moderation data; reports.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(f) GDPR — legitimate interest in moderation, safety and the protection of rights; Art. 9(2)(e) GDPR, where special categories of data have been manifestly made public by the data subject herself; Art. 9(2)(f) GDPR, where the processing is necessary for the establishment, exercise or defence of legal claims.
16. Reporting, blocking and moderation
16.1. At your discretion and by your own choice, you may block another user or you may report: a profile; a profile photo; a post; an answer; a chat; a message; another user’s behaviour. We do not disclose the identity of the reporting user to the reported user where this could endanger rights, security or safety. In the event of serious risk to a child, threats, violence, sexual exploitation, fraud or another serious breach, we may preserve the necessary evidence and notify a competent authority.
16.2. When a report is submitted, we process: identifier of the reporting user; identifier of the reported user; date and time; reason for the report; the reported content; screenshots or descriptions, if provided; technical logs; the moderator’s decision; the actions taken; correspondence relating to any appeal. We use this data for: protecting users; reviewing reports; removing unlawful or inappropriate content; preventing harassment, fraud and abuse; protecting children; protecting rights and legal claims; complying with legal obligations; assisting competent authorities where necessary.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract and the Community Guidelines; Art. 6(1)(f) GDPR — legitimate interest in safety, moderation and the protection of rights; Art. 6(1)(c) GDPR — legal obligation, where applicable; Art. 9(2)(f) GDPR — legal claims, where the report contains special categories of data.
17. Push notifications
17.1. SocialMama may send you push notifications in connection with activities and events in the application, including a new message, interaction with your post, a report or a security action, as well as any other feature for which you have enabled notifications.
17.2. To send push notifications, SocialMama uses the Expo Push Notification Service, which forwards the notification to the corresponding operating system service:
- Firebase Cloud Messaging (FCM) from Google — for Android devices; or
- Apple Push Notification service (APNs) — for iOS devices.
17.3. For this purpose, technical data is processed which may include the device’s push token, type and version of the operating system, identifiers of the application and the notification, date and time of sending, delivery status and technical data about any errors that occur.
17.4. Depending on the type of notification, its content may include a title, a short description of the event that has occurred, a technical identifier necessary to open the relevant screen in the application, and a short excerpt from a message or post.
Where a notification contains an excerpt of user-generated content, that excerpt may in fact reveal personal data, including information about health, pregnancy, the child or other sensitive circumstances, if such information was entered into the message or post. For that reason, you should not include sensitive information in text that you do not wish to be displayed as part of a notification.
17.5. The content of the push notification is transmitted through Expo and, correspondingly, through FCM or APNs. Depending on your device settings, the notification or part of its content may be displayed on the lock screen and be visible to any person with physical access to the device.
SocialMama does not control the way the operating system displays notifications once they have been delivered to the device.
17.6. When notifications are first enabled, the operating system may ask you for system permission to receive them. This permission is a technical condition for the delivery of push notifications and should not automatically be regarded as consent for other processing purposes, including analytics or marketing.
17.7. At any time, you may:
- manage individual notification categories through Settings → Preferences → Notifications in SocialMama, to the extent the application provides that option; and
- allow, limit or switch off the display of notifications through the system settings of your iOS or Android device.
Disabling push notifications does not stop the corresponding information from being displayed inside the application.
17.8. Service push notifications, which are necessary for functioning, security or the use of an expressly requested feature, are distinguished from notifications with advertising or marketing content. Marketing push notifications are sent only if you have made a separate, voluntary choice to receive them, and you may change that choice at any time.
Legal basis: Art. 6(1)(b) GDPR — service notifications necessary for the service; Art. 6(1)(a) GDPR — marketing push notifications, where you have given consent; Art. 6(1)(f) GDPR — security and prevention of abuse.
18. Transactional and service emails
We may send you service emails necessary for the use of SocialMama. These include: OTP codes; registration confirmation; security messages; account notifications; confirmation of account deletion; notices of changes to the Terms of Service; moderation messages; technical messages. These messages are not marketing. Opting out of marketing does not stop service emails.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(c) GDPR — legal obligation, where applicable; Art. 6(1)(f) GDPR — security and evidencing.
19. Electronic messages — service and marketing
19.1. SocialMama may send two main types of electronic message:
- service messages, necessary for the creation and management of the account, security, restoring access, providing a requested feature, notifying you of material changes to the service or complying with a legal obligation; and
- marketing messages, containing news, offers, promotions, campaigns, surveys, recommendations or other information with an advertising or commercial purpose.
19.2. Service messages are not sent on the basis of marketing consent. They may be sent where they are necessary for the performance of the Terms of Service, for the provision of an expressly requested service, for the protection of the security and legitimate interests of SocialMama and users, or for compliance with a legal obligation.
Opting out of marketing messages does not stop the receipt of service messages that are necessary for the use and security of the account.
19.3. Marketing messages by email are sent only if you have made a separate, voluntary choice or have given prior consent to receive them, unless applicable law permits them to be sent on another basis.
Giving marketing consent is not a condition for creating an account or using the core functions of SocialMama.
19.4. When you subscribe to marketing messages, SocialMama may process: name or chosen username; email address; information about consent given, refused or withdrawn; language; date, time, source and method of subscription; selected communication preferences; information about the sending, delivery and technical status of the message; information about engagement with the message — opens, clicks, date and time of the action, IP address, and approximate technical information about the device and email application, to the extent such information is provided by Mailchimp.
This data is collected through tracking pixels and individualised tracking links, which are an integral part of the marketing messages and cannot be switched off separately. If you do not wish this to happen, you may withdraw your consent in accordance with clause 19.6.
19.5. For organising and sending marketing electronic messages, SocialMama uses Mailchimp, provided by The Rocket Science Group LLC, part of Intuit. Mailchimp may process the email address, subscription information, the content and technical parameters of the message sent, as well as data about its delivery and engagement. Information about the provider’s role, the place of processing and the applicable international data transfer mechanisms is set out in this Policy.
19.6. You may withdraw your consent or stop receiving marketing electronic messages at any time through: (a) the unsubscribe link included in every marketing message; (b) the application settings; or (c) sending a request to our contact address. Withdrawal does not affect the lawfulness of processing carried out before it.
19.7. Following unsubscription, SocialMama may retain minimal information in a suppression list, including the email address and the date of unsubscription, in order to ensure that no new marketing messages are sent to that address contrary to the choice you have expressed. This information is not used to re-add you to a marketing list.
Legal basis: Art. 6(1)(a) GDPR — consent; Art. 6(1)(f) GDPR — minimal retention of a suppression/unsubscribe record so that we do not send you marketing after you have opted out.
20. Analytics through PostHog
20.1. SocialMama uses PostHog for product analytics in order to understand how the application is used, which features are useful, where technical difficulties arise, and how its performance, security and user experience can be improved.
20.2. PostHog is not activated before you have made a separate, voluntary choice to allow the use of optional analytics technologies. Refusing, or subsequently withdrawing, consent does not restrict access to the core functions of SocialMama. You may withdraw your consent from Settings → Privacy → Data Analytics. Upon withdrawal, we stop future collection and take steps to delete or anonymise previous identifiable analytics data, unless there is another legal basis for limited retention.
20.3. Analytics data includes: User ID; device information; operating system; application version; screens visited; buttons tapped; features used; timestamps; errors and technical events. We do not send to PostHog: chat content; the content of private messages; exact location; children’s data; medical documents; the content of Community Buzz posts, unless expressly stated otherwise. Analytics is not used for advertising.
Legal basis: Art. 6(1)(a) GDPR — consent.
21. Cookies and related technologies
21.1. SocialMama is above all a mobile application. For that reason, most of the technologies used are not classic browser cookies, but they may perform similar functions, such as:
- storing information on the mobile device;
- gaining access to information already stored on it;
- recognising the application, the device, the session or the user profile;
- saving settings and preferences;
- delivering requested features; or
- collecting information about use of the application.
These technologies are governed by this section regardless of their technical name.
21.2. SocialMama uses two main categories of technology:
- strictly necessary technologies — necessary for registration, login, security, maintaining the session, saving requested settings or delivering a feature expressly requested by the user; and
- optional technologies — used for product analytics, measuring engagement with marketing messages or other purposes that are not necessary for the core functioning of SocialMama.
21.3. Strictly necessary technologies may be used without separate consent where the storage or access is necessary:
- for carrying out the transmission of a communication over an electronic communications network; or
- for providing a service or feature expressly requested by the user.
These technologies are not used for product analytics or marketing tracking.
21.4. Optional technologies are not activated before the user has received clear information about them and has made a free and specific choice. Refusing them does not restrict access to the core functions of SocialMama.
21.5. As at the date of this Policy, SocialMama uses, or may use, the following categories of technology:
| Technology or category | What information is used | Purpose | Mode and control |
|---|---|---|---|
| Authentication and user session tokens | Login token, session refresh token, session identifier and related security data. | Creating and maintaining a secure user session, recognising the logged-in user and preventing unauthorised access. | Strictly necessary. May be removed or invalidated on logout, token expiry or revocation, account deletion or clearing of the application's data. |
| Local and secure storage | Selected settings, language, theme, technical onboarding status and other information necessary to deliver a requested feature. | Saving settings and normal functioning of the application. | Strictly necessary, or necessary for a feature requested by the user. Settings can be changed in the application where that option is provided. |
| Local cache | Temporarily stored screens, images, posts, technical files and other data loaded while using the application. | Faster loading, stability, limiting unnecessary data transmission and correct display of content. | Strictly necessary. The cache may be refreshed or deleted automatically by the application or the operating system. |
| Push token and technical notification identifiers | Push token, operating system, identifiers of the application and the notification, delivery status and technical errors. | Sending the permitted push notifications through Expo, FCM or APNs. | Used once notifications have been enabled and to the extent necessary for the requested feature. Notifications can be managed through the device's system settings. |
| Status of system permissions and device interfaces | Information as to whether access to location, notifications, camera, photos or microphone has been granted. | Determining whether the application can deliver a requested feature, for example using current location, uploading a photo, sending a voice message or receiving a notification. | Access takes place through the system mechanisms of iOS or Android and can be changed from the device settings. The system permission itself does not constitute consent for an unrelated analytics or marketing purpose. |
| PostHog SDK and associated user identifier | User ID linked to the profile, information about the device and application, screens visited, features used, actions taken, time data and technical errors. | Product analytics and improving SocialMama. | Optional analytics technology. Activated only after separate consent and can be switched off through the settings in the user's profile. |
| Tracking pixels and individualised links in marketing emails | Opening of the message, links selected, date and time, IP address and limited information about the device and email application. | Measuring the engagement with, and effectiveness of, marketing messages through Mailchimp. | Optional technology. Used only where the necessary marketing consent has been obtained. |
21.6. A system permission granted through iOS or Android has a standalone technical function. For example, notification permission allows the operating system to deliver notifications, and location permission allows the application to obtain momentary access to the device’s location.
Granting such a permission does not automatically constitute consent to product analytics, marketing or another unrelated purpose. The processing of the resulting personal data is carried out under the conditions and on the legal bases set out in the relevant sections of this Policy.
21.7. Acceptance of the Terms of Service, continuing to the next screen, the system permission for notifications or location, and the user’s inaction do not replace the separate choice required for PostHog or for marketing tracking. Consent to one optional category is not treated as consent to another category.
21.8. You may manage these technologies in the following ways: the device settings; the application settings; the privacy settings in SocialMama. Restricting or removing a strictly necessary technology may result in termination of the session, loss of a saved setting or the inability to use the corresponding feature.
21.9. Upon withdrawal of consent, SocialMama ceases the future use of the corresponding optional technology. Withdrawal does not affect the lawfulness of the use and processing carried out before it.
22. Camera, photos and microphone
We may request access to the camera or to your photos so that you can upload a profile photo, and/or request access to the microphone so that you can send voice messages. We do not use the camera or the microphone without your action and permission. We do not record audio or video in the background. If selfie verification is introduced in future, there will be separate notice and separate consent where necessary.
23. Invitations to friends
SocialMama may allow you to invite a friend by sharing a link. If you use your device’s standard share menu, SocialMama does not automatically gain access to your address book. We do not upload your entire address book. We do not send invitations to your contacts without your express action. If we introduce a contact-based invitation feature in future, we will request separate permission and explain what data is used.
24. Support data and communication with us
When you contact us, we may process: name; email; the content of the message; attachments; technical information about the device, where necessary; correspondence history. We use this data for: responding to enquiries; technical support; reviewing complaints; exercising rights; protecting rights and interests.
Legal basis: Art. 6(1)(b) GDPR — where the enquiry relates to the contract; Art. 6(1)(f) GDPR — legitimate interest in communication and the protection of rights; Art. 6(1)(c) GDPR — where we are required by law to respond.
25. Automated processing and profiling
SocialMama uses automated logic to display more relevant profiles. This includes ordering by: approximate location; parenting stage; approximate age of the child/children; month of pregnancy, where applicable. This does not constitute a solely automated decision producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR. We do not use automated decision-making that by itself denies you a legal right or imposes a legally significant sanction on you. Moderation may use technical signals to detect abuse, but serious measures such as permanent restriction or deletion of a profile are reviewed by a human where this is possible and appropriate. If we introduce new profiling or automated decision-making with significant effect in future, we will update this Policy and provide you with further information.
26. Recipients of personal data
26.1. We may disclose personal data to providers who help us deliver SocialMama. These providers process data only to the extent necessary for the service and under data protection agreements where they act as processors.
26.2. Principal providers
| Provider | Role | Data | Location / Transfer |
|---|---|---|---|
| Supabase Pte. Ltd. — Database, Auth, Storage | Processor. AWS and the other companies on Supabase's list are sub-processors, not direct processors of SocialMama. | Database; authentication; data storage; profiles; settings; posts; metadata. | Primary project: EU, Ireland (EU) (AWS eu-west-1). Possible access/onward transfers to sub-processors in the USA and Singapore. Mechanism: SCCs incorporated in the signed DPA; for storage within the EEA itself, no Chapter V mechanism is required. |
| Amazon Web Services (through Supabase) | Sub-processor of Supabase. There is no direct DPA between SocialMama and AWS for this infrastructure. | Data hosted through Supabase in the applicable AWS region; technical, network and backup data according to the configuration. | Primary region: Ireland (EU), eu-west-1 — to be confirmed. Other locations are possible for certain features, support or sub-processing according to Supabase's current list. |
| PostHog, Inc. — product analytics | Processor. | Product analytics; User ID; device info; app events; timestamps. | Frankfurt — EU Cloud Host, Germany (EU). |
| The Rocket Science Group LLC d/b/a Mailchimp (Intuit) | Processor for Customer Data. Mailchimp/Intuit may act as an independent controller for its own account, billing, security and compliance data. | Email; name; consent status, date and source; audience/tags; campaigns; delivery, bounce, open and click metrics. | USA and other countries in which Mailchimp/its sub-processors process data. Mechanism: DPF for covered transfers to the USA; SCCs are incorporated as a fallback mechanism under the terms of the DPA. The DPA forms part of the contractual framework of the service: https://mailchimp.com/legal/data-processing-addendum/ https://mailchimp.com/legal/privacy/ |
| Resend (Resend Inc.) | Transactional/OTP emails (custom SMTP in Supabase Auth). | Email; content of the message (including OTP code, links); timestamps. | us-east-1 USA. |
| ipapi.co (Kloudend, Inc.) | Geolocation by IP address. | The user's IP address (city, country). | USA. |
| Google LLC / Google Ireland Ltd. — Firebase Cloud Messaging (FCM), push notifications for Android | Processor for Customer Personal Data under the Firebase Data Processing and Security Terms. | Push token; device info; payload (sender name, message text / excerpt from posts, metadata). | Global infrastructure, including the USA. Mechanism: the applicable Data Transfer Solution/DPF; failing that, the corresponding SCCs incorporated through the Firebase Terms. Firebase Data Processing and Security Terms and privacy/retention table: https://firebase.google.com/terms/data-processing-terms https://firebase.google.com/support/privacy |
| Apple Distribution International Ltd. / Apple Inc. — APNs, push notifications for iOS | Separate recipient/provider of a platform service. For its own processing, Apple acts as an independent controller. | Push token; payload (sender name, message text / excerpt from posts, metadata). | Apple Distribution International (Ireland) and global processing, including Apple Inc. in the USA. Apple states that it relies on SCCs for its international transfers. https://www.apple.com/legal/privacy/en-ww/ https://developer.apple.com/documentation/usernotifications/sending-notification-requests-to-apns |
| Expo Notifications (Expo) — relay for push notifications | Processor for User Data within the service. Independent controller for aggregated/de-identified data and for its own account/usage purposes under its terms. | ExpoPushToken; device OS; project/app identifiers; IP/usage data; notification payload (title, body, conversationID / postID / answerID, metadata); push ticket and receipt; technical errors and delivery status. | USA (the push infrastructure is on Google Cloud US). Mechanism: DPF; SCC Module 2 for the processing carried out as a processor is incorporated in the Terms of Service. Terms, §3.2 GDPR; Privacy Policy; Push FAQ: https://expo.dev/terms https://expo.dev/privacy https://docs.expo.dev/push-notifications/faq/ |
| Expo Updates / EAS Update (Expo) — OTA code updates | — | Runtime version; platform; Update ID; device / app info; IP. | USA. |
| Apple — login and App Store services | Independent controller for its own authentication/account environment. It does not become a processor of SocialMama merely because the user chooses to log in through its account. If authentication is implemented technically through Supabase, Supabase remains a processor for the data received by SocialMama. | Login identifiers; store metadata; device / app data. | Apple: Ireland/global, including the USA; Apple states that it relies on SCCs. These are the providers’ own transfers and not a basis for a transfer from SocialMama to a processor. https://www.apple.com/legal/privacy/en-ww/ |
| Google — login and Google Play Store services | Independent controller for its own authentication/account environment. It does not become a processor of SocialMama merely because the user chooses to log in through its account. If authentication is implemented technically through Supabase, Supabase remains a processor for the data received by SocialMama. | Login identifiers; store metadata; device / app data. | Google: global; Google’s own framework/DPF and SCCs under the applicable terms. These are the providers’ own transfers and not a basis for a transfer from SocialMama to a processor. https://policies.google.com/privacy |
| OpenStreetMap Foundation | Conversion of a manually entered address into an area. | The address entered (sent for geocoding; not stored on our servers). They generate their own user ID; they record the date and time (timestamp); they detect GPS location. | Netherlands (EU). |
26.3. Where a user chooses to register or log in through Google or Apple, the relevant provider authenticates her identity within its own service and provides SocialMama with limited information necessary to create or link the account. Google and Apple may independently process information about the use of the relevant account and the authentication service in accordance with their own policies. SocialMama does not control that independent processing.
26.4. We may also disclose data to: technical support providers; security providers; email providers; accountants, if paid services are introduced; lawyers and consultants; competent authorities; courts, arbitration bodies or rights-protection authorities, where necessary and where the law and/or a court decision requires the data to be disclosed. We do not provide personal data to advertising networks for behavioural advertising. We do not share pregnancy or children’s data with advertising partners.
27. International transfers
Some of our providers may process personal data outside the European Union and the European Economic Area. When we transfer personal data outside the EU/EEA, we use one or more of the following mechanisms: an adequacy decision of the European Commission; the EU–US Data Privacy Framework (DPF), where the provider is validly certified; standard contractual clauses; additional technical and organisational measures, where necessary; another valid basis under the GDPR. You may request information about the applicable safeguards through the contact details set out in this Policy.
28. How long we keep data
We keep personal data only for as long as it is necessary for the purposes for which it was collected, unless the law requires or permits longer retention.
| Data category | Period |
|---|---|
| Profile data | While the account is active. Following a deletion request, deleted and/or anonymised immediately in accordance with our internal procedures. |
| Name and email | While the account is active. After deletion — only where necessary for evidencing, security or a legal obligation (primarily in relation to the email). |
| Profile photo | While the account is active. Following a deletion request, deleted immediately in accordance with our internal procedures. |
| Pregnancy data | While the account is active and the data is necessary for the feature. Following a deletion request, deleted immediately in accordance with our internal procedures. |
| Data about the child/children | While the account is active and the data is necessary for the feature. Following a deletion request, deleted immediately in accordance with our internal procedures. |
| Approximate home location | While the account is active and the data is necessary for the feature. After you change the location specified in the application, the previous one is not retained and is deleted. Following a request to delete the profile, deleted immediately in accordance with our internal procedures. |
| Exact GPS coordinates | Used momentarily to calculate an approximate area. Not stored thereafter. |
| Current location | Used while the feature is switched on, until it is switched off. Not stored thereafter. |
| Chat messages and metadata | While the account is active and necessary for the feature. Following a request to delete the profile, messages you sent remain visible to the other participant, attributed to "Deleted user" in accordance with our internal procedures in connection with the rights of other users. |
| Community Buzz posts | While the account is active and necessary for the feature. Following a request to delete the profile, deleted immediately, unless limited anonymised retention is necessary in accordance with our internal procedures in connection with our rights or those of other users in respect of moderation reports and possible claims. |
| Reports and moderation | While the account is active and necessary for the feature. Following deletion or restriction of the account under our policies — up to 5 years, in connection with protecting the parties' rights in the event of potential legal claims. |
| Marketing data | For the duration of the account's activity and until the consent given is withdrawn. Thereafter — a minimal suppression record to prevent future marketing. |
| Analytics data | For the duration of the account's activity and until the consent given is withdrawn. Thereafter — deletion of the identifying data in accordance with our internal procedures. |
| Consent logs | While the account is active and necessary for the feature. Following deletion or restriction of the account under our policies — up to 5 years, in connection with protecting the parties' rights in the event of potential legal claims. |
| Security logs | While the account is active and necessary for the feature. Following deletion or restriction of the account under our policies — up to 5 years, in connection with protecting the parties' rights in the event of potential legal claims. |
| Support correspondence | While the account is active and necessary for the feature. Following deletion or restriction of the account under our policies — up to 5 years, in connection with protecting the parties' rights in the event of potential legal claims. |
| Backups | Overwritten in accordance with the standard backup cycle, no longer than 7 days. |
On deletion of an account, the data is not used for: marketing; analytics; matching; active profiles; display in the application. Limited retention is possible where necessary for: a legal obligation; security; evidencing consents and withdrawals; preventing abuse; defence against legal claims; backups, until they are technically overwritten.
29. Account deletion
29.1. You can delete your account from within the application as follows: Settings → Account → Delete account. We may require additional confirmation before deleting your account, in order to verify that it is you, through: an OTP code; email confirmation; re-authentication; another security mechanism. Before deletion, you may request a copy of your personal data. Following a deletion request, the account may be deactivated immediately.
29.2. Data in the active systems is deleted or anonymised in accordance with the periods set out in this Policy. Deletion triggers, to the extent technically applicable: deletion of the profile from Supabase; deletion or anonymisation of the associated profile data; deletion of the profile photo; deletion of the approximate location; deletion of the pregnancy data; deletion of the children’s data; deletion or anonymisation of the analytics data in PostHog; removal from marketing audiences in Mailchimp; retention only of a minimal suppression record where marketing has been opted out of; deletion or deactivation of push tokens.
29.3. Uninstalling the application does not always delete the account. To delete it, use the function in the application (clause 30.1) or contact us.
30. Your rights
30.1. You have the following rights:
- the right to information about the processing;
- the right of access to your personal data;
- the right to rectification of inaccurate data;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object;
- the right to withdraw consent;
- the right not to be subject to a solely automated decision with significant effect, where applicable;
- the right to lodge a complaint with a supervisory authority.
30.2. You may exercise your rights through: the application settings; an email to info@socialmama.app; another form, if one is provided in the application. We will respond without undue delay and no later than 1 month from receipt of the request. Where requests are complex or numerous, that period may be extended by up to a further 2 months. In such a case, we will notify you. In the meantime, we may request additional information if we need to confirm your identity. Exercising your rights is normally free of charge. If a request is manifestly unfounded or excessive, we may refuse to act or charge a reasonable fee, where the law permits this.
31. Right of access
You may request confirmation as to whether we process your personal data. If we do process your personal data, you may obtain: a copy of the data; the purposes of the processing; the categories of data; the recipients; the retention periods; information about your rights; information about transfers outside the EU/EEA; information about automated processing, where applicable. The right of access must not adversely affect the rights and freedoms of others.
32. Right to rectification
You may correct some of your profile data directly in the application, or request the rectification of inaccurate data by contacting us. At present, you can update: name; profile photo; biography; approximate age of the child/children; location; Current Status; settings; other data, depending on the features available.
33. Right to erasure
You may request the erasure of your personal data by contacting us or through the Delete account function in the application. We may not be able to delete certain data immediately if it is necessary for: a legal obligation; legal claims; security; evidencing consents and withdrawals; preventing abuse; protecting the rights of others. Where we cannot delete the data immediately, we may restrict its processing. You can find out more about deletion by reading this Policy in full.
34. Right to restriction
You may request restriction of the processing by contacting us where: you contest the accuracy of the data; the processing is unlawful but you do not want erasure; we no longer need the data but you need it for a legal claim; you have objected to processing and verification is being carried out.
35. Right to data portability
You may request the data you have provided to us in a structured, commonly used and machine-readable format, where the processing is based on: consent; or a contract, and is carried out by automated means. This may include profile data, settings and other information you have provided. The right to portability does not extend to data created by us, such as internal assessments, moderation notes or technical derived data. For your right to be granted, portability must not adversely affect the rights of others.
36. Right to object
You may object to processing based on legitimate interest. This may include certain processing for: security; prevention of abuse; moderation; protection of rights. If you object, we will stop the processing unless we demonstrate compelling legitimate grounds which override your interests, or the processing is necessary for legal claims.
37. Withdrawal of consent
37.1. Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of the processing carried out before the withdrawal. You may withdraw consent through (a) the following option in the application: Settings → Privacy; (b) the unsubscribe link in a marketing email; (c) contacting us. Please note that: (1) marketing consent and analytics consent are managed separately; (2) withdrawing marketing consent does not stop the receipt of service emails; and (3) withdrawing analytics consent does not restrict the core functions of the application.
38. Complaint to a supervisory authority
You have the right to lodge a complaint under the Personal Data Protection Act within 6 months of becoming aware of the infringement, but no later than 2 years from the date it was committed, with:
Commission for Personal Data Protection
Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
Website: https://www.cpdp.bg
Email: kzld@cpdp.bg
39. Security
39.1. We inform you that we apply technical and organisational measures to protect personal data, which may include: encryption of data at rest; encryption in transit; Row-Level Security in Supabase; restricted team access; individual access accounts; access logs; permission controls; contracts with processors; breach procedures; regular review of access rights; protection of backups.
39.2. In the current version of the application, there may be no separate administrator panel. Access by the founders or the team to the database is limited to cases where it is necessary for support, security, moderation or a legal obligation. All members of our team with access to personal data are bound by confidentiality obligations. You must also protect your device, email and account. SocialMama may keep you logged into your profile until you select “Log out”, delete your account, or the session is terminated for security reasons.
40. Security breaches
If a personal data breach occurs, we will assess the risk to the rights and freedoms of the individuals affected and, where the law requires, we will notify the Commission for Personal Data Protection; and where the breach is likely to result in a high risk to you, we will notify you without undue delay. The notification will set out: what happened; what data is affected; the possible consequences; the measures taken; the recommended actions; a contact point for further information.
41. Data from the App Store, Google Play, Apple and Google
41.1. When you download SocialMama from the App Store or Google Play, Apple and Google may process your data as independent controllers in accordance with their own policies.
41.2. If you use Apple or Google login, we receive the data that the relevant service provides to us, for example: email; name, if provided; a unique identifier; a private relay email, if you use Apple’s feature. We do not receive your Apple or Google account password.
41.4. You can manage the connection with Apple or Google through the settings of the relevant account and device.
42. Data we do not collect
Please note that we do not require data such as a personal identification number (EGN); identity card number; exact home address for public display; a child’s exact date of birth; medical documents; diagnoses; HealthKit data; Google Fit data; banking details in the current free version; or contacts from your address book, in order for you to download and/or use the application. Do not share such data with anyone, for any reason.
If we introduce paid features in future, payment data may be processed by the App Store, Google Play or another payment provider. We will update this Policy if SocialMama begins to process additional payment data.
43. Third-party data
You must not publish other people’s personal data without the right or permission to do so, including but not limited to: photos of other people; photos of other people’s children; telephone numbers; addresses; medical documents; screenshots of chats; personal stories that identify another person. If you publish a third party’s data, you are responsible for having the right to do so. We reserve the right to remove content that infringes the rights of others and/or to notify the competent authorities.
44. Data that users publish voluntarily
You choose what to publish in your profile, biography, Community Buzz and chat. Do not publish information that you do not want other users to see, and/or sensitive information about yourself or others unless you understand the consequences, and/or medical documents, diagnoses or information about children’s health. If you do publish such information, we may process it to the extent necessary for display, moderation, security or the protection of rights.
45. Changes to this Policy
We may update this Policy, and the reasons for doing so may include: new features; new categories of data; new providers; changes to the legal bases; changes to retention periods; changes in the law; requirements of the App Store or Google Play; the introduction of paid features; the introduction of biometric verification; changes to analytics or marketing. In the event of material changes, we will notify you through: an in-app message; email; a push notification; or another appropriate electronic means. If new processing requires consent, we will request separate consent before that processing begins. If we intend to process personal data for a new purpose different from the original one, we will provide information about that new purpose in advance.
46. How to contact us
Lazy Mama Ltd., UIC: 208288161, with registered seat and management address, including for correspondence: Sofia (1715), Studentski district, 102A Nikola Gabrovski St, fl. 5, apt. 9
Email for personal data matters: Delyana Samolova, info@socialmama.app
Link to our legal documents: https://www.socialmama.app/legal
Previous versions
There are no previous versions yet.