GDPR Compliance

Your rights under the General Data Protection Regulation

Last updated: September 25, 2026

Our Commitment to GDPR

JaenWorld OÜ is registered in Estonia, a member state of the European Union. We are fully committed to compliance with the General Data Protection Regulation (GDPR) and Estonian data protection laws.

This page explains your rights under GDPR, how we process your personal data, and how you can exercise your rights.

Data Controller Information

Company Name: JaenWorld OÜ

Location: Estonia, European Union

Data Protection Officer: none appointed β€” we are not required to have one; privacy requests go to the email below

Contact Email: info@jaenworld.com

GDPR Inquiries: info@jaenworld.com

Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

1. Contractual Necessity (Article 6(1)(b))

Processing necessary to provide the Jaen service:

  • Account creation and authentication
  • Service delivery and feature access
  • Checking a subscription you bought in the app with the store that sold it

2. Consent (Article 6(1)(a))

With your consent for:

  • Cloud Sync: backing up your baby's profile and care log to our servers, if you turn it on in the app
  • Sharing a baby's care log with a co-parent, which needs Cloud Sync
  • Usage data from the app β€” usage events, device diagnostics, status reports and crash reports β€” in versions after 0.9.2 (build 1230), only if you say yes
  • Status updates, only after you confirm by email
  • The newsletter, only after you confirm by email
  • The beta waitlist, if you join it with your email address on our website

You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

3. Legitimate Interests (Article 6(1)(f))

When necessary for our legitimate interests:

  • Security and fraud prevention
  • Counting visits to this website and measuring how fast its pages load
  • Usage data from versions of the app up to 0.9.2 (build 1230), which send it without asking
  • Network and system security
  • Feedback reports you send us, and answering them
  • Messages you send us, through the contact form or by email, and answering them

We carefully balance our interests with your rights and will not process data where your interests override ours.

4. Legal Obligation (Article 6(1)(c))

When required by law:

  • Response to legal requests
  • Regulatory compliance
  • Keeping the store's record of a subscription you bought in the app after your account is deleted (accounting law)

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

πŸ“‹ Right to Access (Article 15)

You have the right to obtain confirmation that we process your data and receive a copy of your personal data.

How to exercise: Request your data by emailing info@jaenworld.com

Response time: Within one month

✏️ Right to Rectification (Article 16)

You have the right to correct inaccurate or incomplete personal data.

How to exercise: Update your profile in account settings or contact us

Response time: Immediate (via settings) or within one month

πŸ—‘οΈ Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data when:

  • The data is no longer necessary
  • You withdraw consent
  • You object to processing
  • Data was unlawfully processed
  • Legal obligation requires deletion

How to exercise: Delete account in settings, or email us from the address on the account and we schedule it for you, with the same 7-day grace period and emailed cancel link

What happens: Your account will be deleted after the 7-day grace period, once an administrator has reviewed it (within a month of your request). You can cancel the deletion with the link in our email until the deletion is done, or by emailing us. For a request you email us, the month runs from when your email reached us, and if it would end before the 7 days are up, we may complete the deletion sooner.

Response time: Within one month

⚠️ Note: Some records tied to your account outlive it. The store's record of a subscription you bought in the app is kept without your account attached to it, because accounting law requires us to keep it, and deleted 7 years after the subscription ends, or 7 years after the refund if it was refunded. A record that the deletion was carried out is kept for 7 years and then deleted; it holds a one-way hash of the account's email address, not the address itself, and the time the deletion was requested (for a request you emailed us, the time we scheduled it). Security-log entries that name the account β€” an administrator's action on it, or a sign-in attempt with its address that never reached the account β€” are kept with the same one-way hash in place of the address, and deleted 7 years after the first account deletion they outlive. If it was an administrator's account, the entries it wrote about other accounts are kept the same way, without the account attached to them. A copy of each feedback report you sent us β€” its message, the app version, your device or browser, and your email address β€” stays in our feedback mailbox at Zone, in Estonia, until you ask us to delete it.

⏸️ Right to Restriction of Processing (Article 18)

You have the right to request we limit how we use your data when:

  • You contest the accuracy of data
  • Processing is unlawful but you oppose deletion
  • We no longer need the data but you need it for legal claims
  • You have objected to processing pending verification

How to exercise: Email info@jaenworld.com

πŸ“¦ Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON, CSV).

How to exercise: Export your care log in the app's Settings, or request your account data by email

Available formats: CSV or JSON for the care log

βœ‹ Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

How to exercise: Email us. To stop the emails about a sign-in from somewhere new, switch off Login Notifications on your account's Security page, or ask us to. A sign-in our checks judge suspicious still gets a security alert, whatever that switch says.

Usage data from versions of the app up to 0.9.2 (build 1230): switch off Share usage analytics in the app's Settings, where the version has it. It takes effect at once. For their crash reports, write to us β€” or update the app, which sends none of this without your yes.

Marketing: The newsletter is the only marketing email we send, and only to an address that confirmed it. Use the unsubscribe link in any issue, or your mail app's Unsubscribe button, and it stops at once.

πŸ€– Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that produce legal or significant effects.

Jaen status: We do not make automated decisions with legal or significant effects without human review.

πŸ”„ Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.

How to exercise: Turn Cloud Sync off in the app, under Settings, Back up & sync. That only pauses it: nothing more is uploaded, and what is already on our servers stays there until you delete the baby permanently, delete your account or ask us to erase it β€” our Privacy Policy says how. For the newsletter and status updates, use the unsubscribe link in any email, or your mail app's Unsubscribe button: your address is deleted from the list at once. For the beta waitlist, email us, and we delete your address from it.

Usage data from the app: switch off Share usage analytics in the app's Settings. That takes effect at once: nothing more is sent, not even what was already waiting on your phone.

βš–οΈ Right to Lodge a Complaint (Article 77)

You have the right to lodge a complaint with a supervisory authority if you believe we have violated GDPR.

Estonian Data Protection Inspectorate:

Website: https://www.aki.ee/en

Email: info@aki.ee

Phone: +372 627 4135

We encourage you to contact us first so we can address your concerns directly.

Data Processing Activities

We maintain a Record of Processing Activities (ROPA) as required by GDPR Article 30. Here's a summary:

ActivityData CategoriesLegal BasisRetention
Account ManagementName, email, password hashContractUntil account deletion
Store SubscriptionsThe store's purchase record: purchase token (Google) or transaction id (Apple), product, status, dates, and the store's latest message about itContract; after your account is deleted, legal obligation (accounting law)While your account exists; after it is deleted, kept without your account attached until 7 years after the subscription ends, or 7 years after the refund if it was refunded, then deleted
AnalyticsUsage events, device diagnostics, status reports and crash reports from the app; visits to this website and page-speed measurementsWebsite visits and page-speed measurements: legitimate interest. The app's usage data: your consent in versions after 0.9.2 (build 1230); legitimate interest in 0.9.2 (build 1230) and earlierUsage events, device diagnostics, website visits and page-speed measurements: 90 days. Crash reports: 180 days. Status reports: 12 months after that device was last active
NewsletterYour email address, if you subscribe on our blog, and the record of your consent: when you asked and confirmed, the wording you agreed to, the page you signed up on and a pseudonym of your IP address (a keyed hash, still personal data); and which issues were sent to you. We record no opens and no clicks: our emails carry no tracking pixel and no tracked linkConsentYour address: if you never confirm, deleted 7 days after you last asked (the confirmation link works 72 hours); if you confirm, until you unsubscribe, which deletes it at once. The record of each step β€” asked, confirmed, unsubscribed β€” is kept while you are subscribed and for 3 years after you unsubscribe (or after your last request, if you never confirmed), with a keyed hash of your address instead of the address. The log of which issues were sent to you: 180 days
Status UpdatesThe same as for the newsletter, if you subscribe to status updates on our status pageConsentAs for the newsletter. The addresses given on the status page before 25 September 2026 were never emailed, and none is kept
Beta WaitlistYour email address, if you join the beta waitlist on our websiteConsentNo set period yet: we delete it when you ask
Customer SupportYour messages to us, through the contact form or by email; and for each feedback report you send from the app or the website's error screen, an email copy of its message, with the app version, your device or browser and your email addressLegitimate InterestNo set period yet: contact-form messages stay in our Gmail inbox, at Google; email to info@jaenworld.com and the feedback copies stay in our mailboxes at Zone, in Estonia. We delete yours when you ask
Security LogsRecords of sign-ins and failed sign-in attempts, account changes and administrators' actions, with the IP address and the browser or app they came from; the IP addresses your account has signed in from, which decide when a sign-in from a new one is emailed to you; your sign-in sessions; and the password-reset links you asked forLegitimate Interest12 months, then deleted: an entry 12 months after it was written, or sooner with the account it belongs to; a sign-in address 12 months after it was last used; a sign-in session 12 months after it ended; a password-reset link 12 months after it expired or was used. Kept longer: an administrator's entries about other accounts outlive the administrator's account, and an entry that outlives an account deletion β€” one of those, or one that names the deleted account β€” is deleted 7 years after the first account deletion it outlives; for an account deleted before this rule began, its entries that name it by its id go 7 years after the day we applied the rule to them. The record that a deletion was carried out is deleted 7 years after it was written, and the record of a request to delete an account is not deleted while the request is still pending

International Data Transfers

Our service runs on one server in Estonia, in the European Union, and that is where your account β€” and your Cloud Sync data, if you turn it on β€” is stored. Our emails are sent through Zone Media OÜ, an Estonian hosting company, which also hosts our jaenworld.com mailboxes.

Some services we use are run by companies based in the United States, so what they receive can be processed outside the EU and EEA:

  • Google β€” push notifications (Firebase Cloud Messaging), checking subscriptions bought through Google Play, signing in with Google if you choose to, the public STUN servers the app falls back on when you watch from away from home, the QR-code scanner in the Android app, and Gmail, where the messages you send through our contact form arrive
  • Apple β€” push notifications on iPhone and iPad

Google LLC is certified under the EU-U.S. Data Privacy Framework, and Google states that it relies on Standard Contractual Clauses where a transfer is not covered by an adequacy decision. Apple states that its transfers of personal data out of the EEA are governed by Standard Contractual Clauses.

Two things that might look like transfers are not. The approximate location of the IP addresses your account is used from, and of a shortened one when you visit this website, comes from a location database on our own server, so no address is sent anywhere to look it up. And the map pictures on your account pages come from OpenStreetMap, fetched and kept by our own server: your browser asks only this website for them, and OpenStreetMap receives nothing that identifies you β€” not your IP address, not a cookie. Write to us if you want to know more about any of these transfers.

Data Breach Notification

In the unlikely event of a personal data breach, we will:

  • Within 72 hours: Notify the Estonian Data Protection Inspectorate (as required by Article 33)
  • Without undue delay: Notify affected users if there is a high risk to their rights and freedoms (as required by Article 34)
  • Transparency: Publish incident details on our status page

Incident Response: We keep a written procedure for responding to security incidents.

Children's Data Protection

Jaen is not intended for individuals under 16 years of age (the minimum age for consent under GDPR in most EU countries).

We do not knowingly collect or process personal data from children under 16 without parental consent. If we become aware that we have collected data from a child under 16 without verification of parental consent, we will delete that information promptly.

If you believe we have collected data from a child under 16, please contact us immediately at info@jaenworld.com

How to Exercise Your Rights

Contact Methods

Email (Primary): info@jaenworld.com

Privacy Email: info@jaenworld.com

Data Protection Officer: none appointed β€” requests go to the email above

Company: JaenWorld OÜ

Location: Estonia, European Union

What to Include in Your Request

  • Your name and email associated with your Jaen account
  • Clear description of which right you want to exercise
  • Any specific information or time periods relevant to your request
  • Proof of identity (to prevent unauthorized access)

Response Timeline

  • Response: Within one month, extendable by two further months for complex requests (GDPR Art. 12(3))
  • Fee: Free of charge (unless requests are manifestly unfounded or excessive)

πŸ’‘ Tip: Your care log is quickest to get yourself: use Export care log in the app's Settings.

Related Policies

For more information about how we protect your data:

IP Geolocation by DB-IP

Checking site access...
gdpr