Data Storage and Data Processing Providers

Storage

Each account is synced to cloud storages located in EU and USA. Meaning that, for EU citizens, data is transferred to a third-party country. We only use data storage that complies with EU regulations and with guaranteed safety. You can find the specific data protection information for individual providers here:

 

Google Cloud

 

Google Cloud

 

Provider type:

* Order processor

Data transfer to third-party country:

* YES

Third party country:

* USA

Guarantees:

* EU standard contractual clauses

* EU-US Privacy Shield

 

Google Cloud

 

Google LLC (formerly known as Google Inc.),

1600 Amphitheatre Parkway, Mountain View, California 94043 USA

Quality Management

BodyBarista App uses tools to analyze the usage and optimize the service and features inside of the BodyBarista App. To do so we are using analysis tools provided by subprocessors. These tools generate a unique identifier per installation, which remains the same until uninstallation and reinstallation of the BodyBarista App. They collect action events, like clicking a button or performing a step in the  BodyBarista App, which is not Personal Data. You can find the specific data protection information for individual providers here:

 

Firebase

Facebook Developer

Fabric

 

Firebase

 

Personal Data collected:

* Installation ID

* Country as set by the phone

* Language as set by the phone

How data helps provide the service:

* Installation IDs to calculate the number of unique app instances that access network resources and to ensure that access patterns are sufficiently anonymous for the purpose of providing analytics and attribution information.

* Country and Language are used to provide analytics of the global used of BodyBarista and language preferences.

Legal Reason for Processing:

Legitimate interests

Provider type:

* Order processor

Data transfer to third-party country:

* YES

Third party country:

* USA

Guarantees:

* EU standard contractual clauses

* EU-US Privacy Shield

Retention:

* Installation ID-associated data for 60 days, and retains anonymous reporting without automatic expiration.

 

Facebook Developer

 

Personal Data collected:

* Installation ID

* Country as set by the phone

* Language as set by the phone

How data helps provide the service:

* Installation IDs to calculate the number of unique app instances that access network resources and to ensure that access patterns are sufficiently anonymous for the purpose of generating analytics and insights and usage of the BodyBarista service.

* Country and Language are used to provide analytics of the global used of BodyBarista and language preferences.

Legal Reason for Processing:

Legitimate interests

Provider type:

* Order processor

Data transfer to third-party country:

* YES

Third party country:

* USA

Guarantees:

* EU-US Privacy Shield

Retention:

* A maximum period of 180 days

 

Fabric

 

Personal Data collected:

* Installation ID

* IP Addresses – once received it is geo-coded to a city and displayed on for 10 seconds. Retained temporarily.

How data helps provide the service:

* Provides analytics information based on segmented device data. IP addresses are used to provide geolocation information.

Legal Reason for Processing:

Legitimate interests

Provider type:

* Order processor

Data transfer to third-party country:

* YES

Third party country:

* USA

Guarantees:

* EU standard contractual clauses

* EU-US Privacy Shield

Retention:

* Installation ID data retained for 90 days.

App Performance Management

To find critical and non-critical issues inside the code, BodyBarista is notified by tools provided by subprocessors. You can find the specific data protection information for individual providers here:

 

Crashlytics

Sentry

 

Crashlytics

 

Personal Data collected:

* Installation ID

* Crash traces

How data helps provide the service:

* Helping BodyBarista associate crash data with specific instances in the app.

Legal Reason for Processing:

Contractual necessity

Provider type:

* Order processor

Data transfer to third-party country:

* YES

Third party country:

* USA

Guarantees:

* EU standard contractual clauses

* EU-US Privacy Shield

Retention:

* Crash traces and their associated identifiers are kept for 90 days.

 

Sentry

 

Personal Data collected:

* UserID

* Error/Warning traces

How data helps provide the service:

* Notifies BodyBarista about errors and warnings occurring inside the app or on the server. The UserID helps to associate the error/warning with a unique user which is only accessible by BodyBarista personnel.

Legal Reason for Processing:

Contractual necessity

Provider type:

* Order processor

Data transfer to third-party country:

* YES

Third party country:

* USA

Guarantees:

* EU-US Privacy Shield

Retention:

* Error/Warning traces and their associated identifiers are kept for 90 days.

BodyBarista website performance

In order to analyze the activity on the BodyBarista website and improve the user experience, analytics tools are connected to the website. No personal data is collected apart from IP addresses. The specific data protection information pertaining to these tools can be found here:

 

Google Analytics

 

Google Analytics

 

Personal Data collected:

* IP Address

How data helps provide the service:

* Helps BodyBarista understand where the visitors of the website come from geographically, how they use the website, and how the experience can be improved. It’s not used together with any Personal Data within the BodyBarista app.

Legal Reason for Processing:

Legitimate interests

Provider type:

* Order processor

Data transfer to third-party country:

* YES

Third party country:

* USA

Guarantees:

* EU-US Privacy Shield

Retention:

* IP addresses are stored for up to 50 months, after which they are disposed.