Privacy Policy
This is a translation; the Slovenian version is authoritative. Preberi v slovenščini
1. Controller
The controller of personal data is Vabita.si, Lokarje 41a, 1217 Vodice, Slovenia. The app name Vabita is not the name of the controller. Contact for privacy questions, which is also the contact for appealing a moderation measure and for exercising the right of access: podpora@vabita.si.
A data protection officer has been appointed: Eva Tisaj Žnidaršič, podpora@vabita.si.
2. What data we process
Identity from your sign-in provider: the e-mail address and name from your Google or Facebook account and a technical account identifier.
Profile: display name, an avatar chosen from a closed set of sixteen illustrations, postal code, and the statistical region derived from it.
Children: the date of birth, an optional sex and a chosen illustration for each child, up to six entries. The date of birth and the sex stay private; from the date we derive the age stage (0–6 months, 6–12 months, 1–2 years, 3–5 years, 6–9 years, 10+ years), which is shown together with the illustration to the participants of your gatherings. We do not collect a child's name, photograph or health data.
Pregnancy: the fact that you are pregnant and your expected due date. This is data about your state of health, that is, a special category of personal data; we process it only with your separate explicit consent. The week of pregnancy is calculated when displayed and is not stored.
Interests: values chosen from a closed set (what you like doing with your child and what matters to you as a mother). Interests are private and other users do not see them.
Gatherings: the gatherings you create and your sign-ups with the time of signing up. A sign-up stores a snapshot of your display name, avatar, area and your children's age stages.
Polls: your vote for one of the proposed dates of the next gathering, tied to your account.
Usage: sign-in times and daily activity rows, account status, and any moderation records.
Consents: the accepted versions of the Terms of Use, of this policy and of the Community Rules with the time of acceptance, the declaration of adulthood, and the separate consent to the processing of pregnancy data with the version of its text.
Messages: the text of private conversations and of messages in the chats of the gatherings you are signed up for.
Role: the mark that you are a verified organiser. The role is indirectly public, because every gathering of yours carries your name and avatar and its chat labels you as the organiser.
Attendance: the organiser's mark of whether you came to a gathering. She enters it, not you; the app does not check your arrival.
Device push tokens: the technical identifier of the device we deliver notifications to.
Blocks: the list of users you have blocked. The list is yours and a blocked user never sees it.
Reports of inappropriate content: your report of a profile, a gathering or a message, with a reason and an optional note. A reported message carries a copy of the reported text, so the administrator sees only that message and not the whole conversation.
What we do not collect: your exact location (only the postal code is processed, and only a coarse area label is shown), your date of birth (the app never asks for it; you confirm adulthood with a declaration), and children's names, photographs and health data. There is nowhere in the app to upload a photograph.
3. Purposes and legal bases
Performance of a contract (Article 6(1)(b) GDPR): operating your account, gatherings with their sign-ups, the chats of gatherings, polls about the next date, a participant's public profile, and private messages.
Consent (Article 6(1)(a) GDPR): entering children and interests. You enter data about a child as the holder of parental responsibility. You can withdraw consent at any time by deleting the entry.
Explicit consent for special categories of personal data (Article 9(2)(a) GDPR): the pregnancy entry and the expected due date. This consent is separate from this policy, you give it when making the entry and withdraw it by removing the entry. Without it the pregnancy data cannot be stored.
Legitimate interest (Article 6(1)(f) GDPR): community safety, moderation, and anonymized usage metrics.
Contract (Terms of Use): the organiser role as an agreement between you and the operator.
Consent (the system permission and the switch in the app): delivery of push notifications; you can withdraw the permission at any time.
Legitimate interest in safety: blocks and the handling of reports of inappropriate content.
Data about children, about pregnancy, interests and gathering data are not used for advertising or profiling and do not enter the anonymized aggregates as a separate dimension.
4. What other users see
This version of the app has no directory of users. Your public profile — avatar, display name, an approximate-area label, and the age stage and illustration of each of your children — is seen by the organiser and the participants of a gathering you are signed up for. Because every child is shown separately, the number of your children is visible within that circle too.
The pregnancy entry, the expected due date, a child's date of birth and a child's sex are visible to nobody but you: not in the public profile, not in the sign-up snapshot, not in chats and not in the administrative view.
Your interests are not visible to other users anywhere — not on the public profile and not at a gathering.
Your postal code, e-mail address, exact location and activity times are not visible to other users.
Your private messages are visible only to the other participant of the conversation.
If a directory of users is ever reintroduced, it will require a new, separate consent. Public profile projections created in earlier versions of the app are not used and cannot be reached from the interface.
5. Gatherings and what participants see about you
The place and the meeting point are data about the gathering, not about you; we never derive them from your address and never store them in your profile. We do not read your device location and do not check your arrival.
When you sign up for a gathering, the organiser and everyone signed up — including those who sign up later — see your display name, avatar, area label and your children's age stages and illustrations. Participants of the same gathering can open your public profile and start a private conversation with you. We tell you this before your first sign-up and record your acknowledgement.
The exact meeting point and the list of participants are visible only to the organiser and to those signed up. Before signing up, other users see only the number of people signed up and up to five of their avatars, without names or any other data. Messages in the chat of a gathering are visible to all its members, including the history from before you joined.
The organiser may remove you from a gathering. On removal you are notified, you lose access to the meeting point and to the chat of the gathering, and your messages remain in that chat.
The label "Suitable for pregnant women" describes a gathering and not its participants. Your sign-up for such a gathering is visible to the organiser and to those signed up, exactly like any other sign-up; before signing up, other users see only the number of people signed up and up to five avatars.
After the gathering the organiser marks which of the people signed up came. The organiser and the administrator see the mark; the interface does not show it to participants, but because the list of sign-ups is read by everyone signed up, the mark is technically reachable for them. It is used only for the organiser's overview and for attendance statistics without identifiers.
The chat of a gathering is deleted together with the gathering, even if people are still using it. That is a deliberate limit, so that a gathering does not become a lasting record.
6. Sharing a gathering outside the app
You can share a gathering as an image and a link. Only the public data of the gathering leave the app — its type, title, date, time, general location and any label for pregnant women — together with the random identifier of the gathering in the link. The meeting point, the participant list, the number of sign-ups and the organiser's name never leave the app.
Your name is not on the image. Whatever the social network you post it on shows about you is that network's own processing under its own terms.
The web page the link leads to shows nothing about the gathering, uses no cookies and measures no visits. We do not log sharing: we do not store who shared what.
7. Polls about the next date
After a gathering has ended, its organiser may open a poll about the next date. Your vote says when you are available, so it is personal data; we process it on the basis of performing the Terms of Use at your request, and voting is voluntary.
An individual vote is seen by the organiser and by you; the other participants see only the number of votes for each option. The poll and the votes are deleted together with the gathering; the new gathering created from the poll carries only the date and no votes.
8. Processors and data transfers
Data is processed on our behalf by Google (Firebase services: sign-in, database, server functions, hosting, and the delivery of push notifications through Firebase Cloud Messaging) under a data processing agreement (Firebase Data Processing and Security Terms). Server functions run in the europe-west1 (EU) region. The Firestore database of the production project is in the europe-west1 region (European Union); the database of the development project, which serves the test builds of the app before its first public release, is in the nam5 multi-region (United States).
The content of a push notification — the sender's name or the gathering title and a preview of up to 120 characters — travels through Firebase Cloud Messaging. Server logs never record the text of a notification.
There are no other recipients. We do not sell your data and do not use it for advertising.
9. Retention periods
Private profile, including children, the pregnancy entry and interests: until account deletion.
The pregnancy entry and the expected due date: until they are turned into a record of a born child, until the entry is removed, or until account deletion; on that change the expected due date is deleted and not archived.
Public profile from earlier versions of the app: until the profile is hidden or the account is deleted.
Administrative profile projection: until account deletion.
Gatherings with their meeting point, sign-ups and chat: 6 months after the date of the gathering. The period is deliberately short so that gatherings do not become a lasting record of where you have been.
Polls and votes: together with the chat of the gathering, that is, with the gathering; the votes of a user who deletes her account are removed immediately.
Device push tokens: until you sign out, switch notifications off, or 90 days without opening the app.
Blocks: until account deletion.
Reports of inappropriate content: 12 months.
Conversations and messages: until both participants delete their accounts; when one participant deletes theirs, their name and avatar are removed from the conversation while the texts remain with the other participant.
Consent records: until account deletion, then a further 24 months as proof of consent, without name or e-mail address and without any data about a child, about a pregnancy or any interest.
Daily activity rows: 90 days.
Moderation audit entries and request records: 24 months.
Anonymized daily aggregates without identifiers: no time limit.
The Firebase Authentication account: until account deletion.
10. Your rights
Access: you can request a copy of your data at any time at the controller's contact address in section 1. We send the copy within 30 days, and it covers your profile with its consents, your children and the pregnancy entry, your interests, your gatherings, your sign-ups with the attendance mark, your votes in polls, your blocks, your activity rows and the messages you sent. Device tokens are not part of the copy, because they are a technical device identifier, and neither are administrative audit entries, which carry an administrator's identity. There is no self-service export in the app.
Deletion: you can permanently delete your account in the app. Children, the pregnancy entry and interests are deleted together with the profile without exception, your sign-ups are deleted and the places on gatherings are freed, your votes in open polls are withdrawn and the counts corrected; device tokens and blocks are deleted, your memberships in the chats of gatherings are removed, reports you filed lose your identity and reports about you are deleted; the remaining exceptions are listed in the retention section.
Withdrawal of consent: you withdraw the consent to the processing of pregnancy data by removing the entry, and the consent to entering children and interests by deleting the entry. Withdrawal does not affect the lawfulness of processing before it.
Rectification: you can change your display name, avatar, postal code, child entries, the pregnancy entry and interests in the app; for other corrections contact the controller.
Objection: you can object to processing based on legitimate interest via the controller's contact; use the same address to appeal a moderation measure.
11. Complaint to the supervisory authority
If you believe the processing of your data violates the law, you can lodge a complaint with the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si.
12. Changes to this policy
Each version of this policy carries a date and is published at a public address. After a substantive change the app asks for your renewed consent at your next sign-in.