Babyphony

Privacy policy

This is a translation for convenience. The German version is the authoritative one — the provider, its registered office and the applicable law are German, and a translation can only approximate a legal term. Where the two differ, the German text prevails.

This statement describes which data are processed when you visit this website and when you use the Babyphony app.

1. Controller

The controller within the meaning of the General Data Protection Regulation is the entity named in the imprint. For questions about data protection you can reach us at info@ovonex.com.

2. Server log files

When this website is accessed, the hosting provider automatically records data that your browser transmits. These are:

The legal basis is Art. 6 (1) (f) GDPR. The legitimate interest lies in the technically faultless operation and the security of the website. These data are not merged with other data sources. The log files are deleted by the hosting provider after a short time.

3. Hosting

This website is operated by an external service provider. The host processes the data named above on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place.

4. Contact by email

If you write to us, we process your email address and the details you give in your message in order to answer the enquiry. The legal basis is Art. 6 (1) (f) GDPR — the legitimate interest lies in answering it. Where the matter concerns the initiation or performance of a contract, the basis is Art. 6 (1) (b) GDPR.

We delete these data once the enquiry has been dealt with conclusively and no statutory retention obligations stand in the way.

5. Cookies

This website sets no cookies for analysis or advertising purposes for visitors. No third-party services are embedded — no fonts from external servers, no maps, no embedded videos, no audience measurement.

If you log in to the administration area of the website, the system used sets technically necessary cookies for the session. This concerns editorial access only, not ordinary visits.

6. Spam protection

The Antispam Bee extension is used to fend off automated entries. It works locally on the server of this website and transmits no data to third parties. A comment function is not active on this website.

7. The Babyphony app

Video and sound do not leave the devices involved. The transmission runs directly between the two devices (WebRTC). No recording takes place, and no server stores or sees the content.

A signalling server is needed to establish the connection. In the course of this, the following are processed:

The legal basis is Art. 6 (1) (b) GDPR, since this processing is necessary in order to provide the function. No user account is created; we collect neither names nor email addresses for the use of the app.

Connection helper services (STUN)

So that two devices on different networks can establish a direct connection, each of them has to learn the public network address under which it appears to the outside. For this the app queries two public STUN servers operated by Google (stun.l.google.com and stun1.l.google.com).

In the course of this, the public IP address of the respective device is transmitted to Google. Video, sound and the pairing code are not transmitted — a STUN server sees only the network address of the request. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; processing in the USA cannot be ruled out.

The legal basis is Art. 6 (1) (b) GDPR: without this step, the direct connection between the devices does not come about on many networks.

Push notifications via Apple (iPhone only)

So that the receiving device can be woken from the background as well, Apple’s push service (Apple Push Notification service) is used. A message without content is transmitted to Apple, containing only the pairing code. The provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA. On Android devices this wake-up function does not currently exist; no push service is addressed there.

Camera and microphone

The app accesses the camera and microphone of the sending device. Access takes place only after the operating system has asked you for permission, and only while a transmission is running. The data are not stored.

8. Advertising in the app (Google AdMob)

The app finances itself through advertising. Google AdMob is used for this, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Video and sound from the nursery are not affected by this. The transmission runs directly between the two devices; the advertising network never receives them.

When advertising is delivered, the following are processed:

The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR. On first start the app asks whether personalised advertising may be delivered; on iOS, Apple’s tracking request is added to this. If you decline, advertising still appears, but without personalisation — the technical data named above are then processed as well, to the extent necessary for delivery.

Withdrawal: the consent can be changed at any time in the app’s settings. The advertising identifier can be withdrawn under Settings → Privacy & Security → Tracking.

Transfer to third countries: Google also processes data in the United States. The basis for this is the European Commission’s adequacy decision on the EU-US Data Privacy Framework, supplemented by standard contractual clauses. Further details in Google’s privacy policy: policies.google.com/privacy.

9. The one-off purchase

Freedom from advertising can be bought once. The purchase is handled entirely by the store the app came from — on iPhone by Apple, on Android by Google. We receive neither your name nor your payment details in the process.

The app only asks the store whether such a purchase exists for the account signed in there. No note of its own saying “purchased” is stored anywhere — neither by us nor on the device. The legal basis is Art. 6 (1) (b) GDPR. Which data Apple or Google process during the purchase is set out in their own privacy policies.

10. Your rights

You have the following rights vis-à-vis the controller: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21).

You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the one for your place of residence or the one for the registered office of the controller.

11. Changes

This statement will be adapted if the processing or the legal situation changes. The version in force at any time is available on this page.