Last updated: 26 June 2026
This policy explains how Bebamon handles your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll.
1. Data controller
The controller is Ing. Petr Filip, Company ID (IČO) 07179952, place of business listed in the public Czech Trade Licensing Register, contact e-mailprivacy@bebamon.cz. We have not appointed a Data Protection Officer.
2. Hosted vs. self-hosted
If you run Bebamon as a self-hosted deployment, you are the controller and we have no access to your data. This policy covers the hosted service at bebamon.cz.
3. What data we process
- Account: e-mail, name, password (stored only as an irreversible hash).
- Family & child profile: family name, child name, optional birth date and photo.
- Device data: type, platform, app version, battery level, push token.
- Event metadata: time and type of detected events (cry, noise, disconnect) — not the audio itself.
- Security logs: IP address and browser data at sign-in.
- Billing data (paid plans only): payment-provider identifiers and subscription status.
4. Audio and video
We do not record or store audio or video streams. Media is relayed in real time and encrypted in transit. Sound detection runs on the baby device; for detection events, our application services receive event metadata, not an audio recording.
5. Purposes and legal bases
- Providing the service — performance of a contract (Art. 6(1)(b)).
- Security and abuse prevention — legitimate interest (Art. 6(1)(f)).
- Billing and accounting — contract and legal obligation (Art. 6(1)(b), (c)).
- Marketing messages — consent, or legitimate interest for existing customers.
6. Recipients and processors
We do not sell your data. We use vetted processors: hosting (Hetzner, EU), an e-mail provider, push notifications (Expo), and — on paid plans — payment providers (Stripe / RevenueCat). A current sub-processor list is available on request.
7. Transfers outside the EU
Some processors may process data in the USA; such transfers rely on Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework. All core infrastructure runs in the EU.
8. Retention
- Account data: for the life of the account, deleted within 30 days of closure.
- Event metadata: up to 90 days.
- Security logs: 90 days.
- Accounting records: for the statutory period (up to 10 years).
9. Your rights
You have the right to access, rectification, erasure, restriction, portability, objection and to withdraw consent. You can exercise erasure and data export directly in account settings or at privacy@bebamon.cz; we respond within one month. You may also lodge a complaint with the Czech Data Protection Authority (www.uoou.cz).
10. Security
We apply appropriate technical and organisational measures: password hashing (Argon2id), encryption in transit (TLS, DTLS-SRTP), token revocation, rate limiting, per-family data isolation and EU hosting.
11. Cookies and local storage
We use only essential cookies and browser storage (localStorage) for sign-in (authentication and CSRF cookies), remembering your language and other core functionality. We do not use tracking or advertising cookies, nor third-party analytics. Essential cookies do not require consent.
12. Contact
Questions and requests: privacy@bebamon.cz.