Privacy Policy for the baby lock App
Last updated: 16 July 2026
1. Controller
baby lockConsuendi GmbH
Röhrsdorfer Allee 14
09247 Chemnitz
Germany
Email: info@babylock.de
Telephone: +49 3722 4082 200
2. Data Protection Officer
Susann VoigtConsuendi GmbH
Röhrsdorfer Allee 14
09247 Chemnitz
Germany
Email: datenschutz@consuendi.com
Telephone: +49 3722 4082 202
3. Scope
This Privacy Policy explains how we process personal data when you use the mobile baby lock App. The processing that actually takes place depends on the installed App version, operating system, features used, device settings and permissions you grant.
Personal data means any information relating to an identified or identifiable individual. We process data in accordance with the General Data Protection Regulation (“GDPR”), the German Federal Data Protection Act and other applicable data-protection laws.
4. App delivery and server logs
When online content or App features are retrieved, your device and our systems exchange technically necessary data. This may include the IP address, date and time of access, requested resource, amount of data transferred, HTTP status, App version, operating system, device model, language setting and error data.
We process this data to deliver content, maintain functionality and security, identify errors and prevent misuse. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the App. Where processing is necessary to perform a contract or take pre-contractual steps, Article 6(1)(b) GDPR also applies.
Server logs are generally kept only for as long as required for operation and security and are then deleted or anonymised, unless a specific security investigation, statutory retention duty or legal claim requires longer storage.
5. Data stored locally
The App may store settings, language, consent choices, favourites, recently viewed content or similar preferences locally on your device. This data supports the features you request and improves usability. You can generally delete it by resetting the App's data or uninstalling the App. Device backups are governed by your settings and by the privacy terms of your operating-system or cloud provider.
6. Dealer and location search
If you use a dealer or nearby-location search, we process the location you enter or—only after you grant permission—the location supplied by your operating system. Depending on the feature, the location, search radius and technical request data may be sent to our server or to a map or geodata service to identify and display relevant results.
Processing is necessary to perform the feature you requested under Article 6(1)(b) GDPR or, where consent is required, is based on Article 6(1)(a) GDPR. You can refuse or withdraw location permission in your device settings and, where available, enter a location manually instead.
7. Camera, photos and files
If an App feature enables you to take, select, save or transmit an image or document, the App accesses your camera, photos or files only after you grant permission. Selected content is processed solely for the feature you initiate. Before sending content, check whether it contains another person's personal data and whether you are entitled to share it.
The legal basis is Article 6(1)(b) GDPR or your consent under Article 6(1)(a) GDPR. Content that is not transmitted generally remains on your device. Transmitted content is deleted when the purpose ends unless statutory retention requirements apply.
8. Push notifications
If you enable notifications, your operating system's push service processes a device-related push token. We may process this token together with the App version, platform, language and your notification settings to deliver the messages you select. Depending on your device, delivery is provided by Apple Inc. or an Apple affiliate, or by Google Ireland Limited or a Google affiliate.
Processing is based on your consent under Article 6(1)(a) GDPR. You can disable notifications at any time in the device settings. The token will be deleted or no longer used when consent is withdrawn, it can no longer be associated with the device or the purpose ends.
9. Contact and support
If you contact us by email, telephone, form or a linked support feature, we process your contact details, the content and time of your request and any technical information you submit. We use this data to respond to and document your request.
The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual requests and otherwise Article 6(1)(f) GDPR. Our legitimate interest is orderly and traceable communication. Correspondence is deleted once the request has been dealt with unless statutory retention periods, security reasons or legal claims require further storage.
10. External content, links and web views
The App may open third-party websites, maps, videos, social networks, app stores, shops or other external services. When you actively open such content, the third party will generally receive at least your IP address and technical information about the device and request. The third party's own privacy information then also applies.
External content is embedded or opened only where required for the requested feature, where you initiate the request or, where legally required, after you consent. The legal basis is Article 6(1)(b), (f) or (a) GDPR depending on the feature and integration.
11. Diagnostics, audience measurement and similar technologies
Where the released App version expressly offers diagnostics, crash reporting, analytics or audience measurement and requests consent, technical usage data, device identifiers, session and event data, and error reports may be processed. Analytics that are not technically necessary are used only with your consent under Article 6(1)(a) GDPR, which you may withdraw at any time in the App or device settings.
Independently of us, Apple or Google may process app-store, installation and diagnostic data as separate controllers in accordance with your account settings and their own privacy policies. We may receive only aggregated statistics or diagnostic reports that you choose to share.
12. Legal bases
Depending on the processing, we rely in particular on:
- Article 6(1)(a) GDPR where you have given consent;
- Article 6(1)(b) GDPR where processing is necessary for a contract, pre-contractual steps or an App feature you request;
- Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation;
- Article 6(1)(f) GDPR where processing is necessary for our or a third party's legitimate interests and those interests are not overridden by your interests or rights.
13. Recipients and processors
We disclose data only where necessary for the purposes described, permitted by law or authorised by you. Recipients may include hosting and IT providers, app platforms, push, map or media services, support providers, affiliated companies, public authorities and legal advisers. Providers processing data on our behalf are contractually bound in accordance with Article 28 GDPR.
14. Transfers outside the EEA
For individual technical services, processing outside the European Union or European Economic Area cannot always be excluded. We transfer data only where the requirements of Articles 44 et seq. GDPR are met, in particular on the basis of an adequacy decision, appropriate safeguards such as the EU Standard Contractual Clauses, or a statutory exception. Where necessary, we implement supplementary safeguards.
15. Retention and deletion
We keep personal data only for as long as required for the relevant purpose. It is then deleted or anonymised unless statutory retention periods, evidentiary or security needs, or the establishment, exercise or defence of legal claims require longer storage. More specific periods may be stated in the relevant sections of this Policy.
16. Your rights
Subject to the statutory requirements, you have the right of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR) and the right to lodge a complaint with a data-protection supervisory authority (Article 77 GDPR).
You may withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to object: Where we process data under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons.
To exercise your rights, contact datenschutz@consuendi.com. You may also contact any competent supervisory authority, in particular the Saxon authority responsible for our registered office.
17. No automated individual decisions
We do not use the App to make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR.
18. Children
The App is not directed at children for the purpose of collecting their personal data. Parents and other responsible adults should supervise minors using the App and should not submit children's personal data unless required for a specific feature and legally permitted.
19. Security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. However, no data transmission or storage can be guaranteed to be entirely risk-free.
20. Changes to this Privacy Policy
We will update this Privacy Policy if the App, the services used or the law changes. The current version is available in the App or at the internet address stated there.