Helpaw Privacy Policy

Version: 1.4 · Effective date: 21 August 2026

1. Data Controller

The controller of your personal data is Dawid Kwiatkowski, sole proprietor (Dawid Kwiatkowski, 6572973652, 52329701500000, UL. WOJSKA POLSKIEGO 106B/3, PL-25-201, KIELCE, Poland).

Contact for all data protection matters (also the single point of contact under Art. 12 of the Digital Services Act):

E-mail: info@helpaw.pl

We process personal data in accordance with the GDPR (Regulation (EU) 2016/679).

2. Data we collect

At registration: e-mail address, password (stored only as a bcrypt hash), date and version of accepted Terms.

With Google / Apple / Facebook sign-in: the e-mail address shared by the provider.

Guest mode: an anonymous technical account (no e-mail). Guest accounts inactive for 90 days are deleted automatically.

While using the app:

Collected automatically:

We do not collect: first/last name, home address, profile photo, or special-category data (Art. 9 GDPR). Photos are stripped of EXIF metadata (including camera GPS) during compression. Photos containing people are automatically rejected.

3. Purposes and legal bases

4. Recipients and transfers outside the EEA

We use the following processors (each under a data processing agreement):

Data may be disclosed to competent authorities only where required by law.

5. Data visible publicly in the app

By publishing a report or sighting you share with app users (including guests): pet photos and description, the report location (rounded to approx. 110 m), the pet's name and reward info (if provided), your phone number — if provided (revealed after tapping "Show number"), and your comments/sightings.

⚠️ For lost-pet reports, consider choosing a location other than your exact home address.

Not public: your e-mail, password, chat messages (visible only to participants), push token.

5.1. NFC tag and pet profile card

A pet profile (name, species, breed, photo, notes, microchip number) is private — only you can see it. That changes only when you activate a tag, which you do deliberately in the app ("Add tag"):

Activation is your consent to this publication — until you activate it, no tag shares anything. We record the moment of activation (date and account) so that consent can be evidenced.

When someone scans the tag: we notify you that the card has been opened. The finder may optionally share their approximate area — we ask them explicitly in the browser and never derive it silently from an IP address. Shared coordinates are rounded to about 1 km (the neighbourhood is enough) and kept for 30 days, then deleted automatically. We store no contact details of the finder.

Withdrawing consent: you can deactivate the tag at any time in the app — the card immediately stops showing any data, even though the physical tag still exists. Use this if the tag goes missing with your pet or ends up in the wrong hands. Activating again issues a new token and permanently invalidates the previous one.

6. Retention

Cleanup runs automatically (scheduled database jobs).

7. Your rights (Art. 15–22 GDPR)

8. Security

TLS everywhere, bcrypt password hashing, row-level security in the database, server keys in an encrypted vault, regular backups, and a 72-hour breach notification procedure.

9. Device storage and identifiers

The mobile app uses no cookies. Local device storage holds: the session token, preferences (language, theme), offline cache, and the onboarding flag. The advertising identifier is processed only as described in section 3 - on iOS we do not request it at all. We use no behavioural analytics.

10. Age

The app is intended for users aged 16 or older; registration requires an age declaration. If we learn we process data of a younger person, we will delete the account and data without delay.

11. Changes

We will announce changes in the app and by e-mail at least 14 days in advance. The current version is always available in the app (Settings → Privacy Policy).