1 Data Controller
The data controller is:
2 Data Collected
When using the Harmonia application, we collect the following data:
- Parent account data: email address, password (encrypted).
- Child profile data: first name, age.
- Usage data: missions created, missions completed, points earned, rewards redeemed.
- Technical data: device type, operating system, anonymous identifier for analytics purposes.
3 Children's Data
Harmonia is designed for family use. Child profiles are created and managed exclusively by the parent account holder, under their responsibility.
- The only data recorded about a child is a first name (or nickname) and an age, both entered by the parent.
- No contact details (email address, phone number) are collected from children, and children cannot create an account themselves.
- The child interface contains no advertising, no external links, and no interaction with third parties.
- No marketing communication is ever addressed to children.
Parents can edit or delete a child profile at any time from the application. Deleting a profile permanently removes the associated data.
4 Purpose of Data Processing
The data collected is used to:
- Provide and improve the Harmonia service.
- Manage user accounts.
- Ensure synchronization between family devices.
- Send push notifications (if authorized).
- Generate anonymous usage statistics.
5 Legal Basis
Data processing is based on:
- Contract performance: for providing the service (account creation, mission and reward management).
- Consent: for sending push notifications and using analytics cookies.
- Legitimate interest: for service improvement and fraud prevention.
6 Data Retention
Personal data is retained for the duration of account use, then deleted within 30 days after the user deletes their account.
Transaction records and accounting documents related to Harmonia+ are retained in accordance with Belgian legal obligations (10 years). We never hold your payment-card details: payments are processed entirely by the Apple App Store or Google Play.
7 Processors and Service Providers
To deliver the service, we rely on carefully selected processors, governed by data processing agreements compliant with Article 28 of the GDPR:
- Supabase, Inc. : database and authentication (hosting in an EU/EEA region).
- Vercel, Inc. : website hosting and content delivery.
- Apple App Store and Google Play : app distribution and in-app payment processing.
- RevenueCat, Inc. : technical subscription management (status, renewals); does not receive your payment-card details.
- Amplitude, Inc. : anonymous product analytics, hosted on Amplitude’s EU data center.
- Brevo (Sendinblue SAS) : sending of service and account-related emails; EU-based provider, data hosted in the EU.
- Google LLC : tag management on the website (Google Tag Manager), activated only with your consent.
We do not sell or rent your data. No data is used for targeted advertising.
8 User Rights
In accordance with the GDPR, you have the following rights:
- Right of access: obtain a copy of your personal data.
- Right to withdraw consent: withdraw your consent at any time (for example for notifications or analytics), without affecting the lawfulness of processing carried out before withdrawal.
- Right to rectification: correct inaccurate data.
- Right to erasure: request deletion of your data.
- Right to data portability: receive your data in a structured format.
- Right to object: object to the processing of your data.
- Right to restriction: request restriction of processing.
To exercise your rights, contact us at: hello@withharmonia.com.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA) at dataprotectionauthority.be, or with the authority in your country of residence.
10 International Data Transfers
Application data is hosted on servers located in the EU/EEA. Some of our providers (Supabase, Vercel, RevenueCat) are companies established in the United States and may, for administration or support purposes, access data from a country outside the EU/EEA. Where this happens, appropriate safeguards are in place in accordance with the GDPR, in particular the European Commission’s Standard Contractual Clauses (SCCs).
11 Security
We implement appropriate technical and organizational measures to protect your data: AES-256 encryption at rest, TLS 1.3 in transit, and restricted access to data. As no system is infallible, we cannot guarantee absolute security.
12 Contact
For any questions regarding the protection of your personal data: hello@withharmonia.com.