Amma Privacy Policy (Privacy Notice)
Effective Date: October 24th, 2025
AMMA FAMILY MX, S. de R. L. de C.V., business (registered) address: 03810, calle Montecito, 38, piso 24, numero 28, col. Nápoles, Benito Juarez, Ciudad de Mexico, Registration number (FME): N-2022047843, Tax ID (RFC): AFM2206241A6, and its affiliates, including Period Tracker & Pregnancy and Baby Calendar Limited, a company formed and existing under the laws of SAR Hong Kong, with its principal place of business located at: 2301, Bayfield Building, 99 Hennessy Road, Wanchai, Hong Kong, Business Registration No.: 70409838, ("amma", “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal data. This Privacy Policy (Privacy Notice) is meant to help you understand our privacy practices when you use our services, including what data, how and for what purposes we collect, how we use, disclose, and safeguard your personal data, as well as your rights in this regard.
- Scope
This Privacy Policy applies to all users of our service. We follow this Privacy Policy in accordance with applicable law in the places where we operate and process any information about you.
This Privacy Policy describes the processing of information provided or collected on the site(s) and/or application(s) where this Privacy Policy is posted, including:
- amma mobile application for planning or tracking pregnancy, and parents capturing their newborns’ milestones published in online stores, including Google Play, and Appstore (“Application” or “App”);
- the website amma.family.
The Application allows for the calculation of the estimated due date, and gestational age, provides insights into your life period of planning pregnancy, being pregnant, and being a parent of a newborn baby, and provides users throughout the world with personalized content, messages, recommendations, guides, and other services. Please note that depending on your relationship to the baby, references to ‘your pregnancy’ may relate to either your own pregnancy or that of another individual whose pregnancy-related information is provided to us by you. You agree that you have adequately informed and taken the consent of the individual whose pregnancy information you are providing to us in the App.
Please note that our site(s) and/or application(s) may contain links to other sites not owned or controlled by us, and therefore we are not responsible for the privacy practices of those sites unless explicitly stated otherwise. We encourage you to be aware when you leave our sites or applications and to read the privacy policies of other sites that may collect your personal data.
Please also read our Terms of Use, which describe the terms under which you use our services.
2.1. Data controller
While collecting and processing your personal data, AMMA FAMILY MX, S. de R. L. de C.V., business (registered) address: 03810, calle Montecito, 38, piso 24, numero 28, col. Nápoles, Benito Juarez, Ciudad de Mexico, Registration number (FME): N-2022047843, Tax ID (RFC): AFM2206241A6, acts as a “data controller” (as that term is used under the EU General Data Protection Regulation (“GDPR”), the Brazilian General Data Protection Law (“LGPD”) and other applicable data protection laws). As such, AMMA FAMILY MX, S. de R. L. de C.V. is responsible for deciding why and how the information you provide to us is processed.
2.1. Data processor
However, in some cases, we can be a data processor acting on behalf of a data controller.
For example, some of the features in our websites and applications (including the App) allow you to give consent to and subscribe to our advertising partners’ marketing offers, promotional actions, and loyalty programs. In such a case, amma acts as a data processor collecting personal data on behalf of an advertising partner (the data controller).
You may withdraw your consent to processing your data by such data controllers at any time by means of sending a corresponding request directly to them. You may also opt out of receiving e-mails from an advertising partner by following the unsubscribe link or the instructions provided in the email.
3. Consent
By using our services, you agree to the terms and conditions outlined in this Privacy Policy. Your continued use of our services constitutes implicit consent to the collection, processing, and sharing of your personal data as described herein.
We make every effort to ensure that our privacy practices are transparent and understandable. By using our services, you acknowledge that you have read and understand this Privacy Policy.
If you do not agree with any terms outlined in this policy, please refrain from using our services.
4. Information We Collect
We collect information about you when you interact with our services. The information can be directly provided by you or we can collect it automatically, as well as we may receive information about you from third parties.
4.1. Personal data you provide to us directly or we derive based on the data you provide:
We may collect and process the following personal data you provide to us directly or we derive based on the data you provide through the App, our website, or otherwise while using our services:
Personal and contact details such as your:
- name, surname
- date of birth, age
- phone number
- city
- address
- number of children
Information about your well-being such as:
- pregnancy status (planning, pregnancy, newborn)
- information about multiple pregnancy
- conception date, 1st date of last menstrual period, average period length, average duration of cycles
- estimated due date
- gestational age (including trimester, week, day)
- user`s weight (date, weight, gestational age, gain)
- user`s belly size (date, size, gestational age, gain)
- information about kicks (date, start, finish, period, quantity); first kick (time), last kick (time)
- information about contractions (start, finish, duration, interval)
- height before pregnancy
- weight before pregnancy
- Body Mass Index (BMI)
- information about feeding a baby
Information about your baby such as:
- baby`s gender, date of birth, name, age
- baby`s weight (birth weight, current weight, difference)
Information you choose to share with us such as:
- your favorite baby names
- your hospital bag list
- information about doctor appointments (date, type of doctor, notes)
- medications (medication name, type, dose, number of times per day, frequency, meal instructions, duration, intake time)
- mood
- notes
- the content of your messages to Ammy GPT chat in the App;
- areas or topics of your interest chosen by you; information provided by you in response to quizzes or surveys
- views and opinions: any views and opinions that you choose to send to us, or publicly post about us, including on app stores (e.g., Google Play, Appstore)
- any other information provided by you to us
4.2. Automatically Collected Information
We may also collect certain information automatically when you use the App, visit our website, or otherwise use our services. Under certain circumstances and depending on applicable law, some of this information may constitute personal data. This information may include but is not limited to:
- Information about your baby such as the baby`s id assigned by us, and the date of creating data about the baby.
- Advertising ID, which is a unique, user-resettable identification number for advertising associated with a device (e.g., iOS uses the Identifier for Advertising (or “IDFA”) and Android uses Google Advertising ID (or “GAID”)). If you use the App on an iOS we may only use your advertising ID if you've given your consent that was requested during the first launch of the App.
- Location information such as:
- Internet Protocol (“IP”) address, which is a unique string of numbers automatically assigned to your device whenever you access the Internet.
- GeoIP data that is non-precise information about the approximate physical location (for example, city, and country of a user’s computer or device derived from the IP address of such computer or device.
- Device type, settings, and software used, including unique device identifiers (distinctive number) (device ID), platform of the device and version, operational system and its version, device model, enabled device accessibility features (e.g., screen resolution, display features, hearing features, and physical and motor features), device storage information, cellular settings, mobile operator and network information, time zone, push token from the device, language, App version.
- Data about your use of the services, including frequency of use; areas and features of the Services that you access or use; engagement with particular features, activity events (e.g. history about completed article reading, saved articles, comments, reactions (likes), etc.); date of registration in the App; date and time of the last login to the App; days active; session; connection between App accounts if you have invited a family member, roles (e.g. mother, father).
- Any information necessary to give you access to your account profile, such as your user ID assigned by us, username, and encrypted password.
- Information about subscriptions to our services, including the App (e.g. subscription status (premium status), expiry date, trial period status, renewal status) and Babycash in the App (e.g., quantity of Babycash, items on which Babycash has been spent)
- Financial and payment information(excluding full payment card details). If you pay for our services, we may receive information and confirmations, such as payment receipts, including from app stores (e.g., Google Play, Appstore), or other third parties processing your payment.
- Consent records: records of any consent you may have given, together with the date and time, means of consent, and any related information (e.g., the subject matter of the consent).
- When responding to your questions and requests and to provide customer support, we may track whether you open the email sent in response to your request.
- Searches for and interactions with e-commerce opportunities, such as merchants and offers contained in the Services.
- Browsing history including the websites or other services you visited before and after interacting with the Services.
- Information collected through the use of cookies, eTags, Javascript, pixel tags, device ID tracking, anonymous identifiers, and other technologies, including information collected using such methods and technologies about (i) your visits to, and interaction and engagement with, the services, content, and ads on third party websites, applications, platforms, and other media channels, and (ii) your interaction with emails including the content and ads therein.
- Log files, which may include IP addresses, browser type, ISP referring/exit pages, operating system, date/time stamps and/or clickstream data, including any clicks on customized links.
- Web Beacons, which are electronic files that allow a website to count users who have visited that page or to access certain cookies.
- Pixel Tags, also known as clear GIFs, beacons, spotlight tags or web bugs, which are a method for passing information from the user’s computer to a third party website.
- Local Shared Objects, such as Flash cookies, and Local Storage, such as HTML5.
- Mobile analytics to understand the functionality of our App and software on your phone.
4.3. Information from external sources
We may receive information (including personal data) about you from external sources to supplement the data already collected. This may include publicly available data or data provided by third parties. We may combine this data with the data we already have. We will handle this data in accordance with this Privacy Policy and the purposes outlined when the data was collected. We will notify you if there are any material changes to the way we intend to use this data. Please note that we are not responsible for the accuracy of the data provided by third parties or any consequences arising from the use of such data. Such information about you from external sources may include but is not limited to:
- User ID assigned by service providers used for providing the functionality of and improving the App (e.g., analytics systems)
- apple id/ google id (=email)/ facebook id. You may log in to your account in the Application using your e-mail or your social media profile (e.g., Apple, Facebook, Google).
4.5. Permissions
The App may request your permission to access your phone or sensors (e.g. camera, Wi-Fi, geo-location, or Bluetooth) or other data (e.g. photos, agenda, or contacts) on your mobile device.
We use such data only when it is essential to provide you with the services and only after you have given your explicit consent.
Sometimes, the permission is a technical precondition of the operating systems of your mobile device. In such cases, the App may ask your permission to access such sensors or data, however, we will not collect such data, unless when it is required to provide our services and only after you have given consent.
5. Sensitive, or other special personal data
Our services, including the Application, may operate anywhere in the world and different countries may have different approaches to sensitive data (including health data). Therefore, some of the data that you provide to us may or may not be deemed sensitive, or “special” in your jurisdiction. Also, local laws may have specific requirements regarding protection and processing of sensitive data.
Where we need to process your sensitive personal data for a legitimate purpose, we do so in accordance with applicable law in given jurisdictions. This means that if your country has higher standards of processing and protecting sensitive data then your country’s requirements will apply to your data. Where your explicit consent to process your health data or another special data is required under the applicable law (e.g. GDPR or LGPD), we rely on your explicit consent to process this data.
The only sensitive personal data you may send us (including through our websites, and the Application) is information about your pregnancy if it is considered to be sensitive in your jurisdiction, for example:
We propose you fill in the following information about your pregnancy in order to provide you with the functionality of the App (please, note that without processing such information we are not able to provide you with the core functionality of the App), as well as for other purposes specified in section 6 of this policy:
- pregnancy status (planning, pregnancy, newborn)
- conception date, 1st date of last menstrual period, average period length, average duration of cycles
- estimated due date
- gestational age (including trimester, week, day)
- date of birth of the child
Also, if you choose, you can fill in the following information about yourself in order to provide you with the advanced functionality of the App (e.g., kicks counter, calendar, etc.), providing this information is optional:
- information about multiple pregnancy
- user`s weight (date, weight, gestational age, gain)
- user`s belly size (date, size, gestational age, gain)
- information about kicks (date, start, finish, period, quantity); first kick (time), last kick (time)
- information about contractions (start, finish, duration, interval)
- height before pregnancy
- weight before pregnancy
- Body Mass Index (BMI)
- information about feeding a baby
- information about doctor appointments (date, type of doctor, notes)
- medications (medication name, type, dose, number of times per day, frequency, meal instructions, duration, times to rake).
The examples and list of data that may be considered to be sensitive in some jurisdictions are not exhaustive.
Anyway, except as stated herein above, be aware that we do not process, and we ask you not to provide, including not to send us on or through our websites, applications or otherwise, or disclose, any sensitive personal data that might be deemed confidential under the applicable laws (such as political opinions, religious or philosophical beliefs, trade union membership, biometric data).
You can always revoke your consent to processing your personal data (including sensitive data) by writing to: help@amma.family.
6. Why we process your data and the lawful basis for processing
We collect and process your personal data for the following purposes relying on the following lawful bases:
N | Purposes of processing personal data | Lawful bases for processing personal data |
a) | Service Delivery: We use your personal data to provide you with the products or services you have requested, including the App functionality. Here are some examples of such services:
| We process your personal data to provide you with the products or services you have requested, including the App functionality, relying on performance of contract. However, due to the very nature of the App and some other services we provide (e.g., providing personal guide on pregnancy), we need to process data about your pregnancy or other data that may be considered to be sensitive (special) in your jurisdiction as described in section 5 of this policy. Please, note that without processing such information we are not able to provide you with the core functionality of the App (or a personal guide, etc.). Where your explicit consent to process your sensitive (special) data is required under the applicable law (e.g. GDPR or LGPD), we rely on your explicit consent to process this data. However, you will be unable to use the App (or receive a personal guide, etc.) without providing us with this consent. |
b) | Account Creating and Management: You can use the App with or without an account. You can create a new account using your email address, or using your existing social media account credentials (e.g., Apple, Facebook, Google) to securely log into the App. If you create an account, we process your account credentials and profile details to manage your account, including account setup, verification, and maintenance. This ensures the security and functionality of your account on our platform. | The lawful basis for this processing is typically the performance of a contract to maintain your account. |
c) | Customer Support and Moderation: Your information allows us to provide customer support, respond to your questions and requests, and fix our services. Our moderators use your information to monitor and moderate our websites and applications, including sending you warnings, notifications, and other messages related to your activities herewith.
| We process your personal data based on performance of contract as is necessary to manage our services by identifying and fixing bugs and to provide customer support and reply to your request. However, we may process your data based on our legitimate interests to analyze the performance of and improve the App, our websites, and other products and services provided by us. We always verify that our legitimate interests do not outweigh your privacy rights and interests. |
d) | Improvement of our Products and Services: We analyze how you interact with us and use our products and services (including applications and websites where this policy is published) in order to improve them and develop new features and solutions. This includes enhancing the user experience, developing new features, and optimizing the performance and security of our products. Here are some examples:
To be able to improve our products and services and provide you with more advanced features, we may analyze and combine your personal data (including your pregnancy status). | This processing is also based on legitimate interests to improve and maintain the quality of our products and services, and developing new solutions for society and for you in the personal health domain. We always verify that our legitimate interests do not outweigh your privacy rights and interests. |
e) | Communication. We may process your personal data (including your pregnancy status) to communicate with you via any means (including via push notifications, in-app messages, email, telephone, text message, social media, post or in person) regarding your inquiries or requests, as well as regarding content and other information in which you may be interested considering your preferences and behavior (profiling) or not considering them, subject to ensuring that such communications are provided to you in compliance with applicable law; and obtaining your prior, opt-in consent where required.
Direct marketing. We may provide direct marketing (including targeted and behavioural advertising) to you as described below. We may process your personal data (including your pregnancy status) to contact you via push notifications, in-app messages, email, or other methods of communication to provide you with information regarding the services and products that may be of interest to you considering your preferences and behavior (profiling) or not considering them, subject to ensuring that such communications are provided to you in compliance with applicable law; and obtaining your prior, opt-in consent where required. We may send information to you regarding the services, upcoming promotions and other information that may be of interest to you, using the contact details that you have provided to us.
Data combination. To be able to tailor the communications to your preferences and behavior and provide you with a more relevant and personalized experience, we may analyze and combine your personal data.
Opting out from communication and/or direct marketing. You may opt out and unsubscribe from such communications at any time as described below or by writing to: help@amma.family. You may turn off push notifications in the settings of your device, as well as unsubscribe from our newsletter lists at any time by following the unsubscribe instructions included in every email we send. We will not send you any emails from a list you have selected to be unsubscribed from, but we may continue to contact you to the extent necessary for the purposes of any other services you have requested or for additional emails you have signed up for.
| This processing is based on legitimate interests or, when applicable, your consent if you have provided it. We always verify that our legitimate interests do not outweigh your privacy rights and interests. |
g) | Allowing you to share your data with third parties. Some of the features in our websites and applications (including the App) allow you to share your data with companies that you trust and with our selected advertising partners.
After we share your data with our advertising partners, please note that we no longer have control over how our partners process your data. Such advertising partners process your personal data for their own purposes. Please read their privacy policies carefully in order to know more about the privacy practices they use. Some of our advertising partners may be listed in annexes 2 to this Privacy Policy “special terms for users from specific jurisdictions”. Usually, amma acts as a data processor collecting personal data on behalf of an advertising partner (the data controller). You may withdraw your consent to processing your data by an advertising partner at any time by means of sending a corresponding request directly to them. You may also opt out of receiving e-mails from an advertising partner by following the unsubscribe link or the instructions provided in the email.
| Allowing you to share your data with third parties. We process and share your personal data with third parties based on your consent (e.g., advertising partners), or where you make an express request to us (e.g., login using third-party account credentials). Althernatively, this processing may be based on legitimate interests or the performance of a contract, if applicable. We always verify that our legitimate interests do not outweigh your privacy rights and interests.
|
h) | Legal Compliance: We may process your personal information to comply with our legal obligations, such as tax reporting, responding to legal requests, or assisting law enforcement agencies when required by law.
| This processing is necessary to fulfill legal obligations. |
i) | Fraud Prevention and Security: We use your information to protect against fraud, unauthorized access, and other security risks. This may include monitoring account activities and implementing security measures.
| The lawful basis for this processing is legitimate interests to ensure the security and integrity of our services. |
j) | Aggregated and Anonymized Data: We may aggregate and anonymize your data to create statistical or research reports, which do not personally identify you. This information may be used for business analysis, marketing, and sharing with partners or clients.
| The lawful basis for processing aggregated and anonymized data is legitimate interests and the fact that this data is no longer considered personal data. |
k) | Other Purposes: In addition to the purposes listed above, we may use your personal information for other legitimate purposes, provided that they are compatible with the original reasons for which your data was collected.
| For these other purposes, we will rely on legitimate interests or other lawful bases as required by applicable laws. |
We will not use information received through your use of the Apple HealthKit or Google Health Connect framework for advertising or similar services, or sell it to advertising platforms, data brokers, or information resellers.
7. How do we process your personal data?
We process your personal data by automated means, including in information and telecommunication networks and/or without them.
We process your data by means of collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, including cross-border transfer, alignment or combination, restriction, pseudonymization, anonymization, erasure or destruction. We may also employ other means of processing allowed by the applicable law of your country.
8. Combined Data
We may combine your personal data, including account data, other data provided by you, device data, cookies, location data, data collected during your interactions with amma and/or using digital channels, such as social media, websites, e-mails, apps and connected products, IP address, cookies, device information, communications you click on or tap, location details and websites you visit.
The combined data is analyzed and used to provide you with services such as to give you insights into your pregnancy, your well-being, and your baby's development, and to provide you with personalized content, messages, and tips, and help us improve the content, functionality, and usability of the Application and our services, as well as to develop new products and services. You may opt out and unsubscribe from our communications at any time by writing to help@amma.family.
9. Data Sharing
We will not share your personal information with third parties unless we have a lawful basis to do so, as set forth below. Where the lawful basis for sharing is your consent, giving consent to the processing of your personal data in the manner described in the Privacy Policy hereinbefore, you confirm that you are aware of and agree that your personal data may be transferred, including cross-border transfer, to the categories of recipients listed below for the purposes set forth herein and in the privacy policies of such companies.
We may share your personal information with the following categories of recipients:
- Service Providers: We may share your personal information with third-party service providers who assist us in delivering our products and services. These service providers include hosting providers, automation software providers, payment processors, or customer relationship management tools, analytical services, etc. We will only share the necessary data to fulfill their specific tasks and will have contracts or agreements in place to ensure they process your data securely. The lawful basis for sharing data with service providers is typically the necessity for the performance of a contract or, in some cases, legitimate interests, provided that these interests are not overridden by your data protection rights. Please refer to annex 1 for the list of service providers that we share your personal information with.
- Business Partners and Affiliates: In some cases, we may share personal information with our business (advertising) partners and affiliates, but only when it is necessary for the performance of a contract, the provision of services, or as part of a legitimate business interest, or based on your consent. For example, we may share data with a partner organization involved in co-branded events or services. Sharing data with business (advertising) partners and affiliates may be necessary for the performance of a contract, or based on your consent or legitimate interests, especially when these partnerships are essential for delivering integrated or co-branded services.
- Authorities: We may be required to share personal information with authorities, regulatory bodies, or law enforcement agencies when necessary to comply with legal obligations or respond to valid requests for information, as permitted by the law. The lawful basis for sharing with legal authorities is the necessity to comply with a legal obligation.
- Merger or Acquisition: In the event of a merger, acquisition, or sale of all or part of our business, the sharing of personal information with the acquiring entity or parties involved in the transaction may be based on legitimate interests, as it's necessary for the legitimate interests pursued by us or the acquiring entity. We will ensure that your data remains protected and used in accordance with this Privacy Policy.
- Publicly Available Information: We may share personal information that is publicly available, such as information from public records or online sources, or the information that you publish in the App. However, we will do so only when it is relevant to the purposes for which your data was collected and used. Sharing publicly available personal information is typically based on legitimate interests, as it is in the legitimate interests of our business to use publicly available data for relevant purposes.
- With Your Consent: We may share your personal information with third parties if you have provided your explicit consent for such sharing. We will always request your consent before sharing your data for specific purposes. If you have provided explicit consent for sharing your personal information with specific third parties, the lawful basis for sharing is your consent.
- Other Legitimate Business Interests: In certain cases, we may share personal information with other parties for legitimate business interests. The sharing of this personal information may be based on legitimate interests. We will always ensure that such sharing is conducted in accordance with applicable data protection laws and respect your rights.
Often the information that we communicate to recipients will be encrypted, anonymized, or pseudo-anonymized, so that the third party will receive information to which technical measures have been applied aimed at hiding, masking, or dissociating your personal data, using for this purpose a unique identifier that does not reveal your real identity, but this may not always be the case.
10. Data Subject Rights
As a data subject, we will provide you with the following rights:
- Right to Access
You have the right to request access to your personal data that we process. This means you can ask us to provide you with information about what personal data we hold about you and how we use it.
- Right to Rectification
You can request the correction or updating of your personal data if it is inaccurate or incomplete. We will make the necessary changes and inform any third parties to whom we have disclosed the data.
- Right to Erasure (Right to Be Forgotten)
You can request the deletion of your personal data under certain circumstances. This right is not absolute and can be exercised if the data is no longer necessary, you withdraw consent, or the data processing is unlawful.
- Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data under specific circumstances. This means we will limit the way we use your data but not delete it entirely. This right might be exercised when you contest the accuracy of the data, the processing is unlawful, or you need the data for legal claims.
- Right to Data Portability
You can request a copy of your personal data in a structured, commonly used, machine-readable format, or you can ask us to transmit it directly to another data controller where technically feasible. This right is applicable when processing is based on consent or the performance of a contract.
- Right to Object
You have the right to object to the processing of your personal data, including processing based on legitimate interests or for direct marketing purposes. We will stop processing your data for such purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Automated Decision-Making and Profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which has legal or significant effects on you. You may request human intervention in the decision-making process. We will inform you when such decisions are made, provide you with the opportunity to express your point of view, and ensure there are human interventions available.
- Withdraw Consent
If we process your personal data based on your consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
If you would like to exercise your right and submit a request thereto, including a request to access, rectify, erase, restrict, or object to the processing of personal data that you have previously provided to us, or if you would like to withdraw your consent, or submit a request to receive an electronic copy of your personal data for purposes of transmitting it to another company (to the extent this right to data portability is provided to you by applicable law), you may contact us at help@amma.family. In your request, please make clear what personal data you would like to access, rectify, erase, restrict, or object to its processing, etc. We will respond to your request consistent with applicable law.
Please note that any requests submitted by data subjects will be assessed for validity before being processed, including confirming the identity of the data subject. For your protection, we may only implement requests with respect to the personal data associated with your account, your email address, or other account information that you use to send us your request, and we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.
Please note that if you make use of (some of) the above choices and rights, you may not be able to use, in whole or in part, our services anymore. In certain circumstances, we will not be able to delete your personal data without also deleting your user account.
Please note that in certain circumstances it may be necessary to retain some of your personal data after you request its deletion, to satisfy our legal or contractual obligations, or to meet business needs (as long as it is permitted by applicable law).
11. Data Security
We implement and maintain reasonable and appropriate technical and organizational measures to protect the security of your personal information from accidental or unlawful destruction, loss, alteration, misuse, unauthorized disclosure, or access. This section outlines our practices and policies in line with the GDPR to safeguard your information.
Technical Measures
- Security protocols: our security protocols are aligned to Service Organization Control 2 (SOC 2) Type II standards and are regularly assessed by third-party auditors and customers. Qualys Grade A compliance report of amma's data in transit.
- Encryption: We use encryption protocols such as SSL/TLS to protect data transmitted over the internet. Data stored on our servers is encrypted to prevent unauthorized access.
- Access Controls: Access to personal data is restricted to authorized personnel only. We utilize role-based access controls and ensure that access rights are regularly reviewed and updated.
- Secure Storage: Personal data is stored on secure servers protected by firewalls, antivirus software, and other advanced security technologies.
- Data Minimization: We collect and process only the personal data necessary for the purposes specified in our privacy policy herein.
Organizational Measures
- Employee Training: All employees undergo regular training on data protection and information security practices to ensure they understand their responsibilities in safeguarding personal data.
- Data Protection Officer: We have appointed a Data Protection Officer (DPO) who oversees our data protection strategy and ensures compliance with GDPR requirements.
- Incident Response Plan: We have established procedures for managing data breaches, including prompt notification to affected individuals and relevant authorities in accordance with GDPR requirements.
Regular Audits and Monitoring
- Security Audits: We conduct regular security audits and assessments to identify and address potential vulnerabilities in our systems.
- Continuous Monitoring: Our security team continuously monitors our systems for unusual activity and potential threats to ensure timely detection and mitigation of security risks.
While we implement these security measures to protect your data, it is important to understand that no online platform can guarantee absolute security. Therefore, we encourage you to take necessary, best-practice security precautions such as strong, unique passwords and being cautious with the sharing of login credentials.
In the event of a data breach or security incident, we will take immediate action to isolate and resolve the incident based on our incident response resolution procedures, notify relevant authorities, and inform affected data subjects in compliance with applicable data protection laws.
We continually strive to improve our security measures to protect your personal data and comply with GDPR requirements. If you have any questions or concerns about our data security practices, please contact our Data Protection Officer at bshkolnikov@amma.family
12. Cookies and Tracking Technology
We may use “cookies” (or similar tracking technology) on our websites. Cookies are text files that our web server may play on your hard disk to store your preferences. When you visit our website, you will be presented with a cookie banner or pop-up requesting your consent to use non-essential cookies, if any. You have the right to accept or decline the use of such cookies. Your consent can be managed and changed at any time through your device or browser settings.
Cookies, by themselves, do not provide us with any personal data unless you explicitly choose and consent to provide this information to us. Once you choose and consent to provide personal data, however, this information may be linked to the data stored in the cookie. If you choose to turn off a collection of cookies through your device or browser, certain features of our service may not function properly without the aid of cookies.
Our websites may also incorporate third-party cookies and tracking technologies. These technologies are subject to the privacy policies and practices of the respective third parties. We encourage you to review the privacy policies of these third parties for information on how they collect and use your personal data.
13. Children
Various jurisdictions have different approaches to defining a minor (e.g., under GDPR minor is anyone under the age of 16). In situations where personal data from minors is needed for data processing activities, we will obtain authorization from an appropriate parent or guardian. If such authorization is unable to be obtained, data processing activities for that data subject will be terminated. In the event that we discover that a minor has provided personal data to us, we will make efforts to delete the information as soon as possible. If you have concerns about our website or service offering, wish to find out if your child has accessed our services, or wish to remove your child’s personal data from our servers, please contact us at help@amma.family.
14. European Data Protection Rights
If the processing of personal data about you is subject to the European Union (EU) data protection law, you have certain rights with respect to that data. Please refer to section “10. Data Subject Rights” above for a listing of these rights.
Additionally, our processing of your personal data is based on specific legal bases as defined in EU data protection law. Please refer to section “6. Why we process your data and lawful basis for processing” and section “9. Data Sharing” above for a listing of these legal bases.
As we do not have an establishment in the European Union (“EU”), we have appointed a representative based in Spain, who you may address if you are located in the EU to raise any issues or queries you may have relating to our processing of your Personal Data and/or to this Policy. Our EU representative is: Mr. Stanislav Prodan, located at: Spain, Barcelona, 08019 Carrer de Fluviá, 97, piso 14, app 6. Our EU representative can be contacted directly by emailing them at the following address: sprodan@amma.family.
11. Cross-border transfer
We may transfer your personal data to countries other than the country in which the data was originally collected in order to provide you with our services (including the App) and for purposes indicated in this Privacy Policy. If these countries do not have the same data protection laws as the country in which you initially provided the information, we deploy special safeguards.
In particular, where we transfer your personal information from the EEA to recipients located outside the EEA who are not in a jurisdiction that has been formally designated by the European Commission as providing an adequate level of protection for information, we do so on the basis of standard contractual clauses aopted by the European Commission.
For further information, please email us at help@amma.family.
- How long do we keep your data?
We will retain your personal data for as long as needed or permissible to achieve the purpose(s) for which the data is collected. The criteria we use to determine our retention periods include: (i) the length of time you use our products and services; (ii) whether there is a legal obligation to which we are subject; or (iii) whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).
You should be aware that although we will delete, anonymize, or otherwise de-identify your data where possible, we may retain certain personal data and other information after your account has been terminated or deleted. This is as required and permitted by applicable law, like the GDPR, and will include the following circumstances:
- as necessary to comply with legal obligations;
- establishment, exercise, or defense of legal claims; and
- for archiving purposes in the public interest, scientific or historical research, or statistical purposes.
- Updates to this Privacy Policy
We periodically review this Privacy Policy and may make updates to reflect changes in our practices, for legal reasons, or to meet new regulatory requirements. Your continued use of our services following any notice of changes to this Privacy Policy means you accept such changes. Please refer to the “Effective Date” above for details on when this Privacy Policy was last updated.
- Contact Us
If you have any questions, concerns, or requests regarding your personal data or this Policy, please contact us at help@amma.family or AMMA FAMILY MX, S. de R. L. de C.V., business (registered) address: 03810, calle Montecito, 38, piso 24, numero 28, col. Nápoles, Benito Juarez, Ciudad de Mexico. Alternatively, you have the right to lodge a complaint with a supervisory authority competent for your country or region.
For specific requests relating to your rights as a data subject including the rights noted in section “10. Data Subject Rights” noted above, please write to help@amma.family or contact our Data Protection Officer (DPO) directly at bshkolnikov@amma.family.
- Provisions applicable to specific countries
The Annexes to this Privacy Policy contain provisions regarding the processing of personal data in accordance with the laws of specific countries. If there is any conflict between the provisions of this Privacy Policy and annexes 2, the provisions of the Annex shall prevail in relation to the specific country. To find the Annex that applies to you just find your country in the Index below.
In addition, be aware that for some countries and operating system types the functionality of the Application may be not available to you without creating your personal account in the Application, while for other countries and operating system types you may use the limited functionality of the Application without creating your personal account, but, in order to be able to use the full functionality of the Application (e.g., to save personal information in the account, to make comments, to like comments, etc.), you need to create your personal account and log into the Application using it.
Annexes:
- List of service providers with whom amma shares your personal data and the purposes of sharing
- Special terms for users from specific jurisdictions:
2-USA – for the United States of America.
2-Mexico – for the United Mexican States, Bolivia, Ecuador, Peru, Colombia
2-MENA – for the Middle East and North Africa.
2-France– for France.
Annex 1
List of service providers with whom amma shares your personal data and the purposes of sharing
In pursuance of clause 9 "data sharing" a) “Service Providers” of this Privacy Policy, we may share your personal data with the following service providers who help us operate, provide, improve, understand, customize, support our products and services (including the App) and market our services for the purposes stated below.
Please read their privacy policies carefully because they contain information on the privacy regulations that these companies use including how they use, process, and protect personal data. Where the legal basis for sharing is your consent, giving consent to the processing of your personal data in the manner described in this Privacy Policy hereinbefore, you confirm that you are aware of and agree that your personal data may be transferred, including cross-border transfer, to the companies listed below for the purposes set forth herein and in the privacy policies of such companies.
The list of service providers below is non-exhaustive. We may also share your personal information with other service providers. The lawful basis for sharing data with service providers is typically the necessity for the performance of a contract or, in some cases, legitimate interests, provided that these interests are not overridden by your data protection rights.
Where the legal basis for sharing is your consent, you may withdraw your consent to processing your data by such companies at any time by means of sending a corresponding request to help@amma.family.
Service Provider | Type of the service provider | name of the legal entity of the processor, country of incorporation | privacy policy |
Intercom | customer support | Intercom R&D Unlimited Company (Ireland); Intercom, Inc. (USA); Intercom Software UK Limited (UK); Intercom Software Australia Pty Ltd (Australia), and Intercom's group companies | |
AsoDesk | customer support | ASODESK CY LTD (Cyprus) | |
Storyly | content / feature | The Farm Soho, 447 Broadway, 2nd & 3rd Floor, New York, NY 10013 New York | |
BigQuery (Google Cloud Platform) | push messages / emails | Google LLC (USA), Google Asia Pacific Pte. Ltd. and Google`s group companies | |
SendGrid | push messages / emails | Twilio Inc. (USA) | https://www.twilio.com/en-us/legal/privacy |
Adapty | analytics + settings | Adapty Tech Inc. (USA) | |
AppsFlyer | analytics + settings | AppsFlyer Ltd (israel) and AppsfLyer`s group companies | |
Firebase | analytics + settings | Google LLC (USA), Google Asia Pacific Pte. Ltd. and Google`s group companies | https://firebase.google.com/support/privacy, https://policies.google.com/privacy |
Mixpanel | analytics | Mixpanel, Inc. (USA) and Mixpanel`s group companies | |
Meta Pixel - Event Manager | analytics | Meta Platforms, Inc. (USA) and Meta`s group companies | |
ClickHouse (on Amazon Web Services (AWS)) | analytics | ClickHouse, Inc. (USA) and its group companies | |
Azure Files | tools | Microsoft Ireland Operations Limited (Ireland) and its group companies | |
EmailListVerify | Tools (email verification) | CyberPanda, s.r.o. (Slovakia) | |
Brite Verify | Tools (email verification) | Validity, Inc. (USA) and its group companies | |
Mindbox USA, LLC (Maestra) | email campaigns | Mindbox USA, LLC (USA) and its group companies | |
Maestra (Mindbox) | email campaigns | Mindbox USA, LLC (USA) and its group companies | |
Google Ad manager (GAM) | in-app advertising | Google LLC (USA), Google Asia Pacific Pte. Ltd. and Google`s group companies | https://policies.google.com/privacy. https://policies.google.com/technologies/partner-sites |
AdMob | in-app advertising | Google LLC (USA), Google Asia Pacific Pte. Ltd. and Google`s group companies | |
MAX (Applovin) | in-app advertising | AppLovin Corporation (USA) and its group companies | |
Facebook Ads | in-app advertising | Meta Platforms, Inc. (USA) and its group companies | |
Facebook (incl. Instagram) | direct advertising campaigns | Meta Platforms, Inc. (USA) and its group companies | |
DV360/GoogleAds (incl. YouTube) | direct advertising campaigns | Google LLC (USA), Google Asia Pacific Pte. Ltd. and Google`s group companies | |
TikTok | direct advertising campaigns | TikTok Pte. Ltd. (Singapore) and its group companies | |
ChatGPT | content / feature | OpenAI Ireland Limited (Ireland), OpenAI OpCo, LLC (USA) and their group companies | https://openai.com/policies/privacy-policy/, https://openai.com/policies/eu-privacy-policy/ |
Microsoft Azure | Data hosting | Microsoft Ireland Operations Limited (Ireland) and its group companies | https://privacy.microsoft.com/en-us/privacystatement, https://azure.microsoft.com/en-us/support/legal/ |
Annex 2-USA
Special terms for users from the United States of America
Local specific information: California
We do not sell your information for monetary gain.
Under the laws of California, when we disclose personal information to a third party for any benefit, this can be considered a “sale” or “share” of personal information, even if such third party does not use the personal information for any other purpose. We “share” personal information if we disclose personal information to a third party for purposes of cross-context behavioral advertising.
Request to Do Not Track/Opt-Out: Amma does not sell your personal information. You can opt out of sharing your personal information with our analytics and advertising partners. This includes opting out of “sale” and “Do Not Track” requirements.
Do Not Track is a web browsing setting that adds a signal to your browser header that tells other websites that you do not want their tracking cookies. Amma currently does not respond to such signals in browsers. To exercise this right you can contact us at help@amma.family.
Request to know/access: In addition to the other rights mentioned in this policy, you have the right to request to know (i) the personal and sensitive information we have collected about you and our purposes of use; and (ii) the categories, sources, and third parties involved in personal information we have collected about you or “sold” or disclosed in the past 12 months. You may exercise your right to request to know twice a year, free of charge.
Shine the Light: California Civil Code Section 1798.83 permits our customers who are California residents to request and obtain from us once a year, free of charge, information about the personal information (if any) we have disclosed to third parties for direct marketing purposes in the preceding calendar year. If applicable, this information would include a list of the categories of personal information that was shared and the names and addresses of all third parties with which we shared information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please contact us at help@amma.family.
References to “personal data” in this Privacy Policy include “sensitive/personal information” as defined under California laws.
Local specific information: Texas Sensitive Data Notice
NOTICE: We may sell your sensitive personal data, as defined under and in accordance with Texas law.
Annex 2-Mexico, Bolivia, Ecuador, Peru, Colombia
Special terms for users from the United Mexican States, Bolivia, Ecuador, Peru, Colombia
Advertising partners who we share your personal information with
In pursuance of clause 6 g) and clause 9 b) of this Privacy Policy, Amma may cooperate with advertising partners (Ad Partners) who may process your personal data for their own purposes. By accepting this Privacy Policy, you give amma your consent to transfer your personal data (e.g. name, e-mail, due date/baby`s birthdate, and text and timestamp of consent) to the third parties for the purposes set out in their privacy policies, and you also confirm that you have read carefully and agreed with their privacy policies, where they disclose their privacy practices that they will use once they receive your transferred data, including the type of personal data they collect, how they use, process and protect it. Althernatively, this processing may be based on legitimate interests or the performance of a contract, if applicable. We always verify that our legitimate interests do not outweigh your privacy rights and interests.
Below we've listed such advertising partners we're transferring your data to for the purposes set out in their privacy policies. E.g., such Ad Partners could show you targeted advertising and provide you with commercial information, personalized offers, promotions of products and/or services marketed under the brands of such Ad Partners.
№ | name of the legal entity | Address | Privacy Policy | Contacts | Comments | Applicable to users from the following countries |
1 | MARCAS NESTLÉ, S.A. DE C.V., an entity organized under the laws of Mexico | Boulevard Miguel de Cervantes Saavedra N. 301 | Una vez usted de clic en “Deseo compartir mis datos con Nestlé para recibir información y ofertas de Nestlé” transferiremos sus datos personales como son su nombre, apellido (opcional), correo electrónico y fecha nacimiento su bebé, fecha de registro en la app, a Marcas Nestlé, S.A. de C.V., con el objeto de que sea registrado en su base de datos de consumidores y le haga llegar información comercial, ofertas, promociones de productos y/o servicios comercializados bajo las marcas de Nestlé. Importante menciona, que Nestlé en su momento le hará llegar su propio aviso de privacidad en donde podrá conocer las medidas de seguridad bajo las cuales se estarán tratando sus datos personales.
| the United Mexican States | ||
2 | Colgate Palmolive Compañia, Número de Identificación Tributaria (NIT): 890300546-6 | Dirección: Apartado Aéreo 2324, Cra 1, N° 40-180, Cali-Colombia | n/a | Bolivia, Ecuador, Peru, Colombia |
You can oppose, from this moment, the processing of your personal data for the aforementioned secondary purposes by sending an email to help@amma.family.
The refusal to use your personal data for these purposes may not be a reason for us to deny you the services and products you request from us.
How can you access, rectify or cancel your personal data, or oppose its use, or revoke your consent for the processing of your personal data?
You have the right to know what personal data we have about you, what we use them for, and the conditions of use we give them (Access). Likewise, it is your right to request the correction of your personal information in case it is outdated, inaccurate, or incomplete (Rectification); that we remove it from our records or databases when it considers that it is not being used in accordance with the principles, duties and obligations provided for in the regulations (Cancellation); as well as oppose the use of your personal data for specific purposes (Opposition). These rights are known as ARCO rights.
You can revoke the consent that, if applicable, you have given us for the processing of your personal data.
You or your legal representative may exercise any of the rights of access, rectification, cancellation or opposition (hereinafter "ARCO Rights"), as well as revoke your consent for the processing of your personal data by sending an e-mail to the address help@amma.family. We will provide you with an ARCO Rights Request Form to attend to your request in a timely manner.
It is necessary that you complete all the fields indicated in the ARCO Rights Request Form and accompany it with a copy of your valid official identification.
In order for your request to be followed up, you or your legal representative must correctly prove your identity, for which it is necessary to confirm the ownership of the e-mail you inserted in the Sites, as well as to attach a copy of any valid official identification.
In the event that the information provided is erroneous, insufficient, or it is not possible to prove your identity, within five (5) business days following receipt of your application form, you may be required to provide the missing information. You will have ten (10) business days to meet the request, counted from the day after you received it. If you do not respond within that period, the corresponding request will be deemed not submitted.
You will be notified of the decision made, within a maximum period of twenty (20) business days from the date on which the request was received, so that, if appropriate, it can be made effective within fifteen (15) business days after the answer is communicated. The answer will be given electronically to the e-mail address you used to register on the website. The aforementioned time periods may be extended a single time by a period of equal length, provided that such action is justified by the circumstances of the case.
In case you revoke your consent for the processing of your personal data as said above, it is important that you bear in mind that not in all cases we will be able to attend to your request or terminate the use immediately, since it is possible that due to some legal obligation, we may require to continue processing your personal data. Likewise, you must consider that for certain purposes, the revocation of your consent will imply that we cannot continue providing the service you requested, or the conclusion of your relationship with us.
You may withdraw your consent to processing your data by our Advertising Partners at any time by means of sending a corresponding request to them.
You may also opt out of receiving any or all of communications from us or our Advertising Partners by following the unsubscribe link or the instructions provided in any e-mail you gained from us or our Advertising Partners.
You may withdraw your consent at any time, without affecting the lawfulness of processing based on consent before withdrawing your consent.
How can you limit the use or disclosure of your personal information?
If applicable, you may limit the use or disclosure of your personal data by sending the corresponding request to the e-mail address help@amma.family.
Annex 2-MENA
Special terms for users from the Middle East and North Africa
Advertising partners who we share your personal information with
In pursuance of clause 6 g) and clause 9 b) of this Privacy Policy, Amma may cooperate with advertising partners (Ad Partners) who may process your personal data for their own purposes. By accepting this Privacy Policy, you give amma your consent to transfer your personal data (e.g. name, e-mail, due date/baby`s birthdate, and text and timestamp of consent) to the third parties for the purposes set out in their privacy policies, and you also confirm that you have read carefully and agreed with their privacy policies, where they disclose their privacy practices that they will use once they receive your transferred data, including the type of personal data they collect, how they use, process and protect it. Althernatively, this processing may be based on legitimate interests or the performance of a contract, if applicable. We always verify that our legitimate interests do not outweigh your privacy rights and interests.
Below we've listed such advertising partners we're transferring your data to for the purposes set out in their privacy policies. E.g., such Ad Partners could show you targeted advertising and provide you with commercial information, personalized offers, promotions of products and/or services marketed under the brands of such Ad Partners.
№ | name of the legal entity | Address | Privacy Policy | Contacts |
1 | Nestlé Middle East FZE | P.O. BOX : 17327 JEBEL ALI FREE ZONE DUBAI - UNITED ARAB EMIRATES | https://www.nestle-mena.com/en/info/yourdata | You can contact us via email at: ask@nestle-family.com or post: P.O. Box 17327 Jebel Ali Free Zone – Dubai, United Arab Emirates. |
You can oppose, from this moment, the processing of your personal data for the aforementioned secondary purposes by sending an email to help@amma.family.
The refusal to use your personal data for these purposes may not be a reason for us to deny you the services and products you request from us.
Annex 2-France
Special terms for users from France
Advertising partners who we share your personal information with
In pursuance of clause 6 g) and clause 9 b) of this Privacy Policy, Amma may cooperate with advertising partners (Ad Partners) who may process your personal data for their own purposes. By accepting this Privacy Policy, you give amma your consent to transfer your personal data (e.g. name, e-mail, due date/baby`s birthdate, and text and timestamp of consent) to the third parties for the purposes set out in their privacy policies, and you also confirm that you have read carefully and agreed with their privacy policies, where they disclose their privacy practices that they will use once they receive your transferred data, including the type of personal data they collect, how they use, process and protect it. Althernatively, this processing may be based on legitimate interests or the performance of a contract, if applicable. We always verify that our legitimate interests do not outweigh your privacy rights and interests.
Below we've listed such advertising partners we're transferring your data to for the purposes set out in their privacy policies. E.g., such Ad Partners could show you targeted advertising and provide you with commercial information, personalized offers, promotions of products and/or services marketed under the brands of such Ad Partners.
№ | name of the legal entity | Address | Privacy Policy | Contacts |
1 | LABORATOIRES GUIGOZ, an entity organised under the laws of France, registered in the Nanterre Trade and Companies Register under number 552 120 875 | 34-40 rue Guynemer, 92130 Issy-les-Moulineaux |
|
You can oppose, from this moment, the processing of your personal data for the aforementioned secondary purposes by sending an email to help@amma.family.
The refusal to use your personal data for these purposes may not be a reason for us to deny you the services and products you request from us.