DRAFT — pending legal review. Not a final legal document. This document is missing legally required trader identification.
This Privacy Policy explains what personal data we collect through the SafeguardMDM platform, why we process it, the legal bases we rely on, how long we keep it, who we share it with, and the rights you have. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679).
1. Controller, DPO and supervisory authority
The controller of the personal data described here is:
- Company: [PLACEHOLDER — registered company name + legal form]
- Registered office: [PLACEHOLDER — registered office, full postal address]
- Company register: [PLACEHOLDER — Registro delle Imprese office + REA number]
- VAT number: [PLACEHOLDER — P. IVA]
- Share capital: [PLACEHOLDER — share capital, if the legal form requires it]
We have designated a Data Protection Officer, who you can contact about anything in this policy or about how we handle your data: [PLACEHOLDER — DPO name; contact is dpo@safeguardmdm.it], dpo@safeguardmdm.it. For requests to exercise your rights, use privacy@safeguardmdm.it.
Our lead supervisory authority is the Garante per la protezione dei dati personali, because our establishment is in Italy.
2. Data we collect
2.1 Account data
- Email address and display name
- Account type (parent, caregiver or administrator)
- Authentication credentials, stored only as a secure hash
- Verification tier and, where you use it, identity-verification data
Identity verification (KYC) is optional and unlocks advanced monitoring features. If you choose to verify, you submit a government-issued identity document and, for full verification, a matching selfie. The check is performed by Stripe Identity; Stripe returns the result and extracted fields such as name and date of birth. We keep a copy of the images you submitted so a verification can be inspected if it is later disputed or subject to a fraud-prevention or regulatory enquiry.
2.2 Monitoring data from enrolled devices
Data | Description | Retention
- Location | GPS coordinates, at configurable intervals | 30 days
- App usage | App names, usage duration, open/close timestamps | 90 days (configurable)
- Screen time | Daily screen-on duration, session logs | 90 days (configurable)
- Browsing history | URLs visited, blocked-site attempts | 30 days
- Screenshots | Periodic screen captures for activity review (full verification only, opt-in) | 7 days, up to 90 if flagged for review
- Safety photos | Images captured during an SOS/emergency or an elder visual check-in | 72 hours
- Audio | Analysed on the device for safety keywords only — never recorded, stored or transmitted | Not stored
- Device metadata | Battery level, network status, OS version, device model | 90 days
- Notifications | Notification content from allowed apps (opt-in) | 90 days
- Keyboard input | Text typed across apps for keyword flagging, redacted of card, CVV, national-ID and email patterns (full verification only, opt-in) | 90 days
- Call logs | Call history — numbers, duration, timestamps, never audio content (full verification only, opt-in) | 90 days
- Contacts | Contact names and numbers for safety scoring (full verification only, opt-in) | Communication records 90 days; approved-contact data up to 365 days
- Gallery items | Photo and video metadata with AI content classification (opt-in) | 90 days
- Social and messaging activity | Usage patterns and flagged content, including message keyword flags (opt-in) | 90 days
2.3 Communication data
Where messaging between parent and child devices is enabled, we store message content in order to deliver it. Messages are encrypted in transit and at rest.
2.4 Abuse reports
Abuse reports are stored in an isolated, access-restricted collection. This data is never visible to the account holder concerned and is accessible only to authorised abuse-review administrators.
3. Why we process data, and on what legal basis
We rely on the following legal bases under Article 6(1) GDPR:
Purpose | Legal basis
- Creating and running your account; delivering the monitoring features you configure; billing | Article 6(1)(b) — performance of the contract you entered into
- Processing personal data of a monitored child or dependant on the account holder's instruction | Article 6(1)(f) — legitimate interests of the parent or caregiver in the safety of a person in their care, balanced against that person's rights. The monitored person is always informed that monitoring is active
- Optional monitoring features you switch on individually (keyboard, call logs, contacts, gallery, social, screenshots, notifications) | Article 6(1)(a) — your consent, which you can withdraw at any time in the dashboard
- Identity verification (KYC) | Article 6(1)(c) and 6(1)(f) — legal obligation and our legitimate interest in preventing the platform being used to monitor people unlawfully
- Detecting, reviewing and acting on abuse reports | Article 6(1)(f) — the compelling legitimate interest of protecting a person who may be at risk, and Article 6(1)(c) where we must act
- Security, fraud prevention, service integrity and diagnostics | Article 6(1)(f) — our legitimate interest in a secure and working service
- Retaining billing and tax records | Article 6(1)(c) — legal obligation
- Sending service and safety notifications | Article 6(1)(b) — necessary to deliver the Service you asked for
Where we rely on legitimate interests, we have carried out a balancing assessment and you may object to that processing at any time (see section 12). Where we rely on consent, withdrawing it is as easy as giving it and does not affect processing carried out before withdrawal.
4. Special categories of data
Some data the Service can process falls within Article 9 GDPR — data revealing health, and biometric data used to identify a person:
- Elder-care features may process health-related information such as medication reminders and appointments
- Where facial recognition is used to confirm a check-in, the resulting facial template is biometric data
- Content flagged by safety classification may incidentally reveal health, sexual-orientation or similar information
We process this data only on the basis of the explicit consent of the data subject or their legal representative under Article 9(2)(a), or where processing is necessary to protect the vital interests of a person who is physically or legally incapable of giving consent under Article 9(2)(c). Explicit consent is collected separately from the general terms and can be withdrawn at any time.
5. Children's data
The Service is installed on a child's device by their parent or guardian. We do not offer the Service directly to children and children cannot open an account.
Where the Service is provided to a child and consent is the legal basis, that consent is given or authorised by the holder of parental responsibility, in line with Article 8 GDPR. In Italy the age threshold below which parental authorisation is required is 14; other Member States set it between 13 and 16 and we apply the threshold of the child's country of residence.
- The child's device shows a persistent notification that monitoring is active
- The child has access to an abuse-reporting route that the account holder cannot see or reach
- We never use a child's data for advertising, marketing, or profiling for commercial purposes
- Information addressed to a child is written in clear and plain language
6. People who are not our users
Monitoring can capture the personal data of third parties who never interacted with us — for example the other party to a call, a message or a photograph. We did not obtain this data from them, so Article 14 GDPR applies: the categories of data are those listed in section 2.2, the source is the monitored device, and the legal basis is the legitimate interest set out in section 3. We minimise this data where we can, never use it to build a profile of the third party, and apply the same retention limits. If you are such a person and want to exercise your rights, contact privacy@safeguardmdm.it.
7. How data is stored
- All data is stored in Google Firebase (Firestore and Firebase Storage) in the European Union (europe-west1)
- Data in transit is protected with TLS 1.2 or higher
- Data at rest is encrypted with AES-256 using Google Cloud's platform-managed server-side encryption
- A number of especially sensitive fields — keyboard text, call numbers and contact names, contact identifiers, facial templates, and abuse-report contents — are additionally encrypted by us at the field level before storage, with abuse reports held under a separate key
- Firestore security rules enforce role-based access; an account holder can only reach data for devices enrolled to their own account
- Abuse reports are held in a separate collection with dedicated rules that block access by ordinary users, including the account holder concerned
8. Who has access
- Account holder (parent or caregiver): monitoring data for their own enrolled devices only
- Monitored individuals: can see that monitoring is active; cannot reach the collected data
- Our administrators: access limited to abuse review, technical support and system maintenance, and logged
- Lawful authorities: only in response to valid legal process, and we tell the person concerned unless the law forbids it
- We never sell or rent personal data, and we never share it with third parties for their own marketing
9. Processors and international transfers
We use a small number of processors to run the Service. The current list, what each one does and where it processes data, is published separately in the Sub-processor List.
Our primary storage and processing takes place in the European Union. Some processors — notably for push notification delivery, SMS, payment and identity verification, and some AI classification calls — may process data in the United States. Those transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Article 45 GDPR) where the recipient is certified, and on Standard Contractual Clauses adopted by the Commission (Article 46(2)(c) GDPR) as a fallback. We keep the fallback in place because the adequacy decision is under appeal before the Court of Justice (Case C-703/25 P). You can obtain a copy of the safeguards by writing to dpo@safeguardmdm.it.
10. How long we keep data
- Safety photos are deleted after 72 hours; screenshots after 7 days, or up to 90 days if flagged for review. Audio is never recorded
- Location data is kept for 30 days; app usage and most other monitoring data for 90 days
- Identity-verification images are kept for 90 days for fraud prevention and to answer regulator or law-enforcement enquiries, then deleted automatically. Stripe separately keeps the verification result under its own policy
- Account data is kept until the account is deleted; on deletion, associated monitoring data is permanently removed within 30 days
- Abuse-report records may be kept for up to 3 years to meet legal obligations
- Billing and tax records are kept for the period required by tax law
11. Automated processing and AI
The Service uses automated classification to flag potentially harmful content and to score risk — for example detecting bullying, grooming, self-harm or scam patterns in messages, images or browsing activity. This is a form of profiling.
- These systems generate alerts for the account holder. They do not make decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22(1) GDPR, and they never take enforcement action on a device by themselves
- The logic involved is pattern and content classification, using both rule-based matching and machine-learning models; the significance is that a parent or caregiver may be alerted and may then act
- Classification results can be wrong. An alert is not a finding of fact
- Account suspension following an abuse report is always reviewed by a trained human before it takes effect
- You can object to profiling based on legitimate interests, and can switch off the optional monitoring features that feed it
12. Your rights
You have the following rights over your personal data:
- Access — obtain confirmation of whether we process your data and a copy of it (Article 15)
- Rectification — have inaccurate data corrected (Article 16)
- Erasure — have your data deleted where the grounds in Article 17 apply
- Restriction — have processing limited in the cases set out in Article 18
- Portability — receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible (Article 20)
- Object — object at any time to processing based on legitimate interests, on grounds relating to your situation (Article 21)
- Withdraw consent — at any time, without affecting processing already carried out (Article 7(3))
- Not be subject to a solely automated decision with legal or similarly significant effects (Article 22) — see section 11
Use the Export Data or Delete Account options in dashboard settings, or write to privacy@safeguardmdm.it. We answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising your rights is free unless a request is manifestly unfounded or excessive.
A monitored person can exercise these rights directly, including where the account holder is the person who enrolled their device. If you believe you are being monitored unlawfully, use the abuse-reporting route — it is isolated from the account holder and cannot be seen by them.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. Our lead authority is the Garante per la protezione dei dati personali (https://www.garanteprivacy.it/).
13. Elder-care data
- Monitoring an adult requires that adult's documented consent, or that of their legal representative, and the adult can withdraw it at any time
- Withdrawal stops monitoring; it does not disable emergency and SOS functions, which remain available for the person's own protection
- Elder-care data receives the same encryption and access controls as child monitoring data
- Health-related data is held with heightened access restrictions and is subject to section 4
- A caregiver can share limited access with a healthcare provider the elder has approved
14. Abuse-report isolation
When a monitored person submits an abuse report, that report is stored in a completely separate, isolated collection. The account holder concerned has no access to it. Reports are reviewed only by trained abuse-review administrators, and the reporter's identity is never disclosed to the account holder.
15. Cookies
The web dashboard uses only technical cookies and local storage necessary to sign you in and remember your preferences. Details, and how to manage your choices, are in the Cookie Policy.
16. Changes to this policy
We may update this policy. Material changes are communicated by email and by a prominent notice in the dashboard at least 30 days before they take effect. The Last Updated date above reflects the most recent revision, and previous versions are available on request.
17. Contact
- Data Protection Officer: dpo@safeguardmdm.it
- Rights requests: privacy@safeguardmdm.it
- General support: support@safeguardmdm.com
- Supervisory authority: Garante per la protezione dei dati personali
- Report abuse: Submit an abuse report