1. Controller and contact

The controller for data related to this website and contact with DOBIERO is:

  • JMSOFT Jarosław Maladyn
  • sole proprietorship
  • Polish tax ID: 6443323082
  • ul. Sielecka 24/48, 41-200 Sosnowiec, Poland
  • Contact and support email: support@dobiero.com

The controller has not appointed a Data Protection Officer. Privacy and support questions can be sent to the email address above.

2. Scope of this policy

This policy covers the public dobiero.com website, correspondence about DOBIERO, and the DOBIERO mobile app for Android and iPhone. The app is not yet available in app stores. This policy will be checked again against the exact signed artifacts before distribution.

3. How the app uses location

After you knowingly grant permission, DOBIERO may briefly use current precise location to check on your phone whether a nearby app or service may be useful. A geofence is only a signal for another local check, not proof of a visit.

  • place matching, ranking, and the reminder decision happen on the device
  • DOBIERO does not send precise location to its own server, advertisers, or analytics tools
  • DOBIERO does not create a history of coordinates, routes, or visits; the Release app does not store this data
  • the app creates no user account and contains no proprietary backend or telemetry
  • another app or store opens only after a deliberate user tap

4. Data that stays on the device

Only data needed for current operation may remain on the device:

  • permission state, settings, and muted items
  • one active visit context and the current suggestion
  • cooldowns and markers that prevent duplicates
  • a limited widget projection without coordinates, URLs, or installed-app information
  • one latest redacted diagnostic code without coordinates

Settings and muted items remain until changed, removed with “Delete local data,” or the app is uninstalled. The current snapshot expires no later than two hours after the last good reading, and cooldowns expire no later than seven days.

5. The dobiero.com website

The website has no accounts, forms, analytics cookies, advertising pixels, or tracking tools. It is delivered using Cloudflare Workers Static Assets. Cloudflare provides DNS, HTTPS, CDN, and network protection and may automatically process an IP address, request date and time, requested URL, browser type, and technical data needed to deliver the website and protect it from abuse.

This processing is based on the controller’s legitimate interest in providing the website securely and reliably (Article 6(1)(f) GDPR). The controller does not enable Cloudflare Web Analytics, raw HTTP request log retention, or Workers Logs. Cloudflare automatically creates aggregated operational metrics, such as request counts and response statuses, which may be available for up to three months. The controller does not use them to profile users.

6. Contact and service providers

If you contact us, the controller and Google Workspace process addressing data, message content, and attachments to deliver the message, respond, and handle the request. The legal basis is taking steps at your request or the controller’s legitimate interest (Article 6(1)(b) or (f) GDPR). Correspondence is deleted when no longer needed, taking account of legal obligations and limitation periods.

Cloudflare and its subprocessors provide the website, DNS, CDN, and security, while Google and its subprocessors provide Google Workspace email. They may process data globally, including outside the EEA, under the accepted Cloudflare DPA and Google CDPA. Transfers rely on an applicable adequacy decision or Standard Contractual Clauses.

Current subprocessor lists are published by Cloudflare and Google Workspace.

DOBIERO does not transfer precise location or visit history from the app to the controller.

7. Control and deletion

  • location and notification permissions can be revoked in phone settings
  • reminders can be disabled in the app
  • “Delete local data” removes DOBIERO’s private state, geofences, and current surfaces
  • the app has no server copy of local data

8. Your rights

For data actually processed by the controller, you may request access, rectification, erasure, restriction, portability, or object where applicable. Requests can be sent to support@dobiero.com or the controller’s postal address. We respond without undue delay, generally within one month.

You may also lodge a complaint with the President of the Polish Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.

9. Security and changes

The website uses HTTPS. The app limits stored state, contains no service credentials, and validates external links. We may update this policy when law, providers, or product behavior changes. Material changes will be announced on the website and, where possible and required, in the app.

10. Contact

support@dobiero.com